10 ms·
Android now stops you sharing your location in photos
- egeozcan 6mo agoThis must be a Chrome thing, not an Android thing, no? I didn't test this but I'd be surprised if Firefox behaved the same.
- fouc 6mo agoOr Firefox would still be using android's file system / upload process, which probably hands off the photos with geotags stripped already. I'm pretty sure this is what happens in the iPhone at least, so I'd imagine it is the same in Android.
- darkhorn 6mo agoJust tested with Firefox 149 on Android 13. There are no coordinates when I upload an image to EXIF viewer web sites.
- iamcalledrob 6mo agoSimilarly, the native Android photo picker strips the original filename. This causes daily customer support issues, where people keep asking the app developer why they're renaming their files. https://issuetracker.google.com/issues/268079113 https://issuetracker.google.com/issues/268079113 Status: Won't Fix (Intended Behavior).
- thaumasiotes 6mo agoThis a very weird set of choices by Google. How many users are uploading photos from their camera to their phone so they can then upload them from the phone to the web? I bet almost 100% of photo uploads using the default Android photo picker, or the default Android web browser, are of photos that were taken with the default Android camera app. If Google feels that the location tags and filenames are unacceptably invasive, it can stop writing them that way.
- embedding-shape 6mo ago> If Google feels that the location tags and filenames are unacceptably invasive, it can stop writing them that way. Something can be "not invasive" when only done locally, but turn out to be a bad idea when you share publicly. Not hard to imagine a lot of users want to organize their libraries by location in a easy way, but still not share the location of every photo they share online.
- eru 6mo agoDefinitely. I want to be able to search my Google Photos for "Berlin" and get me all the pictures I took there.
- thaumasiotes 6mo ago> Not hard to imagine a lot of users want to organize their libraries by location in a easy way, but still not share the location of every photo they share online. The location isn't just embedded in the EXIF tags. It's also embedded in the visual content. I imagine people will get tired of their image uploads being blacked out pretty quickly.
- 47282847 6mo agoMy phone: my private space. Anything in the browser: not my private space. I want exactly that: the OS to translate between that boundary with a sane default. It’s unavoidable to have cases where this is inconvenient or irritating. I don’t even know on iPhone how files are named “internally” (nor do I care), since I do not access the native file system or even file format but in 99% of all use cases come in contact only with the exported JPEGs. I do want to see all my photos on a map based on the location they were taken, and I want a timestamp. Locally. Not when I share a photo with a third party.
- TheLNL 6mo agoIt is not just a default when it is the only option. The word default is more appropriately used when the decision can be changed to something the user finds more suitable for their usecase
- lifis 6mo agoObviously an image picker shouldn't leak filenames... The filename is a property of the directory entry storing the file storing the image. The image picker only grants access to the image, not to directories, directory entries or files. If you want filenames, you need to request access to a directory, not to an image
- butlike 6mo agoThe path is different than the filename though. If I want to find duplicates, it will be impossible if the filename changes. In my use case /User/user/Images/20240110/happy_birthday.jpg and /User/user/Desktop/happy_birthday.jpg are the same image.
- dns_snek 6mo ago> it will be impossible if the filename changes. Not impossible, just different and arguably better - comparing hashes is a better tool for finding duplicates.
- morissette 6mo ago^ facts
- butlike 6mo agoFrom a technological standpoint, sure. I'd argue when you're staring down the barrel of 19,234 duplicate file deletions, with names like `image01.jpg`, `image02.jpg` instead of `happy_birthday.jpg`, there's a level of perceptual cognitive trust there that I just can't provide.
- tart-lemonade 6mo agoIf your camera (or phone) uses the DCF standard [0], you will eventually end up with duplicates when you hit IMG_9999.JPG and it loops around to IMG_0001.JPG. Filename alone is an unreliable indicator. [0]: https://en.wikipedia.org/wiki/Design_rule_for_Camera_File_system https://en.wikipedia.org/wiki/Design_rule_for_Camera_File_sy...
- ieie3366 6mo agoMost likely: actually using the geolocation is an extremely niche usecase for images uploaded from mobile browsers. I’d wager 99.9% of the users didn’t realize that they are effectively sending their live GPS coords to a random website when taking a photo. But yes, a prop to the input tag ’includeLocation’ which would then give the user some popup confirmation prompt would have been nice
- embedding-shape 6mo ago> I’d wager 99.9% of the users didn’t realize that they are effectively sending their live GPS coords to a random website when taking a photo. I'd wager 90% of the photos on Google Maps associated with various listings don't actually know their photos are in public. I keep coming across selfies and other photos that look very personal, but somehow someone uploaded to Google Maps, the photo is next to a store or something and Google somehow linked them together, probably by EXIF.
