Location history data in Google Maps will soon be stored on user devices
businessinsider.com
businessinsider.com
And while it’s mildly interesting or useful to some, it’s dangerous to others, especially given it’s stored in a central location out of their control, and running all the time, not just when you’re using Maps.
The earliest record I have is from June 16, 2015, anyone have earlier?
The time capsule is amazing and I've referenced it many times over the years
/s
More serious, if it would be my data under my control, it can be fun checking the past. Exploring where you travelled and when .. but that is kind of my buisness amd not googles. But since I use a android phone, they have it anyway.
Having it enabled for years and then disabling it on the night your spouse went missing is suspicious. Having it disabled for years isn't.
All that your phone data would support is a claim of where your phone was.
For EXIF, there's f.e. PhotoMap for Android.
Would never put such data in the cloud. But i'm also neither on social media nor American nor app-loving, so...
Need? Probably not. It was certainly handy though knowing the week I was there and what the interior looked like.
The goal is to know if you visited <insert questionable places>. They almost certainly already know, so it is also about concealment.
The plus version is on F-Droid for free. It has unlimited map downloads.
If you look at Google Timeline, sometimes the track it records is not particularly accurate, likely because it's only getting updates for significant changes in your location.
I also use OwnTracks to keep track of myself, and there I can see the individual points it gets from the OS notifying it of location changes, and... it's honestly not that great sometimes.
The positions from OSMAnd seem pretty spot on.
I had no idea it did this. Thanks for the tip!
Now I am carrying a dedicated Android phone with me (a Xiaomi Mi 11 Lite 5G) on which I have PhoneTrack [2] installed. The app starts tracking as soon as the phone is moving and saves all the data on device. I used to have an instance of Owntracks [3] running, but now I just run a simple Flask app which pipes the GPS points to a PostGIS database on my local network when I am home. To visualize the tracks, I import them into QGIS. As the phone is solely used for tracking and only when I take it with me, the battery lasts about three days.
[1] http://www.transystem.com.tw/www/product.php?b=G&m=pe&cid=4&... [2] https://f-droid.org/en/packages/net.eneiluj.nextcloud.phonet... [3] https://owntracks.org
I've also used it for remembering what I was doing on specific days. It's wild how the location movements can accurately prompt my brain for the activities on those days
Fun: I travel a ton, I love looking at where I went to relive the experience. Especially if it was a recent travel and I'm showing things off to friends asking about it. I just open up the Timeline and say "Okay, well this day we flew in - then we took a 4 hour car ride, then we hung in this town for a few days, then took a boat to this island for some camping, then flew over to this city for a week, and..."
Utilitarian: As a US Citizen living abroad, I apply for the FEIE tax exemption every year to help me keep my first ~$120k as untaxed from the Feds (Should be my entire income, but no - US needs to tax on citizenship and not residency like nearly everyone else.. but I digress). For this rule, I need to have full 24-hour days in foreign territory, so for my documentation to ensure I'm still within my limit, I like pulling up Timeline - snapping a screenshot/export and saving it for later should I ever be audited.
For work, I have to produce reports of countries I’ve visited and dates. So looking at location history is pretty handy for remembering if I visited Sweden in 2018 or 2019. Etc etc.
But if it's already optional, and being removed entirely, then that persons's existence isn't that relevant; what's relevant is the people who DO like it and are losing something for them.
Google remembers many places I've totally forgotten about, and it's really nice to be able to revisit the nostalgia when I'm older.
I've been logging this for more than a decade, and it's a lot of fun to go back in time and revisit and rediscover old favorites.
It's one of my favorite features in all of Google :(
According to the World Justice Project [1] the USA is in spot 26 of 150+ examined nations. Worse than most European countries, but far better than most of the world. And while the general "rule of law" trend for the USA is declining for the last decade, checks on government power have actually improved in recent years.
If you don't believe me or WJP numbers, I invite you to travel abroad and spend some time in Bangladesh, Ethiopia, Pakistan, Egypt, or even Hungary. If that's too much to ask, just try doing business there. I was involved in projects in some of the above mentioned countries and I tell you, the contrast is startling.
[1] https://worldjusticeproject.org/rule-of-law-index/downloads/...
