19 ms·
Google collects metadata from Android phones
- deleted 10y ago[deleted]
- cm3 10y agoIs there an Android fork where this isn't a problem and which you could suggest?
- cm3 10y agoRelated question: given how short supported update cycles for Android devices are, which of the sub 100EURO Android phones on AliExpress are a reasonable choice in terms of installing an Android fork? I'm eyeing a cheap phone because I expect to buy another one in less than 2 years because of update support politics.
- renke1 10y agoNot <100€ but I can only recommend the Wileyfox Swift [1] which replaced my old Nexus 4 (which I really loved). It runs Cyanogen OS (a commercial version of CyanogenMod). [1]: https://www.wileyfox.com/swift/ https://www.wileyfox.com/swift/
- cm3 10y agoThanks for the suggestion. That one seems nice but too expensive for my use case. Since support cycles are abysmal, I'd like to get cheap devices and treat them almost as dispensable.
- retox 10y agoVery happy with my ulefone power, though there seems to be some hotspots on the backlight. Very capable device for the money.
- akerro 10y agoDepending on how it is implemented. If it's coded into Android OS that's a bigger problem, if it's included in Gapps, you can just remove them of block their connections on firewall. If I correctly understand `Last modified: June 28, 2016, they are writing`, this feature should not be available before that date, so either it comes as an update to a gapps or to Android.
- em3rgent0rdr 10y agoWell when you first boot a custom rom like cyanogenmod or replicant or self-compile android, there is no such terms that you have to agree to. So this privacy issue is not with Android Open Source Project, but rather with the proprietary google apps.
- ocdtrekkie 10y agoPart of the problem is the large percentage of apps that are now tied to proprietary Android, and won't run without Google Apps installed. Even Microsoft apps like Outlook and Skype won't load without Google Play Services installed. (The version of Skype on the Amazon Appstore is around a year old, and won't even take my login credentials.) So even if you find a relatively safe Android version to use, you're getting a heavily gimped experience where a very limited selection of apps work. (Generally, what you find on F-Droid.)
- api 10y agoHmm... so effectively Android is no longer open.
- ocdtrekkie 10y agoIt is a challenging definition, but I would argue that it is not. Because while the core OS is open, you are not effectively able to fork it. Google's developer advocates heavily encourages the use of proprietary Google APIs in app development, which binds those apps to Google's proprietary packages. I guess the question is how you define a platform or an operating system, but I think that the platform apps on it run off of is a major part of it. And the difference in what will run on AOSP and what will run on Google Play flavored Android is staggering.
- cm3 10y agoIs there a page to check what popular app does not work on F-Droid or Cyanogen? Say something like Nokia's mapping app.
- ocdtrekkie 10y agoI don't know, but please tell me if you find one. I have F-Droid and Play on my phone, and disabled Google Play Services to see how many of the apps I have installed and use continued to work. Many gave me "must update Play Services" dialogs, some just crashed outright. I've been trying to transition to open apps or apps available outside the Play Store, but unfortunately, Skype is one need I can't work around right now.
- api 10y agoCyanogen?
- 616c 10y agoIt's called Replicant. It is aggressively free in the GNU sense and has a limited installation base because of strict requirements in hardware due to blobs and general functionality. http://replicant.us/ http://replicant.us/ If you want a compromise, like me, Cyanogen with out GApps. What other options do you have? The more I got into Android, the sooner I realized it was a crap shoot when addressing your question and my core interests in hobbyist computing on phones just like computers.
- Magnets 10y agoThis code won't be in Android but in the Google apps which are pretty much essential if you want to use Android (Play store, Chrome, Maps, Google play Services) Play store alone has enough permissions to collect call metadata
- tshtf 10y agoIs the calling or called number only passed when "Caller ID by Google" is enabled? https://support.google.com/nexus/answer/3459196?hl=en https://support.google.com/nexus/answer/3459196?hl=en
- akerro 10y agoLooks like a different `spying` mechanism. The one described in the article also sends metadata about texts.
- lallysingh 10y agoCaller ID also applies to text messages, right? They have phone numbers on them too.
- thewavelength 10y agoDoes someone really wonder about that?