- eru 6mo agoGoogle prompts you in Google Maps if you want to upload your picture to Maps. I sometimes do that for random pictures, even like selfies, which I don't mind popping up there.
- PokemonNoGo 6mo agoWait... You post selfies on Google Maps? The thought never crossed my mind. What would the purpose be? Sorry I'm probably thick...
- PepperdineG 6mo agoI can say for me that after my father died I posted pictures of him at some of his favorite places or from favorite trips.
- petu 6mo agoGoogle Maps app sees that you took photo near POI and later in the day asks you in notification if you want to share it on maps. You review the photo and go "lol, sure". At least for me that doesn't even feel like posting due to how frictionless it is and that it's about natural discoverability (someone has to click that POI and scroll through photos to find it).
- embedding-shape 6mo agoCouldn't you use <input type="file" accept=".jpg,.jpeg"> (different than image/jpeg mime-type I think, not sure if that also strips EXIF?), then manually parse the EXIF in JS? Shouldn't be that complicated to parse and I'm guessing there is a bunch of libraries for doing just that should you not want to do that yourself.
- embedding-shape 6mo agoI'm not sure why I'm being downvoted for this, so I guess I kind of accidentally nerdsniped myself here... Anyways, I did this: https://jsbin.com/teriduyexe/edit?html,output https://jsbin.com/teriduyexe/edit?html,output Which correctly seems to show the EXIF for uploaded images (both in Chrome and Firefox), and correctly filters things in the file picker window. What am I missing, why is this infeasible as a solution?
- edent 6mo agoI've just tried that in Chrome and Firefox on Android 16. Both just show zeros in the GPS EXIF - the rest of the data are passed through unaltered.
- embedding-shape 6mo agoAha, that'd explain it. Thanks a bunch for trying it out and telling me!
- sixhobbits 6mo agoIt's a sad story and a fun-looking project but I think Google 100% did the right thing here. Most people have no idea how much information is included in photo metadata, and stripping it as much as possible lines up to how people expect the world to work.
- maccard 6mo agoIf google really cared about privacy, they wouldn't have moved maps away from a subdomain. now if I want maps to have my location (logical), I need to grant google _search_ my location too.
- flipped 6mo ago[flagged]
- butlike 6mo agoI'm not sure I follow. maps.google.com still resolves?
- amazingamazing 6mo agoGoogle has your location either way. What difference does it make?
- kevin_thibedeau 6mo agoYou can lock down their usage. Limit it to three months storage and minimize sharing. They still report an old address for home and work for me since I dialed up the restrictions years ago. They have the data but it is less exposed.
- adrianN 6mo agoHow good are LLMs at geoguessing?
- embedding-shape 6mo agoBasically all up to the training data, as things often are.
- eru 6mo agoYou still need some smarts, since the picture you just took won't be in the training data.
- xg15 6mo agoI wonder if that might be another reason to just completely disable this feature and not make it a permission: otherwise people could use it to build trainingsets for geoguesser models.
- GRiMe2D 6mo agoPeople already uploaded tons of images and data while playing Pokemon GO. Probably model is already has been built and being tested right now
- firtoz 6mo agoPretty good. I test it every now and then from random photos. Sometimes spot on, sometimes gets very close, unless it's really ambiguous.
- jcalx 6mo agoQuite good, per Bellingcat [0] — Google Lens and ChatGPT could localize the majority of their test photos pretty specifically. [0] https://www.bellingcat.com/resources/2025/08/14/llms-vs-geolocation-gpt-5-performs-worse-than-other-ai-models/ https://www.bellingcat.com/resources/2025/08/14/llms-vs-geol...
- jillesvangurp 6mo agoPretty good. I played a bit with gpt-4 a year or so ago by feeding it random screenshots from Google street view. It will pick up a lot of subtle hints from what otherwise looks like generic streets. I imagine more recent models might be better at this now.
- softwaredoug 6mo agoIs location sharing something you can disable in iOS?
