8 ms·
Yes, this is the case. I cannot remember the details, but the OS makes applications aware that location mocking is turned on.
by amonon 2y ago
Yes, this is the case. I cannot remember the details, but the OS makes applications aware that location mocking is turned on.
- Ambroos 2y agoYou can just call .isMock() on the location object you receive: https://developer.android.com/reference/android/location/Location https://developer.android.com/reference/android/location/Loc... - without root that can't be bypassed.
- Teever 2y agoThat's a pretty anti-user feature if you ask me. Especially for a device so personal as a smartphone. There needs to be legislation that prevents manufactures from overridinf the will of the user at the behest of app makers for devices like this.
- newaccount74 2y agoHaving a smartphone provide a hard to fake location is a pretty valuable feature. A lot of businesses depend on the fact that location data is hard to fake. Consider caller ID - legislators around the world are working on making it harder to spoof your identity, because there's so much fraud going on with fake caller IDs. It's the same with location. Being able to easily fake location would open the door to so many frauds...
- dmichulke 2y agoSo how do you stop Google or Samsung from using your location data without your consent? - Not using GPS? Not an option because you need it - Disabling permissions? Not possible for "system apps" - Having the 10% privacy aware people block location somehow (via rooted phone or different distribution)? That doesn't help the other 90%. IMO the only solution is to poison the data with fake locations. Are there other options I missed?
- Teever 2y ago> A lot of businesses depend... Do I care? Like not to be glib but as an end user buying a phone for my personal uses, I dont care about their businesses and I loathe the idea that their business model requires such an anti feature to be widely deployed in personal devices such as smart phones. Tell you what. I have a business model that requires your personal location data. Be a dear and send it to me. And again, why do I care about caller ID. It's been trash for years. I just never answer calls and use diffetent platforms such as Signal to communicate with my friends. It may open the door to so many frauds, but it opens the door to so many more abuses. People will talk about these 'features' differently the first time a large genocidal action takes place that makes use of this data.
- mindslight 2y agoI fully agree with where you're coming from, but you kind of veered off with that last sentence. In general I think the threats from fine-grained surveillance databases are a lot more nuanced and pernicious than genocide.
- newaccount74 2y agoRide hailing apps rely on the fact that both customers and drivers phones don't lie about their location. Mapping companies rely on the fact that their crowdsourced data is reliable. Emergency services rely on the fact that phones share accurate locations. Delivery companies require authentic location data from their agents. Apps that allow people to rent scooters or bicycles rely on non-fake location data. If you made it easy to provide fake location data, a lot of apps would suddenly have to deal with a whole new class of fraud. I just don't see how this would be a net beneficial change.
- nayuki 2y ago> Apps that allow people to rent scooters or bicycles rely on non-fake location data. There's a way to fix this. Each bicycle can store a private key, and your phone needs to talk to the bike nearby to do a live challenge-response before you can rent it out.
- singleshot_ 2y agoQuick question: how come every scumbag who calls my phone with a scam has a fake caller ID, but I shouldn’t? Again, this seems pretty user-hostile.
- newaccount74 2y agoThese scumbags shouldn't be able to have a fake ID, which is exactly what legislators in the US and the EU are currently trying to end.
- singleshot_ 2y agoWell, if legislators are trying to fix it, I suppose I feel better about the user hostility. Good luck to the legislators, and thank god we have people like them!
- newaccount74 2y agoWell, legislators managed to abolish roaming fees within the EU, so maybe they'll manage to fix caller ID too.
- singleshot_ 2y agoYou sound like you might be from the EU. I have some bad news for you about US legislators.
- aftbit 2y agoFor the same reason that every movie ends up ripped on piracy sites, but you still can't watch Netflix in 4k on Firefox on Linux. DRM doesn't work because it only takes one person to bypass it to make a copy, and caller ID verification doesn't work because it only takes one janky provider that doesn't implement SHAKEN/STIR correctly and yet is worth too much money to totally block. FWIW I can still generate calls with arbitrary caller ID from a handful of my (legacy) ITSP providers, but if I get a new account today with any of them, they will require me to either verify each caller ID by receiving an inbound call or provide a "valid business justification" for why I can't do that. They are working on tightening up the pathways to generating fake caller IDs but in the telephony world, nothing moves fast and uptime is more important than anything, except maybe revenue, of which spam calls account for a ton.
