• sifar@lemmy.ml
    link
    fedilink
    English
    arrow-up
    10
    ·
    3 hours ago
    • By forcing you to use a non-anonymous Google Account.
    • Then tying it with Google Play Services on that device.
    • Google Play Services are like a combo of arteries and nerves of Android OS.

    That’s how.

    • Frenchgeek@lemmy.ml
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      2
      ·
      2 hours ago

      Good thing I mostly use F-Droid (because finding anything useful on Google Play is a pain)

      • masterofn001@lemmy.ca
        link
        fedilink
        English
        arrow-up
        3
        ·
        1 hour ago

        That doesn’t stop or turn off google services, or services framework, or safety scan, or scanning your images, or reading your contacts and phone logs, what apps you use, when you use them, biometric data, location data, etc.

        You can mitigate against these by limiting permissions or appops with adb or shizuku enabled programs.

        Uninstall/disable as many google apps, components, and services as safely possible.

        Use a DNS filter to block Google from sending data, DNS rebinding, and using mdns for internet.

        Or go all the way and use graphene or similarly degoogled OS.

  • Mike@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    10
    ·
    4 hours ago

    Holy shit, this article is garbage… the base premise that Play Services can access anything is true, but so many bad claims.

    Google Play Services is a system app on phones that ship with Google services, and is the case on the author’s phone too, since he could only disable the app, not delete it. System apps can still be updated separately from the system, if their signature matches the updated version’s signature.

    Also, I don’t think they dedicate enough time to describe just how much data Google gets through your device, like how it logs your location for Google Maps’ business popular times indicators and traffic metrics, or how they use all of your data to give you hyper-targeted advertising.

    As for microG, it also runs with elevated permissions on most custom ROMs, and for some features (eg. integrity checks) it downloads & runs Google-made programs (eg. DroidGuard) with strong privileges. DivestOS (now discontinued) used to run microG in a sandbox.

    There are ways to run Play Services as a normal app if the custom ROM has a compatibility layer for it, like GrapheneOS, where you can selectively enable permissions for Play Services. Of course, if you refuse some permissions, some features will break (eg. refuse SMS/call access and RCS will break), but it’s a mostly usable situation.

  • flemtone@lemmy.world
    link
    fedilink
    English
    arrow-up
    17
    arrow-down
    1
    ·
    10 hours ago

    I have GrapheneOs installed which sandboxes any google bullshit needed for specific apps to run.

    • 1984@lemmy.today
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      4 hours ago

      I dont understand… Its describing what android does. How can that be rage bait?

      Nobody will rage over any of this. Its common knowledge already. Its the same thing that has been discussed for years.

  • mjr@infosec.pub
    link
    fedilink
    English
    arrow-up
    94
    ·
    20 hours ago

    De-googled phones exist, but they’re rooted or using a custom firmware. Usually, these phones spoof Google Play Services, replacing that layer with something called MicroG.

    So root and flash your phone today!

    • A_norny_mousse@feddit.org
      link
      fedilink
      English
      arrow-up
      8
      ·
      edit-2
      16 hours ago

      Is that a quote from the article? I feel compelled to add that, wrt mobile devices, it is possible to live without Google Play Services.

      • furry toaster@lemmy.blahaj.zone
        link
        fedilink
        English
        arrow-up
        2
        ·
        11 hours ago

        i dont bother spoofing google play services, all my apps work without it, infact you can just disable google play services on android phones stock rom (or at least that has been my experience so far) and thats what I have done, sure gmaps embed now doesnt work but i havent needed it, my bank app works fine, whatsapp will throw a random “please enable google play services” notification once day but it works fine without any issues

    • RubberElectrons@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      2
      ·
      edit-2
      3 hours ago

      Got a pixel? Check out calyxos, it’s a free system upgrade that rips out anything google but allows almost everything to work, even the play store and all your usual games and bank apps.

      Calyxos.org

      E: nevermind. It was great while it lasted.

  • tabular@lemmy.world
    link
    fedilink
    English
    arrow-up
    66
    arrow-down
    1
    ·
    edit-2
    20 hours ago

    It bitches very often when you disable Google Pain Services.

    You can’t delete the 1GB malware either.

  • the_q@lemmy.zip
    link
    fedilink
    English
    arrow-up
    34
    arrow-down
    2
    ·
    19 hours ago

    From a strictly privacy standpoint is an iPhone a better option for non-techy folks?

    • chillpanzee@lemmy.ml
      link
      fedilink
      English
      arrow-up
      22
      ·
      16 hours ago

      Looking just at location… Apple is actually better at location tracking precision than Google, and you can’t turn it off (even powering off your phone doesn’t shut it off). Disabling location services doesn’t prevent the data collection by Apple, it only blocks apps from using it.

