The global surveillance free-for-all in mobile ad data
krebsonsecurity.com
krebsonsecurity.com
But I don’t think anyone can honestly say the right amount of regulation is zero, which is what we have now. It is absolutely bonkers to me that anyone off the street should be able to gather such highly granular data about any other person as long as they can pay.
It completely bombed out because people were so freaked out about a device knowing where you were.
I also remember when Nextel came out with an enterprise tracking app for delivery companies where you could track the vehicle and make sure it was on time making its deliveries and could alert a person monitoring the software back at the office if say the van was sitting too long somewhere which indicated they had broken down or something similar.
Two companies tried to install on their vans and there was so much push back from so many people in one company, they canceled their order. The other company did install it and then they had three lawsuits from employees who claimed the software was a breach of their privacy - while in the employment of said company and on said companies time. The company voluntarily removed it after only a few months.
Its just so strange to me that we went from not wanting any of this, to just freely handing over any and all private information to these companies.
I don't think the nature of the data collection was clear and have been creeping up on us.
It took a while for me to realize. E.g. I didn't notice Google was spying on me and stalking on non Google sites until I finally realized it.
Anything can wear people down— make it seem as if it were always normal, even— if it's just persistent enough.
All the more reason it should have been nipped in the bud, I guess.
Has sir heard of the GDPR?
Right after I crossed the border from Austria, my U.S. cell phone started lighting up with spam SMS messages. At first, it was from the local cell phone carrier welcoming me to .cz. A few minutes later, a message from T-Mobile letting me know I was roaming in another new country. Then a few minutes after that, SMS spam for hotels, then restaurants, then casinos. All of this in a time before "smart" phones.
I'm not surprised to see it's gotten so much worse.
I assumed this was only based on voter registration party-spam.
That's awful.
And did those political SMSs honor opt-out requests or not?
There are very few reasons in my mind that anyone, especially law enforcement, would need this "feature" and they're all pretty dark.
Are they even? Or, can they know that? If the suspect has a gun, they'll wake up scared, confused, and with every reason to believe somebody's illegally breaking and entering.
[0]:https://jeffmorhous.com/block-ads-for-your-entire-network-wi...
Also a video for those more YT inclined: https://www.youtube.com/watch?v=eCA24qJBG8Q
Krebs and everyone else he cites is right—it's time for Apple and Google to eliminate MAID altogether.
ETA: Do not downvote this parent! Use trustworthy ad blockers anywhere and everywhere you can!
I self-host DOH using blocky so my Android devices can use it via "Private DNS" that is active on both wifi and cellular.
[0] https://0xerr0r.github.io/blocky/latest/
[1] https://github.com/AdguardTeam/AdGuardHome
[2] https://adguard-dns.io/en/public-dns.html how to configure
How do you know this is the case? (I believe it to be, would like to verify)
Also worth mentioning many apps hardcode DNS servers or fallback to other DNS providers when they fail to resolve hostnames. I see this all the time on my network. (I have a PfSense box that redirects to upstream NextDNS when this happens)
It isn't just people using DNS filtering for ads that have this problem. Network admins at companies face the same problem (see for example https://cleanbrowsing.org/help/docs/block-dns-filtering-evas...)
Some browsers, apps, or devices might let you disable DoS/DoT or might let you configure it to use your own DNS server, but none of them have to let you and even when they give you that option they can still do whatever want (https://discourse.pi-hole.net/t/chromium-bypasses-pi-hole-by...)
Obviously any application or device using a hardcoded IP address will bypass DNS entirely so DNS filtering isn't going to work. See https://old.reddit.com/r/pihole/comments/djacup/im_starting_...
One aspect is to use trustworthy software, not written by an advertising company.
You create a server and host it on IP x. You create a cert for it. You add the public key to your app.
Your app can now communicate with that IP over port 443 with that certificate. Remember that the idea that the domain must match the one in the certificate is a setting, enforced by the browsers. If you run your own code you can perfectly override that.
Now you can do whatever you like on that connection.
In fact, you don't HAVE to go that far. Many applications these days do private key pinning and use that connection to load the ads. IMDb does that on the iPhone.
MyQ and myBMW use the same to 'protect' the connection. MyQ's implementation of this, and subsequent implementation of CloudFlare's bot protection completely broke home-assistant's connection. All because they want you to use their app (and get bombarded with ads).
