15 ms·
Afaik nearby wifi networks are also used to determine location. As long as you have wifi activated Google can use this to determine where you are. I don't know
by ramonverse 2y ago
Afaik nearby wifi networks are also used to determine location. As long as you have wifi activated Google can use this to determine where you are. I don't know if they use this as a hard check.
The only way I can think of to prevent this is to build a faraday cage with a wired vpn router and your phone inside.
- aaron695 2y ago[dead]
- autoexec 2y agonearby wifi networks, nearby cell phones, and also bluetooth devices. Even in airplane mode your phone is looking for beacons and keeping track of your location. Even when you turn your phone off entirely it doesn't give up (https://www.androidpolice.com/android-15-powered-off-finding-pixel-8/ https://www.androidpolice.com/android-15-powered-off-finding...)
- sadboi31 2y agoThey want accelerometer, temperature and other sensor data too where possible. Not just information on the strength of the wifi/cellular signal (and your estimated location). SIM cards can do the most on qualcomm devices. Poking into both of these systems outside of a lab is definitely a violation of the law ordinarily and it's pretty hard to test this in a lab.
- fsflover 2y agoThis is why I use a smartphone with hardware kill switches for WiFi and modem.
- ksp-atlas 2y agoLibrem 5?
- fsflover 2y agoYes.
- reginald78 2y agoDon't forget bluetooth.
- pogue 2y agoI just saw this yesterday about losing Authy for 2FA on non-official Android devices w/o play services. I'm curious how phones like this are handling that. https://arstechnica.com/gadgets/2024/07/loss-of-popular-2fa-tool-puts-security-minded-grapheneos-in-a-paradox/ https://arstechnica.com/gadgets/2024/07/loss-of-popular-2fa-...
- fsflover 2y agoYou can run Android apps with Waydroid, but you can't overcome the DRM. You have to complain that you run an alternative OS, which has a right to exist.
- pogue 2y agoSo you can still access 2FA through non-official Android builds.... or no?
- fsflover 2y agoYes, unless these apps require the "safety"-net.
- usernameks 2y agoEven worse: (Google) play integrity.
- kmeisthax 2y agoGoogle isn't banning hardware killswitches in their compatibility definition, so a phone with such switches can still ship Play Services. The main stumbling block here is that Google wants to tie users' hands in certain aspects, and many of these OSes are specifically designed to undo that control. GrapheneOS does a bunch of stuff to improve security that absolutely could be incorporated into a Play Integrity authorized build. But it also does a bunch of stuff in the name of user privacy that Google would never sign off on. For example, there are apps[1] that refuse to work without a GPS lock, for a variety of reasons ranging from "I save money on streaming rights by only letting you watch in a specific country" to "I need to know if you're a criminal trying to stuff our banking app with stolen credentials in a foreign country we can't prosecute you in". Some of these reasons are pro-user, some are user-hostile[0], but all of them require handcuffing the user, so Android cooperates with app developers instead of you. All the permitted ways for a user to manipulate their location are transparent to the application. That is, if you mock your location, the application is told it's fake and can refuse it. Likewise, if you turn off location, the application is told it didn't get a fix. Hardware killswitches are just a more powerful / legible way to turn off location. If the phone instead had a hardware GPS signal spoofer in it, Google would absolutely ban it from Play Integrity. [0] And, for the user-hostile reasons, those are the terms of sale, so Google cooperating with the user would just get the app taken away because the entertainment conglomerates are big enough to oppose Google's market power. [1] Client and server inclusive, i.e. "an app is just a website with enough IP to make it a felony to block ads in it". Play Integrity exists specifically to frustrate attempts to modify the client. If you modify the client or the OS it lives in, Play Integrity's signed data will have the wrong hashes in them, and the server will refuse service to you.
- kop316 2y agoThis looks to use the dev options to fake it, which I believe bypasses the geolocation apps (as I assume the mock location is used for testing apps if they are in certain locations). That being said, I have tried this for banking apps, and they aren't fooled by it, so I am guessing Android passes on that this is a "mock" location, not a real one. Like you said, if you really want to fake it, probably a faraday cage/fake GPS would be necessary.
