T-Mobile has started selling your app data to advertisers
androidpolice.com
androidpolice.com
"T-Mobile does not currently collect app data on iOS users, fearing it could run afoul of Apple's privacy rules. ...you can opt-out of T-Mobile's program using its official "Magenta Marketing Platform Choices" app."
Their motivation seems to be to gradually reduce in size, and eventually eliminate SIM cards - presumably just to free up internal volume. But they've been successful in forcing MNOs to do that anyway.
How does this work? Does it use heuristics to associate traffic patterns or server IPs with apps? Or packet inspection for apps that don't encrypt traffic?
> Should every tap on your phone be tracked and monetized? I would hope not.
These articles always treat implementation details so infuriatingly casually. There's a vast gulf between analyzing traffic patterns, and installing spyware to report on "every tap", as this sentence implies.
That's what it sounded like to me.
> There's a vast gulf between analyzing traffic patterns, and installing spyware to report on "every tap", as this sentence implies.
I didn't see an implication that every tap was currently being tracked. Only an inference that this is what the marketeers really want, and that allowing such desires to run rampant would be a bad thing. It still baffles me that people see massive surveillance as benign because they think the end result is merely relatively ignorable targeted advertisements.
I don't know myself, but it's possible that they are simply reading unencrypted SNI fields from TLS connections. SNI exposes the website hostnames that you connect to.
Note they're not using DNS records, but rather the SNI portion of the HTTPS requests made by the phone.
Run a VPN on your phone at all times. Use an alternate OS based on AOSP such as Graphene, Calyx, E, Lineage or Linux for the brave. These have no carrier bloatware/spyware. Transfer your phone number to VOIP. Then only occasionally use a burner SIM away from house.
This could probably be scripted using Termux, OpenSSL, and Tasker.
You should check this. Just when they announced (about a year ago?) they would default this to opted in, they changed my already explicit intention to opt out. Wow.
Trust is hard to earn and...
If you trust them with your data....
They are friendly and do have good customer service, though. And they cheat a little bit less than their competitors.
> By the end of 2017, the FCC had revoked net neutrality and allowed internet providers to sell their users’ data without their permission