How apps track your location without asking for permission
blog.trustlook.com
blog.trustlook.com
Is accessing nearby BSSIDs available in a similar fashion on iOS? A quick look reveals: https://developer.apple.com/library/ios/documentation/System...
I honestly think Android's permission system is a joke, and a sceptical Google will fix the majority of the information leaks with this up-coming update.
PS - It is "interesting" that getting your google account address requires a special permission on Android, but getting your phone number does not. Wonder why that is? IMEI too.
This is because GET_ACCOUNTS is under PROTECTION_NORMAL, and so it is automatically granted at install time.
Remember when Google introduced fine-grained permission control, received much praise for it, then removed it almost immediately afterwards? To me, that showed they clearly valued the interests of themselves and their monetising "appvertiser" developers over the freedom of the users.
https://www.eff.org/deeplinks/2013/11/awesome-privacy-featur...
https://www.eff.org/deeplinks/2013/12/google-removes-vital-p...
Unless it needs some sort of location data to provide functionality, what is the minimum set of facts that would cover app behaviour?
I guess they might want to know:
- if the connection is secure and/or explicitly trusted
- if the connection is bandwidth-metered
- if the connection can route to the internet
Then, it can check those flags and decide if it wants to download those 3GB of your personal banking details or whatever.
Or, perhaps better still, it registers one or more 'acceptable network profiles' based on the above fields, and the OS gives it a callback when is becomes available/unavailable.
That would prevent it from polling and building a neighbourhood network map, but I suppose it could still register for all possible combinations, and beacon out to a remote host which can then geo-IP backtrack it to you-ish.
I'm definitely not happy with the carefully secreted privacy options scattered around the android UI. I'm still getting used to it, and every time I poke around in a settings menu I'll probably find at least one thing I would much prefer to default off.
Does the iphone or cyanogenmod do this?
Are there any alternative phones/OS's which don't share your data?
Thanks,
It goes without saying that the OHA-Android [0] is a data mine for Google already. With M, they're really upping that game [1]. Far worser things to worry about.
[0] http://arstechnica.com/gadgets/2013/10/googles-iron-grip-on-...
[1] http://www.computerworld.com/article/2931084/android/google-...
Can someone explain this? It doesn't seem to make sense that with wifi disabled this would be possible (and the code they link to specifically has a fall through if wifi is disabled). Maybe something just got jumbled up in their explanation.
"the Android OS by default performs WiFi scans in the intervals of tens of seconds, even when the WiFi is turned off; the setting to disable background scanning when WiFi is off is buried in the advanced settings."
It looks like you can stop this from happening when the WiFi is off it just requires an extra step. I don't have an Android device so I can't really verify this.
I'm not sure if this was ever a "default", but it is definitely part of the setup prompts now.
I advise turning it off unless you need it to be on, not only for privacy reasons but for battery life. I noticed an increase in battery life by turning that feature off.
With this turned off and GPS turned on (ie, not using Wifi to determine locations) I get a terrible reduction in battery life because all locations are done finely with the GPS chip. With all location services disabled I get much better battery life.
Yes, it's possible, but constantly scanning for APs will have the side effect of an app draining battery even faster than if it used the phone's location service.
Reading the article to the end:
>> The same method also applies to iOS, which has greater user location data privacy protection. Nonetheless, iOS still allows acquiring the current connected wifi BSSID. A user can deny the location requests on an iOS device at will. However, an app using wifi BSSID can still get a user’s static location without asking.
So singling out Android in HN submission title is grossly misleading. Especially since reading this comments shows that people don't read the articles posted -_-
I have always considered HN the 'new Slashdot'
On iOS only the connected wifi will expose the BSSID.
Turn off promiscuous mode on iOS, don't join random networks, and you can't be tracked this way.