5 ms·
I do not see problems with fake ad clicks and have no sympathy for ad companies. Also pre-installed adware is not a surprise, I found adware in the official fi
by codedokode 2mo ago
I do not see problems with fake ad clicks and have no sympathy for ad companies.
Also pre-installed adware is not a surprise, I found adware in the official firmware image of a certain Chinese tablet.
What worries me much more is backdoors from the foreign companies and governments that can be pre-installed at the factory to collect intelligence information. For example, I became aware that a certain maker of a popular mobile OS was collecting the cell tower IDs and WiFi access point identifiers along with GPS coordinates of a device. Obviously they collect this information to be able to guide missiles and drones when GPS signal is jammed (GPS is very low power and easy to jam). This is not acceptable.
How can we prevent this? I think, for every imported device having a CPU and Internet connectivity:
- the user must be able to re-flash firmware with their own code.
- the local government must have access to the full source code and be able to search for vulnerabilities or backdoors, including using AI tools. Found vulnerabilities are considered a reward and may be used against countries not doing inspections. No access - no import permission.
- any telemetry or data collection, or updates must be opt-in only and disabled by default.
- any telemetry or updates must go through a server controlled by the local government, in unencrypted form, to detect attempts to collect intelligence information or install malicious update.
Sadly our government instead only demands that manufacturers pre-install their closed-source software on all imported devices and that's all.
- BoppreH 2mo ago> a certain maker of a popular mobile OS was collecting the cell tower IDs and WiFi access point identifiers along with GPS coordinates of a device. Obviously they collect this information to be able to guide missiles and drones when GPS signal is jammed Is this sarcasm? GPS can take several minutes to get a location, and works poorly indoors. One of the reasons why Google Maps is so quick and precise is because Google has gathered exactly this data through users and Street View drive-bys. Could it be used for missiles? Sure. Is it obviously the intention? No.
- meatmanek 2mo agoYeah this is extremely standard: Apple: https://support.apple.com/en-us/102515 https://support.apple.com/en-us/102515 > If Location Services is on, your device will periodically send the geo-tagged locations of nearby Wi-Fi hotspots and cell towers to Apple to augment Apple's crowd-sourced database of Wi-Fi hotspot and cell tower locations. Google: https://support.google.com/android/answer/15157297?sjid=16484070620133019469-NC https://support.google.com/android/answer/15157297?sjid=1648... > When Location Accuracy is on, Google periodically collects information about the locations of wireless signals and sensors observed by your device to crowdsource location estimates. This helps everyone find locations better. Mozilla used to run a very similar service: https://en.wikipedia.org/wiki/Mozilla_Location_Service https://en.wikipedia.org/wiki/Mozilla_Location_Service Not to mention truly crowd-sourced databases like wigle.net.
- codedokode 2mo agoThey should ask the permission from device owner and local government before collecting the data.
- aeturnum 2mo agoThey do ask the device owner - if you review the location services description on android[1] you will see they explicitly say they collect this information from your device. I strongly disagree that they need to get government permission for this - they are simply recording signals that reach the device, akin to making notes about what kinds of cars you see. This is not a thing a government should have control over people doing and not a thing that should be registered with the governement. [1] https://support.google.com/android/answer/3467281?sjid=666343528399899250-NC https://support.google.com/android/answer/3467281?sjid=66634...
- codedokode 2mo agoIn the article you refer to, I see no mention of asking user's permission. However, I remember, when using an old version of Android, there indeed was a popup nagging me to allow sharing location data with Google every time I enabled GPS. Very annoying, makes you want to never enable GPS in the first place. Regarding the government, the problem is that many people do not fully understand the mechanism of collecting the data. I remember the case when members of US military disclosed the location of secret objects through fitness tracker app. And they were probably smarter than average smartphone user. Obviously it would be better if enabling GPS required an approval from their commander.
- codedokode 2mo agoShould Google ask permission from the device owner, and from the local government before collecting the data? I heard a certain foreign mobile app was banned in US for doing less than that.
- pavel_lishin 2mo ago> Obviously they collect this information to be able to guide missiles and drones when GPS signal is jammed Are there a lot of missiles that travel slowly enough to be able to guide themselves via watching for nearby wifi signals? > for every imported device having a CPU and Internet connectivity Why limit this to imported devices?
- palmotea 2mo ago>> Obviously they collect this information to be able to guide missiles and drones when GPS signal is jammed > Are there a lot of missiles that travel slowly enough to be able to guide themselves via watching for nearby wifi signals? Cheap, slow-moving drones are the hot new missiles on the battlefield of today. This often talked-about model files at 115 mph (https://en.wikipedia.org/wiki/HESA_Shahed_136 https://en.wikipedia.org/wiki/HESA_Shahed_136).
- bee_rider 2mo agoI think that might have been semi-sarcastic. I mean, there are lots of reasons to do this sort of thing, some are bad, some are not so bad, most are not war.
- codedokode 2mo agoIn some areas GPS is spoofed and the displayed location is wrong. If, for example, a "smart" car gets a task from its manufacturer to film some secret object, it would fail if it relied only on GPS and did not use cell towers and WiFi points for determining its location. So knowing their location determines whether the mission would fail or succeed. So foreign devices should not be allowed to collect such information.
