Android launches yet another way to spy on users with “Privacy Sandbox” beta
arstechnica.com
arstechnica.com
I use e/OS with Brave browser --- privacy by default. Both based on Google source but cleansed and stripped of tracking.
Personalized ads are mainly an annoyance and a really dumb idea in my opinion. Context sensitive ads are much easier to implement, more privacy respecting and the only ones that are moderately useful and acceptable.
I run Lineage, where I have not loaded any version of Gapps.
My goto browser is Bromite (https://www.bromite.org), which I have configured default incognito and otherwise high security.
I have loaded Magisk, then the modules for MicroG:
https://www.reddit.com/r/MicroG/comments/shmpng/confirmed_sa...
Wouldn't it be great if all Android users could wake up to this tomorrow? It would be an interesting day.
I should try e/OS sometime. The guy who maintained Mandrake Linux is in charge.
Even without GApps, Lineage still includes links to Google. e/OS had a list of some of these at one time. They remove these links and include MicroG in the default install.
Others may disagree but in my opinion, it is a pretty good compromise between security, privacy and usability.
In exchange for this, Lineage delivers the monthly security patches first, mostly guaranteed to be in place by the 15th of every month (load the first nightly published after that date, and it will be bundled).
settings put global captive_portal_http_url http://captive.example.org/generate_204
settings put global captive_portal_https_url https://captive.example.org/generate_204
settings put global captive_portal_fallback_url http://another.example.org/generate_204
Or, for Android <6.0.1 settings put global captive_portal_server captive.example.org
No Google, no cry. Of course you need to replace those domains with some of your own choice, I use my own server with a bit of nginx configuration to provide this functionality: server {
listen 80;
listen [::]:80 ipv6only=on;
server_name captive.example.org;
# Apple CNA
location /hotspot-detect.html {
return 200 '<HTML><HEAD><TITLE>Success</TITLE></HEAD><BODY>Success</BODY></HTML>';
add_header Content-Type text/html;
}
# Apple CNA
location /library/test/success.html {
return 200 '<HTML><HEAD><TITLE>Success</TITLE></HEAD><BODY>Success</BODY></HTML>';
add_header Content-Type text/html;
}
# ChromeOS, Android
location /generate_204 {
return 204;
}
# Windows
location /ncsi.txt {
return 200 'Microsoft NCSI';
}
location / {
return 302 http://www.example.org/;
}
}Basically. This is how they make their money. So, no one should be under any illusions about the culture of Google and all of their adherents. Go wants to introduce tool-chain telemetry as a default (opt-out only).
What's holding everyone back? I understand that without users there won't be apps, but also without apps there won't be users, since they offer just the basics.
Imagine if TikTok or WhatsApp have had an app for those others OSes
Heck, you can just use lineage os without the Google services to get a taste of this. And that's a system where you still can get all the Apps with a tiny bit of effort, as long as they don't depend on the Google services. It sucks for the most part.
But really, since you asked, just try it. Get some used phone that's supported by lineage OS and challenge yourself to use it exclusively for a month. Or maybe for fun/hard mode, get a Lumia 950 and try that for a month.
A surprising and hilarious number of things, including some of Google's own apps, show "X won't work unless you enable Google Play Services" popups and then continue working just fine. (I'm guessing they link against some client library that shows that on all function calls, but then doesn't throw an exception.)
Its possible to add Android auto stubs to it to give privileged access, compile your own build, sign it, flash it, and install the apks yourself as a DIY middle ground. I did it for a pixel 6 and was happy with it but bootlooped the phone applying my first compiled OTA update so this scared me off trying it again and I went back to stock. I understand why the team is against it but unfortunate.
Maybe another take on your question is why did windows phone and bbm fail?
One such example is CalyxOS. Using it right now. It comes with both F-Droid and Aurora Store. The latter let's you download anonymously from the playstore.
Just yesterday I actually had time to read that new Apple "Privacy" Statement that pops up on a Mac for some reason since a few weeks and they put a blunt lie on top about how "private" their service is and just a few lines later they tell you that they grab actually all your private data.
Every EU website now pops up a "privacy statement" where they actually tell you that they DO NOT respect your privacy.
I am sure there is a technical term for that, I would simply describe it as "producing cognitive dissonance in the most obvious way and make it look fine".
It took already an enormous effort to get all these companies to actually have to report about their abuse of your private data, in EU even make users agree.
However, it did not change anything - most companies still break your privacy even with more fun doing it, as you agreed.
