Your smartphone tracks your location, listens to your conversations, and sells your intimate moments to data brokers.

The law pretends to regulate this, but lobbyists write the rules and enforcement is a joke.

Encryption apps aren’t enough when the hardware itself is designed to betray you.

The phone is a spy device marketed as a lifestyle accessory.

We need radical technical solutions, not incremental privacy policies that change nothing.

The surveillance economy depends on your ignorance and inaction.

Break the chain: use open hardware, de-Googled Android, or build your own tools.

#privacy #surveillance #digitalrights #antitrust

How much of your life are you willing to sell for a slightly more convenient map app?

  • gandalf_der_12te@discuss.tchncs.de
    link
    fedilink
    arrow-up
    0
    ·
    6 months ago

    What we need most at this point are hardware manufacturers that aren’t in bed with the CIA.

    for a long time i have had the feeling that basically there’s only a very small number of hardware manufacturers in the world, we all know them, TSMC and others, and basically i suspect that the CIA puts some kind of spyware directly into the hardware. maybe i’m wrong here, but i have a gut feeling. we need independent hardware manufacturers, maybe stationed in europe or somewhere else in the third world altogether.

    you said it yourself, encrypted apps don’t mean anything when the underlaying system is already flawed. that is the operating system and the hardware. first we need better hardware, then we need a clean, non-invasive operating system, then we need good apps. starting with good apps alone doesn’t actually do that much when your data gets siphoned off through other apps nonetheless.

    • diablomnky666@lemmy.wtf
      link
      fedilink
      arrow-up
      0
      ·
      6 months ago

      Not the CIA, the NSA does this all the time. The documents that Snowden leaked confirmed that the agency intercepts hardware being shipped to targets and swaps out the firmware to allow them to listen in on all network traffic going through that device. They also work closely with ISPs to install devices that mirror all network traffic going through that ISP to another device so they can log and analyze it.

    • ☂️-@lemmy.ml
      link
      fedilink
      arrow-up
      0
      ·
      6 months ago

      graphene is pretty good, but be careful with cell network triangulation. also careful with what apps you run on it.

  • 14th_cylon@lemmy.zip
    link
    fedilink
    arrow-up
    0
    ·
    6 months ago

    i dream about a phone with hw switch, which would be used to lock the screen and at the same moment it would physically disconnect microphone, camera, and gps module.

    not saying it is complete solution to the privacy problem, but it would be good start.

      • 14th_cylon@lemmy.zip
        link
        fedilink
        arrow-up
        0
        ·
        6 months ago

        you can’t really disconnect yourself from the cell network, that would beat the purpose of having the mobile phone ;)

      • 14th_cylon@lemmy.zip
        link
        fedilink
        arrow-up
        0
        ·
        6 months ago

        did not know that. but from the image, that seems like something that is inside of the phone? not really something you casually flip on the street.

        my idea is that anytime you would flip the switch and lock the screen to put the phone in the pocket, its spying capabilities would be physically disabled.

        • Pika@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          0
          ·
          6 months ago

          Yea you are right, the privacy switches are under the battery cover, so it requires taking the cover off flipping the switch and sliding it back on again.

        • girsaysdoom@sh.itjust.works
          link
          fedilink
          arrow-up
          0
          ·
          edit-2
          6 months ago

          I actually have one I’m not using at the moment. The switches at within the back cover but that’s easily able to be reached within 5 seconds or so with no tools. It’s not exactly something you would be flipping on and off regularly though unless you had a very specific use case.

          Anything that isn’t a hardware switch potentially leads itself to being bypassed, so the switches are your best bet for being sure it’s disabled.

          Edit: there’s also this (I linked the case which shows the switches) phone which has switches on the outside for this purpose. I don’t know anyone who has used this one however.

    • cunnililgus@sopuli.xyz
      link
      fedilink
      arrow-up
      0
      ·
      6 months ago

      Fairphone 6 with e/OS can use its physical switch to disable camera & microphone. Its only SW disabling but it forces app that want to use it request it. There’s also privacy setting that gives apps fake geo data.

      Its not perfect but any improvement is good.

  • Cherry@piefed.social
    link
    fedilink
    English
    arrow-up
    0
    ·
    6 months ago

    I would love to think its just a hardware and software issue, it is a habit issue too - i am keen to get away from my phone. I am starting to detest it.