- cm3 10y agoDefinitely not since we've learned that (some) webpages send each keystroke while on the login page.
- techthroway443 10y agoWhat is this referring to?
- 27182818284 10y agoI believe this is referring to the ebay password submission that was on the front-page yesterday. The summary was that Ebay seemed to be sending each typed character of the password field back home.
- deleted 10y ago[deleted]
- sp332 10y agoAt least eBay https://news.ycombinator.com/item?id=12000820 https://news.ycombinator.com/item?id=12000820 and Twitter https://news.ycombinator.com/item?id=12002103 https://news.ycombinator.com/item?id=12002103
- unfathomable 10y ago> Facebook wants to know why you didn’t publish that status update you started writing. > Unfortunately, the code in your browser that powers Facebook still knows what you typed—even if you decide not to publish it.* It turns out that the things you explicitly choose not to share aren't entirely private. http://www.slate.com/articles/technology/future_tense/2013/12/facebook_self_censorship_what_happens_to_the_posts_you_don_t_publish.html http://www.slate.com/articles/technology/future_tense/2013/1...
- fredgrott 10y agobefore we jump to conclusions not based by facts..BB collects same info as part of device metric measuring..its a common secret that most mobile OSes both open source and closed source do this.. While BB gave Canda authorities access..Google by default does not..
- us0r 10y agoAre we really comparing BB to Android? http://cdn.bgr.com/2016/05/screen-shot-2016-05-23-at-9-03-37-am.png http://cdn.bgr.com/2016/05/screen-shot-2016-05-23-at-9-03-37...
- aioprisan 10y agoWe're not comparing market share, but privacy policies.
- _Understated_ 10y ago> Google by default does not.. Not to be a tinfoil-hatter but can you be 100% sure of that?
- jswny 10y agoAre people really surprised about this anymore? I can't say that I am. Google is a company which makes a lot of money off of their platforms. I expect them to be collecting data wherever and whenever they can. I see stories like this every day but I've become accustomed to it because it's such a normal practice nowadays, especially from a company like google which provides so many advertising services. I'm not saying this is a good thing, absolutely not. I'm just saying that I've come to expect this kind of thing in the current day and age.
- supernovae 10y agoMaybe not surprised, but they begrudge everyone else for this more than they do google, and that's what I think sucks. It seems OK for Apple/Google to do whatever they need to do to have a competitive app store with all its analytics and understanding its customer to sell it advertising but if other companies do it, its all the sudden the sky is falling
- toyg 10y agoIt's probably because Google is perceived as giving you something like search, email, maps etc, which is very valuable, and "in exchange" it does stuff that does not directly impact your life. Similarly with Apple, which also works as a status symbol. The sequence is also important: first they build services and products, sell (or give away) them on their merits, and then turn the analytics to 11. Doing both at the same time is a no-no, but once a user is dragged in, natural laziness and other migration costs kick in. They are long cons, and to be fair, the products are pretty nice.
- KeepFlying 10y agoThe products are very nice. And to a point I have started to trust Google innately. Not that that is necessarily a good thing. I understand their need for data. It makes business and technical sense. I just wish they made more of an effort to anonymous it. (but that won't happen as long as ads are the primary market of the web)
- thatcat 10y agoIt mentions that google collects the data in server logs, the telephony in this case may be referring to google voice and not android OS since using android doesn't necessarily imply you're using google servers. (The play store, google services, etc does but can be avoided)
- lost_name 10y agoFor what it's worth, I have my doubts that this applies to a generic call/sms on any old Android device. I would think it's more likely to apply to services such as the Hangouts calling or Google Voice, and probably Google Fi, all of which make sense to collect that data, but the privacy policy doesn't absolve itself of that. > When this Privacy Policy applies > Our Privacy Policy applies to all of the services offered by Google Inc. and its affiliates, including YouTube, services Google provides on Android devices, and services offered on other sites (such as our advertising services), but excludes services that have separate privacy policies that do not incorporate this Privacy Policy.
- danieldk 10y agoFor what it's worth, I have my doubts that this applies to a generic call/sms on any old Android device. Does it matter? This is completely in line with their privacy strategy the last few years. Slowly add new terms to the privacy policy, so that people find it acceptable. When asked, point to some unharmful or obvious application. At any rate, it makes it possible to do what the article stated. And since a lot of stuff happens in Google Play Services these days, it becomes kind of hard to find out how the privacy statement is operationalized.