      Apple is probably better at not sharing your data with others than Goolge, but that’s a position of faith, not fact. If you trust Apple and are diligent about blocking location access to 3rd party apps, it’s better. But you should expect that if you’re giving location access to a free app (like Google maps, a weather app, a ride share app, a streaming app, etc.), you can bet they are selling your location data.

      • furry toaster@lemmy.blahaj.zone
        link
        fedilink
        English
        arrow-up
        9
        arrow-down
        2
        ·
        11 hours ago

        AFAIK google doesnt share your data that much outside of being very permissive to law enforcement, their main thing is advertisement, kinda of a indirect sell, as in it is your data that brings value to their advertising since thats how they do their extremely invasive targeted advertising

      • Alphane Moon@lemmy.world
        link
        fedilink
        English
        arrow-up
        11
        ·
        14 hours ago

        The last time I read the Apple privacy policy it sounded like they pretty much collect everything and let themselves share this data with whoever they feel like.

        There was a lot of calming language, but it didn’t sound convincing to me.

        That being said, if you like the Apple ecosystem and UX, it’s a solid option.

        I personally believe their statements about privacy are nothing more than PR.

        • themurphy@lemmy.ml
          link
          fedilink
          English
          arrow-up
          3
          arrow-down
          1
          ·
          13 hours ago

          The only reason they dont share it with other apps, is because from a capitalist standing point, why the hell would you share information you want to sell?

          Them being the only one having access to a billion peoples location data is why they are the richest company.

          They very much do dell, and they very much share that data with the government they also pay a shitton of money in donations for ball rooms.

          • Alphane Moon@lemmy.world
            link
            fedilink
            English
            arrow-up
            3
            ·
            12 hours ago

            FWIW, from my last reading of their privacy policy, they openly stated that they do share PII with other companies who they consider to be their partners.

            They claim that they don’t share PII with third parties “for their marketing purposes”.

            That being said, you’re at the mercy of their definition of “partner” and interpretation of “for [the third party’s] marketing purposes”.

            I should honestly just re-read their privacy policy (and the same for Google and Meta).

    • hendrik@palaver.p3x.de
      link
      fedilink
      English
      arrow-up
      37
      arrow-down
      1
      ·
      edit-2
      19 hours ago

      I’d say that depends on exactly what you’re trying to protect. They’re both large American companies with control over your data and your data and metadata will end up in their respective clouds. Push notifications will be handled by Google services if you use Android, but there’s an equivalent mechanism for iOS just that it uses their servers. They handle some details differently, but I don’t think any of those options deserve the word privacy.

    • chrash0@lemmy.world
      link
      fedilink
      English
      arrow-up
      26
      arrow-down
      3
      ·
      18 hours ago

      i’d say so. i was a professional Android dev for years, and security and privacy are definitely one of the reasons i prefer iOS. i don’t have time to play with my phone so much for my personal device. Apple is the lesser of 2 evils since their business model doesn’t depend on this kind of tracking (even if they do it as well albeit to a lesser extent)

      • Alphane Moon@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        arrow-down
        2
        ·
        edit-2
        53 minutes ago

        Their service line was growing much faster than hardware, it is a big part of their business. So their business model does depend on data collection.

        • favoredponcho@lemmy.zipOP
          link
          fedilink
          English
          arrow-up
          3
          ·
          8 hours ago

          You’re talking about services? That’s like Apple Music, TV, iCloud storage, etc. That’s different from Google scanning your emails to extract purchase information from order confirmations, logging all search activity, etc.

          • Alphane Moon@lemmy.world
            link
            fedilink
            English
            arrow-up
            3
            arrow-down
            1
            ·
            5 hours ago

            I am just curious, have you ever read Apple’s privacy policy?

            What makes you think they don’t log your searches?

              • Alphane Moon@lemmy.world
                link
                fedilink
                English
                arrow-up
                1
                arrow-down
                1
                ·
                56 minutes ago

                So have you or have you not read the Apple privacy policy?

                Where did I say Apple has a search engine? I said Apple tracks and logs your searches.

                • favoredponcho@lemmy.zipOP
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  20 minutes ago

                  If you think there is something to cite in the privacy policy, go ahead and cite it. It’s not my job to make your argument for you.

                  In reality, I think you’re being deliberately obtuse because you want to defend Google’s business practices for some reason. You’re conflating the way Google collects sensitive user information for the purpose of advertising in every single one of its products, including from non-Google apps and webpages with some technicality around verbiage in a privacy policy, which you have not even cited yourself.

              • DrDystopia@lemy.lol
                link
                fedilink
                English
                arrow-up
                1
                arrow-down
                1
                ·
                3 hours ago

                Let me install some software on your devices and I’ll show you how to track searches without operating a search engine.

