TrueCaller built a billion-dollar caller ID data empire in India
restofworld.org
restofworld.org
For a number of years it was quite common for folks in the lowest income brackets to change their phone numbers quite often because of rampant competition between mobile network providers. The "Mobile Number Portability" system was eventually introduced that minimized this to a large degree. Eventually the competition subsided and this reduced significantly to a point where it's not very common anymore per my understanding.
When I need to use Trucaller I use it via their web interface exclusively with a google account that has 0 contacts for them to steal. I remember finding my number listed many years ago as my name with (web developer) in parenthesis, likely stolen from some old customer of mine.
I asked if she knows they steal your contact list and spy on you and her answer was “so? It’s just phone numbers and names and they need to get the data somewhere as they are providing the service for free”
I live in a developed country and we have a high standard of living.
Giving this anecdote to illustrate many people genuinely don’t see TrueCaller’s spying as a big deal. This is unfortunate but it’s how things often are.
To them features/functionality/cost is first, and privacy is an afterthought. I see this view in a lot of people nowadays.
This is not a one-time sync, either. It will upload future new contacts and changes.
And, finally, if you manage to create a new account without a phone number, Instagram appears to flag your account for suspicious activity at some point and mandates that you do. They can then correspond your phone number with other users' contact lists to determine your identity. It can even suss out if you provided a Google Voice/VOIP number and require a "real" one instead.
Even everyone's much-loved Signal does this. Contacts sync is presented as "not now" or "yes forever." The "not now" message even explicitly says they'll bug you again.
[1] https://support.signal.org/hc/en-us/articles/360007061452-Do...
Regardless of how you hash them, it needs to work on a phone, and it needs to be reasonably unique... so you can just enumerate literally every phone number ever on a decent computer in a few seconds and, if combined with basically any other information at all (like an area code), that's enough to figure out many or most contacts trivially.
The difference, which that article goes into, is that now they're going all-in on you also trusting Intel's SGX and thus every single thing in between you, them, their hardware delivery pipelines, etc. Which makes collecting that data completely ok (it's done securely now thanks to SGX!), because you should obviously trust Intel because CPU vendors have had such a fantastic track record in their on-chip security systems. (</sarcasm> in case that wasn't clear)
There's a lot to like about Signal's privacy, both in isolation and in comparison to other messengers. They're doing great work. But I have absolutely no idea why they persist in this data collection. Their bull-headedness on zero options around it for years on end smells more suspicious than anything else at this point tbh. About 3/4 of the people I've known who installed Signal immediately left forever because someone they knew contacted them to say "welcome" and they got super creeped out wondering how they knew they had joined. And then the contact-er frequently left too because they had no idea it wasn't consensual, and were creeped out as well.
Assuming they are telling the truth, why would you care that your contacts know you also use signal (like them)?
Honestly, Apple needs to get in front of this on iOS just like they've done partially with Location data, Photos/Videos, and data brokering. They need to let you select shareable contacts. Kind of like the Circles that Google Wave had. Instead of letting apps force you into an all or nothing approach.
Also true caller adds security when you're from an under represented or a minority groups. I especially know women who use Truecaller to make sure they know who is calling / texting them from new numbers.
That's everywhere, not just India.
Having multiple SIMs in India will go away, or at least become something only the rich have, it's only a matter of time. This is because having that second SIM is no longer cost-free.
Multiple SIMs in India were a side-effect of it being near-free to have a prepaid SIM to receive calls. This was subsidized by high calling charges (calling from one part of India to another was expensive) and even higher data prices.
Then Jio entered the market with a ground-up 4G network and said, this is BS. Calls and texts are free, with no reasonable limits. We'll only charge you for data, and we'll provide 1.5GB a day or more -- starting at INR 150 a month paid 3 months at a time. The party ended for a lot of operators at that point as they hemorrhaged customers. Most operators simply folded or merged until now there are only 3 private players and one non-serious state player.
Driven by pressure from Jio, the other two private players (Airtel and Vi, aka Vodafone) have decided to amp up monthly charges for pre-paid phones. Essentially, if you're not spending at least INR 120 a month they don't want you. India has number portability so it's not like you're held hostage or anything.
INR 120 sounds super low but it's not for a lot of Indians who earn salaries closer to India's median per-capita income, and also it's an extremely limited level of service, for actual use you need to pay more -- typically around INR 250 monthly for 1.5GB data per day (remember, most Indians don't have wired Internet so 1.5GB data per day is not excessive). Jio and its competitors have hiked prices substantially, of course.
The last refuge for people on limited budgets is the state-run telco, BSNL, but the government will sell it -- it's only a matter of time. Expect prices to spike again, then.
Anyway, multiple SIMs in India are increasingly less viable for ordinary people. It'll take a while for behaviour to change, but it'll change.
