[HN Gopher] Help Us Find the Apps That Sell Your Location
       ___________________________________________________________________
        
       Help Us Find the Apps That Sell Your Location
        
       Author : giuliomagnifico
       Score  : 146 points
       Date   : 2021-10-07 13:40 UTC (9 hours ago)
        
 (HTM) web link (themarkup.org)
 (TXT) w3m dump (themarkup.org)
        
       | kiryin wrote:
       | It's truly mindbending that we've arrived at a point where a
       | database like this is necessary. What a sad and horrible
       | existence this is.
        
         | missedthecue wrote:
         | You should reflect for a moment about how you are fortunate
         | enough to live in the first generation where this is qualifies
         | for being "sad and horrible".
        
         | dylan604 wrote:
         | Having a database like this is useless unless the masses start
         | to care about the subject. There has yet to be a campaign
         | successful enough in educating/convincing the masses into why
         | this is a bad thing. For most, as long as the app allows them
         | to communicate with friends, entertains them (or their kids)
         | with a game, etc, and the app is free the masses just won't
         | care.
        
       | altdataseller wrote:
       | Is there a way to examine the libraries that an iOS app uses?
       | There might be a way to find apps that use common
       | libraries/frameworks that pass your location to other services,
       | if so.
        
       | bruh2 wrote:
       | If I understood correctly, this kind of database already exists
       | at https://reports.exodus-privacy.eu.org/en/
        
         | monkeydust wrote:
         | thanks for sharing - eye opening (!) - https://reports.exodus-
         | privacy.eu.org/en/reports/56347/ - 10MM downloads and 56
         | permissions on your phone. Toxic.
        
       | nubela wrote:
       | I really support this. We need clarity on which offending apps
       | are doing this. And it isn't just location data. It's also apps
       | which added a proxy backdoor powering networks like BrightData or
       | OxyLabs.
       | 
       | Or Contacts app that sell contact information to companies like
       | Lusha.
        
       | titzer wrote:
       | It is incredible to me that location data harvesting (aka mass
       | dystopian surveillance) is so pervasive that it requires a crowd-
       | sourced investigative campaign. A generation ago it was neither
       | technologically nor socially feasible to get even coarse-grained
       | location data on a person's whereabouts.
       | 
       | I hate this future. We sleepwalked into dystopia because money.
        
         | dylan604 wrote:
         | I don't know about the sleepwalking part. I'd say we sprinted
         | towards it. We've had dystopian scifi for much longer than
         | we've had the tech, but the reality makes some of the scifi
         | authors look like they didn't have much of an imagination. Now
         | that we've seen some of the "tech", the modern dystopian scifi
         | like Black Mirror scares the bejeebus out of me. There's
         | somebody out there that sees Black Mirror episodes and thinks
         | "YES!! That's exactly what we need!" Except, we have the tech
         | to actually do some of it.
        
         | streamofdigits wrote:
         | I hate it that not enough peope hate it enough for there to be
         | hope.
         | 
         | Its just mind boggling that society can self-devour in this
         | way, but apparently its part of "how things work"
        
           | newbamboo wrote:
           | Democracy doesn't work and populism is a scare word. Bet on
           | elite outrage or accept the future only a few sagacious,
           | disregarded malcontents warned us about.
        
         | amelius wrote:
         | All because of ads.
         | 
         | We should just ban all ads. That would solve all of these
         | problems.
         | 
         | If people feel they still need ads, we can create a nice
         | sandbox for watching ads.
        
           | boplicity wrote:
           | > We should just ban all ads
           | 
           | Please define what an ad is.
        
             | laserlight wrote:
             | I know it when I see it [0].
             | 
             | [0] https://en.wikipedia.org/wiki/I_know_it_when_I_see_it
        
               | boplicity wrote:
               | I'm not sure how true that is for advertisements. For
               | example, there are many forms of 'hidden' advertisements
               | that are designed to not be seen, and yet influence
               | people. Among them are product placements. Heck, even
               | Hacker News is an advertisement for YCombinator, though
               | it certainly isn't seen that way by many people.
        
             | [deleted]
        
             | 6gvONxR4sf7o wrote:
             | Comments like this are a weird form of semantic catnip nerd
             | sniping that unproductively derails the discussion. "We
             | should ban tall buildings." "Oh yeah? Well define exactly
             | how tall a tall building is." Clearly there's a thing as an
             | ad, because it's a common word everyone understands. If
             | your point is that it would be hard to pin down the part of
             | that that's actionable, well of course. It's always hard to
             | get regulations right.
        
             | [deleted]
        
             | m463 wrote:
             | Folks think advertisements are "showing me something I can
             | buy"
             | 
             | But really ads are a huge detailed dossier on every person,
             | being sold so that water filter companies can bid the
             | highest to get a water filter ad in front of the people
             | with the largest income.
             | 
             | Meanwhile, you like legos and lego will never be able to
             | bid high enough to show you a lego ad (probably they don't
             | need to anyhow)
             | 
             | and the off-label uses for these dossiers... I wonder if
             | used car salesmen can find out your "price insensitivity"
             | and charge accordingly?
        