    • Truscape@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      22
      ·
      edit-2
      18 hours ago

      You’re just changing the bucket which the data is dumped into and the interface used. It’s an unfortunate reality that you need to research and be willing to take charge of your devices to proactively prevent spying.

      GrapheneOS, /e/ OS, and other community ecosystems are mandatory to have complete data security. Google and Apple will never directly grant you the permission to turn all the data taps off.

      • planish@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        5
        arrow-down
        1
        ·
        17 hours ago

        But if a Graphene device takes a non-malicious approach to data management out of the box, can’t you just buy one of those instead of doing research and taking charge of your device to proactively prevent spying? Why not just let a trustworthy organization like the Graphene project manage it for you, instead of an untrustworthy one like Apple?

        • Truscape@lemmy.blahaj.zone
          link
          fedilink
          English
          arrow-up
          16
          arrow-down
          1
          ·
          17 hours ago

          “A graphene device” doesn’t exist. GrapheneOS must be installed after purchasing a compatible device (Currently the Pixel line, but soon to be expanded to another manufacturer).

    • cabbage@piefed.social
      link
      fedilink
      English
      arrow-up
      30
      ·
      edit-2
      19 hours ago

      There are some user friendly Android based alternatives out there, since it’s based on open source. Personally I’m running a device with /e/OS, which you can either install yourself or buy a phone with it pre-installed. There are also some other user friendly options out there such as the Volla Phone.

      But yeah, iOS is probably a better bet than stock Android, as Apple has a history of being abusive towards their customers in other ways than by selling their data. But crucially both Google and Apple are American companies, so you should avoid depending on their cloud services to whatever degree possible. There’s no such thing as safe data if it is stored by an American company.

    • BlameTheAntifa@lemmy.world
      link
      fedilink
      English
      arrow-up
      9
      arrow-down
      1
      ·
      17 hours ago

      Yes, but Graphene is even better. The downside is that Graphene doesn’t currently support non-Google devices.

  • planish@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    26
    arrow-down
    13
    ·
    edit-2
    17 hours ago

    The article seems to go directly from “this piece of software talks to all the sensors and isn’t well sandboxed” to “Google has directed this software to profile and surveil users” without actually providing evidence to support that leap. Is Google Play Services sampling your location so that it can send it in to Google HQ as part of a secret location tracking operation that runs without user consent or knowledge, or so that it can detect if the device has been stolen by the cops and use its proprietary ML model to activate anti-theft mode to protect the user’s privacy?

    If we can actually show mismanagement of user data by Google Play Services, we need to shout it to the hills, because those sorts of scandals are important arguments for increased privacy protections. But we need to actually find that mismanagement occurring, not just assume it must be because Google wrote the code and it isn’t open source.

    • willington@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      9
      ·
      edit-2
      10 hours ago

      I disagree that we need to find mismanagement first.

      Never mind that Google is 100% opaque from outside and is not subject to inspections by its users.

      Even if Google had an open door policy inviting and empowering any and all citizen auditors, I would still disagree that Google gets the benefit of doubt by default, and only after something blows up can we begin asserting our interests.

      I think we can assert our interests any time, for any reason, and for no reason at all, with arbitrary aggressiveness, limited only by our own practical considerations.

      Instead of waiting for things to go wrong, we can protect our interests before there is even a chance of things going wrong.

      Can.

      Will we? Each person has to consider their situation pragmatically, but if they considered everything and decided to assert themselves, we would be idiots to insist Google gets the first dibs, they have the initiative, and so how dare we want to limit Google in any way without first PROVING harm. Horse. Shit.

      I take the same view toward any monopolies in general. We should not bother proving harm. We should break all monopolies as a matter of principle, even if they are “harmless.”

      And Google shound be given as close to zero information as possible. As a matter of principle.

      An ounce of prevention is worth a pound of cure.

      • Peruvian_Skies@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        1
        ·
        3 hours ago

        The problem is that without evidence of mishandling, what can we achieve? How can we force Google to be more transparent? The only way I see is via the courts, and they require proof.

    • RightEdofer@lemmy.ca
      link
      fedilink
      English
      arrow-up
      36
      arrow-down
      1
      ·
      16 hours ago

      Why would you ever give the benefit of the doubt to the largest ad company to ever exist whose entire existence and history depends on tracking user data. They literally just had too settle a lawsuit for tracking users when they said they wouldn’t in incognito mode.

      There are plenty of little hints in Android that they want to enable tracking (eg. Bluetooth and exact location permissions being linked despite there being no real need to). Y’all need Graphene yesterday. And we all need a new total alternative since Apple is quickly chomping at the bit for ad income.