- ndegruchy 6mo agoYes. You can turn it off for Camera if you don't want the geotag to be included in the photo when taken. You can also, as part of the share media picker, opt to include or exclude location data on the photo.
- Barbing 6mo agoYou can also for example just by voice ask the phone to turn off location services, then take your photos. As one can imagine, even when turning location services back on, the photo will never contain location data.
- ndegruchy 6mo agoYeah, toggling in any manner you see fit (a Shortcut would be useful in this case) the location services in its totality or in the context of the Camera app would accomplish the same result.
- II2II 6mo agoYes, I get it. It is inconvenient for legitimate uses. The problem is that our devices leak too much confidential data. Privacy was mentioned outright in the article. Safety/security was alluded to with an example, which is something that goes far beyond a company's image or even liability. Unfortunately, there is no good way to solve the problem while maintaining convenience. As the author noted, prompts while uploading don't really work. Application defaults don't really work for web browsers, since what is acceptable for one website isn't necessarily acceptable for another. Having the user enter the location through the website make the user aware of the information being disclosed, but it is inconvenient. Does the situation suck? Yes. On the other hand, I think Google is doing the responsible thing here.
- SoftTalker 6mo agoAgreed. The default for a web browser should be maximum privacy/minimum sharing/minimum trust. If they want to access photos with geolocation they can make an app instead of a website, then the app can explictly ask for this permission. Too much trouble? Well then I guess it won't get done. Not the end of the world.
- arc_light 6mo ago[dead]
- eminence32 6mo ago> But it is just so tiresome that Google never consults their community. There was no advance notice of this change that I could find. Just a bunch of frustrated users in my inbox blaming me for breaking something. I get it. This unequivocally sucks. It's a clear loss of functionality for a group of people who are educated about the advantages and disadvantages of embedded EXIF data. But I don't honestly think Google could have consulted their community. It's just too big. So when the author says: > Because Google run an anticompetitive monopoly on their dominant mobile operating system. I don't think the problem here is that Google is anticompetitive (though that's a problem in other areas). I think it's just too big that they can't possibly consult with any meaningful percentage of their 1 billion customers (or however many Android users are out there). They may also feel it's impossible to educate their users about the benefits and dangers of embedded location information (just thinking about myself personally, I'm certain that I'd struggle to convey they nuances of embedded location data to my parents). I will note that Google Photos seems to happily let you add images to shared albums with embedded location information. I can't recall if you get any privacy-related warnings or notices.
- edent 6mo ago> But I don't honestly think Google could have consulted their community. It's just too big. The thing is, they frequently do. They have developer relations people, they publish blog posts about breaking changes, they work with W3C and other standards bodies, they reply on bug trackers. But, in this case, nothing. Just a unilateral change with no communication. Not even a blog posts saying "As of April, this functionality is deprecated."
- 1970-01-01 6mo ago>So, can users transfer their photos via Bluetooth or QuickShare? .. Literally the only way to get a photo with geolocation intact is to plug in a USB cable Bluetooth is not QuickShare, stop conflating them. Bluetooth works. I just tried it. It just sends the entire file to the destination, filename intact with all EXIF, no gimmicks, tricks, or extra toggles. As it has always done for 20+ years.
- edent 6mo agoOP here. I'm not conflating them. That's why I used the word "or". I don't know how modern your Android phone is, but on all of mine sharing via Bluetooth strips away some of the EXIF.
- 1970-01-01 6mo agoOn Android 16. Open photo. Hit share. Hit Bluetooth. Pick a device to send it to. Wait for xfer to finish. Observe in exifview. What detail is missing?
- edent 6mo agoAll the GPS data are nulled / set to zero.
- 1970-01-01 6mo agoI'm not able to repro, but you're likely seeing a problem with your flavor of device overlaid on vanilla Android.
- ajifurai 6mo agoIn my testing, when sharing from apps that use MediaStore like Google Photos or Fossify Gallery (using a `content://media/` URI), the GPS location was stripped even via Bluetooth. This seems to be the default behavior from Android 10 onwards. https://developer.android.com/training/data-storage/shared/media?hl=en#location-info-photos https://developer.android.com/training/data-storage/shared/m... > Photographs > If your app uses scoped storage, the system hides location information by default When sharing via FileProvider from file managers like MiXplorer or Total Commander, the raw file is sent as is, and the GPS location stays intact.
- zenmac 6mo agoNice drunk theme! All web site should have one.