- deleted 10y ago[deleted]
- gavinpc 10y agoTheir "Machine learning first" position[0] makes them even more dependent on data collection, even for basic things. I doubt the two trends are unrelated. [0] https://news.ycombinator.com/item?id=11954988 https://news.ycombinator.com/item?id=11954988
- ucaetano 10y agoThis isn't a trend, they've collected such data since 2012.
- deleted 10y ago[deleted]
- cm2187 10y agoBut what is the paid alternative of all this privacy invasion? Even Apple is doing it now.
- avckp 10y agoBlackphone would fit the bill [1] https://www.silentcircle.com/products-and-solutions/devices/ https://www.silentcircle.com/products-and-solutions/devices/
- ucaetano 10y agoIf not enough people are willing to pay, nobody will create an alternative.
- sygma 10y agosource?
- GrumpyYoungMan 10y agoFrom a recent HN article: http://blog.cryptographyengineering.com/2016/06/what-is-differential-privacy.html http://blog.cryptographyengineering.com/2016/06/what-is-diff... "Starting with iOS 10, Apple is using Differential Privacy technology to help discover the usage patterns of a large number of users without compromising individual privacy." To paraphrase, Apple has been collecting telemetry all along and is announcing that they're starting to a new proprietary algorithm to obfuscate it a bit.
- artimaeis 10y agoYou and I are reading that a different way. I see it as they're going to be able to collect this data for the first time since they've found a way to do so without compromising privacy. Their privacy page seems to agree with my interpretation: https://www.apple.com/legal/privacy/en-ww/ https://www.apple.com/legal/privacy/en-ww/ Though since iOS is closed source - we can't know for certain.
- 10y ago
- hvass 10y agoIt says this right before the bolded part: "When you use our services or view content provided by Google, we automatically collect and store certain information in server logs. This includes:" I am not sure this applies to regular phone calls, no? Can someone explain here because I am certainly not understanding. Is this only for, say, Google Voice or related services that they have?
- theGimp 10y agoI actually imagine it does apply to most regular phone calls. Google offers a reverse lookup service in recent versions of Android. It fills in the name of the caller if it's not in your address book. In all honesty though, you are prompted about whether you want to use this feature.
- chappi42 10y agoA Gooxit would be in order. From time to time I wonder why the EU accepts foreign companies stealing so much personal data. China did the right thing. We should learn from them. India, afaik, also has better protection.
- deleted 10y ago[deleted]
- toyg 10y agoClassic example of the difference between nation-states and macro-powers btw. Should an individual market, even a rich one like the UK, complain about this and that, Google would shrug. But when it's the whole of the EU talking, they better listen.
- k-mcgrady 10y ago>> From time to time I wonder why the EU accepts foreign companies stealing so much personal data. Isn't the EU trying to fix this by tearing up safe harbour and instituting new legislation?
- djsumdog 10y agoI moved my e-mail off Google a few years ago after the PRISM leaks (which the world seems to have collectively forgotten about), but it's not easy. I've posted an article before on my struggles with running my own e-mail server and my messages going straight to spam (even with valid DMARC, DKIM and SPF records). I have a lot of friends internationally and I feel I can't exit FB, Google Hangouts, etc. The idea of federated social networking never really made it. :(
- avckp 10y agoSo we need a fork that runs sans Gapps
- em3rgent0rdr 10y agoAlready exists: Use cyanogenmod or replicant, and don't install google play services or any google apps.
- awqrre 10y agoI would rather have a true GNU Linux phone/mobile computer...