A terrible and wasteful development of modern primitive capitalism.
And what do you mean "lying" ? There are no lies anymore. Only "sources", CIA press releases and "insert your enemy here" propaganda. /s
"Always dispose of the difficult bit in the title. Does less harm there than in the text." https://www.youtube.com/watch?v=40Br165MhLU
You can buy a ready to use phone on their web site or you can install the OS on a compatible phone of your own. I have installed this on about 10 phones (all Motorola) for friends and family. Here is an example of one that I just put together as a Christmas present.
https://www.amazon.com/Motorola-T-Mobile-Unlocked-XT2113-2-S...
As a de-Googled phone, the Google Play store doesn't work but that's no big loss because I can get any software I need from F-Droid and Aurora Store.
It's the loss of an entire ecosystem worth of apps.
If you want an inexpensive phone that will get five or six years of first party support with security updates after that, go with an iPhone SE.
The original $399 version got six years of OS updates and just got another security update last month. That's $67 per year that got both an OS update and security update.
No, it's not. With very few exceptions, the Aurora store pulls apps from Google Play. About the only thing I have seen missing from Aurora store is a few super strict banking apps but you can usually just use their web site.
This isn't so bad if you use a privacy focused ROM and create a special, single purpose Google login that is only used for app purchases. I also suggest keeping a Google gift card for the occasional purchase.
Privacy invasion doesn't really kick in until you start re-using your Google login and your phone/apps are reporting back to Google on a regular basis with your location, device IMEI, advertising ID, hardware fingerprint, email address, browsing/search history, banking/purchase details (aka Google Pay), etc..
He literally just said that he used the Aurora store as an alternative. If you don't know what that is, it is basically an anonymous version of the Play Store. Highly recommended
https://divestos.org/pages/devices#device-fp4
Super happy with it, but yeah no headphone jack, but i have it with the usb-c convertor.
It's everything that the average Joe really needs for only $99 refurbed. As I said above, I just installed e/OS on one as a Christmas present. It runs very smooth and fluid, better than stock because the background Google spyware crap is gone.
And check your vibe meter, it is acting up. The main person behind this was the creator of Mandrake Linux.
Termux is the one android exclusive software I can't live without and they managed to fuck even that up by killing processes indiscriminately in order to save battery or whatever. If there's no solution by the time my phone dies, my next one will be an iPhone.
Wait a minute, will something like this really come to Android phones? I guess that installing a custom rom will become impossible at the same time?
If this happens, then there truly isn't going to be much point in using an Android phone over an iPhone
Why wouldn't an app require this? Banks want it because "fraud", streaming services want it because "piracy"... You can come up with pretty much any reason for any "rightsholders" to want control over our computers. If WhatsApp starts requiring this, it's either accept Google control or my phone turns into a paperweight.
Android already provides a mechanism for apps to refuse to run on modified devices, it's called SafetyNet and is widely used for example by banking apps. Currently, it's usually possible to trick it, but with hardware attestation it will become practically impossible.
The simple solution --- install the bank's web site as an app.
Go to the site, click the browser menu button (3 dots on Android or up arrow on iOS) and select "Add to Home Screen". You now have a link icon on your phone that looks and acts just like any other app.
Some banks (Chase for example) offer a "Progress Web App" which removes the browser interface elements so the causal observer can't even tell it's not a native app.
https://www.howtogeek.com/342121/what-are-progressive-web-ap...
Google has been doing this for quite some time to prevent unlocked devices from accessing the Play Store. The solution is to avoid Google Play --- along with all other Googly things.
If your solution is to just be less secure go ahead, but don't complain when services don't want to serve you or treat you different since you are less secure than the other users.
> don't complain when services don't want to serve you or treat you different since you are less secure than the other users
Hell no. They should not be allowed to discriminate against me just because I chose to own my system. They should not even be able to figure out what software I'm running, to say nothing of "treating me different".
"Don't want to serve us" unless we let them invade and own our machines? Please. This should be illegal.
App developers don't care if you own your system. They just want a way to prove that the device their app is running on is secure and that the client has not been modified. If there was a way for you to prove that to them they wouldn't mind.
>They should not even be able to figure out what software I'm running, to say nothing of "treating me different".
They just want to know that the client has not been tampered with so that they know you are not going to shall user's tokens, scrape people's information, or mondo automated actions as a bot. A signal that you are using the vanilla client makes you much more trust worthy to a service.
>"Don't want to serve us" unless we let them invade and own our machines?