- OuterVale 6mo agoThe author wrote about it here: https://shkspr.mobi/blog/2025/09/drunk-css/ https://shkspr.mobi/blog/2025/09/drunk-css/
- adzm 6mo agoThis is the right move. https://github.com/whatwg/html/issues/11724#issuecomment-4192228562 https://github.com/whatwg/html/issues/11724#issuecomment-419... and adding a feature to browsers to explicitly use the info is the best solution really. The problem is that there was a change without a backup solution without making a native app, but preventing people from accidentally uploading their location in an image is the right move. It really needs to be more well known and handled automatically.
- jeroenhd 6mo agoWhile I think it's the right move to disable location tags by default, I also think Google should've waited until a solution to the missing functionality had at least hit the WHATWG spec.
- master-lincoln 6mo agoI would agree if they switched the order: first make a UI to opt-in/out and then change the default. Now they just made operations impossible
- deleted 6mo ago[deleted]
- antiloper 6mo agoI don't know a good solution for this. 99% of websites asking for this hypothetical permission would not deserve it. Users (rightfully) don't expect that uploading a photo leaks their location. Element (the matrix client) used to not strip geolocation metadata for the longest time. I don't know if they fixed that yet.
- flipped 6mo agoGrapheneOS already does this, since forever. Android can't stop copying GOS. Maybe they'll add a network toggle after a few years and call it a privacy win.
- edent 6mo agoI don't think that's quite right. Up until recently I was able to share photos with geolocation from my GrapheneOS device.
- flipped 6mo agoMetadata can be attached but it's off by default.
- palata 6mo ago> Android can't stop copying GOS. Well that's a good thing, isn't it?
- HumblyTossed 6mo agoGood?
- flipped 6mo agoNSA agent getting burned?
- pjmlp 6mo agoGrapheneOS only exists because Google hasn't yet completely closed shop on AOSP availability. Who knows, it may eventually be only available on Motorola devices.
- cremer 6mo ago[dead]
- celsoazevedo 6mo agoFor most users, I think this is a good change. I used to run a small website that allowed users to upload pictures. Most people were not aware that they were telling me where they were, when the picture was taken, their altitude, which direction they were facing, etc.
- p_stuart82 6mo agodefaulting to strip location on share, fine. demoting plain old <input type=file> into "find a usb cable" / "go build an app" is a hell of a line to draw
- izacus 6mo agoApple was massively praised when they started stripping location data from shared and uploaded photos.
- kalleboo 6mo agoApple gives you the option in the photo picker to include or not include the location data.
- bilsbie 6mo agoDoes iPhone do this? Kind of scary to be accidentally sending your home address anywhere you upload a photo.
- nozzlegear 6mo agoYou can choose whether you want to share the location or not when selecting photos in iOS. You'll see at the bottom a label that says "Location is included", and you can click the three dots to remove location: https://imgur.com/a/lm0stDE https://imgur.com/a/lm0stDE Not sure if there's a way to do that by default, I've never checked.
- sambellll 6mo agoI feel like that's the optimal implementation - best of both worlds Wish android copied them for once lol
- Barbing 6mo agoI know which one works better for us. Which works better for grandma? (Of course, Google's move shouldn't have been altruistic, it would have been pragmatic as mentioned elsewhere.) If I got paid a nickel every time someone talked about protecting children online and I reinvested it into technology accessibility for seniors, it'd be fully funded! :)
- bilsbie 6mo agoInteresting. How does it work for texting?
- nozzlegear 6mo agoI just checked in iMessage. When you add an attachment and select photos, you get the same picker that the rest of the OS uses, it's just in a collapsed state. If you swipe up, it'll expand to fill the screen and that same "Location is included" label and configuration menu is available.
- merlin1de 6mo ago[dead]
- srcoder 6mo agoAlready use imagepipe [0] since forever, sometimes it takes soms extra time, still worth the effort. Most of the time I take a picture share with imagepipe, share with external and don't share anything else I will never share my location via images with anybody then myself. I do use location for my local Photoprism on my own server 0 https://codeberg.org/Starfish/Imagepipe#how-to-get-the-app https://codeberg.org/Starfish/Imagepipe#how-to-get-the-app
- simonw 6mo agoSurprisingly iOS doesn't do this - at least not for photos uploaded via a web form these days. Try this tool to see that (it should demonstrate the Android EXIF stripping behavior too): https://tools.simonwillison.net/exif https://tools.simonwillison.net/exif
- smileybarry 6mo agoiOS does this by default too, but it tells you about it and gives you the option to not strip the location from EXIF: the bottom of the photo picker has the text "Location not included", and the context menu opened by the "..." button on the left has a "Location" toggle. Just tested this myself on iOS 26.4.1.
