We report on measurements of the data sent to Google by the Google
Messages and Google Dialer apps on an Android handset. 

We find that these apps tell Google when message/phone calls are
made/received. The data sent by Google Messages includes a hash of the
message text, allowing linking of sender and receiver in a message
exchange. The data sent by Google Dialer includes the call time and
duration, again allowing linking of the two handsets engaged in a phone
call. Phone numbers are also sent to Google. In addition, the timing
and duration of other user interactions with the apps are sent to
Google.

There is no opt out from this data collection. The data is sent via two
channels, (i) the Google Play Services Clearcut logger and (ii)
Google/Firebase Analytics. This study is therefore one of the first to
cast light on the actual telemetry data sent by Google Play Services,
which to date has largely been opaque. 

We informed Google of our findings and delayed publication for several
months to engage with them. On foot of this report Google say that they
plan to make multiple changes to their Messages and Dialer apps.

Continua su
https://www.scss.tcd.ie/doug.leith/privacyofdialerandsmsapps.pdf


Non capirò mai questa attenzione alle esigenze di Google da parte
dell'accademia, in particolare quando i ricercatori scoprono queste
nefandezze perpetrate ai danni di miliardi di persone.

Quanti MESI hanno aspettato prima di pubblicare questa ricerca?
Cosa hanno ottenuto i lobbisti di Google nel frattempo?
Perché rendersi complici?


Google Dialer e Google Messages sono fra le applicazioni che non è
possibile rimuovere senza rootare il cellulare.

Ci sono però diverse alternative possibili disponibili su F-Droid [1],
fra cui Simple Dialer [2] e Simple SMS Messenger [3] e funzionano anche
disattivando Google Play Services e Google Play Store dalle
impostazioni.


Giacomo

[1] https://f-droid.org/

[2] https://f-droid.org/en/packages/com.simplemobiletools.dialer/

[3] https://f-droid.org/en/packages/com.simplemobiletools.smsmessenger/
_______________________________________________
nexa mailing list
[email protected]
https://server-nexa.polito.it/cgi-bin/mailman/listinfo/nexa

Reply via email to