14 ms·
Android wallpaper images can threaten privacy
- vorejdajo 5y agoIt's not constant. I expect that people change wallpaper frequently.
- Daniel_sk 5y agoI don't think an average person changes wallpapers frequently.
- eric__cartman 5y agoIt's been more than a year since I last changed my wallpaper.
- b112 5y agoI've used the same wallpaper on every computing device I've owned, for the last 26 years.
- doublepg23 5y agoWith the downside of fingerprinting yourself it seems, would you be willing to share the wallpaper?
- b112 5y agoIt isn't special, merely a blue/green colour with mild dithering. It is a little like looking at the morning sky. It's on all phones, desktops, etc. And if I were to give it to you? Well. Maybe you're the NSA, maybe I'll be pulled off the street, thrown into a chair, and in a NDA-drugged, mildly confused state, be told "look, it is your desktop, see your familiar backgroud? You should enter your password." No sir, I will not disclose my background image!! Sneaky! Good try though.
- shadowgovt 5y agoUnfortunately, constancy is irrelevant. If a malicious app is using this API to locate you, it can detect when your wallpaper changes and use its app_id (unchanged) plus wallpaper fingerprint (changed) to phone home with "Yo, this user's wallpaper thumprint is now Y."
- MrDresden 5y agoAndroid dev here. Still have the same default wallpaper as my Pixel 3 came with 3 years ago.
- refulgentis 5y agoThat wallpaper would have the same 3 colors as many, many, other people. The problem here arises when your wallpaper is unique, no?
- Daniel_sk 5y agoYou can still use as input along with other parts that are accessible without any permissions - for example the android version, device name, IP address...
- gambiting 5y agoDo they? I've had the same "live wave animation"(that looks like the PS3's XBM menu) for at least 5 years now and I don't see any reason to change it.
- yumaikas 5y agoI mean, I go and set up ASCIIQuarium on every phone I have. Hunting down the APK gets harder and harder though.
- deleted 5y ago[deleted]
- curiousgal 5y agoI mean apps already have access to your device ID, no?
- Daniel_sk 5y agoThey don't - without special permissions on newer Android versions (10+). There is an ANDROID_ID but it's scoped to your application on Android 8.0+, reinstalling the same app signed with same key will give you the same key but it returns a different value in other apps. This way you can't use for cross-app tracking. https://developer.android.com/training/articles/user-data-ids https://developer.android.com/training/articles/user-data-id... https://developer.android.com/reference/android/provider/Settings.Secure#ANDROID_ID https://developer.android.com/reference/android/provider/Set...
- judge2020 5y agoHow does Google share logins between different apps then? Is there some shared keybag/storage location that only works for the developer's own apps (and is it scoped to the actual developer account, not one that different developers can collude to use together)?
- deleted 5y ago[deleted]
- Daniel_sk 5y agoI am not sure what mechanism is Google using. But Android apps can talk to each other on the same device and you can restrict this to only applications that are signed with the same certificate (and this is guarded at the OS level).
- gruez 5y ago>How does Google share logins between different apps then? google play services
- azurezyq 5y agoIt seems that you don't use Android. There's an account system apps can use in the os. Just checked mine, I can see Google, Facebook, Reddit and quite a lot others there
- jeroenhd 5y agoAlthough this is an interesting, novel method, there are so many fingerprinting capable APIs in native code that I don't think this matters much. Many apps I use daily require internal storage permissions and a bunch of them drop random dotfiles with magical IDs in there. Xiaomi even dumps a world readable unique device ID on the emulated SD card. Not all apps require external storage permissions, but even then there's tons of APIs that can be used to fingerprint the device. Google is trying their absolute hardest to reduce the fingerprinting surface but as long as system APIs that work with user content like these exist, there will always be something to fingerprint users by. If everything else fails, you could just embed a webview that uses all the javascript stalking we've grown so accustomed to. It's sad but I don't think you can prevent native code from fingerprinting your device. The sandbox just isn't tight enough and users are too willing to give out permissions. I can see Google using a predefined set of colours in some update instead of the raw colour values to combat this, but that's only one of many ways apps abuse their users' devices. Unless app stores kick out apps that fingerprint devices, I don't think we'll see any non-fingerprinted devices any time soon.
- gruez 5y ago>Many apps I use daily require internal storage permissions and a bunch of them drop random dotfiles with magical IDs in there. Xiaomi even dumps a world readable unique device ID on the emulated SD card. They're fixing this with soon with scoped storage api.
- a_large_rat01 5y agoA decade later and they're implementing folder permissions...?
- onkoe 5y agoBetter late than never! But.. yikes!
- searchableguy 5y agoAt this point, I am starting to feel permission fatigue.
- no_time 5y agoInteresting article but its rich as fuck coming from a company whose sole product is weaponizing the ever increasing scope of browsers against users
- basicplus2 5y agoI take the article as an advert to say 'use us to fingerprint people, we are always thinking of different ways to reliably finger people'
- bogwog 5y agoYeah I don't know how to interpret this article. Is it a warning to users about a new threat to privacy, or is it an announcement to customers about improved tracking capabilities in Android 12/a potential product update? Even if it's just some inbound marketing blog spam bullshit, why would a company whose business it is to violate and exploit privacy want to post an article that will attract people who are concerned about privacy?