Remember that the prosecution says anything no matter how trivial can be used to revoke citizenship. Does your HN username count as a nickname? Prosecution might say yes. And again this isn't about you or me. It is the same thing as dragnet surveillance. I don't matter but somewhere in our nation or beyond the next MLK or the next great activist will be born and I want them to be able to develop and achieve their goals without being caught up in gotchas.
It is for that person probably not yet born that I don't want a two tiered citizenship system.
Context from the New York Times
Justice Sonia Sotomayor asked about the failure to disclose an embarrassing childhood nickname. Justice Elena Kagan said she was a “little bit horrified to know that every time I lie about my weight it has those kinds of consequences.”
Mr. Parker said the law applied to all false statements, even trivial ones.
Justice Stephen G. Breyer said it was “rather surprising that the government of the United States thinks” that the naturalization laws should be “interpreted in a way that would throw into doubt the citizenship of vast percentages of all naturalized citizens.”
Chief Justice Roberts added that the government’s position would give prosecutors extraordinary power. “If you take the position that not answering about the speeding ticket or the nickname is enough to subject that person to denaturalization,” he said, “the government will have the opportunity to denaturalize anyone they want.”
https://www.nytimes.com/2017/04/26/us/politics/supreme-court...
What if you can't afford a lawyer?
Though there is a corrolary: occasionally you'll see suits filed against John/Jane Doe defendants. The plaintiff knows they've been wronged and wants justice, but they don't know who the entities are they need to sue for some reason. In those circumstances you can get subpoenas issued to produce e.g. phone logs or security footage, etc... in order to move the case along.
None of the "constitutional protections" matter if they don't apply to broad classes of situations.
This is especially effective if you're a powerful person or corporation and can find a litigant willing to sacrifice their own assets and/or freedom to pursue a fake lawsuit on your behalf. The justice system is subject to Sybil attacks like any other system.
If your experience is closer to the truth, then maybe the tech industry should retain lawyers to redesign our security systems!
I've already looked into OpenTracks and Locus. Trying to find another app I trust to do this anyway...
Also, it's great for trying to fit loose memories in dates and locations.
The government probably has a list of international flights I've taken somewhere. I honestly don't think they will use it they probably don't deny citizenships because I missed a couple of trips (unlike, say, not reporting frequent trips to North Korea).
It's still nice to do the right thing and fill up that data to the best of my knowledge.
Even if I get an e-visa, I get an in and out stamp. Not having these would invalidate the whole reason for having a passport.
For example if you’re applying for citizenship based on the 5 year rule, then you must’ve been physically present for at least 30 months (913 days to be exact) in those 5 years prior to your application. 18 months (548 days) if you’re applying based on the 3 year rule as a spouse of a US citizen.
So 8 days instead of 12 can mean it’s no big deal or it can mean you’re not eligible if those 4 days make or break your required amount of days physically present in the US.
It’s one of those silly things the government already knows but wants you report anyways.
While the US doesn’t do a passport check before leaving via the airport, airlines automatically send over departure information to CBP, that’s how they are able to show this information in the I-94 on the website.
Obviously entry is also recorded.
I suppose it’s a way to make it easier to filter out ineligible people at the beginning of processing applications without having to delve into the records to verify and in part to see if you’re honest.
the US (ESTA).
Israel famously does not. They’ll give you a small slip with your details on it. I was told that an Israeli stamp on your passport would automatically bar you from entry in many Arab states so they came up with another system
Also pretty much anytime I have entered the UK via the global entry lanes I never got stamped.
Then there is the whole topic of oversee territorys... Not sure if those count as international territory but also no passport required..
There is also a bunch of places where I only need national Id and no passport to travel there, I would assume it's the same for the US?
>If you do decide you want that information in the cloud — say, as a backup for when you get a new phone — the data will be encrypted.
So maybe it'll still be available? https://www.washingtonpost.com/technology/2023/12/14/google-...
It's great to hear that Google is making such a big move. Google is not known for respecting user privacy.
As a Googler, I’m always confused by this sentiment. We live in times where car manufacturers reserve the right to collect and sell any data the car can sense, up to and including your sex life. But somehow Google does not sell or share any of your data with anyone, makes it public how it fights a lot of law enforcement overreach, even outright exits markets and sunsets features and products due to privacy concerns… And is everyone’s top focus when it comes to privacy.