- CaptSpify 10y agoI would pay a decent amount for a good phone like this. I'm wondering how the ubuntu phone is doing. I'd love it to become available
- DKnoll3 10y agoWhat do you think of this? https://pyra-handheld.com/boards/pages/pyra/ https://pyra-handheld.com/boards/pages/pyra/
- kxyvr 10y agoI've thought about getting a Pyra and then trying to use it for regular phone calls as well. What's not clear to me is what the landscape is for telephone software running on Linux that directly accesses the sim card. Does anyone know? I recall there being a libgsm, but a quick search isn't pulling up much information. I also recall there being at least two Raspberry Pi phone projects, this being one of them: https://learn.adafruit.com/piphone-a-raspberry-pi-based-cellphone/overview https://learn.adafruit.com/piphone-a-raspberry-pi-based-cell... The software for this project can be found on github: https://github.com/climberhunt/PiPhone https://github.com/climberhunt/PiPhone Candidly, the code there looks pretty simple. Most of it is using pygame for the graphics and then just sending serial commands to the modem. It looks like most of the complicated functionality is just part of the chip. Anyway, yes, I've thought about doing a phone implementation on top of some kind of Linux distribution and Pyra was high on that list. If someone else has some information or knows of other projects that have done this, please let us know.
- ucaetano 10y agoJust go on activity controls and disable "device information": https://myaccount.google.com/activitycontrols?hl=en&pli=1&otzr=1 https://myaccount.google.com/activitycontrols?hl=en&pli=1&ot...
- jeromeflipo 10y agoI disabled every control on this page months ago. Unfortunately, the Google Maps app won't remember searches unless you're logged in and share your entire location history. There's just no way to keep a local history of places in Maps. I'll get rid of Google Maps as soon as Maps.me let me stream OSM maps instead of downloading packages one-by-one.
- ocdtrekkie 10y agoYeah, this is one of those extreme punitive peeves about the way Google has written it's products. It's either "we get all your data" or "even you don't get your data on the same device". There's no good reason not to let location history work on the local hardware.
- AstralStorm 10y agoA very good reason for Google though - they want your data. As is not providing full API to their service.
- deleted 10y ago[deleted]
- tdkl 10y agoI voted with my wallet, bought an offline navigation app and disabled Maps.
- ucaetano 10y agoAnd I applaud that, even if I wouldn't do the same. People need to understand that in a competitive market, you vote with your wallet. There's no such thing as a free lunch.
- 616c 10y agoI don't care what people say, the ethics, or legality, you should consider dumping fake identifying info. http://xposed.info/ http://xposed.info/ http://xprivacy.eu/ http://xprivacy.eu/ Use apps from other app stores, in my case F-Droid.
- gvurrdon 10y agoThe functions of which xprivacy is capable seem excellent. Unfortunately, when I tried it I found it to be an enormous hassle to use. The UI was bad enough but upgrading Cyanogenmod with xposed and xprivacy was more of a nuisance. Cyanogenmod's Privacy Guard is easy enough to use though its protections don't go as far as I'd like. Pdroid seemed to be a reasonable compromise in ease of use and protection between the two, though that seems no longer to be available.
- 616c 10y agoPrivacy Guard will not allow API calls and stuff them with fake data, which I imagine is not possible with Cyanogen or any conventional outfit for legal and regulatory reasons. I do not think the UI is great, but articles like this are not either. I made my choice.
- gvurrdon 10y agoIndeed, Privacy Guard can't do that, unfortunately.
- deadowl 10y agoI know that at least Sprint already does this. You can typically see your call log on the bills, but getting text messages requires a notarized form. https://support.sprint.com/support/article/Get_your_text_message_usage_details/a9035f32-ee60-43ec-8895-d9c84712488d https://support.sprint.com/support/article/Get_your_text_mes...
- gsnedders 10y agoPretty much every telecom company keeps call logs for the sake of verifiability of the billing.
- throwanem 10y agoTelecom companies have a reasonable need for the information. (It's also impossible for them not to have it; otherwise they couldn't provide service at all.) Device manufacturers, not so much.
- goombastic 10y agoHalf the enterprise apps I know stop working on cyanogen. Is there an alternative? Also is there a way to separate work and personal phone usage on a single device? Tools like mobile iron seem to demand all of my info be made available for whatever it deems fit for the corporate I work for.
- dublinben 10y agoThe alternative is a physically distinct work and personal device. This has been the solution for many years. Only recently have people wanted to "BYOD" and use their personal device for work purposes.
