Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.mobile.android > #56790 > unrolled thread

Proof that you cannot avoid google/alphabet on Android

Started byChris <ithinkiam@gmail.com>
First post2018-10-23 09:20 +0100
Last post2018-10-24 17:54 +0100
Articles 15 — 9 participants

Back to article view | Back to comp.mobile.android


Contents

  Proof that you cannot avoid google/alphabet on Android Chris <ithinkiam@gmail.com> - 2018-10-23 09:20 +0100
    Re: Proof that you cannot avoid google/alphabet on Android Andy Burns <usenet@andyburns.uk> - 2018-10-23 09:27 +0100
      Re: Proof that you cannot avoid google/alphabet on Android Chris <ithinkiam@gmail.com> - 2018-10-23 11:50 +0000
        Re: Proof that you cannot avoid google/alphabet on Android Joerg Lorenz <hugybear@gmx.ch> - 2018-10-23 18:19 +0200
    Re: Proof that you cannot avoid google/alphabet on Android Joerg Lorenz <hugybear@gmx.ch> - 2018-10-23 18:18 +0200
    Re: Proof that you cannot avoid google/alphabet on Android VanguardLH <V@nguard.LH> - 2018-10-23 12:51 -0500
      Re: Proof that you cannot avoid google/alphabet on Android Andy Burns <usenet@andyburns.uk> - 2018-10-23 19:03 +0100
        Re: Proof that you cannot avoid google/alphabet on Android Chris <ithinkiam@gmail.com> - 2018-10-23 19:17 +0000
        Re: Proof that you cannot avoid google/alphabet on Android VanguardLH <V@nguard.LH> - 2018-10-23 16:24 -0500
    Re: Proof that you cannot avoid google/alphabet on Android Frank Slootweg <this@ddress.is.invalid> - 2018-10-23 18:33 +0000
      Re: Proof that you cannot avoid google/alphabet on Android Chris <ithinkiam@gmail.com> - 2018-10-23 19:09 +0000
        Re: Proof that you cannot avoid google/alphabet on Android M.L. <me@privacy.invalid> - 2018-10-24 01:56 -0500
      Re: Proof that you cannot avoid google/alphabet on Android nospam <nospam@nospam.invalid> - 2018-10-23 15:20 -0400
        Re: Proof that you cannot avoid google/alphabet on Android 123456789 <12345@12345.com> - 2018-10-23 13:19 -0700
    Re: Proof that you cannot avoid google/alphabet on Android Java Jive <java@evij.com.invalid> - 2018-10-24 17:54 +0100

#56790 — Proof that you cannot avoid google/alphabet on Android

FromChris <ithinkiam@gmail.com>
Date2018-10-23 09:20 +0100
SubjectProof that you cannot avoid google/alphabet on Android
Message-ID<pqmljo$r5h$1@dont-email.me>
Or facebook, twitter, etc. A study has tracked where data leaked from 
android apps ends up
https://ig.ft.com/mobile-app-data-trackers/

[toc] | [next] | [standalone]


#56791

FromAndy Burns <usenet@andyburns.uk>
Date2018-10-23 09:27 +0100
Message-ID<g384c9Fd17fU1@mid.individual.net>
In reply to#56790
Chris wrote:

> Or facebook, twitter, etc. A study has tracked where data leaked from 
> android apps ends up
> https://ig.ft.com/mobile-app-data-trackers/

To visit that URL directly you'll an FT subscription, if you don't have 
one, put that URL into a search engine and follow the result, which will 
give you a referrer: that allows viewing without subscription ...

[toc] | [prev] | [next] | [standalone]


#56793

FromChris <ithinkiam@gmail.com>
Date2018-10-23 11:50 +0000
Message-ID<pqn1uo$47g$1@dont-email.me>
In reply to#56791
Andy Burns <usenet@andyburns.uk> wrote:
> Chris wrote:
> 
>> Or facebook, twitter, etc. A study has tracked where data leaked from 
>> android apps ends up
>> https://ig.ft.com/mobile-app-data-trackers/
> 
> To visit that URL directly you'll an FT subscription, if you don't have 
> one, put that URL into a search engine and follow the result, which will 
> give you a referrer: that allows viewing without subscription ...

