TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Investigation Xoth: Smartphone location tracking

170 pointsby giladover 4 years ago

10 comments

square_usualover 4 years ago
The current link is to the press release for a paper. Link to the paper: <a href="https:&#x2F;&#x2F;www.expressvpn.com&#x2F;digital-security-lab&#x2F;investigation-xoth" rel="nofollow">https:&#x2F;&#x2F;www.expressvpn.com&#x2F;digital-security-lab&#x2F;investigatio...</a><p>E: The vice article [1] on this paper brings one aspect into focus:<p><pre><code> At least five more Muslim prayer or similar apps worked with data broker X-Mode, which has sold location data to military contractors and by extension U.S. military intelligence, according to multiple technical analyses. </code></pre> 1: <a href="https:&#x2F;&#x2F;www.vice.com&#x2F;en&#x2F;article&#x2F;epdkze&#x2F;muslim-apps-location-data-military-xmode" rel="nofollow">https:&#x2F;&#x2F;www.vice.com&#x2F;en&#x2F;article&#x2F;epdkze&#x2F;muslim-apps-location-...</a>
评论 #25998011 未加载
评论 #25998287 未加载
评论 #25998089 未加载
cookiengineerover 4 years ago
As always, I would recommend to use an AOSP build without google service integration (like LineageOS builds).<p>I&#x27;d also recommend to use AppWarden [1] and the Exodus project [2] to verify for yourself what your Apps do behind the scenes.<p>Regarding an App masquerading as Telegram: Use the Telegram FOSS fork [3] which disables Firebase&#x27;s trackers.<p>[1] <a href="https:&#x2F;&#x2F;gitlab.com&#x2F;AuroraOSS&#x2F;AppWarden" rel="nofollow">https:&#x2F;&#x2F;gitlab.com&#x2F;AuroraOSS&#x2F;AppWarden</a><p>[2] <a href="https:&#x2F;&#x2F;exodus-privacy.eu.org&#x2F;en&#x2F;" rel="nofollow">https:&#x2F;&#x2F;exodus-privacy.eu.org&#x2F;en&#x2F;</a><p>[3] <a href="https:&#x2F;&#x2F;github.com&#x2F;Telegram-FOSS-Team&#x2F;Telegram-FOSS" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;Telegram-FOSS-Team&#x2F;Telegram-FOSS</a>
评论 #25999047 未加载
评论 #25998488 未加载
评论 #25999348 未加载
评论 #25998573 未加载
rapnieover 4 years ago
A good practice is to consult Exodus Privacy before installing your app. If the app is not already analysed, you can start an analysis via the UI.<p><a href="https:&#x2F;&#x2F;exodus-privacy.eu.org&#x2F;en&#x2F;" rel="nofollow">https:&#x2F;&#x2F;exodus-privacy.eu.org&#x2F;en&#x2F;</a>
评论 #25998602 未加载
评论 #26006191 未加载
jay_kyburzover 4 years ago
I would be interested to know how many of the 450 apps actually needed your location data to do their job. If the app is an exercise app with a map, its a feature that it knows where I am.<p>If it&#x27;s a messenger app with a feature that can share your location, then its expected that it will have access to the API&#x27;s.
评论 #25998050 未加载
评论 #25998596 未加载
评论 #25997902 未加载
评论 #25997984 未加载
swileyover 4 years ago
IMO: if you don&#x27;t treat your phone like another PC and run postmarketOS (or similar) than you shouldn&#x27;t use a &quot;smartphone.&quot; Almost everything in the iOS and Android ecosystems is pathologically malicious.
评论 #26003872 未加载
qartover 4 years ago
I only buy LineageOS compatible phones. Its Privacy Guard feature allows fine control over permissions.
评论 #25998281 未加载
评论 #25998606 未加载
评论 #25998289 未加载
smitty1eover 4 years ago
If there is a market demand for functionality without spyware, why is not there some company capitalizing on that demand?
评论 #25998636 未加载
评论 #25999138 未加载
everdriveover 4 years ago
This is a ridiculous problem. Stop installing smart phone apps. Even better, get rid of your smartphone.
99_00over 4 years ago
Are these apps granted location permissions by the user? Are they listed as having location access in Settings?
SulfurHexaFluriover 4 years ago
The article seems somewhat absent of information, They list telegram as one of these location tracker apps. I use telegram and it has some features like sending your location to a friend but I&#x27;m not aware of it ever just grabbing your location without requesting it. I&#x27;m also not sure that ios allows grabbing the location without the app being in use either.
评论 #25998006 未加载