Doh/DoT was supposed to bring in MORE privacy for users, as it allowed users to resolve addresses without the system servicing the connection (ISP / StarBucks / McDonald's) from being able to see or modify the responses (think captive pages).
But all it brought was more spying. I am a firm believer that I should be able to inspect all traffic that an application sends out over my internet connection.
Bad traffic could flow to a "good" domain, and then you need to decide whether that domain is actually "good".
All large corporate and governmental entities love the data. Industries (tech, finance, etc) and planned future governance (technocracy) are based on it.
So, it is baked into the plan that days will be collected. It's just whether the individual will know about it.
A look at data for how many people were aware the whole time during any scandal, and how often abuse and crime gets covered up or exploited instead of reported or opposed, will leave you with a very banal impression of malice. "The only thing necessary for the triumph of evil is for good men to do nothing."
…Idk, companies are just groups of people. Maybe people also need stronger incentives to not let the "company" do antisocial things. At least the execs.
Maybe it's the companies that hide it. Maybe it's the people that lie to themselves. I'm sure they're smart enough; they can probably figure it out. At some point ignorance becomes wilful.
This in turn would lead to an industry that hunts for evidence on a contingency basis.
The reaction to that idea taught me a lot about incentives.
At a societal level we fully deserve all this because apparently we can't be fucked to care about basic rights anymore (cf. "everyone gets the government they deserve"), too lost in Huxley's dystopian future of infinite dopamine distractions.
We're all proud of you but this is barely related to avoiding ads. You can build your own car too, and you'd still have to look at the billboards on the highway. Or you could build your own phone and never giving anyone the number, then you'll still get to enjoy 5 spams/day during election season when someone decides to simply call every phone number in the region.
Ads are the new certainty besides death and taxes. If they aren't in your face yet, be assured that whole legions of shitheads are very busy trying to make it happen.
The advertising industry is so large that it's basically private taxation, except that you get nothing in return from it.
My interests align with advertisers to an extent. I do want to know what products are out there. I'm an adult, I won't forget that their descriptions of their products are biased.
Surveillance advertising is a bad thing, but it doesn't help to take the most extremist position possible. Advertising is information, and it's not difficult to use that information to your benefit.
The big spenders are in the game for brand awareness (there's not even a product being shown sometimes) and then there's a parallel world of which I would call scams which went on top of it (less than half of the Youtube ads I see look legal)
If you remove those two, I'm not sure how long the advertising industry would survive.
The problem with online ads is mostly orthogonal to FOSS. Of course, it does help to not use an OS with ads baked into the Start menu...
Our information paradigm has changed; so should advertising. Let consumers seek out new products, if they wish to.
(If you search for “the best ways to Y” and find an article that tells you about X, congratulations—chances are, you are reading an advertisement.)
You have not provided a viable argument so far. I can’t say you failed to provide supporting evidence, because you have not even made a claim. Inventing a meaningless term like “information paradigm” and implying it has somehow changed is not one.
You either lack a point to make, or are struggling to express one.
Repeating something ad nauseam does not make it true.
Advertising is just attempted demand generation for otherwise weak product offerings, a ploy to exploit human psychology by appealing to needs to be part of an in group, desire for sexual appeal. It is exploitative and harmful to its viewers.
Hows that for a claim?
Just like money is just a vehicle for abuse and fraud.
Advertising is disseminating information about a product. The rest is you describing how advertising is abused, which I already addressed in my first comment. Yes, it is also used for malicious and abusive purposes, just like everything else is also used for malicious and abusive purposes.
If we talk about things that can be used for bad stuff, how about we start with E2EE comms and cash. The amount of evil, abuse, violence that they directly enable simply drowns out any potential downside of ads.
I guess either you want to ban it all, in which case there is no more argument to be had, or you can acknowledge that the world is not black and white and something that can be used for evil can also be a crucial part of an ecosystem.
However no one need this amount of data, all advertiser need is : you search for a pair of shoes on Google, show you ads for shoes. That's good advertising and sometimes it can be useful for the user.
Let consumers who are searching for product information be given advertising. Contain the virus to ecosystems that want it.
If you look at old ads for random products from e.g. the turn of the (last) century, they seem to often give this slight "wall of text" impression. Image of the product, surrounded by prices and descriptions of what it was and what it (purportedly) did. The motivating belief seemed to be that if a company communicated the benefits of buying from them, they would attract customers.
