Slashdot is powered by your submissions, so send in your scoop

 



Forgot your password?
typodupeerror
×
Android Google Privacy

Android's Messages, Dialer Apps Quietly Sent Text, Call Info To Google (theregister.com) 140

Google's Messages and Dialer apps for Android devices have been collecting and sending data to Google without specific notice and consent, and without offering the opportunity to opt-out, potentially in violation of Europe's data protection law. From a report: According to a research paper, "What Data Do The Google Dialer and Messages Apps On Android Send to Google?" [PDF], by Trinity College Dublin computer science professor Douglas Leith, Google Messages (for text messaging) and Google Dialer (for phone calls) have been sending data about user communications to the Google Play Services Clearcut logger service and to Google's Firebase Analytics service.

"The data sent by Google Messages includes a hash of the message text, allowing linking of sender and receiver in a message exchange," the paper says. "The data sent by Google Dialer includes the call time and duration, again allowing linking of the two handsets engaged in a phone call. Phone numbers are also sent to Google." The timing and duration of other user interactions with these apps has also been transmitted to Google. And Google offers no way to opt-out of this data collection. [...] Both pre-installed versions of these apps, the paper observes, lack app-specific privacy policies that explain what data gets collected -- something Google requires from third-party developers. And when a request was made through Google Takeout for the Google Account data associated with the apps used for testing, the data Google provided did not include the telemetry data observed.

This discussion has been archived. No new comments can be posted.

Android's Messages, Dialer Apps Quietly Sent Text, Call Info To Google

Comments Filter:
  • I've got a good message alternative (QKSMS), but can anyone suggest a good alternative dialer app?

    • Have you tries Simple Mobile Tools? It should have alternatives to pretty much everything relevant.
      • by jwdb ( 526327 )

        Have you tries Simple Mobile Tools? It should have alternatives to pretty much everything relevant.

        Thanks for the suggestion - I already use their gallery app since it has edit functionality. Will try the dialer.

      • Only a few days ago I started using both qksms and simple mobile contacts. Coincidence?

    • I've been using Signal almost exclusively for about a year. Text, voice, and video calls. Got most of my friends and family on board. A few friends insist on using Whatsapp exclusively, but Signal lets me text them using SMS.

      • by Plugh ( 27537 )
        I switched from Signal to Briar [briarproject.org] about a year ago. Never going back.
        • Whilst you're plugging it, care to enlighten those who've but heard of that what the advantages are? With Signal, it's hard enough to get people to use it, but it's received lots of press since a year or two. What's Briar got that makes it good/better? Even fewer people who use it?
          • by Meneth ( 872868 )

            Signal uses a central server to connect users together. This is theoretically vulnerable to an adversary who could take control of the server, such as the government where the server is hosted, or an advanced hacker, or if the Signal team themselves become corrupted.

            Briar does not have any servers. Instead, you use your contact's Tor address (appearing as a long base-36 string) to connect directly from your phone to theirs.

            • Technically, that sounds awesome. Practically, it will be useless to me, since I won't have anyone to talk with. I doubt have many friends maybe I'd find some new ones, and for many in my family asking to install Signal was already too much... But if it works for you/ others, more power to you!
        • Signal and Briar are for different uses. Signal is not perfect, but a vast improvement in security with minimal loss of convenience. Signal can send and receive SMS which lets me stay in contact with my friends who are trapped in Zuckworld.

    • by Rotting ( 7243 )

      Replace the entire OS and install https://grapheneos.org/ [grapheneos.org]

      Seriously, fuck Google.

      • by jwdb ( 526327 )

        Did that with my last phone. Fine if you want to treat your phone as a project, but I need it to be an appliance.

      • GrapheneOS is not, and most likely never will be, an option of any sort for the vast majority of people, as it only supports Pixel phones (perhaps not even all of them). The PinePhone, even though it's totally unusable as a phone, stands a better chance of being useful.

    • I was just going to ask if others also use that one. It's my favourite open source SMS app. From F-droid, in my case. Tip the developer if you like it.
    • I've used Signal as my messenger for years - it uses Signal if the recipient has it, or SMS if not. They do calls and video now too.

      I do have one friend who signed up for Signal but doesn't have it installed on his phone. That's a pain in the backside - he SMSes me, I Signal back :-(

      You asked about diallers - and no, not found one that didn't look like it was "dodgy" :-(

    • If you want it FOSS, try Koler off of F-Droid. I like it better than Simple tools.