Apps aren't invading your machine. They just want some guarantees about the environment they are operating in. The information that they get from you is the package's name, certificate, version, whether it's from the play store, whether your device passes integrity checks, and whether the app is properly licensed.
> They just want a way to prove that the device their app is running on is secure and that the client has not been modified.
Contradictory. If I own the system, I can obviously modify it and everything running on it. Including your app. Therefore what they want is proof that I don't own the system.
> They just want to know that the client has not been tampered with
"Tampered with" -- there's that language again. Owning my computer is not "tampering", it is freedom.
> They just want some guarantees about the environment they are operating in.
Who cares what they want? It's my machine, I decide what they get. If they get anything at all. If I want them to believe they are running on a clean environment, that's what they should believe.
> The information that they get from you is the package's name, certificate, version, whether it's from the play store, whether your device passes integrity checks, and whether the app is properly licensed.
"Integrity" checks? Rooting my phone does not violate its "integrity". If anything it restores it.
Certificates? Store? Licensing checks? Look at all this crap that must be installed on "my" system just to give you your "guarantees". My phone's gotta come out of the factory pwned at the hardware level for your "guarantees" to be worth anything. It has to come with a full root of trust from the firmware to the bootloader to the operating system to each individual app just to prevent my "tampering". But you're seriously claiming apps aren't invading our machines.
An app "wanting" anything is invasion enough.
I disagree. You can have control in modifying your system, but the software just needs a way to prove that the security features it assumes are true. There could be a way for it to analyze the changes you made and decide whether or not it should trust your system.
>"Tampered with" -- there's that language again. Owning my computer is not "tampering", it is freedom.
It's someone else's software. You may own your computer, but you don't own the YouTube client. Google owns the YouTube client. Tampering with Google's client is tampering.
>"Integrity" checks? Rooting my phone does not violate its "integrity". If anything it restores it.
No, it does not. One part of Android's security model is that app's have storage that only they can access. Take for example a 2FA app which stores it's private key in this location. This makes it so that you must physically have your phone in order to get a 2FA code. This is the "something you have" part of 2FA. Rooting your phone violates the integrity of the system because now someone can just become root and steal the private key. Now they can generate 2FA codes without physically having the device with them. It then becomes another "something you know."
>My phone's gotta come out of the factory pwned at the hardware level for your "guarantees" to be worth anything.
These are security features. Your phone is less secure without them. It's not pwned.
>An app "wanting" anything is invasion enough.
Everyone wants something. Every business transaction includes both parties wanting something from the other.
Damn how i hate to write that: At least on Android you can turn off WI-Fi and mobile data, unless iOS which keeps it enabled "for system services".
You realize that Apple is still doing the tracking, just not allowing third parties?
Apple is in a league above Amazon in protecting user privacy. It is the most privacy-conscious firm out there. Apple only stores the information that is necessary to maintain users’ accounts.
https://stockapps.com/blog/google-tracks-39-types-of-private...
The problem is companies like Google and Facebook, which track users across the web and relentlessly spy on everything they do.
Google literally spies on everyone's credit/debit card transaction data now, so they can spy on your offline life as much as they already do online.
>Of course, Google has been able to track your location using Google Maps for a long time. Since 2014, it has used that information to provide advertisers with information on how often people visit their stores. But store visits aren’t purchases, so, as Google said in a blog post on its new service for marketers, it has partnered with “third parties” that give them access to 70 percent of all credit and debit card purchases.
https://www.technologyreview.com/2017/05/25/242717/google-no...
It doesn't just show ads based on current search terms. It uses your install and usage history to show personalized ads. https://www.macrumors.com/2022/10/22/apple-announces-more-ap...
The difference between Android and iOS is that with Android, you don't have to use spying services from Google or Apple. With iOS, you are required to use spying services from Apple.
> Google literally spies on everyone's credit/debit card transaction data now, so they can spy on your offline life as much as they already do online.
Google gets your purchase history whether you use Android or iOS. iOS is strictly worse for privacy.
> Apple only stores the information that is necessary to maintain users’ accounts.
The difference is clear.
It's impossible to take this seriously.
Google, literally has surveillance capitalism as it's entire business model.
You have no choice but to let Google get your purchases (except maybe via some opt out with your card issuer). You do have a choice not to send your app usage to Apple and Google, but only if you use Android.
As far as whether Google or Apple is worse for surveillance capitalism, only the former (and Microsoft and Mozilla) lets me opt out of them collecting my SSID location. That is yet another reason iOS is worse for privacy than Android. Even worse, it is impossible to get your location on iOS without also sending your location to Apple.