- simonw 6mo agoThanks, just found that option hidden in the "..." and then "Options" menu: https://gist.github.com/simonw/6d530cdca574ac56450dfa805f25e7fd?permalink_comment_id=6096592#gistcomment-6096592 https://gist.github.com/simonw/6d530cdca574ac56450dfa805f25e...
- Barbing 6mo agoDoes the location messaging also feel more prominent to you from the Photos share sheet compared to the native image file picker? For example, that you would see when uploading to the ImgUr site. Mainly top versus bottom placement, I think, but also font size.
- akamaka 6mo agoI just tested this and the default setting is to include location, but once turned off it stays off (unlike the iPhone share sheet where you need to turn it off each time).
- smileybarry 6mo agoOdd, it was off for me the first time I opened that website, maybe it's persisted from some other context.
- NelsonMinar 6mo agoI wish they'd just switch to fuzzing the location instead of stripping it entirely. Instead of specifying 6 digits of lat/lon, publish 1 digit to identify what rough area you're in (to about 10km). I've done a lot of neat projects with geolocation over the years. Including a personal travel diary, a bunch of visualizations of tweets and Flickr photos, etc etc. I am sad that's become nearly impossible but I do respect that most people don't understand the privacy risk. Meanwhile on the advertising backend Google knows your exact location and is using it to help third parties target ads to you. And sleazy apps like Grindr sell location streams to anyone who asks. The bad guys get this data, just not the useful apps.
- hn_throwaway_99 6mo agoTotally disagree, as I think that would be the worst of all possible worlds - too fuzzy to be useful for many of the niche use cases where it's needed, and still a privacy violation for the majority of users who don't know their photos reveal their location. The other suggestion about requiring something like a useLocation or includeExif attribute on the file picker, and then requiring confirmation from the user, seems like a much better solution to me.
- ryandrake 6mo agoDepending on how populated your current location is, even a fuzzed location can reveal personal information. In a city, 10km is fine, nobody is identified. But if your home is the only one for 10km in any direction, and your fuzzing threshold is 10km, you've identified down to a single home.
- simondotau 6mo agoFuzzing should go to the centre of the nearest town with some minimum population, so long as that town is in the same state/country/timezone.
- Zak 6mo agoI don't like this. The Right Thing is for camera apps to not add location metadata by default. If you go in and turn location on (which should have a warning on it), then you're the sort of person who changes defaults, a more sophisticated user than the majority of the population who is able to take responsibility for the consequences. Yes, I can imagine a scenario where someone ends up with this setting turned on through no fault of their own, but it shouldn't be the role of an OS vendor to prevent every possible mistake.
- edent 6mo agoThe default camera app has this off by default. Most of the ones I've tried do. But do you remember every options you've randomly toggled over the years? It's pretty easy to see how someone would flip on geotagging, forget about it, then be shocked a few months later when they discover all their photos are leaking their location.
- black_puppydog 6mo agoIn a very similar situation to OP, this move totally broke a volunteer-run platform that allows (allowed...) users to report issues with bicycle lanes, missing racks, dangerous spots for cyclists etc... https://app.vigilo.city/ https://app.vigilo.city/ The app is very basic, but has amazingly little barriers to entry. Notably you don't need an account to just report things, what I'd call an "open door" app. Sadly, without gps exif, this is much higher friction now. Pretty pissed at this. It's not hard to design a clean flow that permits to inform the user specifically of location sharing in the picker.
- WhyNotHugo 6mo agoThis is a common approach to "privacy" taken by orgs like Google. You don't get to access or export your own data in order to protect your privacy, but Google still gets 100% access to it. Some messaging apps do the same and won't let you take a screenshot of your own conversations. Like, someone sent me an address, but I can't take a screenshot to "protect my privacy".
- Barbing 6mo agoImagine my surprise when I attempted to record the iPhone mirroring application, which was running on macOS. Apple did a great job on their DRM because I simply recorded a black screen while I was attempting to play back a video from an app on the phone. I'm sure it's given some businesses the confidence to invest in iOS app development, but it felt bad.