- SavannahJS 5y agoHey there, I work at FingerprintJS. We don't believe in third party tracking and only focus on first party anti-fraud use cases. We publicly reveal any methods that we detect as being pure third party tracking privacy violations so that they get patched.
- sa1 5y agoI suspect first party anti-fraud tracking methods and third party tracking methods have a lot of overlap. What are meaningful differences?
- SavannahJS 5y agoIt is certainly a discussion we are having internally often. Overall we focus on identifiers that are not uniquely identifiable to a person on their own without taking them in aggregate, which makes them harder to share across unrelated domains. We also generally avoid anything personally identifiable (name, email, etc) that could be tied back to anyone in particular - we aim only to accurately identify a browser or app instance itself.
- ChrisArchitect 5y agohow am I being tracked from this? It takes pages to get to the point where supposedly the wallpaper color reduction could be unique enough ....but when is that going to be used to track me? Or rather, who is going to depend on that to track me across the device? Stretch no?
- healsdata 5y agoIt generates a unique fingerprint for your phone that can be used across apps without permissions. So if you have multiple apps using the same ad network SDK, each of them will get the same unique fingerprint for you and can tie your activity together. If you're logged into one of the apps, then your activity across all the apps can be tied to your login even when you change your wallpaper.
- techrat 5y agoColor theme is generated from Wallpaper. Color theme consists of at least 3 colors taken from the wallpaper. At least 3 unique colors is enough to make the user potentially uniquely identifiable, depending on how rare the color combos are. 2²⁴ (R⁸G⁸B⁸) combinations for every color times 3 colors means 2⁷² combinations. And there are color samples taken from potentially two different wallpapers. Other apps have access to the colors picked for the theme generated from the wallpaper so they can theme themselves accordingly. This means an app can use your color theme (of 3 or 6 colors) as a nearly unique fingerprint. The odds of collision for smaller apps (sub 1 million downloads) are pretty damn low.
- deleted 5y ago[deleted]
- ohazi 5y agoModern high-end phones use OLED displays. Save your battery and set your background to black.
- izacus 5y agoMost apps will skip all that and just ask you to login before working. Much easier and they get your email ;)
- mleonhard 5y agoDo you have anything to back up your claim? I think the opposite is true: Nearly every app bundles an ad-serving or analytics library which uses fingerprinting techniques like this. Apps require login in addition to fingerprinting, not instead of it. Analytics libraries are extremely easy to include. Some even get included without the knowledge of the developer. For example, when a Flutter app includes the Firebase library, it starts automatically sending user behavior data to Google. Specifically, it sends the title of every screen the user opens and how long they spend on it. This happens even on Flutter apps for iOS.
- zaik 5y ago> This color extraction algorithm is basically a map from the set of all possible images to the RGB color space. The set is infinite and the RGB color space is limited by 2^24 combinations. Theoretically, this means every RGB combination is possible. I know this is missing the point of the article, but this is not how the pigeonhole principle works.
- seaish 5y agoI'd guess at least half of the colors are extremely unlikely. Anything near the edge of the RGB cube would require some very uninspired artwork to show up in the set.
- tanduv 5y agoWould the way to counter this be using a default / well-known wallpaper? You'd have the same the wallpaper "ID" as several others who stick to the default wallpaper.
- kyle-rb 5y agoThat, and/or change your wallpaper relatively frequently. There seem to be apps that can automate changing your wallpaper, including an official Google one.
- mleonhard 5y agoChanging your wallpaper frequently doesn't reduce fingerprinting. Each new wallpaper is a new data point for fingerprinting. The timestamps of wallpaper changes are also data points. The only way to thwart fingerprinting is to make the data points the same on most devices. If you're changing the wallpaper, then it must change in sync with the other devices. Leaving the wallpaper at the default is simpler.
- hilbert42 5y agoI'm beginning to feel as if after I'd put my Android phone though a metal shredder that the individual remaining atoms will somehow still have my ID on them à la QM's conservation of information. It's been clear to me for quite some while that the whole notion of trying to achieve privacy on the internet is broken - the paradigm we're now using (and have always been using) to achieve privacy is wrong. As no matter what steps we take - such as making browsers more private and less fingerprint prone to, say, sandboxing apps etc., etc. - someone sooner or later will always find ways around our best defenses. As it stands, it's an ongoing incremental battle over privacy that we citizens can never have any long-term certainty about. Somehow our ID and personal data have to be separated from the hardware, software, means of transmission and IP addresses, etc. in ways that any chance of ever linking them are not just difficult but are also logically impossible. It's only then that we'd be in a situation where no matter the amount of hacking the 'system' would ever reveal or encroach upon users' privacy. This wallpaper example may still be somewhat of a stretch to implement in practice but chances are it won't be so in the future; its existence only goes to illustrate my point. If anyone ever manages to solve the problem in an easy implementable way then he/she will either be deemed a hero genius or a pariah. Which of these views one has will depend on which side of the political fence one's sitting.
- pas 5y agoIt's simple information theory (or basic OPSEC). Every kind of customization, every differing behavior reduces entropy. That's why Tor recommends using the browser with a fixed size window and with default settings. (Of course neither simple nor basic means easy.)