      • willington@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        4
        ·
        edit-2
        10 hours ago

        Because he or she works for Google’s image and status management interests.

        Does not matter consiously or unconsciously. Does not matter paid or free. Dependent or independent. Good faith or bad. Bot or human. None of it matters.

        What matters is the result of their action/speech, and the priorities. And it is loud and clear what those are.

        “Google must be trusted and given all the information first. Then, if you can find mismanagement, try to prosecute your grievance AFTER an injury has occured and was proven.”

        ^^^ We need to flip the script here.

        Protect your iterests first. Google’s interests mean nothing to you.

        If Google can serve my interests they get paid. They don’t get freebies or deference or first dibs or ownership of the phone, or part ownership, or benefit of doubt, fucking NOTHING. They get just what they need to render a service. That’s it.

        If Google does not like that they are to serve, and instead Google’s managers have aristocratic ambitions, we need to talk.

    • majster@lemmy.zip
      link
      fedilink
      English
      arrow-up
      4
      ·
      12 hours ago

      When you open the maps indoor you get immedieate location. This is not from GPS but from Wifi and cell tower data. This is only possible because your phone constatly transmits your location and network data. You can also call it surveilance because its 24/7 logging and processing of your location data.

      • furry toaster@lemmy.blahaj.zone
        link
        fedilink
        English
        arrow-up
        1
        ·
        11 hours ago

        does not happen to me, probably because i keep mobile data off and in the developer settings there is a keep mobile data always option that is enabled by default, for “fast network switching”, I disable it and beyond that I disable google playservices and all google related or adjacent apps that cant be uninstalled from my oem rom

    • Kairos@lemmy.today
      link
      fedilink
      English
      arrow-up
      14
      ·
      17 hours ago

      Part of the problem with this stuff is that the corporations using it are very hush-hush about what exactly they use it for. The privacy policy just lists what they may collect (everything) and what they may use it for (anything).

      • A_norny_mousse@feddit.org
        link
        fedilink
        English
        arrow-up
        7
        ·
        16 hours ago

        And the very few valid reasons for data collection are drowned in this. You consent to either all or nothing. Some consent that is.

        • Kairos@lemmy.today
          link
          fedilink
          English
          arrow-up
          1
          ·
          16 hours ago

          I was more wanting to point out that it is reasonable that the article wouldn’t go into extreme depth

    • chillpanzee@lemmy.ml
      link
      fedilink
      English
      arrow-up
      5
      ·
      16 hours ago

      Is Google Play Services sampling your location so that it can send it in to Google HQ as part of a secret location tracking operation that runs without user consent or knowledge

      Yes they track your phone’s location and movement constantly, but it’s not a secret.

      For an example of the evidence you seek… Google SensorVault location data was how they identified and convicted the January 6 terrorists. You might argue that complying with warrants isn’t misuse of the data, but I’d argue that both the data itself, and the level of precision and detail, shouldn’t be captured and logged in the first place. And I’m fairly sure that most google customers have no idea how pervasive and extensive the tracking is.

    • A_norny_mousse@feddit.org
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      1
      ·
      edit-2
      16 hours ago

      Is Google Play Services sampling your location so that it can send it in to Google HQ as part of a secret location tracking operation that runs without user consent or knowledge, or so that it can detect if the device has been stolen by the cops and use its proprietary ML model to activate anti-theft mode to protect the user’s privacy?

      They’re the same picture.

      If we can actually show mismanagement of user data by Google Play Services, we need to shout it to the hills

      We can, and many have been for many years.

  • rnercle@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    24
    arrow-down
    1
    ·
    20 hours ago

    easiest way to stop that ☞

    pm uninstall --user 0 com.google.android.gsf
    pm uninstall --user 0 com.google.android.ims
    pm uninstall --user 0 com.android.vending
    
    • A_norny_mousse@feddit.org
      link
      fedilink
      English
      arrow-up
      8
      ·
      edit-2
      16 hours ago

      This is a good tip, but what will stop working or start acting up and is this guaranteed to survive reboots, upgrades?

      • rnercle@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        1
        ·
        edit-2
        5 hours ago

        yes, it reboots without play services. You may need to execute the code again after an update (when not only disabled bloat is reinstalled but often new bloatware too is pushed without your consent)

        the other comment above mine covers your other questions

      • furry toaster@lemmy.blahaj.zone
        link
        fedilink
        English
        arrow-up
        3
        ·
        11 hours ago

        from my experience none of my apps broke, only get some annoying please enable google play services notifications from whatsapp, and embed google maps also breaks, suprisingly my bank app works fine, havent had any issues beyond this, survives reboots but I havent tried updates as my phone doesnt receive those anymore and the rom scene for my model is non existent