- busymom0 6mo agoI think that's for apps like Netflix or other movie streaming apps being recorded for piracy?
- Barbing 6mo agoYes, or a video editing app that wants you to buy it. I'm not _entirely_ upset Apple is encouraging the market to develop high-quality solutions by allowing them to protect their revenue. But it felt bad as if they were reaching into my Mac. My iPhone is Apple’s playground. They let me use it. But I own my Mac, and if my eyes see something on the screen it feels dumb to send Tim Apple and Reed Hastings into my homeoffice telling me “no no get a capture card(?) or set up a DSLR to record your screen. But no direct recording big guy!”
- jojobas 6mo agoAs if day 0 rippers needed this sort of mucking around to rip their stuff.
- xigoi 6mo agoWhich messaging apps are those? I have only seen such behavior for one-time photos, where it makes sense (although one-time photos are security theater because nothing prevents you from taking a photo of the screen with another device).
- shevy-java 6mo agoNow, I don't fully understand why people want their images to be tracked - but to each their own. I think this just shows that Google is very selfish, from A to Z. People should not empower this evil empire. Recently Google also stated that "cookies can not be stolen": https://www.heise.de/en/news/Google-Chrome-makes-cookie-theft-pointless-on-Windows-11251710.html https://www.heise.de/en/news/Google-Chrome-makes-cookie-thef... However had to me this reads as "we control the now private web". This also aligns, in my opinion, with age verification (systemd already pushes for it). So we move into a not so open world wide web. Are you identified? If yes, you can get information; if no you can not. Personally I am in the underground anyway, as long-term linux users so I don't really care that much (though I also use Win10 on a computer on my left side, for various reasons). But I am really annoyed at Google. Every day Google adds to problems and drama. It is not good that this monopoly can control so much in the whole ecosystem, even if I don't understand why people want to share photos and geolocation and what underwear they were wearing at that moment in time ...
- codethief 6mo agoIn a similar move (silently changing a feature crucial to some users), in Android 11 Google suddenly removed the possibility to use "special" characters ":<>?|\* in filenames[0], presumably because they're not allowed on Windows/NTFS and Windows users might end up struggling to transfer them to their Windows computer. I don't care about NTFS at all, though. I just want to be able to sync all my files with my Linux machines and now I'm no longer able to. Makes me want to scream. [0]: https://github.com/GrapheneOS/os-issue-tracker/issues/952 https://github.com/GrapheneOS/os-issue-tracker/issues/952
- ThePowerOfFuet 6mo agoPutting a star into a filename is a pain in the ass, no matter the OS.
- xp84 6mo agoEscaping and quoting isn’t really that hard
- raw_anon_1111 6mo agoYes and who needs Dropbox since for a Linux user, you can already build such a system yourself quite trivially by getting an FTP account, mounting it locally with curlftpfs, and then using SVN or CVS on the mounted filesystem. From Windows or Mac, this FTP account could be accessed through built-in software.
- xigoi 6mo agoI have a personal convention that all files I put into my synced folder must consist of lowercase alphanumeric characters, hyphens and periods (to be precise, match the regex /\.?([a-z0-9]([-.][a-z0-9])?)+/). It saves a lot of pain.
- raw_anon_1111 6mo agoAnd you don’t see why Google would cater to Windows and a Mac users at the expense of Linux users?
- Aachen 6mo agoI noticed this in an app's changelog recently, saying something along the lines of "remove metadata comparison function because new Android versions no longer support it" Thankfully F-Droid has a "never update this app" checkbox for now, but eventually I'm sure third-party developers will require minimum Android versions that mean I need to lose this functionality :/ Edit: found it, it was VesIC https://github.com/VincentEngel/VES-Image-Compare/releases/tag/fdroid-v2.3.1 https://github.com/VincentEngel/VES-Image-Compare/releases/t...
- drnick1 6mo ago> If anyone has a working way to let Android web-browsers access the full geolocation EXIF metadata of photos uploaded on the web, please drop a comment in the box. No. I don't want people like you unknowingly spying on me when I upload a picture. GrapheneOS patched that insane behavior long ago, but not including leaky metadata should be the default, sane behavior.
- netsharc 6mo agoHooray for nanny-enabled computing being forced on us!