1. More people have phones than cars
2. Cars take someone to a general location (i.e a shopping mall carpark) but phones are precise enough to say which section of a store (or hospital) you are in
3. Car manufacturers can't inherently link the passengers of the car to the driver, or to each other
4. Manufacturers of cars don't have ads as a core business model
That's not to say what car manufacturers are doing isn't scummy -- it deserves more light. But what Google does affects more people in a much more complex way. Google doing this essentially takes attention away from these smaller cases of privacy violations -- if the Google issue is solved (and I'm using Google here as a supplement for "phone tracking") then the world would turn their focus to the smaller issues like car tracking.
3. No, but based on driving patterns and sensor data, police can infer certain things.
4. Very soon. Very very soon.
This is not an image/PR issue, Google really is doing Evil™ things.
How so?
You can reference numerous previous discussions on HN regarding WEI for more information.
I used to work at Google, I got over the initial 'gee we're pretty nice and concerned' thing, but would like to gently point out the tendency of people to be slightly histrionic and misinformed about it. The gap between what it was, briefly, and the confidence you have in its intent and current state are quite wide. Certainly well-intentioned and appreciated, but ultimately alarmist and inaccurate.
These types of ideas with significant potential for abuse should be introduced with extreme caution and with at least majority agreement of everyone affected. Instead Google tried to pull a fast one and refused to engage criticisms in good faith. My response might seem alarmist at first glance, but I don't think that's a fair accusation given Google's behavior. I expect this proposal to return under a different name once everyone's forgotten about it and I hope the backlash then will be as severe as it was against WEI.
> No, this client isn't using an ad blocker
Sure, but I still fail to see how it would "obliterate any remaining semblance of privacy on the web".
WEI is following Apple’s lead isn’t it? But unlike Apple, Google got pushback and abandoned it.
When it comes to GDPR, that’s even funnier. Most companies woke up in 2018 and looked for a way to brush this off. My org in Google was investing serious development (we’re talking engineer-years, don’t know how many) into GDPR compliance in 2015. And that’s not some superficial fronted tweak. I’m talking about adding data removal to analytical storage, something where first design assumption was that it has immutable append-only history.
Manifest v3… I don’t understand what are they trying to achieve.
Google is hostage from ad selling.
Well, except we know about PRISM, so it's not even a theory anymore. And all their ad system tapping into the user data is pretty creepy as well.
I don't want to share any data to Google because of their poor track record and Google makes it as hard as humanely possible to not do that.
Several features in maps that would be super useful are unavailable if you have location history disabled. I'll be glad to turn it back on.
There's too many awful or just self-dealing forces in the world which will legislate access to user's data. There's nothing your company can do to defend itself. The situation will only intensity and get worse, governments will only ever expand their legal access to the cloud's many data-keeps.
Data is toxic. It's a risk to your company, given the 195 different nations which each might hit you up to demand uncomfortable & scary privileges. Having data will encourage people in your company to use it, which half the time is bad & scary. Don't have data.
This goes against so many of my desires, is against my aspirations for the Information Age, but it seems so impossible to give users their own sovereignty, to leave them in control. Everyone else has all the power over the data, and that makes data toxic.
Currently, data as toxic waste is still in the phase in which toxic waste was cavalierly dumped everywhere, including into water supplies.
Industry loves this phase.
Once org charts start going to jail, and companies start getting hit with existential levels of fines and lawsuits, then data will be in a much better phase of toxic waste.
There are tons of little data brokers buying locations from cell companies and unscrupulous ad networks driving all those apps on your phone collecting locations for no benefit to you; these brokers are behind Delaware shell corps or offshore.
Data is still gold to them.
https://www.schneier.com/blog/archives/2016/03/data_is_a_tox...
[1]: https://en.m.wikipedia.org/wiki/Tyranny_of_the_majority
https://blog.google/products/maps/updates-to-location-histor...
I'd never have an internet-connected camera in my home for example but I get genuine use and joy out of Google keeping 10 years' record of everywhere I've been, including the night I first hooked up with my wife and we fell into a taxi at 1am. Neither of us can properly remember it, but Google does.
We do this at verida.io
Yes, the key management is the issue.
> You can encrypt and upload a copy of your Timeline from this device to your Google Account, in case you lose your device or need to switch devices.
You can recover the data after losing your device (which would be the only "end" in end to end encryption), which means that the data isn't actually E2EE, and thus Google or anyone with access to your Google account can still access it.