- throwanem 10y agoOn that point, I very recently discovered [1] that connecting an iOS device to an Exchange account via ActiveSync enables the organization's Exchange administrators to remotely wipe the entire contents of the device - not just the content actually provided via the account, but everything. I am astonished and disappointed that Apple saw fit not to warn the user this could happen. Even Google gets this right; when you connect an Android device, you get a warning and are required to confirm before proceeding. It's inexcusable that Apple doesn't do the same - while I understand and agree with the reasoning behind the existence of the capability, the fact that it's silently enabled is appalling. [1] Yes, I know it's hardly news, but (I flatter myself that) I'm generally reasonably savvy, and if I only just found out about it, then there's probably someone else reading this thread who could benefit from it being mentioned. So I mention it.
- jevinskie 10y agoIt is news to me. I thought iOS simply didn't implement that functionality without being enrolled in MDM. With Android I knew about it and was able to build a custom firmware with that functionality disabled. I wonder if you can make an Exchange proxy that frees your iOS device via filtering.
- evilduck 10y ago
- JTenerife 10y agoAnd people freak out about some Microsoft telemetry collection.
- userbinator 10y agoUntil very recently, Microsoft's business model had not been about profiting off collecting user information. They were one of the last remaining companies who didn't attempt to monetise the crap out of their users.
- Spivak 10y ago> who didn't attempt to monetise the crap out of their users. * By using and selling user data and profiles. There's a reason people still refer to them as M$.
- whoopdedo 10y agoBecause they would eliminate all viable competition then jack up their prices knowing that customers were locked in. Microsoft is late to the monetization of data game.
- 0xmohit 10y ago> Until very recently, ... And then Microsoft acquired LinkedIn.
- RhodaLs 10y agoFor the same reason people freaked out about a very easily disabled Amazon search integration in Ubuntu. People had higher expectations of Microsoft (and Canonical) than Google. Plus, the desktop / laptop environment is one in which regular monitoring outside of the browser is something usually only done by malware. Microsoft should have recognized they were considered more trustworthy, in one sector anyways, than Google or Facebook. Building on that trust by building a Windows 10 with great privacy would have helped their reputation and stemmed the bleeding a bit. At any rate, I have no idea why MS doesn't just allow a "disable all tracking and telemetry" option on all versions of the OS. Would kill most of the complaints immediately, and most people wouldn't bother opting out so Microsoft would still have the data they think they need.
- williesleg 10y agoSomebody's gotta do it. Information is power. Google, Microsoft, Amazon, Apple, heck, everybody except Intuit know that.
- delroth 10y agoThe article seems to imply that this is a recent addition to the privacy policy. Google keeps archived versions of their privacy policies (https://www.google.de/intl/en/policies/privacy/archive/ https://www.google.de/intl/en/policies/privacy/archive/), and you can easily see that the "telephony log information" was added in the March 1st 2012 revision of the Google privacy policy. You can see a summary on https://www.eff.org/deeplinks/2012/02/what-actually-changed-google's-privacy-policy https://www.eff.org/deeplinks/2012/02/what-actually-changed-... As the EFF mentions, this was a big privacy policy change, and it was widely announced. For example, I searched through my emails right now and found an email from Google (on my @gmail.com address) on 2012-01-28 announcing the change and asking me to "please take a few minutes to read our updated Privacy Policy and Terms of Service at http://www.google.com/policies" http://www.google.com/policies". For completeness sake, the diff from the changes on June 28th: https://www.google.de/intl/en/policies/privacy/archive/20160325-20160628/ https://www.google.de/intl/en/policies/privacy/archive/20160... Disclaimer: I work at Google, but not on anything related to this. I speak for myself, not for the company. EDIT: Interestingly, the language in the 2012 unified privacy policy matches very closely the language that was used in Google Voice's privacy policy since 2009: https://web.archive.org/web/20090315193708/https://www.google.com/voice/help/privacy https://web.archive.org/web/20090315193708/https://www.googl... > Google's servers also automatically collect telephony log information (including calling-party number, forwarding numbers, time and date of calls, duration of calls, SMS routing information, and types of calls).
- jsprogrammer 10y agoAccording to that diff, Google moved from opt-in sharing of DoubleClick cookies, to...potentially default-in, with a possible opt-out option buried in some unidentified settings page?
