7 ms·
Hi everyone. I wanted to start a company that builds privacy preserving/enhancing products+services. The first product was this location sharing service (scratc
by apayan 6y ago
Hi everyone. I wanted to start a company that builds privacy preserving/enhancing products+services. The first product was this location sharing service (scratching my own itch), and my friend said I should just put it out there to see if anybody is actually even interested in it. The code is AGPL [1], the crypto is based on libsodium and the mobile apps are all native.
I’d like to find a way to charge for this service so I can spend more time on it, and building other privacy preserving services, but I’m not sure of some things:
* Is this a service you would use?
* Would you pay for it?
* Would you or your company sponsor it?
Happy to answer any questions you may have. Any feedback is appreciated.
P.S. I'm sure you may be wondering "where is the iOS app?". It's coming. Real soon. Now'ish. Later. It's currently undergoing a UI overhaul, and because all of the people I share with are Android users, it hasn't been as high of a priority.
[1] https://github.com/zood https://github.com/zood
- 0x53 6y agoMy wife and I currently use Google maps to share locations with each other. I really hate doing this because I really dislike Google having access to my location. So yes I would use it. I would probably pay $15-20 once or a $1-2 a month for something like this
- thewojo 6y agoNo JS on the website (so far)…nice. Interesting. Been thinking about something like this. You mentioned other privacy preserving services; which products do you think are most in need of privacy preserving alternatives?
- apayan 6y agoFor Zood Location, I'd like to add a 'Find my phone' feature. It's already mostly done in the Android client (I don't think it's possible on iOS). I just need to implement a landing page on the web that folks can use to log in and make their phone start ringing. Re: other services. I'd like to implement something akin to Google Photos but where all your images are encrypted before going up to the cloud for storage. All the fun face recognition features and indexing would have to happen on your phone, but phones are plenty powerful enough these days to do that while you're sleeping and your phone is plugged in and charging. I'd like to implement a simplified personal assistant like Google Now, that doesn't depend on sending your personal data into the cloud. Again, phones are so powerful and they already know so much about you based on local context, that I think there's a big opportunity for making a "good enough" assistant that doesn't compromise your privacy. More mundane, but I think still very useful, is being able to store your contacts in the cloud, but making sure they're encrypted with a local key you control, so the storage provider (e.g. Zood) can't see your contact list. An actually trusthworthy VPN provider. Mozilla entered this space a couple months ago, and I think it's great that there is at least one trusthworthy VPN brand now. It's a very confusing market for people to navigate, but I'd like to earn the trust of people so a Zood VPN product would become a viable service. Along the theme of helping people extricate themselves from the advertising and surveillance economy, a service that helps people remove themselves from these junk snail mail lists. You can do it on your own right now, but it can be overwhelming. I have lots of other little ideas, but they aren't quite ready for discussing. :-)
- wh33zle 6y agoRe Google Photos: Checkout "Stingle Photos" [1], very similar stack to what you described. [1]: https://stingle.org/ https://stingle.org/
- novok 6y agoThere is also https://www.mylio.com https://www.mylio.com which E2E encrypts photos on the cloud, is iOS, Android, Windows and macOS and is very performant. There is also photostructure, but they don't seem to be planning to make mobile clients any time soon :| One thing I've actually not seen is E2E contacts & calendars. Everything seems to be based on CalDAV & CardDAV which I think forces you to sync them with a server in plaintext. Email is mostly a lost cause, the closest you could approach it is something like protonmail AFAIK. Also as far as 'good' VPN providers, I think PIA & Mulvad have fairly good reps. Mulvad even lets you pay in mailed in cash.
- mceachen 6y ago> There is also photostructure.com, but they don't seem to be planning to make mobile clients any time soon :| Sorry about that. I certainly get the appeal of "one app to rule then all," but as an indy solo dev, I have to focus on building features that give my users the best bang from my limited time. File sync is surprisingly hard to do cross-platform--most apps have pretty abysmal app store ratings, including the built-in ones from NAS manufacturers. I personally use Resilio Sync as a one-trick-pony that just copies my smartphone photos to my NAS. There are several other apps to that do this, as well: https://photostructure.com/faq/how-do-i-safely-store-files/#how-do-i-back-up-files-on-my-phone https://photostructure.com/faq/how-do-i-safely-store-files/#... PhotoStructure's sync process then automatically finds and imports new files into my library. A homepage bookmark icon on my phone that links to my personal PhotoStructure library works well.