It seems like at some point the focus shifted away from expressing factual information, and to creating vague associations and implications. I think that's still fine on its own, and in fact quite fun and the source of a lot of creativity, but it also created the opportunity to mislead in new ways. E.G. most famously harmfully maybe, the very mid-20th century idea that cigarettes are "cool". In modern times this seems to have gone even further towards exploiting basic quirks in human psychology— A dancing bear, chocolate man, or screaming celebrity has nothing to do with selling a product, but it's bizarre and surprising and therefore memorable, so by making an ad around it you're cluttering the viewer's brain with useless information designed to redirect mindshare to your capital-B "Brand".
So at that point it becomes dishonest and manipulative. But at least it's still broadcasted, e.g. on radio, TV, in newspapers and magazines. It's predatory, but everyone gets the same thing. You can still sorta avoid or ignore it. It doesn't single anyone out.
That's changed now with the Internet. The mass collection of location and personality data, identifiable to individual profiles and paired with tools allowing those individuals to be targetted with a combination of terrifying granularity and omnipresent scale— That adds an entire new dimension to "advertising", and it would still be wrong, because it would still comprise many violations of privacy and basic decency, even if it weren't being actively exploited for commercial gain. If any one individual knew as much about you and had as many tools for trying to influence you as Facebook and Google have built on an industrial scale, they would be either a stalker deserving of a restraining order, or some kind of a (probably malevolent TBH) supernatural spirit.
So "advertising", in terms of "informing the market of a product" and "connecting customers to businesses in mutually beneficial transactions", is fine I guess. Good, even. Stalking, lying, manipulating, and rent-seeking through dominance are wrong.
And with technology centralizing power in the hands of a few organizations, the modern practice of "advertising" seems to be less about "informing people" these days and more about dominating the information space in order to manipulate human behaviour with neither the consent nor the knowledge of your targets. No wonder it's apparently being abused by law enforcement.
...To be clear, I use the word "you" only as an indefinite pronoun here. Small businesses that use ad networks aren't the ones to blame for a large system having messy incentives and malicious central actors.
yes, take driving for instance. Some people drive responsibly, watch for bicycle and walkers, others drive like maniacs yet it's the same thing, driving a car.
It's not so much what you do with advertisement than how you do it, but advertisement in itself isn't bad.
Now if you take the worst example possible, Facebook, Google, Microsoft etc. all these companies behaving like rats trying to extract as much data as possible from you, it's going to look bad. But for instance, when we still had phonebook you would look for a plumber and some plumber who paid for advertisement would get a bigger space, in exchange the phonebook company would make money and everyone would receive phonebook for free.
That is an exemple of usefull advertisement.
If you've gone one step further and disabled location access for apps and disabled the global ad id, it would seem difficult to do the searches described.
The article refers to "25 percent of Apple phones". Is that just legacy phones running older versions of iOS prior to removal of IDFA?
Location tracking of phones is out of control (arstechnica.com)
https://news.ycombinator.com/item?id=41930818
Related comment:
486sx33 8 hours ago | next [–]
About 2 years ago, an isp we use for one of our operations in Canada called R… which is also a media company and an advertising company… came to us and said hey! We have this amazing new technology , all you do is geofence your competitors and then we will retarget anyone who visits their location with your web ads for as long as you want! Since they are also the isp for mobile data , they just force replaced ads for the targets web browser. (Basically they inject ads)
They also made it clear their system is not at all dependent on your phone location services or even your advertiser ID, since they are the isp and the cell provider they just use your SIM ESN to track you. ( cell towers know where their users are, with better accuracy than ever now )
It worked, but it’s darn scary. This has been around for awhile.They've tried that approach but it's actually less efficient than "good old fashioned police work" because it turns out that 99/100 of your hits are gonna be lawful weirdos, 1/100 is gonna be a petty drug dealer and the career advancing prosecution you actually wanted would have been much easier to find by using normal methods like inferring that a dealer has a supplier, a spy has a handler, etc, etc and trying to suss out who those people are. The NSA figured all this out post 9/11 when they were building data haystacks in search of terrorists.
What the data haystacks do get used for is dragnet policing wherein an agency picks some crime they're gonna go hard on, pulls up a bunch of results of people who probably did it, tosses all the people who are likely to pose any risk to them (e.g. you don't see the ATF knocking on doors asking about Temu glock switches in bad parts of Detroit) and kicks in the doors of whoever's left.
