98 ms·
Did I miss something in the article? They see the connections were made, it was plain http, but they didn't actually show any of the real payload/data? Instead
by kayson 3y ago
Did I miss something in the article? They see the connections were made, it was plain http, but they didn't actually show any of the real payload/data? Instead they quoted the list of what Qualcomms policy says could be collected? Seems like low hanging fruit...
Disclaimer: work at Qualcomm but have nothing to do with any of this
- yabones 3y agoYeah, I'd be interested to see what's _inside_ the request, not just that it was made. Was it a connectivity self-test or empty GET request? That's not ideal, but fairly benign. Or was it a "phone home" reporting the device's ID, SN, IMEI, etc? That's a lot worse. Or, did it truly contain PII or geolocation data? that's really bad. It matters a LOT what's inside the request, and it seems a little dishonest to not include it in the report.