- apayan 6y ago> One thing I've actually not seen is E2E contacts & calendars. Everything seems to be based on CalDAV & CardDAV which I think forces you to sync them with a server in plaintext. Email is mostly a lost cause, the closest you could approach it is something like protonmail AFAIK. Totally agree. I think the natural progression of things to replace would be contacts and then calendaring. For the life of me, I can't figure out what should/how to replace email. Or simply make it more secure for the masses.
- rasengan 6y agoThis is a hell of an idea and very important. I have a question though - by enabling location sharing on device, is the location not being leaked to Apple and Google regardless? Either way, awesome idea and love to see what you’re doing.
- apayan 6y agoThanks for the supportive words rasengan. :) My current understanding is that location data is not leaked to Google or Apple by just enabling location services (I'm always happy to be proven wrong :-) ). In the case of Google/Android, they make it very easy to unknowingly opt-in to sharing your data with them, but it's not too hard to double check that and disable+delete the data it if was on [1]. I know there has been much news about Google providing police with a list of devices near the time and location of a crime, and I believe that data is coming from the Location History feature of Google accounts. But that's something that can be turned off. Apple more explicitly requests the data via app permissions on your iPhone, so it basically comes down to what Apple apps to which you've given location permission [3]. [1] https://support.google.com/accounts/answer/3467281 https://support.google.com/accounts/answer/3467281 [2] https://support.google.com/accounts/answer/3118687 https://support.google.com/accounts/answer/3118687 [3] https://support.apple.com/en-us/HT203033 https://support.apple.com/en-us/HT203033
- StavrosK 6y agoIt is, to get back coordinates you have to use Google's location API, which tells Google where you are. That's why the actual app doesn't matter to me (a privacy advocate) because no matter how private your app is, Google will always have my location. Nowadays I just keep the GPS off unless I need to use Maps, hopefully that does something.
- lern_too_spel 6y agoOn Android, the user can disable Google Location Services and still get location from the GPS sensor. https://support.google.com/accounts/answer/3467281?hl=en#location_accuracy https://support.google.com/accounts/answer/3467281?hl=en#loc... This is not possible on iOS. If your app gets a user's location, Apple will get it also. https://support.apple.com/en-us/HT207056 https://support.apple.com/en-us/HT207056 "To use features such as these, you must enable Location Services on your iPhone and give your permission to each app or website before it can use your location data." "If Location Services is on, your iPhone will periodically send the geo-tagged locations of nearby Wi-Fi hotspots and cell towers (where supported by a device) in an anonymous and encrypted form to Apple" "By enabling Location Services for your devices, you agree and consent to the transmission, collection, maintenance, processing, and use of your location data and location search queries by Apple and its partners and licensees to provide and improve location-based and road traffic-based products and services."
- lambda_obrien 6y agoI would pay/donate up to $20 once, or $1 a month or something, if you created a (very easy) containerized deployment I could deploy on my home server and limit to only the phones I choose to allow access, that way only my wife and I (and later my son) can hook into this and share locations with each other. I already have our phones setup to VPN home when off the home WiFi, so this would be great for privacy. I would pay that much for the cloud offering if you had a contractual/legal obligation NEVER to sell my data EVER, or to sell the service to any company without wiping ALL of my data first.
