Hacker News new | ask | show | jobs
by g-garron 2184 days ago
Android gives one more freedom here and there, but tracks you more. At the very end we are tied to Google or Apple, and that is bad.
3 comments

1. We don't really know what Apple is or isn't collecting from you.

2. You can run de-Googled Android and still do the important 80% of things that a smart-phone is good for.

1. Sure we do, they spell it out very clearly here: https://www.apple.com/privacy/

2. I beg to differ. A completely de-googled phone is not only extremely difficult to achieve but about as useful as a 2009 blackberry. Yeah it runs and will maybe let you check your email with 5+ hours of work just to get push notifications running but it is so completely impractical for anyone that doesn’t want to devote serious amounts of time to it. With Apple you a good balance of privacy and utility imo.

My intention here isn't necessarily to tell you what to use or buy.

1. There is nothing legally binding here, as far as I can tell. Apple software is almost entirely closed source. Zoom told us they were encrypting our stuff, too. I know that Apple can't get away with too much because of their size, but I have a very strong distrust of big tech companies that I'll likely never shake because of the disgusting track record silicon valley has toward privacy and short-sighted profit-making. Take this text for example: "Apple can’t read your iMessages while they’re being sent between you and the person you’re texting." What does it mean that it can't see them while they're being sent? Can they see them once they're at rest? Is this just innocent vagueness of the English language, or sneaky shit? Similarly, they say they can't see your location in Maps. They make no promise with the browser. In fact, they don't promise they aren't snooping on 100% of the stuff in Safari- they only say they try to protect you from other companies tracking you.

2. I don't disagree with you. And I'm just kind of a Luddite because I just don't care if I can run SnapChat or whatever on my phone. I can browse the web with a solid, privacy-respecting, browser (Firefox) with all of the privacy addons I want. I can use that browser to access the things I care about. I do use a closed-source navigation app, unfortunately, but it isn't Google and doesn't require Play services. I lock down its permissions as best I can. I use Signal for most of my messaging needs, which works fine. The one thing I actually do miss is ride-sharing apps when I travel. That's a major inconvenience. But some shitty game or social media app whose entire purpose is to track you (whether you use/trust Apple/Google's OSes or not...)? No thanks, anyway. In fact, I think there's another point in here that most of these apps are tracking the hell out of you, regardless if you trust your phone's OS.

> Is this just innocent vagueness of the English language, or sneaky shit?

They use simple language to make it not seem like legalese - If you want the tech details see the white papers they have linked.

> What does it mean that it can't see them while they're being sent? Can they see them once they're at rest?

No messages are end to end encrypted by default

https://support.apple.com/en-us/HT202303

> they say they can't see your location in Maps. They make no promise with the browser

Apple Maps doesn’t have a browser version, just and iOS and Mac OS app. Additionally see above link, all location and search history is end to end encrypted - maps searches (and other location based events that cannot be encrypted due to server side processing) are not linked to your Apple ID.

> In fact, they don't promise they aren't snooping on 100% of the stuff in Safari

Again see above link, safari history and tab sync is also end to end encrypted

I wasn't being clear with the maps-browser comment. I meant that they make no promise that they aren't tracking your location outside of the Maps app.

It's great that they claim to end-to-end encrypt their stuff. And after the FBI standoff around the San Bernardino shooters phones, I recommend that my friends and family use Apple because the options for most humans are between Windows and macOS on PCS, and iPhone and (stock, OEM) Android for phones. They definitely talk the talk and appear to walk the walk. We can never truly know, though.

I know there's no point in arguing further. I fully acknowledge that I have less objective reason to believe that Apple is tracking me than you have to believe that they're not. But all of my friends thought I was the crazy tinfoil hat guy in the period between the signing of the U.S. Patriot Act and Edward Snowden. And after that... they still think I'm the crazy tinfoil hat guy. Maybe I'm a broken clock and was right once, or maybe Silicon Valley is full of corporate scumbag liars and maybe companies lie about their encryption (Zoom) and about their stance on privacy (Facebook). Maybe Apple is the lone shining beacon of privacy in SV. Maybe.

> Apple Maps doesn’t have a browser version

It can, however, be integrated via the JavaScript SDK. DuckDuckGo uses it, for example.

There is nothing legally binding here, as far as I can tell. Apple software is almost entirely closed source.

So is everything that makes Android, Android -- Google Play Services. Not to mention all of drivers.

Everything except for the Android part, sure.

But you're definitely letting perfect be the enemy of good if you think that closed-sourced drivers means that e.g., a closed source web browser doesn't increase your privacy attack surface.

Life is full of choices between imperfect options. And security/privacy is always qualified with "from whom". Sure, closed source drivers are not ideal and I am more vulnerable to privacy attacks from state actors. But why should my response to that be to just willingly give all of my personally identifiable information to Google, Inc?