The data haystacks are also really useful for witch hunts when they get egg on their face and need to make someone pay, like that time they prosecuted anyone and everyone who they could construe as having done anything to help the kid who bombed the Boston Marathon, and the January 6 people of whom a great number were certainly just hapless.
And this is in addition to the usual "opposition research" like the FBI bugging MLK and all that sort of crap.
Parallel construction makes the mere existence of these data sets extremely dangerous.
For example: https://marketinginsidergroup.com/marketing-strategy/digital...
Not being skeptical, but curious
i think most people are on the fence / undecided, and the few that do "pick a side" only do so based on their personal life experiences (which includes family and community influences)
Also, people are influenced by what other people say, especially people in tech. You can see people on HN saying how hopeless it all is. People on HN and your social circle are listening to what you say.
Convenience wins out for the vast majority of people. People just want to be left alone and have nice things. As long as it is just advertisers knowing everything, the masses just won't care. Even if the state starts to take action, as long as it doesn't happen to them, they won't care either.
For some reason, when it comes to other causes, people repeat the obviously false (and hypocritical) right-wing talking point that it's all useless and hopeless.
(Throwing around words like 'wack' and 'preaching' isn't evidence or a stronger argument.)
These are not my words, but words I've been called when droning on and on about the evils of social media and ad tech. <shrug>
This has been a widespread problem for the better part of at least half a decade, likely much more.
They managed to outsource it on accident just because of a shared need with advertisers to target people.
If only our society had some orderly process to balance privacy with public safety - such as by having the cops explain to a judge why they need to track a given person, for how long, and so on.
Perhaps also some rules about what counts as a good enough reason, and telling judges they can't grant overly broad, blanket permission.
Someone should put something in the constitution about that.
> One DEA official had told Reuters: "Parallel construction is a law enforcement technique we use every day. It's decades old, a bedrock concept."
Constitution or not, they're doing it.
[0]: https://theweek.com/speedreads/651668/hundreds-police-office...
Welp, that's the final straw I needed to nuke that fucking GasBuddy app from my phone. Goddamn I hate them so much
There are popular third-party libraries, used by apps, offering whatever functionality.
Those third-party libraries do deals with whoever, to include into the library whatever code it is the whoever wants to get out onto a ton of phones.
I worked for a company in Germany, who wanted to get some Bluetooth base station detection functionality out into phones, so they could track people.
Company put Bluetooth base stations into a bunch of locations, and then paid a major third-party library to include their code.
Bingo. One week later, millions of phones being tracked.
When you install an app, you are in fact installing God knows what from shady friend-of-a-friend-of-a-friend, who's got money.
Do not install commercial apps. Only install open source apps. Anything else, you're going to be abused, whether you know it or not.
This advice is about as practical as "go live in a cave". At some point, you have to decide whether avoiding the privacy harm limits your ability to function, and sadly, that is increasingly the case.
Crazy I work with Zoomers that install seemingly every dumb retail app so they can get a dollar off a Big Mac or whatever.
There's no reason for a "McDonalds App" to be on anyone's phone. I can wait a few minutes in line, thanks.
But, to answer your question, yes: I just checked and the spread seems to be $5.19 to $4.19 here. But to circle back to your original premise it's quite possible that even $15-ish is not worth the glucose/time spent interacting with this objectively terrible app and then driving to some likely inconvenient station
If you go to Settings -> Privacy, the top two options in iOS 18 are:
* Auto-deny Advertising ID access
* Which apps have location access ("X always, Y while using the app" is summarized right at the top)
Is that possible with IOS to avoid Apple? I think not.
Edit: Clarified my question as to what's possible with IOS.
I've heard that from a number of folks on various forums, although I have not experienced that myself.
No one has forced me to use such an app. Probably because I'd rather have my tonsils extracted through my ears than do anything financially related on my device.
Perhaps I'm just curmudgeonly and set in my ways, or perhaps my 25+ years of professional infosec experience tells me that these devices (brand/version/OS is irrelevant) are hopelessly insecure and shouldn't be used for anything important.
I'm guessing probably a bit of both.
That being said with the exception of Qubes desktop devices are dramatically less secure than Graphene, so unless you're foregoing digital payments altogether I don't see how you could avoid some degree of risk.
Why would I want to use anything from those scumbags?
>That being said with the exception of Qubes desktop devices are dramatically less secure than Graphene, so unless you're foregoing digital payments altogether I don't see how you could avoid some degree of risk.
