3 ms·
The address is used to show you a google street view pointing in the exact direction and part of the sky the satellites will cross. It's a super useful feature
by thefreeman 7y ago
The address is used to show you a google street view pointing in the exact direction and part of the sky the satellites will cross. It's a super useful feature because it would otherwise be really hard to tell what angle or what part of the sky to watch. And accusing the guy of harvesting PII? Get a grip.
- allovernow 7y agoLook I can't edit the comment now but this isn't the kind of information that could be collected without the warning. Especially since an address with an IP can be deanonymizing. I didn't click the "notify me" button but I imagine it's asking for either a phone number or an email. If this is truly innocent I'm sorry for my reaction, but you should be asking people first, given the current state of advertisement and surveillance on the net. We both read HN. It was a nice idea though.
- oarsinsync 7y ago> Edit 2: Jesus Christ man I had no idea I was giving you my fucking address. That's a little too granular for my taste So the accuracy of the location being provided depends entirely on your device. From a website (or any other app) perspective, they simply request the client provide it's location. Now if you happen to have a strong GPS lock on your device with 5m or less accuracy, that's not something the website (or app) knows ahead of time. > If this is truly innocent I'm sorry for my reaction, but you should be asking people first, given the current state of advertisement and surveillance on the net. We both read HN. Not trying to victim blame here, but if you're claiming more technical audience and concerns about privacy, are you genuinely unaware that this is how location services and permissions works? If so, I guess this is a painful learning experience for you. You're gonna have a bad time now as you think about how many different apps you've given location permissions too, because a lot of those apps will have a bunch of third party trackers involved that are connecting your IP, location, along with device identifier and any other information they can use to add to a much larger database to identify exactly who you are and everyone you know (think I'm exagerating on the last part? Have you ever shared your contacts list with an app like Whatsapp to find other contacts?) The internet today sucks. I don't think this particular author is the person you want to be pooping hard on, they're highly unlikely to be part of the problem.
- allovernow 7y agoAs a matter of fact I default to explicitly turning off all location permissions. I've gone to great pains to practice clean opsec. This is effectively a forced breach. I clicked on something cool expecting to be promoted for a zip code.
- pault 7y agoThat's fine, but as GP said, the browser geolocation API asks for location data from the device, and this is what it gives you back. Every app and website that has a "use my location" button will provide your latitude and longitude as accurately as possible, which is usually high enough to know not only your address, but also that you are currently in your downstairs bathroom. I'm also a bit surprised that you are technically savvy enough to maintain strict opsec but you didn't know how geolocation services work on a smartphone. Regardless, the developer of the website does not deserve your ire for using a common browser API. The app could be improved by offering a UI for entering a zip code, but they didn't set out to steal your PII.
- oarsinsync 7y agoFor this to be a forced breach, the website must be intentionally exploiting a security issue on the device to expose exact location coordinates. If so, I’d suggest perusing the source code, as there might be bug bounty money there. Or patching your device. EDIT: to be clear, this would also be a dick move by the website author and they should be publicly shamed more than this. Alternatively, they may be accidentally triggering a vulnerability (more bug bounty money or reasons to patch) Alternatively, you accidentally gave the permission for location services when prompted. Alternatively, your IP has a GeoIP location that is at / very close to your home address. If this is the case, GeoIP databases are like telephone directories of yore. Except not only are they globally public, you also cant opt out. Sorry!
- mirimir 7y agoI entirely understand your reaction. And I suspect that you're using a VPN service, given the comment about deanonymization. But really, this is exactly why it's kinda sorta pointless to use VPNs and Tor browser on smartphones. All it takes is one slipup, and your anonymity is toast.