Google Will Track Your Location 'Every 15 Minutes'–'Even with GPS Disabled'
forbes.com
forbes.com
So if you're worried about NSA or the like - you better not have a mobile phone/device (or a car - because new cars sold in EU all have eSIM for builtin emergency calls) at all.
And for particular first hand example - Xplora smart watch/phone got super confused when my kids school physically moved.
New building has indoor sports/gym (I think it's basketball court size) on the top floor - and all the reinforced concrete means mobile reception can be hit and miss (even on 3/4G).
Despite phone/watch never connecting to school (staff only) wifi. After move to new building - watch and parent app would regularly think/bounce location between old and new school buildings.
When even 3rd party companies have a mapping between wifi/ssid and approximate geo location, you can imagine state sponsored actors have at least next order of magnitude.
> "Because the testing took place with a new, default account, the team did not test to see the effect that user changes to privacy and security settings might have."
And bizarrely the article claims:
> "You can’t say no to Google’s surveillance..."
Well sure, you can't say no if you refuse to even look at the privacy and security settings.
The "Even With GPS Disabled" part of the headline is particularly misleading, since location data often (even mostly?) comes from WiFi too. The idea that turning off GPS would disable location data isn't how location data works.
Side note: I’ve opted out of giving Google my location on the web but when I search they still use my “approximate location” based on my IP and past searches. Trackers gonna track I guess.
I mean, it's a search engine. If you type in the name of a restaurant, you want to get the one in your area, not the one halfway around the globe. If you type the name of a store, you want to get their website for your country, not another continent.
You don't want Google to know your location down to a resolution of meters, that makes sense. But it makes a lot of sense for a search engine to try to figure out your city and country from your IP address, at least.
Otherwise, I want results to be location agnostic.
If I try to search in another language for news or information local to another part of the world from an associated device or while logged into Google services, I also get mostly US or English results. I can't just explore the Chinese web, or the non-commercial web, or whatever it is I'm actually looking for, just whatever they want their idea of what they want me to see.
A related peeve, but if I'm planning a trip and want to know where certain stops, like Costcos, are in a state, in Maps, I can't zoom to the level of the state and then "search this area" without it returning a very incomplete list mixed with pins for related results, often unlabeled until clicked on. I have to know or guess where a business might have a location, zoom in, and search repeatedly to be sure. Generic queries like "south indian restaurants" are even more limited.
This is especially frustrating when I know there's a location that isn't showing so I can't set a detour, or if I'm physically nearby something that's not being shown in relevant results, for whatever reason. Our locations aren't always especially useful to us, but having that data is apparently creating some value for them.
Even more concerning where the apps, like AT&t's and Fidelity, that do it just to make the money by reselling the data, not to show ads.
I use an android phone but just don't use any other google services - no search, no gmail, no default apps. I do most browsing in tor-browser, so google ads won't correlate with me.
I think the issue is the patents with the hardware needs to run out, but by then 6G or 7G will be out and you'll have the same problem. Anything with DMA that isn't closed source cannot be trusted. I'll die on that hill.
Even with projects like PinePhone, the best they can do is a privacy switch that turns off the modem. It's just not good enough to take it seriously.
While this is a large surface in rural areas and older technologies, it's not the same in urban/newer technologies. It could easily be associated with a given building.
To protect our location, it would need something akin to a mobile proxy that would relay the communication but to my knowledge, there are no such things for mobile communications. And this is not really secure, it's just outsourcing security to another entity which may be be compromised.
(I am quite rusty, but I was a telecom engineer)
If you care about the NSA, then you better not have any phone. Whatever it's a android, iphone, grapheneos, anything. Israel blowing up pagers is a proof that nothing is impossible to them.
But if you want to say fuck off to the big data harvester like Google, Microsoft, Facebook, and so on.. then apple isn't bad at all.
You just got to deal with the usual apple bullshit, no side loading, repairability, thunderbolt charger, no headphone jack, etc.
so instead of an actual improvement just settle for second least worst? ironically google pixels are 100 times more private than any apple device will ever be because you can securely run your own 100% controlled open source OS such as grapheneos.org which is an actual private as in feature not marketing OS.
A gyroscope sensor is able to accurately record what one say close to his phone. It doesn’t even need Android to run he has access to private information.
This 'but X will get you anyway if they want' or '5$ wrench' is used by alot of people I know to rationalize selling themself out privacy wize.
That's a lost battle, if they want to see what you do, they do and there is nothing one can do but force them legally not to do so.
They literally sell your traffic to Google.
https://en.wikipedia.org/wiki/Apple–FBI_encryption_dispute
Apple's reaction to a number of such things has been to further enhance encryption.
They go to a good deal of trouble to make things they can't break. Look at the new cloud compute model they're introducing:
https://security.apple.com/blog/private-cloud-compute/
And if you've missed it, note the prior "verified contact" key exchange added to iMessages, as well as the "sorry we can't read your backups to help you recover your data" security added to iCloud (provided you only use devices up-to-date and opted in). This one is a customer service nightmare, they added it anyway.
All that said, this article is less interesting since (a) if your cell phone uses a telco, "they" know where you are, and where you've been, no Apple needed; and (b) unlike Apple segmenting your Maps directions to prevent themselves from knowing where you are going, Google's always been about your location.
https://news.ycombinator.com/item?id=41184153
Apple was caught issuing issuing OCSP queries (hello, XKEYSCORE) every time an app was launched, promised to stop logging and build an opt-out, then reneged and memory-holed the promise.
I’d probably get one as well, but who else would?
I'm just guessing it just doesn't make financial sense to develop one.
But you have no defense against that if casual users regularly visit your location or just come near it.