You're talking out of your ass and it smells that way too. Yuck!
https://news.ycombinator.com/item?id=16776028#16776762
I've pretty much deleted all apps. I'm working on dumping my phone all together but shit like mandated 2FA is screwing that up.
All you’d need is a camera to read QR codes, a display, a few kB of storage and some pretty basic processing.
But then I guess that storage would need to be encrypted with some sort of authentication. Hmm.
We could call it something like Web Authentication. I could even imagine small, keychain-sized USB authenticators that you have to touch a capacitive button on to approve an authentication :)
People used to risk their lives to try to erase much less data.
eg. https://en.wikipedia.org/wiki/1943_bombing_of_the_Amsterdam_...
And that's why I gave my mother my iphone and went back on the wasteland that is Android.
She, as a normal person, doesn't understand all of these and go with the default settings. With apple it means she has 75% chance of being protected, with Google 80% chance of being tracked.
Me, as a nerd, i know about advertising id and I even root my phone to have afwall firewall.
This is why Google is just bad, they always technically allow you to do the right thing but it's buried under a ton of sub menu and convoluted settings. On purpose of course, their goal is to make money.
You can complain to the Irish DPA (because that's where the broker is likely hiding, pro-forma), which will respond within a year or two with a request for more information.
If the broker made the mistake to be domiciled in a location with a more competent DPA or you are willing to drag them to court, you might stand a better chance.
The developer got kicked out of the Play Store for bogus reasons, and had to continue to develop it as an externally funded effort. Support him, buy a pay what you want license, and give him a couple bucks for it if you value open source software like this.
(I'm not affiliated with the project, I just love the app and it runs on all my degoogled devices)
Additionally, degoogle your phone by installing an open source ROM like GrapheneOS [4] or LineageOS [5], and install only the most essential apps on your phone.
There's also App Warden [6] which audits installed apps, by scanning them for malicious libraries and adtrackers. It's based on the dataset provided by Exodus Privacy [7] where you can search for Apps or their APK identifiers and find out what kind of fingerprinting libraries they're using. For example, this is what the Facebook App uses behind the scenes [8].
Don't install gapps and neither the google play services. If you want an app store for the convenience of updates of open source apps, there's also f-droid [9], a libre app store for Android.
Additionally you should keep in mind that every app that needs google play services to run is spyware, by definition of what these services offer as APIs. Websites that require you to install their app to "verify" you are usually spying on your activity.
[1] https://openwrt.org/toh/start
[2] https://openwrt.org/docs/guide-user/services/dns/adguard-hom...
[5] https://wiki.lineageos.org/devices/
[6] https://gitlab.com/AuroraOSS/AppWarden
[7] https://reports.exodus-privacy.eu.org/en/
[8] https://reports.exodus-privacy.eu.org/en/reports/com.faceboo...
say, my parents own phones but don't do much on them except navigation, photos, messaging, and web browsing. if you're not into Uber, Doordash, mobile banking, and so on, then you're not really giving up much by switching to the alternatives.
generally, it's harder to _remove_ something from your life than it is to forego _adding_ it. if you're content with the functionality of your tech as it exists today, then a feasible route to de-apple/de-google really is to just not start doing too much _new_ with it, and within some number of years you'll find the alternatives have developed to the point where you can switch to them without going backward.
--
We made surveillance capitalism the default method of financing every free-at-point-of-use service on mobile devices before we understood what that meant, and people now have zero perception of the worth of mobile-based software. People happily pay for desktop software but the decades of everything on a phone being free by default despite the economics of that making no sense have made it borderline impossible to sell software to people for their phones.
At the same time government has been completely asleep at the fucking wheel with regard to any regulation to protect consumers. Consumers shouldn't have to know the "tradeoffs" of free software, they shouldn't need to vet vendors of software on app stores for privacy policies. People should be protected by default. This "informed consumer" garbage is why we can't get anything done in a regulatory sense because these companies will make the argument that users consented when talking to any layperson user of MyFitnessPal will have you understand they really did not within 5 goddamn minutes.
Could people read terms of service? Yes. Do they? No, because people have shit to do and nobody aside of an activist or someone with an interest in it is going to read 110 pages of terms of service each from the 50 services they're currently using and it's unreasonable to suggest that they should, and that's JUST the reading, even if they read it, do they understand it? Because most people according to a stat I saw recently about the United States read at about a sixth grade level, which is going to be a struggle to get through any legal document. And 4% apparently are completely illiterate.