Your phone unlock code is typically not complex enough to withstand brute force attacks, so brute force attack resistance is added using an HSM in the datacenter (just as brute forcing the code locally is prevented using an HSM in the phone). A similar technique is also used by Signal, you can read about it here: https://blog.cryptographyengineering.com/2020/07/10/a-few-th...
Let me explain. I’ve been rocking the same iPhone backup since 2010 and I never lost anything… but now if I lose my phone I will lose my eSIMs, as well as any non-passkey 2FA. What next?
Just recently I was unable to reinstall my eSIM for an hour and my headache was growing stronger as I imagined what all the services that (still) relied on SMS 2FA, all of which would not be activatable without it.
Switching to a new phone now requires me going through my long app list to determine which apps “probably” need to be reactivated on the new phone, while still having access to the old phone.
Back on topic: now I also have to worry about my location history being lost forever should I need to uninstall a buggy Google Maps (happens just about yearly)
It's much more convenient to have a yubikey+backup or something with a sane backup/sync system (eg password managers like Bitwarden).
As long as the data on my device is synced to iCloud storage or backups, that meets my needs. If the UX around an app is not great when switching phones or requires some esoteric incantations, I just won’t use it.
But is it though? That’s the major catch. Something as important as Google Authenticator is not backed up, so you must enable sync to your account to ensure you don’t lose it (which wasn’t a thing at all until recently)
Of course, syncing TOTPs comes with its own threat model. Something to keep in mind.
https://security.googleblog.com/2023/04/google-authenticator...
> you must enable sync to your account
Google's location scraping felt more bulletproof because they seemed to prioritize it at the OS-level on Android over how normal apps function
Only annoyance is Android has a thing where it doesn't allow apps that start on boot to automatically start getting GPS data, so on every boot you have to tap a notification to kick things off.
During a bout of Degoogling I‘ve imported my Google Location History Takeout into php-owntracks-recorder and used it happily with the OwnTracks app on my phones.
About a year ago I’ve replaced it with PhoneTrack running on my NextCloud - while keeping the OwnTracks app as a client.
These days, I want to check out Traccar and how it compares to PhoneTrack. I believe Traccar can also work with OwnTracks data. So if the Traccar client doesn’t behave, it’s a nice alternative.
> If you’re getting a new phone or are worried about losing your existing one, you can always choose to back up your data to the cloud so it doesn’t get lost. We’ll automatically encrypt your backed-up data so no one can read it, including Google.
> These changes will gradually roll out through the next year on Android and iOS, and you’ll receive a notification when this update comes to your account.
All cloudy stuff should operate that way really, to maintain the users privacy expectation which is 'this data is only accessible to me, not my government'.
https://blog.google/products/maps/updates-to-location-histor...
I'm slowly moving away from Google and other companies clouds where I can. Would be nice to take this data out in takeout and explore it locally, but it's such a useful feature for looking back on my travels.
Since you explicitly mentioned moving away from Google, I'll note that the app has an opt-in integration with Google Places. You have to click a "Search Google Places" button to activate it so you won't accidentally use it.
It's self-hosted in the sense that it's just an app.
https://apps.apple.com/us/app/arc-app-location-activity/id10...
https://voussoir.net/writing/obsessed_with_gpx
I have a few recent commits in my repository that I haven't put into a versioned APK yet though.
The output GPX files can be viewed on the PC with JOSM:
Furthermore I expect that there will a way to move that data to a new device, even a new phone replacing a dead one. It's one of the reasons to buy a new one, it happened to me 2 times out of 3 since I had modern smartphones.
The safest and most convenient way would be an encrypted backup to Google Drive (for Android, I don't know where for iOS,) with a password that only the user knows, different from the one of the Google account.
https://blog.google/products/maps/updates-to-location-histor...
https://blog.google/products/maps/updates-to-location-histor...
I wonder if that means it can't be accessed by google remotely once it's deleted.
Mr. Jones: Just grabbing dinner, nothing more.
Store location history locally: this is just a scheme to cut down on storage costs.
There's no winning here, is there? Personally, I'm a fan of Google never giving the option to store location history remotely and this is a step in the right direction.
You know, I'm not going to bother to flip over an envelope on this one. That's at least a million times smaller than Youtube daily traffic. And I might be short a few orders of magnitude.