[HN Gopher] Surveilling the Gamers: Privacy Impacts of the Video...
       ___________________________________________________________________
        
       Surveilling the Gamers: Privacy Impacts of the Video Game Industry
        
       Author : infodocket
       Score  : 38 points
       Date   : 2021-07-09 20:54 UTC (2 hours ago)
        
 (HTM) web link (papers.ssrn.com)
 (TXT) w3m dump (papers.ssrn.com)
        
       | api wrote:
       | Is anything not spying on you?
        
         | PenguinCoder wrote:
         | Board games and card games.
        
         | Dig1t wrote:
         | I don't think my Debian desktop computer is spying on me.. but
         | that may be the only computer that isn't.
        
           | teawrecks wrote:
           | _Might_ be.
        
           | shadilay wrote:
           | Are you sure the computer inside the computer (Intel ME)
           | isn't spying on you?
        
           | quesera wrote:
           | Many people are unhappy about Debian popcon.
        
             | Nextgrid wrote:
             | It's opt-in (and the preselected option is "no" so even if
             | you accidentally press enter you won't opt-in) and very
             | clearly explained during installation.
        
           | [deleted]
        
         | enlyth wrote:
         | I doubt it, I bought a new Sonicare toothbrush and it came with
         | an app to supposedly help you track your brushing or whatever;
         | I was curious so I installed it.
         | 
         | After updating my toothbrush firmware, I got a prompt on my
         | phone asking for it to track my location.
         | 
         | Why does my toothbrush need to know my location constantly?
        
           | anyfoo wrote:
           | I got that, too. I said "okay, let's try it out", but the App
           | wanted me to register and log in before even being able to
           | use it. Even with refusing location tracing, I just don't
           | feel like telling Philips when I brush my teeth, and how.
           | 
           | Luckily the toothbrush works perfectly without the App or any
           | Bluetooth connection at all, wouldn't have even noticed it
           | had Bluetooth if I hadn't looked at the packaging.
           | 
           | My treadmill was a bit different: While unpacking and
           | building, I saw what was probably 8 or 9 notices claiming
           | that the treadmill is "locked", has to be unlocked by
           | registering it with iFit, and _will_ not work otherwise. It
           | was everywhere: On the packaging, as a piece of paper inside,
           | in the manual, on the treadmill itself... New York Times had
           | an article mentioning you just have to hold down the  "iFit"
           | button for 20 or 30 seconds, and that unlocked it
           | permanently. Without having to pair with anything. Weird
           | world.
        
           | shadilay wrote:
           | What model is it? I recently bought a sonicare and it didn't
           | come with an app.
        
             | enlyth wrote:
             | DiamondClean 9000
        
           | 1ris wrote:
           | because bluetooth and gps are still not separate permissions,
           | i guess?
        
             | 542458 wrote:
             | On Android at least this seems to be the case. Bluetooth
             | leaks data that can be used to locate you, so Android just
             | ties the two permissions together.
             | 
             | https://android.stackexchange.com/questions/160479/why-
             | do-i-...
             | 
             | IMO this is counterintuitive for users. It would be like
             | telling people on windows "This app wants to wipe your C
             | drive" every time an app asks for admin permissions - it
             | _could_ wipe your C drive, but that's not what it's asking
             | for. IMO the permissions should be separate, but the
             | approval modal should note that info about leaking
             | location.
        
               | gruez wrote:
               | >IMO this is counterintuitive for users. It would be like
               | telling people on windows "This app wants to wipe your C
               | drive" every time an app asks for admin permissions - it
               | could wipe your C drive, but that's not what it's asking
               | for.
               | 
               | Well the flip side is that they don't warn the users
               | enough, and they get roasted by the media for "not
               | sufficiently warning the users" or "being complicit in
               | user tracking" or whatever.
        
           | [deleted]
        
           | GeneralTspoon wrote:
           | Bluetooth permissions are grouped in under the Location
           | permissions on both iOS & Android.
           | 
           | This is because Bluetooth _could_ be used to determine a
           | user's location by using beacons and constantly scanning or
           | whatever.
           | 
           | But this has led to nothing but endless confusion for users
           | (and constantly gets highlighted as suspicious in online
           | forums), so they really need to come up with better wording.
           | Like "This app is requesting Bluetooth permissions, which
           | _could_ be used to determine your location".
        
         | Negitivefrags wrote:
         | The paper isn't saying games are spying on you. It's saying
         | that if someone decided to analyse the data about someone
         | playing then they could infer certain things.
         | 
         | I mean sure I guess.
         | 
         | I'm pretty skeptical that this is really occuring though. I
         | mean, to what end?
         | 
         | As someone who runs an online game we have text logs of user
         | actions, yes. They sit there because it's useful debugging
         | info. A server crash happens and we look at the logs of what
         | the user was doing at the time. An exploit is reported and we
         | look at the logs of what the user doing the exploit did so we
         | can fix it. Etc etc.
         | 
         | I really don't know what nafarious thing people imagine is
         | really occuring.
        
           | spicybright wrote:
           | Same.
           | 
           | On a naive surface level of this, it's a game, not your
           | banking account. How much is really at stake here?
        
           | ev1 wrote:
           | > I really don't know what nafarious thing people imagine is
           | really occuring.
           | 
           | Unregulated anticheat software retaining user clipboard
           | contents, sending/uploading arbitrary files, all window
           | titles, all processes and computer and username, and any
           | other IPs on LAN and ARP cache, sending in plaintext across
           | country borders, ignoring GDPR/CCPA/etc.
        
             | LordOfWolves wrote:
             | In the meantime, most users with that anticheat software
             | installed presume that it is simply looking out for them,
             | in terms of eliminating cheaters in __ video game, and
             | could not possibly be doing the nefarious things you
             | mention. Yet, all of us working in software know this is
             | not a far stretch, given the application is already
             | designed to gather information about the environment
             | surrounding the running game. We have a long way to go with
             | software, put simply..
        
       ___________________________________________________________________
       (page generated 2021-07-09 23:00 UTC)