I don't mean to rant here but this pisses me off so much. Our entire society is constructed around a set of assumptions about people who are at least some level of educated, with decent english literacy, who have the time and energy to dedicate to managing these various things, and yeah, if you're that theoretical person, you can probably do quite well for yourself in the United States. But what if you aren't?
What if you're one of the millions who have to work three fucking jobs to survive and don't have time to read the terms of service for twitter, and just want to relax? What if you're illiterate? What if you're disabled in some way that impedes your ability to read, or your ability to understand what data harvesting is or means? Does your inability to meet the standard I've outlined above just mean you're fodder for the scummy business alliance, ready to be taken advantage of at every single turn by everyone who can, because it's more profitable that way even if it means you will be broke, exposed, and/or otherwise exploited at every single turn and probably have a pretty miserable life?
I am long tired of living in a society that is clearly, bluntly, at every turn designed for companies to live and thrive in and not people. I'm tired of people being hung out to dry because "freedom." Nobody needs or wants the freedom to be recklessly and hopelessly exploited to the ends of the goddamn earth, and I'm sick of pretending there's no way for us to know that difference.
/rant
I think it could work. You can call, text (probably hard, I remember those swipe-out keyboards) so you should be good in an emergency. But that's it - the rest you do on your desktop, where you have far greater control over the software you use and far less data available (no location, no photos, etc).
The trouble is there's some gaps. If you want decent pictures, you'll need a camera. If you want to do something simple like check your email, it's a whole thing.
I recently graduated college and by my senior year a lot of college functionality was done over phones (and phones only, no desktop or browser options). This ranged from ordering food at an official campus store, to requesting an advisior meeting or basic administrative functionality (tracking financial aid, filing a course exemption request). Granted, for the last you still could do it via other methods like email or an in person visit, but it was heavily deincentivized. Even the LMS switched to something that was designed as mobile forward.
The other thing I've noticed is that some countries like India effectively run on the phone and a dumb phone doesn't cut it for any business deals or even purchases. It's all done on the phone. You use your phone to order groceries, pay for them, and then track the delivery.
I'm actually flying now and things like TSA digital ID and CBP's MPC make it such a massive QoL difference that I think you'd be hard pressed to find people who'd willing go back.
cursing aside, you are doing them a favor by saying "they are asleep" .. it is not that simple; misaligned incentives for decision makers is a polite phrase
Neoliberals look at GDP rising and have faith that the world is good. It's time to call these folks out for what they are: dogmatic zealots.
It's a passable measure of the financial class's wealth, which is not the same thing at all.
The use of GDP as the headline number in demagoguery is a psyop
That’s really the key difference between US and European thinking on privacy. Europe was slow but always thought it was fucked up. Americans don’t seem to grasp why they should care or understand how perverse their blindsight is.
Not to be overly cynical, but I believe this is a feature, not a bug. I don't believe it's isolated to any one political ideology though. The system seems to rely on a perpetual underclass, and if you are slightly outside the norm or deficient, the system tends to use you as mulch for the uber wealthy's private jet funds.
> Could people read terms of service…
Even if they do read licences and such, companies have a vested interest in making them as complicated, obtuse and self-serving that you have close to no recourse. It’s weasel-worded to the nth degree. They also change them largely at their leisure, and if the new terms are bad, again, there’s often very little you can do.
“If consumers don’t like it, they wouldn’t buy it” is the other lie that’s successfully kept itself alive. Consumers are kept time and spare-resource poor, and are largely presented with a predefined set of options to choose from that the companies at play feel like presenting us with. Rarely is there an _actual_ varied choice. Only the illusion. Combine that with scenarios in other industries like enterprise sales where the “customer” is an exec and the user just gets lumped with some garbage software.
Philosopher kings would fit it at the political level.
Your ID + other people's IDs seen from the same non-CGNAT IP establish a link, i.e. they also have part of your social graph.
And if one of the web site requests location permissions to e.g. show you where that shop's nearest branch is, I wouldn't put it beyond the ad networks to detect and abuse that to add your location to the above data pile.
Of course, all that becomes entirely moot once you have a single application with ads installed on your phone that has location permissions...
Actually thinking about it a bit more with 5G being so short range I can see how a social graph could be made. I do have 5G turned off on my phone though because I don’t know what benefit it gives me because if the 4g tower is already not overloaded bc other people are on the local 5g
However, your friends using your WiFi, or your coworkers and you using the work WiFi, provides a link.