Thanks. Forgot about that as they allow you one or two views a day from
Twitter for free. 

[toc] | [prev] | [next] | [standalone]


#56801

FromJoerg Lorenz <hugybear@gmx.ch>
Date2018-10-23 18:19 +0200
Message-ID<pqnhmu$959$2@dont-email.me>
In reply to#56793
Am 23.10.18 um 13:50 schrieb Chris:
> Andy Burns <usenet@andyburns.uk> wrote:
>> Chris wrote:
>>
>>> Or facebook, twitter, etc. A study has tracked where data leaked from
>>> android apps ends up
>>> https://ig.ft.com/mobile-app-data-trackers/
>>
>> To visit that URL directly you'll an FT subscription, if you don't have
>> one, put that URL into a search engine and follow the result, which will
>> give you a referrer: that allows viewing without subscription ...
> 
> Thanks. Forgot about that as they allow you one or two views a day from
> Twitter for free.
> 
In relation to the topic the ft-website is one of the worst you can find.

[toc] | [prev] | [next] | [standalone]


#56800

FromJoerg Lorenz <hugybear@gmx.ch>
Date2018-10-23 18:18 +0200
Message-ID<pqnhke$959$1@dont-email.me>
In reply to#56790
Am 23.10.18 um 10:20 schrieb Chris:
> Or facebook, twitter, etc. A study has tracked where data leaked from
> android apps ends up
> https://ig.ft.com/mobile-app-data-trackers/
> 
Tell us news, you smart ass you! ;-)

[toc] | [prev] | [next] | [standalone]


#56802

FromVanguardLH <V@nguard.LH>
Date2018-10-23 12:51 -0500
Message-ID<76hkbr1496d9.dlg@v.nguard.lh>
In reply to#56790
Chris wrote:

> Or facebook, twitter, etc. A study has tracked where data leaked from 
> android apps ends up
> https://ig.ft.com/mobile-app-data-trackers/

If there was indeed a "study" then it is published somewhere OTHER than
just this web site.  Give a URL to the study itself since your link is
worthless - and, no, I'm not signing up to register at a web site just
to read an article posted there that apparently is just a blurb or
analysis of a study published elsewhere.

If the article cites a study, there WHERE is that study published?  Is
it an actual newsworthy study or just someone's blog?

[toc] | [prev] | [next] | [standalone]


#56803

FromAndy Burns <usenet@andyburns.uk>
Date2018-10-23 19:03 +0100
Message-ID<g39649FjrebU1@mid.individual.net>
In reply to#56802
VanguardLH wrote:

>   Give a URL to the study itself

When I saw the study was at arxiv, I assumed you'd need to pay for 
access there instead, but it's freely available

<https://arxiv.org/pdf/1804.03603.pdf>

[toc] | [prev] | [next] | [standalone]


#56806

FromChris <ithinkiam@gmail.com>
Date2018-10-23 19:17 +0000
Message-ID<pqns4l$iu3$1@dont-email.me>
In reply to#56803
Andy Burns <usenet@andyburns.uk> wrote:
> VanguardLH wrote:
> 
>> Give a URL to the study itself
> 
> When I saw the study was at arxiv, I assumed you'd need to pay for 
> access there instead, but it's freely available
> 
> <https://arxiv.org/pdf/1804.03603.pdf>

Yep. By design, everything is freely accessible on arxiv. 

[toc] | [prev] | [next] | [standalone]


#56816

FromVanguardLH <V@nguard.LH>
Date2018-10-23 16:24 -0500
Message-ID<1v2fxlk1q75u.dlg@v.nguard.lh>
In reply to#56803
Andy Burns wrote:

> VanguardLH wrote:
> 
>>   Give a URL to the study itself
> 
> When I saw the study was at arxiv, I assumed you'd need to pay for 
> access there instead, but it's freely available
> 
> <https://arxiv.org/pdf/1804.03603.pdf>

Thanks for the link.  Something about that study seems familiar;
however, I didn't see a reprint or obsoleted version noted in it.  Could
be just prior studies and this one having similar data and conclusions.