- gcb0 10y agogotta love the double standard. when verizon did their super cokie, everyone went crazy (as they should). now that its google (doing that since before verizon it seems) the top coment is a googler throwing the issue to the side in a hitchhikers-guide-to-galaxy way ("you should have checked the alpha centaury records in 2012")
- known 10y agohttps://github.com/SilenceIM/Silence https://github.com/SilenceIM/Silence
- reacharavindh 10y agoSo, we are pretty much bound to choose between Android and iOS, because of the whole apps platform thing. I've always considered Google to be evil if not proven otherwise. It is a simple conflict of interest to trust Google with the user's privacy. They make money by creating profiles on users and serving relevant ads. I'd be an idiot to keep on asking them to play nice and respect my privacy. Apple on the other hand seems to be aligned to respect privacy in principle, and publicly claims it doesn't violate user's privacy. But, there is no way to verify their system because of the proprietary nature. So I treat them as less evil. Before you suggest something like Replicant. They are only slightly better than the feature phones because of the lack of the new and fancy apps and with a label that reads "If you need serious privacy stay away from any telephony-enabled device" http://www.replicant.us/freedom-privacy-security-issues.php http://www.replicant.us/freedom-privacy-security-issues.php So, I guess the only choice is to stay paranoid and not trust your phone with any sensitive private data.
- noir_lord 10y ago> So, I guess the only choice is to stay paranoid and not trust your phone with any sensitive private data. Your metadata is sensitive private data, who you call, when you call them and how often you call them is sensitive. Suicide Hotlines, Charities for LGBT people, Medical Numbers etc all build a picture about you and that's beyond personal contacts.
- tdkl 10y agoCompanies should rather post diffs, not "we updated the policy".[1] I don't intend to spend my time to go through myself, it's hard enough for one company, not a myriad of services we use nowadays. But I guess this is a nasty way to implement some unpopular policies, then point the finger at the user stating he complied to it. [1] And by fixing this I mean make it a law.
- jvolkman 10y agoGoogle does provide diffs. https://www.google.com/intl/en/policies/privacy/archive/20160325-20160628/ https://www.google.com/intl/en/policies/privacy/archive/2016...
- tdkl 10y agoThanks, didn't know that, I stand corrected in Googles case. Is this linked with the initial statement sent to users ?
- whoopdedo 10y agoI assume the reach of HN means more than a few people who are reading this thread are currently working with telemetry or tracking data. Yet rarely do I see any posts offering an insider's perspective of how it is used. Obviously there are privacy and ethical barriers, not to mention NDAs. But without the opposing view these discussions are always heavily slanted toward the "data collection is bad" opinion with no evidence that the data being collected is actually being used in the nefarious ways being speculated. Who will be the Snowden of the advertising industry?
- EdSharkey 10y agoGoogle tells you what it's doing with the data in the terms of service, though. What more do you need to know from a whistleblower that isn't already disclosed?
- VOYD 10y agoduh.
- cm3 10y agoThis most likely also collects call (meta) data about any phone called from Android and anyone calling a number terminating on an Android phone.
- packetslave 10y agoSays the guy using a free gmail.com email address.
- blahi 10y agoDon't let facts ruin a good outrage. This is HN and we like to be hypocrites.
- dang 10y agoPlease don't post unsubstantive comments.
- lostlogin 10y agoDepends when the service was signed up for as I see it - it used to be less creepy.
- gvurrdon 10y agoIndeed, I got a Gmail account when it was invitation only, and back then it didn't really seem particularly sinister. It was also very useful compared with the other services which were available (the excellent spam filtering was notable). Although I'd rather not I still use it mainly because the Inbox application is excellent and it is useful to be able to search my email archives. I have other accounts as well, of course.
- retox 10y agoWell 'decrypted', that's my spam account.
- dang 10y agoPersonal attacks, which that crosses into, are not allowed on HN. We detached this subthread from https://news.ycombinator.com/item?id=12016316 https://news.ycombinator.com/item?id=12016316 and marked it off-topic.
- blahi 10y ago
- namesbc 10y agoThis clause was carried over from the Google Voice privacy policy when Google merged all of their policies into one in 2012.