- apayan 6y agoThanks for the feedback lambda_obrien. Zood Location only sends your location to users that you have explicitly added, and your location data is end-to-end encrypted before leaving your phone meaning that the data can only be decrypted by the person your sharing it with (i.e. your wife or your son. As for your personal data, Zood doesn't get any of it because of the end-to-end encryption. All the server [1] does is accept blobs of effectively random bytes (encrypted) from users to deliver to other users. Even if I wanted to sell user data, there wouldn't be anything to sell. Everything is encrypted before it leaves your phone. It's just like Signal in that regard. [1] https://github.com/zood/oscar https://github.com/zood/oscar
- fitblipper 6y agoI would like more information on what information exactly zood receives and stores. Does zood know who is sharing with whom? Is the data usage to username logged? Is the amount of data sent to zood increase as a function of 1. How many people you are sharing your location with 2. If you are traveling quickly 3. If you are on battery saver or not?
- apayan 6y agoHey fitblipper. Good questions. :) > I would like more information on what information exactly zood receives and stores. When you sign up, the Zood Location server receives * the username you picked * (optionally, if you provided it) your email address The server also stores a backup of various pieces of data for you, but this data is encrypted on your phone before being backed up to the server. It's exactly like how a password manager backs up your passwords to the cloud so you can access them from any machine. THIS DATA IS ALL ENCRYPTED ON YOUR PHONE with a key DERIVED FROM YOUR PASSWORD before the blobs are sent to the server. The encrypted data includes: * your symmetric key * your asymmetric key * your password salt * the algorithm used for your password derived key (currently, argon2id) * your friends list and their public keys (for TOFU reasons) Again, all that data is encrypted in the app on your phone before it ever leaves your device. This is no different than using a password manager. > Does zood know who is sharing with whom? The most information that the server can ever see is that some user sent some communication to a particular user. The contents of the message are unknown. Location sharing actually happens through "drop boxes" to make it more difficult for the server to see when and how often users send communications. When a friendship is established, the friends agree upon drop box addresses to use for each other, and they simply place encrypted data in the drop box for the other user to check whenever it wants. In theory, I could perform metadata analysis to try to statistically determine friendships, but I still wouldn't know anybody's location. The server code is available, and not terribly complicated so it's easy to verify that no analysis is happening there [1]. > Is the data usage to username logged? For debugging purposes, I can have the server log to stdout when a user makes a REST call to drop an encrypted blob on the server, or when a REST call is made to send an encrypted blob to another user, but that's off in production. It was there to help me build the thing. In general, thwarting metadata analysis by the person running the service is tough. I look to what the Signal messenger folks are doing in this space to improve things. > Is the amount of data sent to zood increase as a function of 1. How many people you are sharing your location with If you have more friends, your phone will send more encrypted blobs to different drop boxes on the server. The reason is that though you only physically exist in one point of space at a time, because communication with each friend is end-to-end encrypted, your phone will encrypt the location info payload for each friend with their own public key. So if you have 5 friends, every time your location changes, your phone will encrypt the payload 5 different times and place it in five different drop boxes on the server. > 2. If you are traveling quickly That's based on your phone's operating system and version. Google and Apple are always tweaking how often location updates are reported to apps. But if a location update comes in, Zood will encrypt it and upload it. > 3. If you are on battery saver or not? I don't really use battery saver, but I think location services is disabled when your phone is in that state, so Zood wouldn't get any location updates at all. I could be wrong about that. [1] https://github.com/zood/oscar https://github.com/zood/oscar
- huhtenberg 6y agoExcellent stuff. I especially like that this focuses on solving an actual, very specific problem rather than being some amorphous platform. That said and if I read you correctly, the backend must be some sort of a dumb relay that just routes blobs of data between clients based on how they are grouped. Correct? If so, then nothing restricts you from relaying any type of data, which is a fantastic foundation to have. Do you have any details on how two clients would establish trust, exchange keys, if there's a replay protection, etc.? It would make for a good read. PS. One thing I'd change is the name. It's just... not nice, unpleasant. It also doesn't help that it means an "itch" (зуд) in some languages, the kind you get from not taking a shower for a month.