"applications which derive revenue from monetising user data and
displaying behaviourally targeted advertising"

So the real source of all that tracking and data leaking are by the apps
you choose to install.  Many developers just copy the code into their
app to do the ads and tracking.  Some developers won't even offer an
ad-free paid version since they can generate what revenue they want from
the prebuilt ad platform they incorporate into their app.  Monetizing of
mobile apps is a long-time problem.

Instead of using ad/content/tracking blocker extensions in web browser,
a proxy is needed to monitor the targets of all network connections by
all those spying apps.  Alas, that could mean having to root the phone.
I remember one called AdAway (https://adaway.org/) but never used it
because by the time I feel that I might root my phone is after a couple
years of use and then I'm onto the next phone whose warranty I don't
want to void.  Adguard's freeware is just for web browsers.  You must
pay ($10/yr, $30/lifetime) for their payware VPN proxy version but it
doesn't need root.  Instead it redirects through their VPN server that
does the content stripping.  DNS66 is another non-root VPN-based
solution that was free.  DNS works by blocking the DNS lookups to ad and
tracking sources - but that won't work if an app uses IP address;
however, it interfered with the Google Play store app getting new apps
or automatically updating them.  You had to revert to not using their
VPN proxy to get apps via Google Play Store or to update those already
installed.  You also have to assume that DNS66, Adguard, and AdAway
aren't collecting their own statistics on your traffic to sell it off.

Even though the study has a recent publish date (18-Oct-2018), the
problem of apps incorporating an ad & tracking platform (chunks of code
the authors paste into their app) isn't new.  AdAway has been around
before 2013 when Google yanked it from their store.  AdGuard has been
around a long time and, in fact, has some blacklists that I use in
uBlock Origin in my web browsers.  DNS66 showed up sometime around Fall
of 2016 and seemed a good free choice but I don't how much volume of DNS
requests they can handle over a VPN connection to their server(s), and
it interferes with keeping my apps up to date except through manual
intervention (so not automatic).  Also, the VPN'ed DNS lookups are not
encrypted, so it's possible to monitor to where you mobile device is
connecting.  Rather than use DNSCrypt (as does Adguard), Julian is
looking at rewriting DNS66 to use TLS but doesn't look to have much
progress.  He might just wait until Android 9 which has native DNS over
TLS support.

Even if you use a root or non-root scheme to block ad and tracking
content, that doesn't means apps won't continue displaying ads.  Some
come with a fixed number of ads or will cache them up.  The space for
the banner bar will still be in the app but missing content; i.e., you
don't get back any screen realestate by blocking the sources for the ads
the app would otherwise display.  However, it sure would be nice to kill
off those fullscreen ads that app authors deny responsibility that
interfere with using their app or even with using your phone.

[toc] | [prev] | [next] | [standalone]


#56804

FromFrank Slootweg <this@ddress.is.invalid>
Date2018-10-23 18:33 +0000
Message-ID<pqo0i7.60c.1@ID-201911.user.individual.net>
In reply to#56790
Chris <ithinkiam@gmail.com> wrote:

> Proof that you cannot avoid google/alphabet on Android
>
> Or facebook, twitter, etc. A study has tracked where data leaked from 
> android apps ends up
> https://ig.ft.com/mobile-app-data-trackers/

  More meaningless FUD.
  
  Of course you *can* avoid tracking. The *point* however is that many
people *'want'* to be tracked. I.e. they want to use 'free' services,
apps, etc.. Hence they - implicitly or explicitly - consent that *they*
are the product and hence will be tracked.

  IOW, DUH!

[toc] | [prev] | [next] | [standalone]


#56805

FromChris <ithinkiam@gmail.com>
Date2018-10-23 19:09 +0000
Message-ID<pqnrl4$fiv$1@dont-email.me>
In reply to#56804
Frank Slootweg <this@ddress.is.invalid> wrote:
> Chris <ithinkiam@gmail.com> wrote:
> 
>> Proof that you cannot avoid google/alphabet on Android
>> 
>> Or facebook, twitter, etc. A study has tracked where data leaked from 
>> android apps ends up
>> https://ig.ft.com/mobile-app-data-trackers/
> 
>   More meaningless FUD.
>   
>   Of course you *can* avoid tracking. The *point* however is that many
> people *'want'* to be tracked. I.e. they want to use 'free' services,
> apps, etc.. Hence they - implicitly or explicitly - consent that *they*
> are the product and hence will be tracked.
> 
>   IOW, DUH!