    But we do still need things that genuinely aid us. People do need maps. and bank apps on the go. I am trying to break my habits. I have been tempted to go back to a nokia flip but i need a map. I miss the days of flips, that satisfying clip closed. The actual physical act of opening it.

    I will be moving to graphene pretty soon but its still a touchscreen, and even if i buy second hand it bumps google prices, i begrudge that. Jolla is too far away and a tad on the pricey side. Motorola is still another big brand just producing touch screen smart phones that lean towards bad habits. I would love a physical switch too.

  • jabjoe@feddit.uk
    link
    fedilink
    English
    arrow-up
    0
    ·
    6 months ago

    This is a legal/poltical issue more than a technology one. The good guys are the EFF, OpenRightsGroup, EDRi and others in the same side. Increasingly phone apps are forced on us to do things at all, and those apps are not only closed but only run on locked down OSs. It’s anti competitive, anti-freedom, authoritarian, etc etc.

    We need to get better at convincing non-nerds. We need to stop fighting political fights by burying ourselves ever deeper in tech. Which I’m guilty of too!

    • FineCoatMummy@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      0
      ·
      6 months ago

      Very well said. Everything you said I agree about 100%.

      We need to get better at convincing non-nerds.

      I’m doing my best. It’s hard tho. They just… don’t care. They don’t understand why it is important. Important for their future, and for all of our future. They don’t seem to grasp why it matters so much, and what price we have to pay when we get it wrong.

      I try to find concrete examples for them. But when people are invested already in some big tech ecosytem, it’s easy to discount the examples. “That wouldn’t apply to me”.

      I’m trying so hard, but it is an up hill fight :(.

      • jabjoe@feddit.uk
        link
        fedilink
        English
        arrow-up
        0
        ·
        6 months ago

        Yeah, it’s hard. People don’t want to see the problems because they don’t want to change. Law makers are the ones we really can’t fail to convince.

      • jabjoe@feddit.uk
        link
        fedilink
        English
        arrow-up
        0
        ·
        6 months ago

        I’ve donated monthly to OpenRightGroup well over a decade now. I make sure it is always more than my wife’s Netflix (DRM pusher) to maintain a net positive!

  • CommanderCloon@lemmy.ml
    link
    fedilink
    arrow-up
    0
    ·
    6 months ago

    Some stuff that you can use are

    • AdNauseam, visually blocks ads but under the hood clicks on them, nuking the usefulness of ad trackers

    • TrackMeNot, spams queries on search engines, clicks some links here and there, all in the background. Works perfectly with AdNauseam, nuking both ad & search profiling

    Then there is this experimental (HARPO: Learning to Subvert Online Behavioral Advertising) paper on using ML to obfuscate online tracking, it’s a research paper so my understanding is limited to the excerpt 😅 https://arxiv.org/pdf/2111.05792

    • FineCoatMummy@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      0
      ·
      6 months ago

      visually blocks ads but under the hood clicks on them

      I get where they’re coming from on the idea. But the problem I have… it would still run all the fingerprnting scripts and other shit. Sure it makes some bad data added to the good… but still plugs me into huge adware ecosystems. It leaves such a bad taste in my mouth, if any of their shit hits my comp.

      I really mostly want to not be part of any of that shit. 🤮 Just leave me alone, surveilance companies, thank you.

  • partofthevoice@lemmy.zip
    link
    fedilink
    arrow-up
    0
    ·
    6 months ago

    We need bots, automations… I don’t know… we need a new category called “telemetry jammers.” If the tools existed, I’m almost certain people would not mind running them. Spam the hell out of telemetry sensors of all kinds, with random data… destroy the usefulness altogether. The more spam, the fewer people we actually need to participate. The more transparent to the actual user, the better.

      • CommanderCloon@lemmy.ml
        link
        fedilink
        arrow-up
        0
        ·
        6 months ago

        Nah, a reverse faraday cage, something that would make telemetry useless by flooding it with trash. We can try all we can not to be spied on, but it’s an uphill battle. If we start being so noisy that they’d have to sift through tons of crap to maybe perhaps get a tiny speck of useful data, it won’t economically make sense to continue harvesting the data.