- nayuki 2y agoYou're basically arguing for https://en.wikipedia.org/wiki/Trusted_Computing https://en.wikipedia.org/wiki/Trusted_Computing . You're saying that the manufacturer should have more power than the consumer, that the consumer cannot run arbitrary code, that the consumer cannot examine and disassemble the manufacturer's code. Even if the device is unmodified, you can still spoof GPS signals by generating them in a box: https://www.reddit.com/r/electronics/comments/4unzp2/cheating_in_pok%C3%A9mon_go_using_a_signal_generator/ https://www.reddit.com/r/electronics/comments/4unzp2/cheatin... , https://www.youtube.com/watch?v=9mC71c6zRUE https://www.youtube.com/watch?v=9mC71c6zRUE . That's why I think "trusted computing" is pointless.
- Zak 2y agoWe basically already have that on smartphones. Both Android and iOS have remote attestation, and a significant number of apps use it to refuse to run on devices with anything but an unmodified first-party OS. I was surprised there wasn't a bigger outcry over it in the tech world.
- aftbit 2y agoAs someone who habitually roots my Android phones, I'm always somewhat annoyed when I can't use features like tap-to-pay, but I'm really annoyed when apps refuse to start, especially when they are for things like McDonalds. I shouldn't need to have a known-trusted operating system to buy a burger.
- Zak 2y agoBe sure to give them 1-star reviews. I've found that the Play Integrity Fix module for Magisk usually solves it, though there are a couple exceptions. They still earn a negative review for the attempt.
- warkdarrior 2y ago> I shouldn't need to have a known-trusted operating system to buy a burger. That's for the app developer to decide, no?
- Zak 2y agoThat the client isn't trustworthy is a pretty fundamental rule of network security. Attempts to circumvent that rule are making it so users can't trust their own devices, and that's a dark path to go down.
- nottorp 2y ago> A lot of businesses depend on the fact that location data is hard to fake. You spelled "spammers and personal data spies" wrong and it somehow ended up as "businesses"...
- newaccount74 2y agoThere are a lot of legitimate use cases that require reliable location data. I mentioned a few that I could think of in a sibling comment, but I'm sure there are more. Maybe you can come up with a use case for accurate location data yourself? Anyway, spammers and data brokers probably wouldn't care at all if say 10% of people spoofed their location. They don't really have a lot to lose if some of their data is incorrect.
- chii 2y ago> a lot of legitimate use cases that require reliable location data. if the use cases are aligned with the user, they will give the correct location data.
- newaccount74 2y agoUsers also need other users to be honest about their location. Consider a dating app; you want to meet real people who live in your area, not a fraudster pretending to live just a few blocks away. Or a delivery driver: You want them to actually drive up to your house and ring your bell, rather than just pretend to drive there and drop your package somewhere else. Location data is worth a lot more if it is reliable. The user should be in control of sharing their location. But you shouldn't be able to just provide a fake location.
- nottorp 2y ago> Consider a dating app; you want to meet real people who live in your area, not a fraudster pretending to live just a few blocks away. So you shouldn't be able to use the dating app to set up a date for when you're back home while on a business trip or holiday? Maybe you should just upload proof of residence to the dating app instead. But I'm sure you'd consider THAT a violation of privacy, while 24/7 location tracking of your phone isn't because ... it's electronic? By the way, do you want to give your exact location to a profile on a dating app? Even if they're local, maybe they're serial killers. > Or a delivery driver: You want them to actually drive up to your house and ring your bell, rather than just pretend to drive there and drop your package somewhere else. This other case is legitimate but it can be solved by issuing the driver a work device that has tracking. Unfortunately the other 10000 cases are unneeded violations of privacy.
- bongodongobob 2y agoI think it might be a legal requirement for emergency services. I used to work a lot with VoIP and each line was required to have an address associated with it.
- Teever 2y agoI'm fine with that, provided that there's sufficient oversight to prevent abuse. What I'm not fine with is one large corporation who makes phones baking this feature in so that other companies that make apps can profit off it. That's two parties conspiring to fuck over their customers. That needs to be regulated.
- ClassyJacket 2y agoAlso: screenshots. Firefox won't allow me to screenshot a private window. It's my damn phone and I should be able to screenshot or record whatever the hell I want.
- didsomeonesay 2y agoGo to settings -> private browsing and enable "allow screenshots in private browsing".
- chii 2y agoIt's not just firefox (which, fortunately has a setting to turn off). There are apps whose name(s) i won't mention, that uses DRM to prevent screenshotting, and it's way harder to bypass.