No, I'm just not gullible enough to buy into such a ridiculous premise.
Spying on users is Google's entire business model.
What does that have to do with anything? On Android, I can use as few Google apps as an iOS user. Even better, I can use fewer spying Apple apps. Apple's entire business model is marketing to gullible users who hand over their money and their data.
You get the usability of Android with (optional)sandboxes google services/microg.
Almost all apps work and its really usable.
You can block some of their access but it's hard from airtight.
Sounds interesting. Goes and looks it up.
>>From: $1,999.00
You must be joking...
This is the cost of Librem 5 USA (made in USA) [0], not Librem 5 (made in China) [1]. Also, I preordered it for $600 a long time ago, and sometimes you can buy from resellers for a similar price [2].
[0] https://puri.sm/products/librem-5-usa
[1] https://puri.sm/products/librem-5
[2] https://forums.puri.sm/t/librem-5-for-sale-eu-630-eur/19445
I suppose that helps a little. I seem to have incorrectly assumed that the USA model was intended for use in the USA, not simply assembled there. Still crazy expensive. For that price I'd expect it to come with a keyboard and mouse and replace my Thinkpad altogether.
You have my attention.
....
[goes and looks it up]
Niiiiice. Reads more...
https://puri.sm/posts/what-is-mobile-pureos/
The only problem I'm seeing is this is all Gnome and I'm a big Mate desktop guy. I wouldn't really have a desktop replacement unless I could get the traditional desktop back. Still this situation is a much better one than I originally feared. I'll be watching this closely. Thanks for educating me.
The linked source has a lot of stuff that is done "in the future" and basically all of those "in the future" suggestions, are inferior to what AOSP has had for years.
The document lists some of the drawbacks of Librem 5, such as the use of memory-unsafe languages, and then blames Android for also relying on the same memory-unsafe languages and even some Android-specific components written in memory-unsafe languages. The fact is that Android has tons of mitigations specifically for this problem, which Librem 5 completely lacks. They're not comparable in that way. Librem 5 basically exposes the entire Linux kernel attack surface, whereas Android has multiple layers of protection between userspace and the Linux kernel. Apps written in memory safe language, proper app sandboxes, hardened memory allocator, extremely strict SELinux policies, CFI, PAC, ShadowCallStack, etc.
The only nice thing Librem 5 has, are the killswitches, but do those really matter at this point?
For example, if you do not trust the manufacturers in China, you can verify the schematics, or order Librem 5 USA. Or, if you suspect your device is compromised, you can rely on the kill switches to make sure you are not tracked or listened to. Can you do these on Android? I'm sure there are known vulnerabilities for the latter on the black market.
Another example: If you use the smart card to read or sign your emails, you can be sure that even a hacked or stolen unlocked phone would not allow the attackers to manage your email identity.
People who say that Librem 5 is less secure than Android do not take into consideration that threat models can affect it a lot. You cannot simply declare "it's insecure" without considering the threat models. Also, I guess if you are fine with the security of your GNU/Linux laptop, which you take with you, you should be also more or less fine with the Librem 5 security.
I am not even speaking about the freedom benefits. Also, there is no security and privacy without freedom (https://puri.sm/posts/why-freedom-is-essential-to-security-a...). In the long term, Google is heading toward the walled garden on Android, just like Apple does. I would not bet on it for the future. If you care about security more than freedom and need Android-style security now, then Librem 5 is not for you.
Lots and lots of people say they don't want to be tracked by ad companies. But how many are willing to open their wallets to make it happen? I'd say you can judge how sincere their commitment is by that.
They didn't get buy-in from other browsers, so they are doing it at OS level.
Nice /s
0: https://en.m.wikipedia.org/wiki/Federated_Learning_of_Cohort...
> On Android, the Privacy Sandbox tracking is in addition to all the usual individual tracking methods; it's not being pitched as an alternative to anything. The Privacy Sandbox on Android is toothless, and Google has no plans to reduce tracking on Android.
Who does Privacy Sandbox benefit? It doesn't benefit users, because it's not mandatory for apps to respect it. It doesn't benefit developers, because it's non-zero work to migrate, and zero benefit (because existing tracking and analytics systems will continue to work). It's doesn't benefit Google, as a whole, because it's one more API that they have to continue to support.
What was the point of all this?
Google could easily switch to context sensitive ads but they don't because advertisers pay extra for "personalized".