- IncreasePosts 2mo agoFake ad clicks cost the advertiser money, not the ad company. Ad companies generally try to detect fake clicks, but any fake clicks that get through just earn money for the ad company (at the cost of making the advertisers campaign have a lower ROI)
- mcphage 2mo ago> Fake ad clicks cost the advertiser money, not the ad company. It also diminishes the value of the clicks provided by the ad company. It doesn't cost them dollars directly, but makes all their advertising worth less.
- codedokode 2mo agoGood products do not need much advertising. For example, when buying DRAM, I compare the specification and prices and do not look at the advertisement.
- Thrymr 2mo ago> I do not see problems with fake ad clicks and have no sympathy for ad companies. I am not shedding any tears for the ad companies, but I don't exactly expect or want a consumer device to be doing this in the background without the owner's knowledge.
- jrm4 2mo agoSure. And you'll quite literally never be able to get any meaningful reduction in this practice unless you attack it at the level of big, publically known companies; the warnings about these local dinky things I suppose are not harmful and help individuals a bit -- but I'm concerned they give the entirely false impression that the extremely similar stuff coming from the big boys is definitely a-ok.
- Dylan16807 2mo agoReduction in what practice? Are there big companies doing ad fraud? I want big companies to stop spying on me, which is a completely different issue.
- jrm4 2mo agoThey're not at all "completely different issues." Both are well within the category of "If you buy a device to do a thing, then the device does something else that is not readily apparent to the user that user would find objectionable if they had clearer knowledge." This is immoral and harmful regardless of precise vector/action.
- Dylan16807 2mo agoThat spying harms me while ad fraud harms random companies is already enough to separate them by a lot, I'd say. But also the spying is expected by a lot of people. And a lot of people wouldn't object so much to screwing up internet ads.
- mcphage 2mo ago> I do not see problems with fake ad clicks and have no sympathy for ad companies. Yeah, it's like—a cheap streaming stick AND it poisons the advertising well? I'm pretty happy with my Fire TV Stick, but they're really tempting me here.
- exe34 2mo agoMy pinenote runs the original spyware image - I don't have a problem with Winnie the Pooh reading along with me.
- autoexec 2mo ago> Yeah, it's like—a cheap streaming stick AND it poisons the advertising well? Keep in mind that it's your IP and identity associated with those clicks and anything else criminals decide to do with your IP address. That means you're identity is being linked to things you may or not want to be known as being interested/involved in. The ads your TV stick clicks on can cause data brokers to include your name in lists of people who are heavily into drugs, have mental disorders, belong to certain religions or political parties, etc. All of that can come back to haunt you later. Depending on what other activity your connection is used for as a proxy it can also get you in trouble with the police or with your ISP.
- inigyou 2mo agoSo you're saying it's going to weaken the presumption that an IP can be easily tracked to an individual? Even better!
- mcphage 2mo agoTalk about the gift that keeps on giving…
- autoexec 2mo agoNo, your IP will be easily tracked to you as an individual. You'll just suffer the consequences of whatever your streaming stick does with your IP. If your stick clicks a bunch of ads for fast food your heath insurance bill goes up because their algorithm thinks you're a higher risk. If your streaming stick clicks a bunch of ads for high end luxury goods, online stores start charging you more than they charge your neighbor for the same items because their algorithms think you have money to burn. Your streaming stick clicks a bunch of ads for addiction recovery services, you don't get a call back for the next job you apply to because the HR department paid a data broker to run a background check looking for "red flags". What you do on the internet has very real impacts on your life offline and it's going to happen more and more over time. AI will make it easier for companies to leverage the massive amounts of data avilable to them about you. Surveillance pricing is spreading. Consumer reputation services are spreading. Law enforcement is buying up data from data brokers. Extremists are using data brokers to decide who to target with violence. Nobody cares if the data they have isn't 100% accurate. The data broker doesn't care. He gets paid either way. The companies buying your data don't care either. It's all a numbers game to them. They just have to be right enough times to justify the cost of the data.
- Cider9986 2mo ago>What worries me much more is backdoors from the foreign companies and governments that can be pre-installed at the factory to collect intelligence information. Most Americans are at a greater threat of harm from their own government that a foreign one. What worries me is all the mass surveillance done by big tech which bypasses the 4th Amendment and gives the government Americans data without a warrant. There's already a front door with the adtech for US alphabet boys. This could likely be collected by others as well. We saw this happened where foreign hackers exploited a backdoor designed for American authorities[1]. This is what experts are referring to when they say there's no backdoor only for me. This could be compelling to politicians, though, and would certainly be a step in the right direction. >- any telemetry or data collection, or updates must be opt-in only and disabled by default This should be how it is for everything foreign made software or not. Would be very hard to get done with the big tech lobby in the US. [1] https://techcrunch.com/2024/10/07/the-30-year-old-internet-backdoor-law-that-came-back-to-bite/ https://techcrunch.com/2024/10/07/the-30-year-old-internet-b...
- arjie 2mo agoOh this was a failed device that Mozilla offered. I had a couple back in the day. It was called Matchstick. Sick t shirts. Basically an OSS chromecast.
- soulofmischief 2mo agoThe problem is that when you need these powers most as a citizen is when your government is least likely to allow it.
- Tangurena2 2mo ago> What worries me much more is backdoors from the foreign companies and governments that can be pre-installed at the factory to collect intelligence information. The Snowden leaks showed that the US was already doing this. I'm certain that everything purchased is already infected with something. Most likely bugs and bad security.