        It’s one of the things I do with a combo of trackmenot + adnauseam, spam web search & click websites and all their ads automatically while I use my computer. Good luck profiling me correctly

    • Typotyper@sh.itjust.works
      link
      fedilink
      arrow-up
      0
      ·
      6 months ago

      At some pint the extra data being sent to the trackers might start to consume more battery power and heat from CPU usage.

      Pokemon GO did something similar to this and those were the side effects

      • CommanderCloon@lemmy.ml
        link
        fedilink
        arrow-up
        0
        ·
        6 months ago

        Could be done on another device though, a computer could pretend to be your phone and start sending tons of useless data maybe? I don’t know how feasible it is.

        You’d have to automate the retrieval of IDs for each data harvesting platform (including web based cookies to be feature complete) and manage to send the properly formatted data on each platform.

        Funnily enough though, the kind of fuzzy data generation that just looks plausible enough could be a great usecase for LLMs

  • traxex@lemmy.dbzer0.com
    link
    fedilink
    arrow-up
    0
    ·
    6 months ago

    Best friend is stuck on his iPhone. Does anybody have any quick and easy links that show how bad Apple is at privacy? I’ve been trying to get a few together to show him and hopefully break the cycle.

      • peacefulpixel@lemmy.worlddeleted by creator
        link
        fedilink
        arrow-up
        0
        ·
        6 months ago

        i mean this with sincerity, and not as a means to further the Android vs Apple bullshit. please stop drinking cyanide.

        • traxex@lemmy.dbzer0.com
          link
          fedilink
          arrow-up
          0
          ·
          6 months ago

          But where is the data? I’m genuinely curious since I want to get my friend off the platform but if there is nothing to show them then I don’t really know if I can (or even should tbh).

      • Echo5@lemmy.world
        link
        fedilink
        arrow-up
        0
        ·
        6 months ago

        It’s not as bad as Google but still pretty terrible. I too would like to see a comprehensive list on Apple issues.

      • freedickpics@lemmy.ml
        link
        fedilink
        arrow-up
        0
        ·
        6 months ago

        Apple devices aren’t the best but theyre definitely not the worst. If the leaked Cellebrite documentation is to be believed then the newest devices running the latest iOS builds are well protected against hacking tools, second only to GrapheneOS. The iOS permissions system is relatively robust, lockdown mode is a good bit of extra protection too. And iirc full-disk encryption is enabled by default on iOS these days. Advanced Data Protection lets you E2E encrypt (most) cloud storage too. These are all good things

        For the most part, you can set up an Apple Account without using genuine information (though the age verification thing might change this, but Google is implementing that too). For both iOS and GrapheneOS you need to either trust Apple or Google with your phone number to set up an account.

        I’d be interested to hear people’s criticisms so long as they’re not just random claims with no elaboration or evidence

          • freedickpics@lemmy.ml
            link
            fedilink
            arrow-up
            0
            ·
            6 months ago

            I stand corrected, but do you need a Google account at any point for activation etc.? I’ve had increasing difficulty creating a Google account at all without a phone number

    • gandalf_der_12te@discuss.tchncs.de
      link
      fedilink
      arrow-up
      0
      ·
      6 months ago

      friend is stuck on his iPhone

      my honest opinion is that it’s a lost cause. people superficial enough to be on an iphone in the first place probably aren’t gonna think through the deeper ramifications of privacy and information security practices at all.

      • traxex@lemmy.dbzer0.com
        link
        fedilink
        arrow-up
        0
        ·
        6 months ago

        The site says user privacy is a concern on iPhone but doesn’t actually list any incidents. Is this correct?

    • FG_3479@lemmy.world
      link
      fedilink
      arrow-up
      0
      ·
      6 months ago

      He needs to enable lockdown mode, then go into the privacy settings and turn off “allow apps to request to track”, disable the system services in location settings which aren’t needed, turn off personalised ads under Apple advertising, then he well be good.

        • alana 🏳️‍⚧️@lemmy.mldeleted by creator
          link
          fedilink
          arrow-up
          0
          ·
          6 months ago

          I think Lockdown might be too much for the average person, since it imposes limitations to reduce the attack surface (breaks some websites, some apps dont work properly)

          I would just recommend he enables Advance Data Protection on his iPhone, disables analytics, and switches to privacy-focused apps. Apple has decent privacy, even by default compared to Android

          • l3db3tt3r@piefed.social
            link
            fedilink
            English
            arrow-up
            0
            ·
            6 months ago

            Lockdown mode for websites and apps isn’t terrible to manage/configure on the fly, bonus is it makes you (re)consider if you should.

