6 ms·
Awesome write-up! When my friends laugh at my obsession over privacy and data collection, this is the kind of thing I point at. There's no reason to believe th
by TheBozzCL 3y ago
Awesome write-up!
When my friends laugh at my obsession over privacy and data collection, this is the kind of thing I point at. There's no reason to believe they're doing this for malicious reasons, but we really have no way to know. It's probably just ignorance/incompetence.
- x1sec 3y agoThanks! Part of my motivation to documenting this is to raise awareness and also provide encouragement for others to start looking at what their devices/apps in their home are doing. The amount of location data the device maker is collecting is significant - perhaps they are monetizing it? If so, would you consider this malicious (if not disclosed to the end user this was happening)? The AMap SDK the app uses collects much more location data - here I feel they are likely using it to improve the accuracy of their location service/mapping software. I don't consider this malicious, unless this behavior is not disclosed to users and developers. Their site is in Chinese [1], would anyone read through their fine print to verify? [1] https://lbs.amap.com/api/lightweight-android-sdk/download https://lbs.amap.com/api/lightweight-android-sdk/download
- TheBozzCL 3y agoThat's my thought exactly: there's no logical reason for this to need to send your location, so it's probably monetized by AMap to improve location accuracy. The fact that it's not disclosed is worrisome but sounds more like incompetence or ignorance to me. I haven't taken the time to fully dig into your posts, did you notice if they're generating a user ID? For me, that would be the difference between using it for location accuracy or tracking user locations. That being said, the data they already have is probably more than enough to track individuals. Reminds me of this one post that I just can't find anymore: a (danish? finnish?) journal bought a pack of "anonymized" location data and chose one individual. They were able to track where they lived and worked, and where they went for vacation. They even went to their place and talked to them, and they had no idea this was happening whatsoever. I really wish I could remember where I read it.
- urgent_skittle 3y agoSounds like this New York Times article: https://www.nytimes.com/interactive/2018/12/10/business/location-data-privacy-apps.html https://www.nytimes.com/interactive/2018/12/10/business/loca... Edit: or actually I was thinking about this article, One Nation, Tracked: https://www.nytimes.com/interactive/2019/12/19/opinion/location-tracking-cell-phone.html https://www.nytimes.com/interactive/2019/12/19/opinion/locat... Which is one in a series they did after some employees of a data broker or digital ad company (if I recall correctly) leaked a dataset to the New York Times because they actually were concerned about this kind of dataset existing.
- raxxorraxor 3y agoIt is itself a special case or inversion of the tragedy of the commons when people share their data without thinking too much about it. It isn't applicable everywhere of course, but there is a price to adopting to the most naive.
- TheKarateKid 3y agoIt doesn't matter if the intent doesn't seem malicious. And if they had nothing to hide, why weren't they upfront about the data collection? Remember when we thought having all those Facebook "Like" buttons on every website was harmless until we learned the level of which everybody was being tracked without consent? This is China's typical playbook. Purposely collect data in seemingly harmless ways, or intentionally leave wide open security flaws that they can exploit in the future. And when they get caught it's an "oops sorry, we'll fix it right away". The worst part is that there is no consequence for this behavior. Google, the EU, and/or FTC should be lodging fines.