I wonder what the percentiles is for number of networks in populous and large countries. Perhaps 3 networks is the number of maximum economically viable long term networks due to the enormously high cost of installing all the fiber and cell station infrastructure across the country.
They're broadly compatible from a handset perspective - sometimes there's better coverage for one or the other in some area or newer tech but for most day-to-day use you can get a SIM from any carrier and expect to be able to use it any (non-network-locked) device.
If I am not mistaken some shell company bought the spectrum then Jio bought the shell company.
Fortunately we’ve agreed on not sharing kids pics and information on places like FB insta etc.
I have zero issues with my neighbors having my phone number. If I lived in a smallish place, extending that would be fine.
I have huge issues with spammers and con artists having it.
A locally distributed physical book works great for the first and, at the very least, makes the second work for it.
Online databases are basically made to order for the second, and are far more extensive than needed for the first.
It is just another example where adding automation and cheap storage actively makes a situation worse.
Fun fact: Elector rolls are public record. Your address is already out in the open.
> Giving this anecdote to illustrate many people genuinely don’t see TrueCaller’s spying as a big deal.
That's because it makes no material difference to them.
Especially as part of a commercial transaction to a for-profit company?
"Hey, Bob! I'm going to give some company your name, phone number, occupation, and whatever else I know about you stored in my contact list in exchange for a beer. Is that OK?"
Once you give your info away it is not "your" info anymore. It is info about you, but you do not own it.
Is it rude? sure, but not illegal.
Depends on the jurisdiction. Under the GDPR this might very well be illegal, though obviously enforcement of it is significantly lacking so it's unlikely to ever actually be tested in court.
okay.
I started using TrueCaller some 8 years back and the biggest reason for me to use it was to prevent Robo callers/spams.
What if you avoid using the system default contacts store, i.e., keep it empty, and instead you use an app like OpenContacts.^1 To apps like TruCaller, it will appear the the user has no contacts.
1. https://f-droid.org/packages/opencontacts.open.com.openconta...
Guess which one gets all the apps - It's definitely not the one that costs me over 100$/mo to maintain!
I also want to minimize their information about my network.
Oh it's the classist "I'm smarter than the average person in my country" crowd again.
Why do you assume you know better? Perhaps they know what they're trading and perhaps it's worth the cost.
I have a number of stories for this. Indians are so used to this that sometimes people are shocked when I say no to sharing information that they request.
For example in a startup, the HR reached out on WhatsApp to all employees in a group and asked for certain documents and information etc.
About Truecaller: - It’s default opt in (with almost no way to opt out*)
- It requires access to your entire contact list - to mitigate this, I request Apple and Google to implement folders for contacts or something similar to how you can limit access to all photos on iOS per app. That way you can create an empty folder and share it with Truecaller
- It’s also impossible to change the wrong data that Truecaller somehow gets from some other contact list
My sibling recently got a new number and Truecaller assumed some other name and identity. Fellow Indians believe Truecaller more than they believe the person they are talking to (shows how much spam gets passed around)
This is NOT just TrueCaller. The same thing happens with Paytm and other payment apps.
Paytm for example assumed another identity and they requested us to submit multiple docs to prove our identity even though we never used the platform before. Even after multiple attempts and submitting multiple ids they refuse to change the data
Aadhaar - “Universal” identifier. Needed for pretty much anything. Including, apparently, buying jewellery.
Spain has a similar thing for this, you have to give your NIE/DNIe number everywhere. Like when ordering something online. But not in brick and mortar shops.
Still I find it a very poor practice in terms of privacy.
Government doesn’t operate in series on an issue one by one. This is why you have so many ministries in the govt. Just because roads don’t exist doesn’t mean govt should stop building railways and only think of roads.
In other words, privacy is a luxury that poor people can ill afford. Do poor deserve privacy? Absolutely. But it doesn't take much to get them part with their private data. They are stuck at the lowest level of Maslow hierarchy where as privacy is at least two level above them. Can government do something to protect their privacy? Probably, but I just can't see how it'll be successful when the citizens themselves don't care much about privacy.
I think this idea generalizes to other permissions too. Want to know my location? I hit the "placeholder" button and the app gets some generic location that never changes. Valid data flows through, so the app can work, but not my private information.
How do you check whether your number is "in"?
Once you do, you have to log in with either your Google or Microsoft identity and agree to let them download your contacts.
Since they have already done an action without your consent or agreements they should be able to remove you permanently without requiring you to agree to anything, signing up or mailing crap.
Seems seriously shady.
Always worth remembering, in any case, that someone always registers <your-area-code>-867-5309. Use that to get discounts wherever, like Safeway. I remain a little surprised they didn't long ago put that number pattern on a blacklist.