             | ChrisMarshallNY wrote:
             | _> Please define what an ad is._
             | 
             | I made this comment[0], where I talk about "building buzz."
             | 
             | Basically, ads without ads.
             | 
             | [0] https://news.ycombinator.com/item?id=28788169
        
           | sebow wrote:
           | Well some way along capitalism it was "found" that it's more
           | effective to spend the money you could use to improve a
           | product to actually brainwash people into buying the product
           | (what would be ads here).
           | 
           | Ultimately it's also our, the "mass consumers" fault for
           | behaving this way, and for not upholding a certain value
           | regarding choosing a more quality-oriented
           | product/service.(and i might add: consuming less instead of
           | more frequently)
           | 
           | It's not really a fault of "capitalism", just reflects the
           | commodity some people fall into.Ads were always there,and
           | they always be, we just massively expanded the information
           | mediums where ads could be implemented.
        
       | dotBen wrote:
       | The app stores typically tell you what permissions an app
       | requires, including location.
       | 
       | It would seem to me to be more efficient to programmatically
       | analyze the permissions listed of the top 10,000 apps (or more)
       | than have readers send in random screenshots.
        
         | burkaman wrote:
         | > This will help us understand how these prompts are worded and
         | could help us identify apps that are using your location in
         | ways the app developer does not disclose.
         | 
         | They are specifically interested in how the location request is
         | worded for each app, and maybe at what point during usage it
         | asks. I think on Android the prompt is always the same, but
         | apparently on iPhones they can add a short explanation.
        
         | alufers wrote:
         | You would get a lot of false positives, meaning apps that
         | legitimately need the location. For example navigation apps or
         | unfortunately apps on Android which use Bluetooth.
         | 
         | This really annoys me, because the dialog looks the same for
         | apps that want to use GPS data and apps that use Bluetooth, and
         | there is no way to grant just Bluetooth permissions.
        
           | soco wrote:
           | And what do we do with apps which have a legitimate reason to
           | use your location, then proceed to sale your location history
           | to third parties? No confirmation dialog can save us from
           | that.
        
           | esc861 wrote:
           | Yes, and the same goes for information about the WiFi
           | network. Lots of apps for IoT devices require this
           | information to set up products, but the OS presents this as
           | location tracking.
        
             | ascar wrote:
             | Well, that's because scanning for WiFi networks and
             | Bluetooth devices nearby effectively reveals your location.
             | 
             | It might still make sense to split these permissions, but
             | it should be clear that you're giving up your location.
        
           | meibo wrote:
           | This is fixed in Android 12, BLE and Location are properly
           | disconnected now. The permission dialogue reads "determine
           | relative position of nearby devices" if you request BLE
           | access.
           | 
           | You can also declare that your app "never needs physical
           | location", which excludes BLE beacons that could be used for
           | that purpose from the data the app receives.
           | 
           | https://developer.android.com/guide/topics/connectivity/blue.
           | ..
        
         | anothermoron wrote:
         | I don't mind app that use my location for stuff which requires
         | it, what this project is meant to do is find who SELLS the
         | information.
        
         | SilasX wrote:
         | Yeah but that's not enough, I thought? Wasn't there that
         | scandal where Uber figured out your location anyway from the
         | WiFi access points you were near?
        
       | dreyfan wrote:
       | It's not just apps, it's the providers themselves. e.g. Sprint
       | sells customer location/app/usage data directly [1]. They don't
       | even try to obscure that fact.
       | 
       | > "Leveraging verified, first-party mobile data from more than 32
       | million mobile users straight off the network"
       | 
       | [1] https://www.inmobi.com/company/press/inmobi-
       | acquires-u.s.-ba...
        
         | e40 wrote:
         | The only solution to this is legislation. None of the
         | politicians seem to care, I wonder why (follow the money...
         | both sides of the isle are paid off).
        
           | brewdad wrote:
           | > both sides of the isle are paid off
           | 
           | The expression is both sides of the aisle since traditionally
           | each party sits on its own side of the legislative hall. I
           | like this use however since it suggests they are all off on
           | an island separate and distant from the rest of us.
        
             | [deleted]
        
       | mfrye0 wrote:
       | A friend introduced me to localblox.com a couple years ago to get
       | some company data, though it looks like they have already closed
       | up shop.
       | 
       | These guys seemed to have everyone's data. The demo started off
       | by showing me the company data we were interested in, but then
       | veered into picking a random person's life to delve into.
       | 
       | The deep dive began by showing work/education info, then went
       | into where they live, the cars they drove, how many kids/pets,
       | then even deeper into the location data...
       | 
       | They showed detailed maps of everywhere they went on a daily
       | basis. The routes they took to work, they places the visited,
       | etc.
       | 
       | Any of the data was for sale if we wanted it. It was beyond
       | disturbing. We obviously passed on working with them.
        
       | RegW wrote:
       | The article seems to make the assumption that this data is
       | collected by apps that would otherwise have no good reason for
       | requiring permission to access your location. Seems like a bit of
       | an assumption.
       | 
       | It strikes me that to build a useful location dataset, just one
       | widely used app would be more effective than any number of niche
       | apps asking for strange permissions. I would build an app that
       | provides many people with a really useful service that obviously
       | requires access to your location. So it would probably provide
       | some sort of mapping or navigation service. To consistently
       | collect data it might well force the user to have data enabled
       | rather than just hold the map data on the phone.
       | 
       | Perhaps I could also shut others out of this lucrative operation,
       | if I could just get my app pre-installed and enabled by default
       | on every phone.
       | 
       | Just speculating - who really knows.
        
       ___________________________________________________________________
       (page generated 2021-10-07 23:01 UTC)