- nthcolumn 10y ago"Fuck these guys"
- nameless912 10y agoIn other news, water is wet.
- jalami 10y agoAs I've said before, I'd love to have an open source dumbphone. I know there are some big duct tape and PCB examples out there, but something polished and minimalistic would be fine with me. I think there would be a solid niche market in the current climate. I wouldn't buy a new one every other year and it would be way easier to lock down. You can't buy an open source 2d printer, but can buy and build 3d OSS ones no problem. In like kind, I don't think people find dumbphones interesting anymore, sadly. Actually, why print at all when you can "Google Cloud Print"?
- Johnny555 10y agoI'd be more upset about this if I weren't already using Google Voice and Hangouts to make all of my SMS's and calls so I know Google is watching - I'd rather give that info to Google than give it to my telco.
- okgooglestop 10y agoTo me, this is no different than someone from Toyota demanding I tell them where I'm going, who I'm going with and for how long every time I drive somewhere because I drive a Toyota and those are the terms. Google is kinda like having a psycho girl/boy-friend that wants to know your every move. Creepy.
- ak4g 10y agoThis is completely fucking ridiculous. Of course Google's privacy policy says they can store that information. That's why I can go to google.com/voice and get a comprehensive, time-ordered, millisecond-precision (if you poke around the network tab a bit - I forgot that epoch values started "12" back then!) list of > your phone number, calling-party number, forwarding numbers, time and date of calls, duration of calls, SMS routing information and types of calls. that I have made over the past 6 years, 10 months, and 20-something days. This is a service they provided, that I'm using, if the data were not there, I would have gotten rid of my gvoice number, found a service that preserved my data like any self-respecting service provider (I'm really at a loss here - is this not available on iOS?) and complained loudly that Google Caused Data Loss For Users and should probably get hit with a lawsuit for damages. I cannot believe how one-sided the discussion here is. The claim that GOOG is capturing all this data on all calls and texts on all android devices is -completely- unsubstantiated. There's one link to a german-language blog, whose (admittedly, Google-) translated claim seems to be that they tested - a - phone. One. With phone calls. Did they test SMS too? Was there a network connection to google's servers? The omission could just be the translation, but right now I think this is actually a story with 181 comments about, at most, a phone that also has hangouts, that pings the server to tell google to mark their user as being in a call. Completely ridiculous. My only affiliation with Google is as a user. Oh, and let's not forget here, that if Google were trying to subtly reinterpret "your use of our services" as "we capture everything from all Android devices", why on earth would they do a time-synchronized, easily-reproducible log when the call starts? (And how would they already have the call duration, blah blah blah at that time?) I can assure you, they're quite familiar with queuing data on the device to be sent later. The most irritating comment thread I've read in a long time. None of what is being claimed is even remotely cogent, on the face of it, and the reaction is just an endless woe-is-me of "what did you expect, we all saw this coming, what can ya do, the companies these days, they're just not like they used to be" I mean, is this a brexit hangover or what? Just sprinkle on a little "the NSA does exactly thing tho omg" and "metadata===murder" (yup, I think of you as js fanboys, that's how bad it is) just and... yeah, the expletive is necessary. Completely fucking ridiculous.
- martinza 10y agoNo shit
- partiallypro 10y agoEvery major OS collects telemetry data, and most mobile OSes have an "advertising ID" (which you can disable.) This is to be expected in a world of "big data."
- test_pilot 10y agoI was typing in a mac terminal, and needed to google something unrelated. Only to find google auto suggested on a very obscure command I just typed into the terminal. I'm almost certain keystrokes are logged when the chrome browser is running on a mac.
- KDewciKy 10y agoOr... confirmation bias.
- 0xmohit 10y agoThe question to ask is whether Google would release a sequel to "The Lives of Others" [0]. [0] https://en.wikipedia.org/wiki/The_Lives_of_Others https://en.wikipedia.org/wiki/The_Lives_of_Others
- YeGoblynQueenne 10y agoAdditionally, Ursidae defecate in forest biomes.
