Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
x1sec
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
x1sec
3y ago
Nice find. It appears the application is by the same developer [1]: The play store page for this app states: - No data shared with third parties - This app may collect these data types - Data isn’t encrypted - You can request that data be d
32.
▲
by
x1sec
3y ago
The manifest has ACCESS_FINE_LOCATION. When you run the application, the developer actually displays a popup saying to grant the permission so it can do BLE scanning to connect to the hardware device. Of course they neglect to say they will
33.
▲
by
x1sec
3y ago
Great - good luck and most of all, have fun!
34.
▲
by
x1sec
3y ago
Good point, and I assume this is why Google has taken this approach. That said, the more location data points you have, the more accurate the location (larger sample size, time proximity data - GPS is accurate always , SSID/BSSIDs can
35.
▲
by
x1sec
3y ago
Can you link me to the app store for this? Happy to take a look.
36.
▲
by
x1sec
3y ago
I agree and Apple's approach does this. You can deny the location permissions and still use the Bluetooth services. This is not the case with Android.
37.
▲
by
x1sec
3y ago
The OIAC (Privacy regulator in Australia) notes [1]: > If you’re concerned your personal information has been mishandled, you first need to complain to the organisation or agency you think has mishandled it. If they don’t respond to your
38.
▲
by
x1sec
3y ago
In the second part of the blog post series, I show that they AMap SDK they use encrypts data data first using AES and then further encrypting the AES key(s) with a public RSA key embedded in the application. Not trivial. If certificate pinn
39.
▲
by
x1sec
3y ago
Android warns the user that location related permissions are required. The issue is, is that this is required for Bluetooth scanning and the app developer abuses this by collecting other 'location data'. The app developer even tri
40.
▲
by
x1sec
3y ago
> don't install apps unless absolutely necessary Very sound advice. What if you have purchased some Bluetooth enabled device that requires an app? Don't purchase Bluetooth/connected hardware? Perhaps! My next blog post wil
41.
▲
by
x1sec
3y ago
Most defiantly. iOS is a different kettle of fish. Same challenges are present with performing forensics on an iPhone! The top commercial forensic toolkits will try to jailbreak the handset if possible to pull off artifacts. Good luck on ne
42.
▲
by
x1sec
3y ago
Thanks! Part of my motivation to documenting this is to raise awareness and also provide encouragement for others to start looking at what their devices/apps in their home are doing. The amount of location data the device maker is coll
43.
▲
by
x1sec
3y ago
I know someone who actually has a few of these devices - they are big into their FWD'ing - they have solar panels on their roof and spend days 'off the grid'. Another (more common) use case is people that take their caravan o
44.
▲
by
x1sec
3y ago
This is very true. I make an effort to point out that MITM proxy now supports Wireguard [1] to tunnel traffic out from the handset. It literally should take no more then 5 minutes from download to packet inspection. Of course if TLS is use
45.
▲
by
x1sec
3y ago
The best way is to just start practicing. I would say pick some simple apps on your (Android) phone and dig straight in. The great thing about Android applications is that often they generally decompile quite nice into human readable Java s
46.
▲
by
x1sec
4y ago
Had a similar experience, so I decided today to write a Github action[1] that automatically takes the contents of an Obsidian[2] vault, generates static content with Hugo and publishes it on Github pages. Hopefully I have documented the ste