9 ms·
The saluspa from "bestway" demands your location before allowing you to setup wifi remote control of the portable hot tub on the android app. I wonder how on an
by rnk 3y ago
The saluspa from "bestway" demands your location before allowing you to setup wifi remote control of the portable hot tub on the android app. I wonder how on android I can spoof the location used by an app, or if anyone figured out if you can control it without the app.
I set it up away from my house and use a separate wifi network but it pissed me off.
- niij 3y agoAndroid apps used to need "location" access for bluetooth discovery. https://www.androidpolice.com/2021/05/19/android-12-apps-wont-ask-for-location-permissions-when-all-they-want-is-bluetooth-scanning-which-yes-was-a-thing/ https://www.androidpolice.com/2021/05/19/android-12-apps-won...
- netsharc 3y agoBecause your location can be inferred by finding which Bluetooth devices are around you, as that article says... > See, back in Android 6 Marshmallow, Google changed things so that apps needed location permissions to scan for Bluetooth devices. At the time, the rationale was that Bluetooth was going to be used for things like interior navigation or location tracking in a more abstract sense, and your location could indirectly be inferred via Bluetooth scanning alone if a given hardware identifier was tied to a specific location.
- rightbyte 3y agoI have always assumed that is a way for Google to normalize granting the position permission. You could "pair" apps with devices if Bluetooth position spyware was a concern.
- GauntletWizard 3y agoBefore Android required that permission, there were marketing companies selling malls the ability to see who was around by the ID of their Bluetooth beacon.
- folmar 3y agoBut pairing work well without the app involved, we could just give a permission to a specific already-paired devices and keep location for apps that actually need to scan.
- GauntletWizard 3y agoAgain - That still sends out a beacon. Searching for already-paired bluetooth devices still sends a bluetooth frame with your bluetooth MAC address, (which has to be consistent, because that's how bluetooth devices identify each other).
- thaumasiotes 3y ago> Searching for already-paired bluetooth devices still sends a bluetooth frame with your bluetooth MAC address, (which has to be consistent, because that's how bluetooth devices identify each other). It doesn't have to be readable by third parties. Given that the devices are already paired, it's perfectly feasible for that frame to be encrypted gibberish that only the other device can understand.
- GauntletWizard 3y agoI think that the math of battery life if you had to decrypt anything that looked like a handshake packet to see if it's for you is the opposite of feasible.
- Larrikin 3y agoThe other poster already explained the old permission. There's also a new permission specifically for Bluetooth LE now as well for newer devices so location shouldn't be needed.
- radlad 3y agoHowever, scanning and connecting to Wi-Fi IoT devices still requires it.
- izacus 3y agoNo it doesn't, there's a whole API for last few years where app can connect to its own IoT device without getting location or full scanning grant.
- radlad 3y agoWhy do you think that? I literally just wrote an app to do this. From my notes: > Android 13 still requires `ACCESS_FINE_LOCATION` to call `startScan()` and `getScanResults()` - `NEARBY_WIFI_DEVICES` is not sufficient See here: https://developer.android.com/reference/android/net/wifi/WifiManager#getScanResults https://developer.android.com/reference/android/net/wifi/Wif...() I tried getting by without it, but it was required.
- Larrikin 3y agoThat poster I assume is referring to this for your own devices. https://developer.android.com/guide/topics/connectivity/companion-device-pairing https://developer.android.com/guide/topics/connectivity/comp.... Depends on the specific use case but you ideally shouldn't need those calls. Our app request both the old location permission and the new nearby permission just because not all of our vendors keep their libraries up to date and its not unreasonable for the app to know where you are when using those features.
- radlad 3y ago
- maldev 3y agoThis could be a overly cautious legal requirement. I know heaters(dyson) won't allow you to control heat remotely in some locations, so instead of yanking out hot water from the app, they decide to ask your location to verify you're home.
- dylan604 3y agoThe 4 outlet water timer I bought came with bluetooth remote functionality. It needs GPS location data for it to work. Nope. Should have known some shit like that would be part of the deal, and could have saved a few bucks by getting the version without remote. People need to just stop with this tracking bullshit.
- hedora 3y agoIn fairness, some of those pull precipitation, heat and transpiration info from weather reports. It still shouldn’t require it though. At least on iOS, requiring it should get them banned from the app store. I want side loading to exist for iOS, but I also want bans like the above to apply at my discretion to anything I pay money for.
- dylan604 3y agoanyone making a "smart" water timer using today's weather forecasting would be something that could be called "The Plant Killer". my area can say that there's 80% chance of rain, yet not one drop can fall where I am while other areas can say they received .25" of rain. sounds like watering isn't necessary. oops. dead plants. There's other times where no weather is forecast, yet I've received .25" of rain. oops. wasted water. also, your "smart" decision to not water because of rain means all of the plants on my patio didn't get watered while I was on vacation/work trip/etc, which is the primary reason I bought the timer in the first place. Your smart is dumb. Just turn the water on at the time I said. That's plenty smart for me. If I can update the schedule from my couch, great! But...not at the expense of all of this tracking bullshit
- kalleboo 3y agoBluetooth permission implies location permission since you can use Bluetooth beacons to find your location.
- qingcharles 3y agoI tried to use Fanduel last night to place some bets for my friend in prison. It requires your location. You have to install some horrible app that installs a Windows Service and has no UI. It still won't work. After a lot of digging around, I discovered you cannot use Fanduel if you have a wired device. The app _requires_ you to connect to your router by Wifi or it will not work. WTF.
- bippihippi1 3y agoI wonder if their terms of service states claims to give them permission to distribute malware or if they think they won't get caught.
- gruez 3y agoMaybe it's for compliance reasons? in other words they really want to know you're in a jurisdiction that allows gambling, and not using a VPN or whatever.
- qingcharles 3y agoThat's exactly what it's for, but historically these sites would just do an IP check at the server, not install some horrible malware on your PC and then tell you an ethernet connection is evil.
- deleted 3y ago[deleted]
- JohnFen 3y agoI would have returned it for a refund, personally.