- apayan 6y agoHi huntenberg. Thanks for the thoughtful reply. :-) > That said and if I read you correctly, the backend must be some sort of a dumb relay that just routes blobs of data between clients based on how they are grouped. Correct? You're correct. It is just a dumb relay. That's the reason why it's so difficult (impossible?) to come up with a freemium monetization strategy. The server can't see the contents of your communications, so it can't restrict functionality. > If so, then nothing restricts you from relaying any type of data, which is a fantastic foundation to have. I suppose so. What did you have in mind? > Do you have any details on how two clients would establish trust, exchange keys, if there's a replay protection, etc.? It would make for a good read. I don't have anything written up about this (other than the code in the repositories), but if there's interest, I could compose a blog post about it. For the time being, users can verify the privacy of the communication with another friend by comparing the safety number of the friendship (tap the friend's avatar on the map, in the info panel that pops up click the triple dots at the top right, then select 'View safety number'). If you're safety numbers match, you know your share with that friend is secure. I got the idea from Signal messenger. > PS. One thing I'd change is the name. Yeah, I'm still reconsidering the name. I've already changed the company name once, but I may have to change it again. It's just hard to come up with an easy to remember+spell name that also has an available domain.
- huhtenberg 6y ago
- vorpalhex 6y ago> Is this a service you would use? Yes! I already use a non-privacy centric service like this, and would very much like to swap it out. > Would you pay for it? Yes. I'd be willing to pay $30/year for quicker updates. Maybe have a freemium model of an update per 30 mins or 60 minutes, a middle tier of 5 minute accuracy (good enough for most users) and then a premium tier of ~30s accuracy. Maybe play around with the amount of people in a group too - it makes sense to charge more if you're sharing with a small family versus a single friend. As always with subscriptions, please make them have clear pricing, an option to pay annually (even if there's no savings) and allow auto-renew to be opt-in instead of by default. On the monetization front, you likely can leverage the same infrastructure for an Enterprise version of the app. What many companies want is a rough geofence app that can let them know when someone is abroad for work and give them location specific information - "Oh hey, you're near the Ohio office. The alarm code is XYZ, and your badge has been given temporary access for the next 3 days." Especially if you can assure employees that they're only giving rough location information to their employer ("Mary is in Nevada" and not "Mary is at So-and-so brothel in Las Vegas") then it feels like an acceptable tradeoff of information and benefit.
- storrgie 6y agoI'd say that it's worth 30$/year for "family" as well rather than individual. For example, I'd happily pay that fee for my family but I feel like I'd have a hard time telling my family to each pay that fee when "they have it from google already".
- CobrastanJorji 6y agoMaybe I'm missing something, but where's the product part? The app looks free. There's no discussion of paying. Where's the part where you make money? Is there idea that I install and start using it now, and then once enough people sign up, you yank the free version and begin to charge?
- apayan 6y agoIt's a fair question. I want this to be sustainable, and you want the services you rely on to be sustainable. In truth, I'm trying to determine a pricing model right now via this Show HN. I don't intend to "yank the free version" from anyone. Maybe I'll be able to find a freemium model, maybe I'll be able to acquire sponsorships, maybe there will be a way to simply charge for it... I don't know. But folks that start using it now will be grandfathered in, so you don't have to worry if you don't want to pay. I don't (and won't) have any investors that I need to satisfy. So there's no VC breathing down my neck, pressuring me to squeeze users. I hope that's a satisfactory answer to your question and that it allays your fears. :-)
- JoshTriplett 6y agoI would absolutely use this, particularly with map integration and messaging/Signal integration. I'd also love to use this to trigger events (e.g. turning off lights when everyone leaves, turning them on when anyone gets home). Regarding payment: I would get value from this, but primarily in conjunction with a higher-level service built atop it (providing features such as those mentioned above), and I'd want to pay for the higher-level service with this integrated, rather than paying for the building block. (That'd mean either you're providing the higher-level service and getting paid directly, or providing the building block and getting paid by the higher-level service rather than by the end user.)
- apayan 6y agoThanks for the feedback JoshTriplett. :) Could you describe in more detail what you have in mind regarding "map integration and messaging/Signal integration"? I totally get what you mean about triggerring events based on location (turning off lights, etc.).