- trashb 6mo agoLocation data should be opt in on capture, a checkbox deep in the settings: "capture location meta data" would be sufficient, or a button similar to the flash. Strange UI that they are involuntarily capturing but then removing it.
- izacus 6mo agoLocation data is off by default on pretty much all phones.
- rickdeckard 6mo agoI don't know, a quick check in Android documentation seems to describe this quite well [0]: If your app targets Android 10 (API level 29) or higher and needs to retrieve unredacted EXIF metadata from photos, you need to declare the ACCESS_MEDIA_LOCATION permission in your app's manifest, then request this permission at runtime. Caution: Because you request the ACCESS_MEDIA_LOCATION permission at runtime, there is no guarantee that your app has access to unredacted EXIF metadata from photos. Your app requires explicit user consent to gain access to this information. I made another quick check on my device, Chrome doesn't have the ACCESS_MEDIA_LOCATION permission and doesn't seem to request it at runtime, so the location info is stripped from the EXIF data (by the OS!) when a file is selected. Chromium also seems have no feature to ask the user whether he agrees to share the stored location when uploading images, so there is probably no capability to request the permission at runtime. Not satisfying, I know, but despite some judgements in the tickets the implementation seems to work as designed. Instead, it could be considered a feature-request for Chrome to ask the user about this on upload, or couple the location-permission of a website to the permission to share EXIF-location data when uploading files (Although I think the logic on that is not really tight, the user giving permission to share his location now doesn't necessarily mean that he agrees to share all his locations from the past from EXIF-data) [0] https://developer.android.com/training/data-storage/shared/media#media-location-permission https://developer.android.com/training/data-storage/shared/m...
- dgoldstein0 6mo agoMy personal pet peeve is that iOS strips exif time taken (probably all exif) through certain flows - I think iMessage does it? So then if my family texts me a photo of a trip way after it happened and I save it it ends up in the wrong part of my photo timeline. Whereas if they share it a different way like Dropbox it comes through with that metadata intact. I care less about the location data as I usually know where the photos are just by looking at them but I understand there are good use cases for it and agree including location should be a user choice
- adolph 6mo agoThe article is about browsers filtering EXIF metadata from image uploads and not about advising users when observable sun angle or other distinctive features may disclose the photograph's location. Suncalc models the relationship between the date, time of day, the geographic location of a place, and the position of the sun in the sky, together with the length & direction of the shadows it casts. [0] 0. https://bellingcat.gitbook.io/toolkit/more/all-tools/suncalc https://bellingcat.gitbook.io/toolkit/more/all-tools/suncalc
- CodesInChaos 6mo agoA warning before uploading with the option to strip metadata would make sense. But I want to ability to upload a file to a website without it getting silently corrupted in transit.
- Johnny555 6mo agoI like having location in my photo album (so I can easily search for vacation photos, or figure out where a photo was taken), but I don't want it stored in the photo metadata I share the photo. Is there any way to have Apple or Google photos track the location when the photo is uploaded, but not store it in the photo itself?
- izacus 6mo agoThat's the default behavior on Android these days - using the share sheet strips location data.
- ButlerianJihad 6mo agoI noticed that this headline is in lowercase, and I can tell you why Google/Android is doing this: because of the uppercase app "Photos" by Google. Recently, I've been struggling with adding locations to some photos after-the-fact, such as edited photos as well as screenshots (because these screenshots are from location-based apps). The Photos app always tells me that "location will only be visible inside Photos" -- that is, only to users of the app, and those who I share with inside the app. If the image is downloaded or extracted from the Photos app, apparently it will lose that location info and it won't be stored in the EXIF as normal. This is because Android, like iOS, seeks to assert control over the JPEG/PNG image file types, and claim them as a special object type which can only be handled by Photos and other image-handling apps. These image-format objects will no longer be treated as normal files that you can just throw anywhere, but as something that only Photos can handle on your phone, and tied inextricably to the Photos app. Therefore, any metadata that you add shall be stored and managed by Photos, and not in the file itself, because that would be interoperable, and that would be absolutely nuts!
- phatskat 6mo agoAFAIK iOS gives you the option to include location data when sharing a photo, no?