Personally, I doubt anyone can really justify the added expense. The entire process is opaque to make any comparison difficult if not impossible. Just because I bought pet supplies last week, does it really make sense for pets supply ads to follow me all over the internet --- even on unrelated web sites?
But they can sell customized ads stating that they will be very well targeted regardless of current content. Which seems to be what advertisers want much more, and reason why facebook never opened up their apis to google+ IIRC, your social graph and its use is basically the only worthy thing on whole facebook.
It of course brings all this tracking evil, why google stopped being morally OK company etc. But the money are there.
>Personally, I doubt anyone can really justify the added expense.
The CPM of an ad is based off on auction. There is no extra fee for personal ads. The ad spot is just worth more and advertisers are willing to bid more money for access to the ad spot. If people can't justify the expenses the price of the ad spot will fall until people can.
So I installed that and the Play store, which, due to GrapheneOS's sandboxing, was probably better than the stock Android. But it didn't even work well. Plenty of apps I tried to install wouldn't. After about 3hrs of playing with it, I said "fuck it," and flashed the stock Android back onto the phone.
I really want to switch, but that was far too much work.
GrapheneOS developers aren't really the most considerate of beginners.
You can even keep separate profiles for apps that do and don't need play services.
I keep Google play services in a separate profile on grapheneos so that use it as minimally as possible.
Either way, you don't have to use Sandboxed Google Play or Play Store on GrapheneOS. You can install whatever third-party store you want.
The author falsely claims Chrome is killing off ad blockers too with manifest v3 since manifest v3 protects the privacy and security of users better. This guy isn't consistent about being pro privacy. He simply hates Google. Manifest v3 doesn't even kill off ad blockers, nor does the Chrome team intend to as they have been improving the APIs to enable them to function. The strongest argument is that chrome extension store will reject manifest v3 extensions that want overly broad permission to access the content of any site you visit.
[1]: https://developer.android.com/design-for-safety/privacy-sand...
Every other outlet "google releasing their version of Apple's ATT"
Ars Technica guy "Google will watch you while you sleep"
So yes, while the Ars Technica headline may be a bit hyperbolic, I think it's far closer to the truth than a headline which claims that Privacy Sandbox is comparable to ATT.
Personally my biggest issue with this is its naming. I think it is a borderline deceiving name given what it is actually doing.
But they chose a good marketing term so other outlets would say exactly what you think Ars should be saying, but they are not falling for it and actually reporting what it is doing.
That name will trick users into thinking that Google is actually taking privacy seriously (they are not).
News journalists should dog food Firefox (to encourage end users) and then avoid Chrome. (i.e) they make sure the webpages work great with Firefox. Usually everything works better with Chrome. The reason for the give would be sorry... Our livelihood depends on tracking/ads etc. Oh BTW, I (as a journalist ) am all for privacy but my corporate overlord (CondeNast incase of Ars) forces us to do this/that.
It is the same thing w.r.t. Firefox.
Secondly Ars Technica works completely fine for me on Firefox. I say that as someone who exclusively uses firefox and only ever breaks out chrome to debug compatibility issues and I can't recall ever having a problem with Ars Technica. Are you saying it doesn't work for you?
Because I really don’t care about advertisers having a new cool way to track me, I care that I can force them off by policy and the sandbox seems to not have that feature.
> On Android, the Privacy Sandbox tracking is in addition to all the usual individual tracking methods; it's not being pitched as an alternative to anything. The Privacy Sandbox on Android is toothless, and Google has no plans to reduce tracking on Android.
But such is the way of modern digital media - do you think "Google creates a new Privacy Sandbox feature for Android" would bring the same type of clicks, comments and advertiser revenue than one titled "Google will spy on your in your sleep" ? :D
Journalists should pick apart lies, not parrot them.
Is Privacy Sandbox really a lie and bad? Who knows, ArsTechnica will be biased against it either way so you need a better source.
(Unless of course you deeply hate Google, then they'll be writing to soothe your soul and confirm your bias. Go ahead then.)
[1] https://www.theverge.com/2022/1/25/22900567/google-floc-aban...
That's all I need to know personally.
This is a hit peace written by an iZealot who doesn't even address Apple's system shortcomings.
> party tracking cookies in Chrome once the system rolls out. On Android, the Privacy Sandbox tracking is in addition to all the usual individual tracking methods; it's not being pitched as an alternative to anything. The Privacy Sandbox on Android is toothless, and Google has no plans to reduce tracking on Android.