  • HubertManne@piefed.social
    link
    fedilink
    English
    arrow-up
    0
    ·
    6 months ago

    I don’t like smartphones and im kinda paranoid so turned off and in an rfid blocking bag. Even with dumbphones because who knows what is hidden away active without me knowing. I would have laughed at such paranoia 15 years ago.

  • biggerbogboy@sh.itjust.works
    link
    fedilink
    arrow-up
    0
    ·
    6 months ago

    This is why I’ve wanted a PDA for a while now. But nobody makes them anymore because everyone pivoted to making smartphones, so DIY would probably be one of the only options unless I want to buy used tech from I believe 2 decades ago.

      • biggerbogboy@sh.itjust.works
        link
        fedilink
        arrow-up
        0
        ·
        6 months ago

        What I was describing was more an actual PDA, with very low power needs while still being very useful, and being very easy to back up the entire OS and its data, maybe even with some sort of minimal linux distro.

        However, I might actually flash a pixel with grapheneOS, since it does fulfill many of those needs, so I’ll consider it. Good suggestion.

  • chunes@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    6 months ago

    Cell phones started to become popular while I was in college. I still have not used one. I have a dumb phone for businesses and institutions that absolutely must call for whatever reason. Everything else can be easily handled on my computer.

    • npcknapsack@lemmy.ca
      link
      fedilink
      English
      arrow-up
      0
      ·
      6 months ago

      How do you get around 2FA? I was able to stay off of phones for so long, but the standard 2FA implementation has made it impossible.

      • chunes@lemmy.world
        link
        fedilink
        arrow-up
        0
        ·
        6 months ago

        I’ve never been forced to use 2FA except on GitHub. I just ditched it and went to Codeberg.

        • npcknapsack@lemmy.ca
          link
          fedilink
          English
          arrow-up
          0
          ·
          6 months ago

          Ah, lucky. All the banks around me seem to require it now. My kingdom for an independent authenticator they’d accept!

    • bridgeenjoyer@sh.itjust.works
      link
      fedilink
      arrow-up
      0
      ·
      6 months ago

      Lyft/uber, airlines, hotels? Its nearly impossible to use any of those without a smartphone. Or its a huge hinderance.

      I’m convinced most of the people on this instance don’t leave their basements !

      • dubyakay@lemmy.ca
        link
        fedilink
        arrow-up
        0
        ·
        6 months ago

        Huh? I’ve flown and booked hotels recently and you absolutely do not need a smart phone for that.

        • bridgeenjoyer@sh.itjust.works
          link
          fedilink
          arrow-up
          0
          ·
          6 months ago

          Sure, but youll be the one gramps running through the airport with your paper ticket because you didnt see your gate change on the airport TV and you’re late. On the phone app, the gate changes alert you immediately.

          There’s also no way they’ll have printed tickets anymore in ~5 years . i havent seen someone use a paper ticket in a very long time, and if I do, they’re 85 year olds who can barely walk. (Related note, my younger friend was absolutely baffled I still write checks. They’re 26 and never wrote a check in their life).

          The normies dictate the market. There’s zero way I’d convince my SO or any family member to get a phone that doesnt support flight apps and hotel check in apps. Especially because hotel check in apps can remotely unlock your door with no key, so you dont have to talk to anyone at 3 am when you get there (a lot of people like that).

      • chunes@lemmy.world
        link
        fedilink
        arrow-up
        0
        ·
        6 months ago

        Everyone has cars where I live. I’ve never needed a smartphone for a hotel. That sounds like utter nonsense.

        And you’re right, I haven’t flown in decades, nor do I have any desire to, since it sounds like a nightmare.

    • paper_moon@lemmy.world
      link
      fedilink
      arrow-up
      0
      ·
      edit-2
      6 months ago

      It depends on what kind of devices you’re using.

      It’s my understanding that SIM cards in phones are just to tie an account and identity to your phone, for purposes of enforcing people to be paying customers for the phone/data services, and tracking your usage based on what level service you’re paying for and what you should receive (5GB of data monthly, unlimited texts, etc)

      But if your phone doesn’t have a SIM card in it, its still connecting to cell towers for purposes of emergency dialing, and the phone itself can continue to be tracked by cell carriers based on what physical cell towers its connecting to, as you travel around. The cell phone modem itself can control and connect to networks independently of what the OS running on the phone tell it to do, its a self contained black box.