- rstuart4133 6mo agoI suspect this horse has bolted. When I see a photo on a website and I want to know where it's taken, I assume it's been stripped already and ask an AI. The accuracy is uncanny. Since it's a rare web site that leaves the EXIF data intact, I guess this is aimed at apps harvesting photos on the device itself. I hope Firefox gets a new site permission that allows you to upload photos with the EXIF intact, because that's often what I want. But that won't happen for a while, and until apps do get their permissions updated it's going to be annoying. It will be a right proper PITA to discover later your EXIF data is gone from the photos you transferred to your laptop.
- Self-Perfection 6mo agoThis is a push for privacy and it is fundamentally pushes in the opposite direction from let's say "forming accurate knowledge about the world". How can we combat being mislead by false AI generated images? I'd say keeping track of provenance is what we should adopt, at least as an option. I hope we will find solutions to propagate images over the net reliably keeping how, when and where they were taken.
- linzhangrun 6mo ago[flagged]
- msla 6mo agoInterestingly, the Wikipedia app devs prevent you from opting out of sharing supposedly-anonymous data with their app. Supposedly-anonymous because I think we all know how deanonymizing works by now, and how easy it is: https://phabricator.wikimedia.org/T356260 https://phabricator.wikimedia.org/T356260 Just more push and pull on privacy, mostly pulling it away from you, it seems.
- skyberrys 6mo agoI am developing an Android application that uses image location data, in fact, the primary purpose of the app is for the user to curate the location data so it is accurate enough to depict the location and life cycle of a flower from a series of timestamped photos of the flower. I guess I share to point out that the solution of developing a android native app is not that burdensome, and it is some kind of data you want the user to be intentional with.
- Animats 6mo agoThis prevents uploading pictures, with chain of custody data attached, of law enforcement misbehaving. Was there pressure from ICE to install this feature?
- Terr_ 6mo agoI feel this is a failure to capture/model the different use-cases between: 1. Copy file from A to B 2. Publish file to a public realm If Google thinks that the average site cannot be trusted to indicate/clarify the difference... Well, that's fair, but (as the blogpost says) I'd rather see some browser permission thing like: "Can this website see original filenames and GPS data inside any media you upload?"
- klinquist 6mo agoYeah, I also find this annoying. I created a site that lets Ham Radio Parks on the Air operators share photos of their setups in parks (https://www.potaparkpics.com https://www.potaparkpics.com). I do it with no login - you simply specify what park you are in, then upload photos. I use the geolocation (comparing the photo exif against the park you said you were in) as authentication. Works great - but only for iPhone users.
- mark124mj 6mo agoIt's interesting that Android is actually ahead of iOS on this, as simonw pointed out, iOS still doesn't strip location data from photos uploaded via web forms. This should be the default on both platforms. Most people have no idea they're attaching exact GPS coordinates to every photo they share, and the safety implications alone (stalking, doxxing) make it worth the tradeoff for the small number of use cases that rely on it.
- stek29 6mo agoBut iOS allows to choose whether location should be included or stripped, and remembers your choice for next upload if I remember correctly.
- netsharc 6mo agoGod, I hate that OSes have nannies that are getting more and more involved, and look at how many HNers like you are saying that it's a great idea... What's next, "I can't let you view this content, it has been deemed too radical "?
- jiri 6mo agoIs it possible to extract exif info client side (in browser, via javascript) and then upload photo standard way and exif metadata via side channel?
- rickdeckard 6mo agoNo, the Chrome app doesn't do the stripping. It uses native APIs to request the media file from the OS and since the app doesn't request the permission to receive location data along with it, the OS provides the files without the location Related permission: https://developer.android.com/training/data-storage/shared/media#media-location-permission https://developer.android.com/training/data-storage/shared/m...
- netsharc 6mo agoHow lovely, a file read API that lies to you...
- sparkupcloud 6mo ago[dead]
- baumschubser 6mo agoI understand that you want the location of the photo and not the location of the user uploading that photo, but given that both are identical in many cases, getting the location with the regular geolocation API might be an acceptable solution that is also transparent to the user. Show a location picker with the user's current location and the option to select an alternative location. Not as smooth as using EXIF data, but doable.
- guanyuxiaxue 6mo agoGoogle always loves to keep a tight grip on Android to use it as their ultimate trump card. I reckon they should stop updating the Android Open Source Project source code; that way, Google would have even more control over Android and it would set the stage for more of their outrageous behaviour.
- redsocksfan45 6mo ago[dead]
- coreyburns 6mo agoWhew! Glad I can stop tell folks to turn that feature off then.