- JoshTriplett 6y agoThe most common thing I'd want to do with location information is display it on a map. For instance, I'd love to use this to help coordinate meeting up with someone, so that we could each see each other on a map. I'd also like the client-encrypted private historical record for a variety of purposes; everything from "what path did we walk on that romantic evening?" to the mundane "where did we park?" or "where did I leave my phone?". All of those need map integration, and that map integration needs to not compromise the privacy properties of the location service. That would be well worth paying for. The issue is that I wouldn't want to use a separate mapping application for that. I don't want to use Google Maps for directions/navigation/restaurants/etc, and a separate app for location sharing. I also don't want Google Maps to have my location information/history. I'd pay for an all-encompassing map service with this feature, and privacy would motivate me to happily pay for that even though Google Maps is "free". But I can't honestly say I'd pay for just the location feature if I still have to use a different (and non-privacy-preserving) mapping service for everything else. If I can have a single "Maps" application on my device, and that application preserves privacy, I'd love to pay for that; if that app also has location sharing, that's even better. Messaging or Signal integration would be for the same kind of "meet up" purpose: send someone a link that gives them time-bounded access to a subset of location information (most commonly live information about current location).
- dangerboysteve 6y agoHow is this any better than using Signal and sharing location.
- apayan 6y agoSignal allows you to explicitly open the app, get your current location, and send that snapshot of your location to someone immediately. That's definitely fine for some use cases. Zood Location lets you share your location with other people without having to do anything on your part (besides accepting the initial friendship). Then your friend can simply open Zood Location on their phone and they'll be able to see where you are and you won't have to do anything. It's very useful for families trying to coordinate dinner plans after work, determining how soon your partner might be back home to help with the kids and other seemingly trivial things that usually require multiple disruptive calls and text messages.
- hiq 6y agoAs you surely know, WhatsApp already has this feature ("Live location"). I'm not sure that it's E2EE in WhatsApp, but I would say so. What does Zood Location offer over this? There's value in having a minimal app for the sake of it, but I would expect your userbase to be a small niche for consumers. There might be better vistas in B2B. See also this comment: https://news.ycombinator.com/item?id=25354165 https://news.ycombinator.com/item?id=25354165
- apayan 6y agoHi hiq. I think WhatsApp's Live Location definitely satisfies many use cases. The biggest distinction I see between it and Zood Location is that Zood shares your location continuously, which is useful for families. The sharer doesn't have to re-enable the share every 8 hours. Zood also has an expiring share feature called Timed Sharing [1]. Zood will generate a link you can send to anybody (no Zood required) and the recipient(s) can view your real time location via any web browser, all end-to-end encrypted. > There might be better vistas in B2B. That may indeed be the case. It's something I need to investigate further. [1] https://ara.sh/private/hn-zood-timed-share.png https://ara.sh/private/hn-zood-timed-share.png
- Aaronstotle 6y agoFirst off, I've been considering building a privacy-centric service as well. I want to say that yes, I would gladly pay for a service that protects my privacy, and would use it.
- atonse 6y agoIs it possible to use this for a business to put on their employee phones? Before anyone pounces on me (I actually have strong opinions about privacy)... I have a client that has 300 employees that are enforcement officers in the field on company issued phones during their shifts. (think tow truck drivers or parking enforcement officers) and they'd like to be able to quickly dispatch the "nearest" officer to the scene. Is this something we could use to get real-time locations of these officers? I was asked for advice on coming up with a solution and I had a tough time finding a good solution that is API-first, battery optimized, and has solid Android support, and a privacy-friendly DNA. We just need the real-time location tracking piece so we can use the information for dispatching them.
- apayan 6y agoHi atonse. Believe it or not, this was a use case that I was considering when developing the service. Speaking with folks at various conferences I've been at, there seem to be more than a few industries where it's necessary to quickly identify the physically closest employee that can be dispatched to resolve an issue. If you'd like to chat about it some more, send me an email [arash at zood dot xyz]. I think a private instance of the service might even be the most useful solution for you.
- unixhero 6y agoJust so you know, this is a MASSIVE market. I have implemented one such solution for a large multinational cable-guy company. They spent many millions on this solution.
- apayan 6y agoHey unixhero. If you have the time and interest, I'd love to have a call or video chat with your about your experience in this market [ arash at zood d0t xyz ].