      If you have something like a desktop or laptop, both Intel and AMD have “management engines” embedded in the CPU’s themselves that can take control of the device for purposes of shutting down, wiping, etc a company machine that has sensitive information or access on it, and has been reported stolen, not returned by an ex employee, etc. These management engines have direct access to the network stack and can phone home whenever a network connections is present, either from a WiFi network, physical Ethernet cable, or 4G/5G WWAN card.

      https://en.wikipedia.org/wiki/Intel_Management_Engine

      If you have a device that is basically air gapped, no WiFi, no cellphone chip, than it’s still possible to exfiltrate information off the device, but the software running on the device would have to be programming to be searching for methods to do that. Your average device, unless it’s running malicious software, probably won’t be doing that.

    • pinball_wizard@lemmy.zip
      link
      fedilink
      arrow-up
      0
      ·
      6 months ago

      Can this be true if you use a device without any connection to the internet and no SIM card?

      You’ve got the idea. There’s a bunch to unpack here:

      • If the device is truly offline, your privacy is okay.
      • But there’s lots of ugly ways vendors work around “being offline”
      • Denying the device a SIM card means the device is not authorized to get online, but certain emergency services that require a network will work anyway. The SIM is to make sure we’re paying to be online, and is otherwise not actually needed to connect.

      I mean could a hardware connect to some kind of network to send private information?

      If you’re asking if it is possible to hide a secret antennae in an officially offline device, yes, absolutely.

      I’ve heard privacy nerds theorize that these will become common in smart TVs, so the TV can phone the vendor with screenshots, even (especially) when playing pirated local media.

      Because the basic thing is, it won’t expose your data if doesn’t leave your phone, right?

      Exactly. And you’ve also caught the tricky bit - it’s hard to be 100% sure a device isn’t phoning home if the device is a closed proprietary (secret) design, running closed proprietary (secret) software.

    • 14th_cylon@lemmy.zip
      link
      fedilink
      arrow-up
      0
      ·
      6 months ago

      Let’s assume it can read wireless network even with wifi turned off, it still needs to find a network and a password to connect to it.

      rather than hacking wifi, it connect to mobile internet even without sim card. that is much simpler, the mobile internet is basically anywhere and it is free as part of some spying cartel with the mobile network operators.

      any new car also spy on you and you don’t need to provide sim card for that.

  • jdr@lemmy.ml
    link
    fedilink
    arrow-up
    0
    ·
    6 months ago

    How much of your life are you willing to sell for a slightly more convenient map app?

    30% max

    • Pika@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      0
      ·
      6 months ago

      However much is earned by time saved by that app.

      I stopped using openstreetmap because it wasn’t reliable enough for me. I found myself going the wrong direction, or not finding what I wanted to find and having to swap back anyway.

      I liked the goal but, it just wasn’t a valid tool for me.

        • Pika@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          0
          ·
          6 months ago

          I firmly agree. It’s a give and take, I don’t have the time or energy to spend a couple hours mapping the local area on OSM that way it can be properly used. I did that for my home town, and then realized that outside of big corporate entities, it wasn’t done at all for any of the surrounding towns or even cities. To me having an accurate map with ability to give directions and traffic reports is worth more than my location data.

        • lumpenproletariat@quokk.au
          link
          fedilink
          English
          arrow-up
          0
          ·
          6 months ago

          Not having a map when going to a new location is one of the most anxiety triggering things for me. They have been lifesavers in helping me get out more.

            • JustEnoughDucks@slrpnk.net
              link
              fedilink
              arrow-up
              0
              ·
              6 months ago

              It often gives incorrect maps simply because of update schedule and them encouraging not reporting construction <3 months or whatever.

              We have construction all over in Belgium and tons of detours such that it makes open street map pretty much unusable as it will just incessantly reroute you to a blocked path even after you are well on a different route.

            • lumpenproletariat@quokk.au
              link
              fedilink
              English
              arrow-up
              0
              ·
              6 months ago

              You said precise maps apps and ‘an app to fit your life’, not closed source corpo map sources.

              I’m fine with using open source if it’s capable of navigating me around without issue, I’m not fine with not having an app too fit my life or be precise.