- amonon 2y agoYes, this is the case. I cannot remember the details, but the OS makes applications aware that location mocking is turned on.
- Ambroos 2y agoYou can just call .isMock() on the location object you receive: https://developer.android.com/reference/android/location/Location https://developer.android.com/reference/android/location/Loc... - without root that can't be bypassed.
- Teever 2y agoThat's a pretty anti-user feature if you ask me. Especially for a device so personal as a smartphone. There needs to be legislation that prevents manufactures from overridinf the will of the user at the behest of app makers for devices like this.
- newaccount74 2y agoHaving a smartphone provide a hard to fake location is a pretty valuable feature. A lot of businesses depend on the fact that location data is hard to fake. Consider caller ID - legislators around the world are working on making it harder to spoof your identity, because there's so much fraud going on with fake caller IDs. It's the same with location. Being able to easily fake location would open the door to so many frauds...
- 2y ago
- mindslight 2y ago> The only way I can think of to prevent this is to build a faraday cage with a wired vpn router and your phone inside. Another option is to not be running an operating system that betrays your interests. Google can only determine your location using nearby wifi networks if that list of nearby wifi networks has been given to Google through Android/Play backdoors. In fact most privacy issues with phones boil down to running a malevolent OS - protecting against malicious application code is still a difficult problem, but it is at least tractable if you can trust the system code. (Personally I think the functionality of the OP should be included by default as part of the OS permission system, and configurable on a per-application basis)
- gorbypark 2y agoAt one point in time the Google street view vehicles were logging wifi position data as well. I don’t know if they still do it, though.
- mindslight 2y agoSure, that's a related but different problem - cataloging the location of wifi APs versus inferring your personal location based on what APs your phone can see. Running user-representing software on your phone doesn't fix all problems everywhere, it just gives you a platform with which you can address them to the fullest extent possible.
- gorbypark 2y agoFair, I took your original comment to mean that Google was mapping WiFI AP locations using people's phones (which could still be true). However, after re-reading it I see you meant that Google is pin-pointing your own location based on which AP's are visible.
- mindslight 2y agoAh. Yes, that is what I meant. I would think they are certainly using phones to collect Wifi AP locations. In fact if they've stopped doing so with the mapping cars, then it's probably because the phone backhaul is good enough. The ways of preventing this are much less straightforward though. Stopping your phone collecting them will only remove some datapoints (perhaps significant for some people, but not for most). Disabling AP beacons or continually rotating ssid/bssid can mitigate it for your own APs, but at the cost of some UX.
- ape4 2y agoThis app registers a location provider. Probably the phone wouldn't resort to using wi-fi networks if there is a location provider present. Probably, maybe.
- dheera 2y agoWith all the beamforming shit Wi-Fi has these days it's actually surprisingly hard to make a good faraday cage for a phone. Even a very tiny amount of signal and it still works. My office elevator is stainless steel on all sides and yet somehow Wi-Fi works inside. A miniscule amount of signal must be getting through a crack somewhere.
- edm0nd 2y agoWiGLE ftw!
- acka 2y agoPlease note! Modern versions of Android will passively scan for Wi-Fi networks and use them for location tracking even if Wi-Fi is turned off* by the user. I don't know if turning off location tracking also stops the passive Wi-Fi scanning, let alone whether anything related to this is phoned home to the Google mothership, or whether Android devices are now part of a giant botnet tasked with improving Google's location services. *Turning off Wi-Fi in Android now only has the effect of disconnecting any active wireless network connection, the radio stays on and the lower level of the wireless network stack remains running to facilitate the passive network scanning.
- t0bia_s 2y agoYour phone is easily located in moment you put SIM card and turn phone on. GSM signal reach closer tower and try connect to other near by. By making approximation of those signals, you can locate position of phone on ~10m.
- outadoc 2y agoOr, you could just turn it off in the Location Services settings.
- princevegeta89 2y agoBut doesn't the GPS always take precedence over wifi if it is turned on?