- b1daly 10y agoI'm somewhat amazed at the near uniformity of opinions on this thread that having such information collected by Google (or other company) is an obvious bad thing. And that decision of millions of everyday people to give up their "privacy" in such a way is a very unfortunate reality of modern life. I am open to argument, but it seems to me that most experience of terrible problems on the internet come from malware, browser hijacks, spam, basically the actions of criminals. IMO, the only hope for a "civilian" in maintaining a semblance of online security is to rely upon the large providers of mass computing services. I do not know of anyone who has had a negative experience as the result of not having a high level of online privacy. From actions undertaken by the government or business. The closest I know of is cases where individuals have been arrested on possessing or accessing child porn. There are also numerous examples in the media of people involved in the drug trade, or sex industries. I don't think your average citizen is going to be swayed by such accounts that they should undertake costly efforts to protect themselves from such activities. On the contrary, I would hazard a guess that they would see the surrender of such "liberties" to be a net benefit to society. I'm not saying this is a correct view, I could be persuaded that it's not, but I have yet been so persuaded. I'm befuddled by apparent disconnect here.
- a_imho 10y agoprism company in data collection shocker
- partycoder 10y agofrom google browser bar to google browser to google os to google isp. so nosy
- dlmetcalf 10y agoThis is why it annoys me so much when apps like Signal refuse to run on open source Android, yet claim to be pro-privacy and call anyone who doesn't like it "FOSS moralists". What privacy?
- freemius 10y agoIf you are using an Android or any other Google product you should assume every piece of data is being collected. If you don't want that, move to iOS.
- rpgmaker 10y agoIt's a minor quibble but is it accurate to put the project under the US "government" umbrella (@usgov)? I don't think the USG existed in any meaningful sense before confederation.
- mspielkamp 10y agoI’m managing editor of mobilsicher.de (https://mobilsicher.de https://mobilsicher.de), the news site this story originated from. We are a relatively new site (launched in Sept. 2015) and only now looked into this. The fact that it had remained undetected because no one had taken a closer look at it for several years does not mean that the questions we ask are unwarranted. Peter Schaar, former German federal commissioner for data security and - at the time - chairman of the ARTICLE 29 Data Protection Working Party of the EU, says Google’s practices may even violate fundamental rights under German and European law. The current German federal commissioner for data security is looking into it because of our reporting, so does the commissioner for data security of the German federal state of Hamburg, which has authority over Google because the company’s German headquarters are located there. We will hopefully hear from them shortly on how they assess the situation. Also, a request for a statement from the Irish DPC (Google’s EU headquarters are located in Dublin) is under way. Researching our original story, we of course asked Google to answer our questions on whose data exactly is collected under the provisions of the private policy, what data is collected, for how long, where it is stored and why Google thinks it can justify this data collection and processing on consent to their terms and services alone. Now, after the story was picked up by dpa, Germany’s largest national news agency, and several influential tech news sites (German language only, Golem: http://www.golem.de/news/ueberwachung-google-sammelt-gespraechsprotokolle-von-android-geraeten-1606-121856.html http://www.golem.de/news/ueberwachung-google-sammelt-gesprae... | heise: http://www.heise.de/newsticker/meldung/Google-Wirbel-um-private-Vorratsdatenspeicherung-mit-Android-3252902.html http://www.heise.de/newsticker/meldung/Google-Wirbel-um-priv...), Google has now issued a statement that poses more questions than it answers. We published our story today (https://mobilsicher.de/aktuelles/google-speichert-telefondaten-welche-bleibt-offen https://mobilsicher.de/aktuelles/google-speichert-telefondat...) and also provided an English language version (Google admits it collects telephony log information, doesn’t specify which exactly - https://mobilsicher.de/uncategorized/google-admits-it-collects-telephony-log-information-doesnt-specify-which-exactly https://mobilsicher.de/uncategorized/google-admits-it-collec...) because we think this discussion is very relevant for an international community. We are a small team but will keep reporting on this, trying to clarify the legal situation as well as the technical details. For this we’ll be doing more of our own analysis. In case any of you has helpful information, i.e. logs showing telephony data being transmitted to servers, please let us know (m.spielkamp at mobilsicher.de). But please make sure it can be reproduced by us, otherwise we’ll have a hard time using it.
- justifier 10y agoi always assumed they went with 'ok, google ..' so that it could be legally considered consent