You mean the “Android parts” that Google keeps abandoning for their own closed sourced versions?

https://arstechnica.com/gadgets/2018/07/googles-iron-grip-on...

Do you have some evidence on how Android tracks you or is this just a guess?
Just go see for yourself: https://myactivity.google.com/

Location, web searches, app usage etc etc. Try turning all tracking off and your phone becomes a brick. Google Assistant no longer works, google maps can no longer remember where your home and work are (cause that can’t happen on device for some reason). Top it all off and you’ll get constant pop ups asking you to turn it back on.... not fun.

Yes, I know about the Google profile, it's transparent and I turned Google's app activity off. My Google profile is right now empty.

That's not Android.

Let me repeat the question — how does Android track you?

https://en.m.wikipedia.org/wiki/No_true_Scotsman

That’s virtually every android device in existence. Just because someone degoogled an android once as an experiment doesn’t mean it becomes the new definition of what android is.

I am familiar too with the "No true Scotsman" fallacy, I don't necessarily see how it applies here.

Dare I ask what the point is?

---

I am not talking about de-Googled Android. Turning off web/app activity in your Google profile is not equivalent with de-Googling your Android.

I am asking how does Android, Google's Android distribution not anything else, tracks users?

> I am asking how does Android, Google's Android distribution not anything else, tracks users?

And I am saying it is a pointless thought experiment to separate Google from Android. Next you’ll say it’s the hardware that is android, not the software and ask how the hardware directly tracks users.

Edit: Read my original comment again, you are changing the subject. I haven’t said anything remotely conspiratorial, Google is open about their tracking in android. My point is that Google tracks you on android and if you turn it off your phone becomes crippled and in many cases for no reason except that google wants to make it as painful as possible to turn off data collection. Data collection is their business model after all.

Android is commonly understood as Android with Google stuff as pre-installed on most phones. As opposed to AOSP.
> google maps can no longer remember where your home and work are (cause that can’t happen on device for some reason)

This is such a user-hostile product choice. Google will happily let me favourite a place but refuse to create work and home labels.

That's not Android. Those are Google apps. They would track you just the same if you ran them on iOS or any other OS, and you can turn them off very easily.
This is not limited to just those with Google Play Services installed. Even nearly pure AOSP builds like LineageOS still default to Google’s DNS servers, wifi gateway checks, and SUPL server, and replacing those defaults with privacy-respecting alternatives has been made harder due to changes that Google pushed into AOSP.
Google Play Services provides valuable services that need a backend component.

I asked for evidence that Google tracks you in nefarious ways via Android.

Am I being tracked when using their DNS servers, which are otherwise very valuable for people suffering from DNS-level banning of websites?

And what do you mean by "privacy respecting"?

Words are cheap. I hope the privacy respecting apps and services you use can guarantee that either via technology (encryption, open source, reproducible builds), or via contract (and a ToS that can be changed on a whim for a free service isn't a contract that can protect you).

> I hope the privacy respecting apps and services you use can guarantee that either via technology (encryption, open source, reproducible builds)

This is what the F-Droid repository is all about. But again, Google has insisted on changes to AOSP that will shortly make it much more difficult for ordinary users (i.e. those who cannot use the command line) to make use of such free and libre offerings.

You can replace them much more easily than you can on iOS, and you don't even need to install a third party ROM. You can turn SUPL off entirely on any Android phone out of the box, while you cannot on iOS.
On the contrary, iOS actually tracks you far more than Android. This is just marketing-driven conventional wisdom that doesn't hold up when you take even the most cursory look at it. https://news.ycombinator.com/item?id=23329646
You're citing your own claim, but it doesn't look like anybody's buying it.

Here's an actual study: https://www.tomsguide.com/us/android-privacy-vs-iphone,news-...

You are comparing default apps privacy and saying that is OS privacy. I specifically pointed out data collection in the OS (that you can't turn off) that make iOS far worse than Android for privacy.

Your paper also compares the amount of data sent to Google for an Android device using default apps vs. an iPhone using default apps and shows that the latter sends much more. That's not a very useful comparison. If you compare how much each device sends to Apple, the Android device would win by a landslide, though again, that is not a useful comparison.

> I specifically pointed out data collection in the OS (that you can't turn off) that make iOS far worse than Android for privacy.

I think this claim is even more absurd when constrained to "default apps". But I'm listening—citations welcome.

I gave you a link. https://news.ycombinator.com/item?id=23329646

Which part of it my assertions did you have trouble following? I'll quote it below in case you have trouble following the link, but I worry this might violate a repetition rule:

iOS having better privacy is a myth. iOS sends your location to Apple every time any the GPS is used, and you can't turn it off. You cannot install apps on your phone without telling Apple which apps they are, and if you want to develop your own apps for your device without having to reinstall weekly, you have to hand over payment information.

Stock Android devices from nearly any vendor do not suffer from these problems, and reputable vendors do even better (like in this case, where even voice transcription does not send data off device).