I'm not sure what a small-time tea stall would do.
back in 2011. i had "heard" about this. i had an iphone 3GS and an iphone 2G at the time. the 3GS had gotten ios5 if i remember correctly.
installing the app, it asked me very strangely to "allow truecaller to access your contacts". it took me a few moments to decide no. at the time, IOS had a "parental setting" to hide permissions behind a separate password, like location, contacts, payments, gallery, web, yada yada.
i learned that truecaller works on "you give your contacts and in exchange we give you a one way access to just search for numbers with names and not the other way around.
over time, it became ubiquitous, with people relying on it because "who saves a contact".
now its an obnoxious app that comes preinstalled on all cheap custom roms, shows full page ads every time it displays on screen after a call, it even shows up AFTER you have disabled screen overlays, i assume it gets preferential treatment by these rom makers,
this is the reason why i have never signed up to whatsapp or given facebook any contacts access or even 2fa ( old fb account, not logged in 3 years)
fuck truecaller
1. Anyone that has your phone number and Truecaller automatically gets you a name:phone_number entry in the Truecaller database. To get around this, I created a Truecaller account using my own phone number on a phone with zero contacts and gave myself a fake name(with my choice of subtle cuss words). This takes priority over other entries in the database. Am not sure if it works that way anymore.
2. Anytime I need to look up a number, I sign in using a dummy gmail account that I have.
There were a good few years where people looked up my number on Truecaller and it showed up a very obscene name that would shock em.
I hate Truecaller so much!
I keep all crap apps in the work profile since there is a shortcut in the android drawer to turn it off and on in 1 click. I also assume it saves a bit of battery since these apps can't drain it while work profile is off.
In my personal experience, I found that not creating a TrueCaller account itself avoids having spam calls. I tried this by getting a new number years ago. I do get some spams, but from some services that I am using/has used a few months ago, and they want me to get back in (looking at you, ACT fibernet).
Anyway, it's okay to not use such an app for blocking contacts, most modern smartphones has blocking functionality, and some Free/Libre apps has ways to block a number range and works offline without ads. They are more than sufficient for most of us, use them instead.
But as the article said, not having proper legislation is the root cause of this problem, from how many services running in India can you delete your account (not unsubscribe/delete app, but delete “account” with personal information) from? Yeah, think about it.
People don't know privacy and not aware of misuses in India.
And phone number in India is not considered private info. We keep putting banner with number everywhere offline to online.
I don't see anyone in this discussion saying that what Facebook did was OK.
Or is that the point that you're making? Because one person stole a car, it's OK for everyone else to steal cars, too?
Before I knew any better, I was ignorant of the permissions and saw it as a worthy trade-off since my contact(s) will somehow end up there, if they weren't already. As all it takes is for someone else who has saved my number to download the app and give it permission.
Didn't give them much thought until I started seeing them buy advertisement spots in some of the local daily newspapers. They were getting greedy for more data. From that moment, I deleted my account and created a new account signed in only with a random Microsoft login and the app now lives in the work profile where there are no contacts.
The app will refuse to work until you grant it permission to make calls (read your IMEI pre-Android 10) and obviously read contacts permission. It is also quite intrusive. Coincidentally, the other app I found employing such dirty tactics by refusing to launch at all before being granted sensitive permissions is Whatsapp.
That's the problem with maintaining absolute privacy. The privacy and security of your information depends on other people even if you do everything to save it.
https://youtu.be/WyYp9xPLa8s?t=423
These lists must be a gold mine for intelligence agencies.
Ekata reverse phone is a plugin inside the twilio plugins directory (or whatever they are calling it this week).
I wrote a unix command named 'lookup' which takes a single argument (phone number) and spits out "associated people" in a nice yaml output:
"is_commercial": false,
"associated_people": [
{
"name": "Ms. Amanda Joy Lastname",
"firstname": "Amanda",
"middlename": "Joy",
"lastname": "Lastname",
"relation": "Household",
"id": "Person.02884d55-980e-450c-a1e2-99999999999b"
},
I haven't checked but I'll bet I could get API service (for a fee) from Ekata and query these person IDs they are using and then fill out a whole social graph.It's a neat trick but other than confirming mobile=true and carrier:
"carrier": {
"mobile_country_code": "311",
"mobile_network_code": "489",
"name": "Verizon Wireless",
"type": "mobile",
"error_code": null
... I haven't found much use for it.The best bet is to try to get a phone number from across the country. If you live in NY, get a phone number from a city you have no relation to, say Seattle. Then, anyone calling from Seattle is almost certainly spam and you can still pick up 212 or 646 numbers.
It is astounding that common person understands the tradeoff when using free service but these ignoramus critics do not.
I didn’t grow up with them so I might be wrong.
I would say most people would use contacts like “Joe Plumber” or “Maria Tinder”.
Truecaller is kind of a substitute for identifying spam calls where I grew up where there is no alternative. Also helps when someone is calling you and you want to avoid answering them.
Most people definitely don’t care that it’s taking all your contact info though the utility of the app is well worth it.