- ajvs 6y agoIt's a bit too basic for me at the moment. If there was location history
- ajvs 6y agoIt's a bit too basic for me at the moment. If there was location history and the ability to create custom maps (see Google My Maps/uMap/GeoJSON) then it'd be valuable enough for me to get subscription for.
- cookiengineer 6y agoCould this be a potential start for an end to end encrypted microg cloud alternative? Personally, I would love to see a service like that. Even more if it had payments via crypto, so you can guarantee anonymity.
- rndgermandude 6y ago>Is this a service you would use? Sorry, but no. I might if I had small-ish kids, maybe. As an adult, I would be wary of a service like that, and it would be outside of my comfort level. I'd need assurances that the other parties who I trust today but maybe shouldn't (or don't trust tomorrow) won't be able to snoop on me, neither my current location nor historical locations the app may have collected, without my knowledge. I could imagine something like a scheme where the data is double-encrypted. An outer layer of encryption where the key is known only by either the app or the server, and only revealed when the other party requests it, thus leaving an auditable action. The inner layer of encryption would still ensure that only the trusted parties could perform the final decryption step, or something like that. I am just spitballing here and this is surely not a finished, well-thought-out scheme.
- wasmitnetzen 6y agoI'm running an OwnTracks[1] instance on my own server, and that's the only way I will ever use such a service. I don't think I will ever use a service which keeps the data on their servers, no matter how privacy preserving it is. Real-time location data is just too valuable. That being said, I might consider using a self-hosted version of your software, but then I would only pay maybe 1 to 2$ a month maximum for it. But my use case is mostly location history, not real-time sharing, so it doesn't really match yet. [1]: https://github.com/owntracks/recorder https://github.com/owntracks/recorder
- apayan 6y agoHi wasmitnetzen. I don't want to discourage you from self-hosting OwnTracks, but I would like to clarify one thing about Zood Location. The server doesn't store any location data in plaintext. Your location is encrypted before it leaves your phone in such a wat that only the intended recipient can decrypt it (Zood can't view it). That encrypted payload is placed in a drop box on the server for the recipient to pick up later. Newer payloads of encrypted location info will then overwrite the old data in the same drop box. A case could be made that hosting an instance of OwnTrack with your location data in the clear on a VPS somebody else controls is less safe than storing it encrypted on someone else's server.
- wasmitnetzen 6y agoThanks for the answer! I'm not saying Zood isn't safe to use, but security isn't binary, and a centralized service is always a more lucrative target than a self-hosted one just because there is more data there. And it's also not just a technical question - what stops you from being acquired by $MEGACORP, pushing an update which removes the E2E and start mining the data? That (the acquisition, not the E2E removal) actually happened to me before[1] with a location tracking app. [1]: https://www.pcmag.com/news/facebook-acquires-fitness-tracking-moves-app https://www.pcmag.com/news/facebook-acquires-fitness-trackin...
- apayan 6y agoI don't know of any legal way to guarantee that a company won't be acquired, and start exploiting it's user base, but I think there are some signs you can look for to see if it's the kind of company that you want to patronize. In the case of Moves, it wasn't open source and didn't offer end-to-end encryption. Privacy and consideration for its users was never in its DNA. If Zood offers Moves-like location history in the future, it will also provide a method for exporting the location data to CSV or similar (data portability).
- raxxorrax 6y ago> Is this a service you would use? Perhaps to track my grandma, who lives alone. Or on festivals or while skiing with friends. Not in everyday life. > Would you pay for it? Yes, but I would prefer a solution where I host a server myself to be honest. I would more gladly pay for a license here instead of a service with monthly costs. In reality I have some dev friends and if it was a feature we really wanted, we might hack something ugly together ourselves. But for commercial use I would do pay for it. > Would you or your company sponsor it? No. I am in a position where I could influence such decisions in the company I work for, but I think it would just lead to employee surveillance, which I don't support. My boss might, but I would recommend to refrain from doing so and would gather arguments against it. I know it is common in logistics, but that shouldn't mean everyone has to accept such tracking. Poor souls...