The point is that the amount of data sharing is more than you'd expect. 90%
of ~1m apps tested share data to third parties most to several. 

Given the ubiquity, i frankly don't know how you'd avoid it unless you
don't have a smartphone at all. 

What's good about the FT page is that you can input a list of apps and
details who they share your data with. I realise now that the FT is
viewable by most, which is my mistake. 

The arxiv paper than Andy shared is the original source of the study,
although it only has high-level summaries so not as useful as the FT
checker - if you can see it. 

[toc] | [prev] | [next] | [standalone]


#56822

FromM.L. <me@privacy.invalid>
Date2018-10-24 01:56 -0500
Message-ID<sp50td1dqejruk6eg1gsdbi61viq3i7g3p@4ax.com>
In reply to#56805

>The point is that the amount of data sharing is more than you'd expect. 90%
>of ~1m apps tested share data to third parties most to several. 
>
>Given the ubiquity, i frankly don't know how you'd avoid it unless you
>don't have a smartphone at all. 

AdClear is a no-root VPN ad-blocker and firewall that works locally
and can directly block Internet access to specified apps, so no adware
from them. For apps that need Internet access it uses an ad-blocker,
hosts file imports, and can block data access when the screen is off.
I never see ads on my unrooted phone.

AdClear: https://www.seven.com

[toc] | [prev] | [next] | [standalone]


#56807

Fromnospam <nospam@nospam.invalid>
Date2018-10-23 15:20 -0400
Message-ID<231020181520033654%nospam@nospam.invalid>
In reply to#56804
In article <pqo0i7.60c.1@ID-201911.user.individual.net>, Frank Slootweg
<this@ddress.is.invalid> wrote:


> > Proof that you cannot avoid google/alphabet on Android
> >
> > Or facebook, twitter, etc. A study has tracked where data leaked from 
> > android apps ends up
> > https://ig.ft.com/mobile-app-data-trackers/
> 
>   More meaningless FUD.

it's not fud. it's very real, and getting worse.

>   Of course you *can* avoid tracking. 

tracking can be minimized with a lot of effort and compromises, but
it's basically impossible to avoid all of it short of going off the
grid.

>   The *point* however is that many
> people *'want'* to be tracked.

some might, but most do not. ask them directly.

> I.e. they want to use 'free' services,
> apps, etc.. Hence they - implicitly or explicitly - consent that *they*
> are the product and hence will be tracked.

they may want to use free services, except that they don't realize what
they're giving up in order to use them. if they knew how effective and
invasive the tracking actually is, they would likely reconsider their
choices.

[toc] | [prev] | [next] | [standalone]


#56812

From123456789 <12345@12345.com>
Date2018-10-23 13:19 -0700
Message-ID<pqnvo0$1712$1@gioia.aioe.org>
In reply to#56807
On 10/23/2018 12:20 PM, nospam wrote:

> they may want to use free services, except that they don't realize
> what they're giving up in order to use them.

What am I giving up? My information is pretty much everywhere already.
The barn door is already open, as they say... ;)

> if they knew how effective and invasive the tracking actually is,
> they would likely reconsider their choices.

Philosophical question: Which is worse: A bunch of real humans who know
lots of stuff about you and discuss your affairs regularly or a some
non-sentient computers transferring data about you?

BTW I spent the morning freezing 6 credit report accounts online. Lots
of my sensitive data crossing those computers... 8-O

[toc] | [prev] | [next] | [standalone]


#56828

FromJava Jive <java@evij.com.invalid>
Date2018-10-24 17:54 +0100
Message-ID<pqq851$rhi$1@gioia.aioe.org>
In reply to#56790
On 23/10/2018 09:20, Chris wrote:
> Or facebook, twitter, etc. A study has tracked where data leaked from 
> android apps ends up
> https://ig.ft.com/mobile-app-data-trackers/

The BBC Technology news website is now carrying this story, but I'm not 
sure that there's much there that hasn't already been covered elsewhere:

https://www.bbc.co.uk/news/technology-45952466

"Mobile app data sharing 'out of control'"

[toc] | [prev] | [standalone]


Back to top | Article view | comp.mobile.android


csiph-web