  • Does it say in the PDF? Sounds like a job for your Pi-hole. PersonalDNSfilter for Android blocks 90% of the connection requests on my pho^H^H^Htracking device.
  • Last year, 1 billion "dumb" phones were sold compared to 1.4 billion "smart" phones. Articles like this show why more and more people [bbc.com] are ditching phones which occupy their lives for no reason other than to enrich someone else.

    • That would be the way to go except that phone service providers are cutting off dumb phone service now. AT&T, Boost, others have cut off the 3G service that flip phones use, leaving users no choice but to upgrade to a 4G-or-better phone. Many older dumb phones are now unusable, as well as appliance IoTs that used 3G. This leaves decade-old cars dead in the water too.
      • AT&T, Boost, others have cut off the 3G service that flip phones use, leaving users no choice but to upgrade to a 4G-or-better phone.

        I have AT&T and use a flip phone without any issue. They gave it to me free because I held out for so long to upgrade. My dad was in the same boat for his Tracfone. We went out and picked up the same phone I have and he's off and running without any issues.

        You were saying?

        • Comment removed based on user account deletion
          • Walt Dismal is absolutely right. "Talk and data services will only work for AT&T WirelessSM phones and devices that support at least 4G LTE and HD Voice." Link has a PDF to check your phones serial number to know if it's affected.

            https://www.att.com/support/ar... [att.com]

            Reading comprehension isn't your best suit, is it? AT&T gave me an upgraded phone for free, one that works on its network. What I did not say is it 4G LTE capable.

            If it's now March and AT&T cut off 3G phone service, how could I be using my phone?

      • For those who just can't part with their flip phones, there are at least new versions of them that work over 5G.

        https://www.washingtonpost.com... [washingtonpost.com]

      • by AvitarX ( 172628 )

        Decade old?

        My 2016 i3 lost connected drive in February.

        Can't even pay for the replacement part even though the cell module from the 2017s works (the device is needs to be registered).

    • So you think your dumb phone service provider isn't collecting your call data? Really?

      • So you think your dumb phone service provider isn't collecting your call data? Really?

        How much data are they collecting if all I'm doing is making and receiving phone calls? They get my location and who I'm calling/getting calls from. That's about six or seven phone numbers over and over. They also see I don't answer the phone if I don't who the caller is. Yeah, that's help them out a lot.

        • That is the entire complaint of the article we are discussing, that Google Phone app is recording what numbers you call, and to whom, and for how long, to Google. And yes, flip phone users send and receive texts all the time, and that covers the other half of the complain of TFA.

          • Well, Google has no business knowing who you call when for how long. Your phone network service provider does, and for billing they have to keep records too.
      • A local mobile operator is at least easier to reach for local law enforcement.
        • Who said anything about "local" mobile operators? Most dumbphones are connected to nationwide carriers like:
          - Cricket (owned by AT&T)
          - Boost Mobile (owned by Dish Network)
          - Walmart Mobile (TracFone)

          Each major cell company (T-Mobile, Verizon, AT&T) also operates prepaid networks that are very popular with flip phone users.

          Flip phone does not imply small mom-and-pop wireless provider.

          • Uh, what? "Local" == "nationwide". "Global" == "HQ somewhere else, commonly in the United States" -- like, say, Google, which this article is about --- you may have noticed that? If my country has a problem with what O2 does with the data of local users, the management responsible is in our capital. If my country has a problem with what Google does with the data of local users, the management responsible would have to be extradited from the US. See the difference?
      • That's the thing - Google is getting the same data as Verizon et al. and using it for antispam and such.

        It's about at the bottom of the list of things Google does that piss me off.

        PSTN is nearly obsolete, fortunately.

      • So you think your dumb phone service provider isn't collecting your call data? Really?

        Dumb phone provider collecting call data is better than dumb phone provider plus Google collecting your data. One giant hole below the water line is better than two giant holes.

        The dumb phone however is significantly worse when using a software program you trust to privately communicate over a hostile network.

        It's just sad we/me still haven't got our shit together and put POTS/SMS out of business. Carriers desperately need to be relieved of the burden of doing anything other than forwarding opaque datagra

        • One giant hole below the water line is better than two giant holes

          And yet you are using THIS web site, which sends your data to:
          - Google (hole #2)
          - aaxads.com (Acceptable Ads Exchange)
          - taboola.com ("Content discovery and native advertising")
          - slashdotstore.com (of course)
          - ml314.com (Data Co-op...that contributes content consumption data to a massive pooled data set that details the buying intent of a company.
          - LinkedIn.com

          That's just what I can see from looking at "View Page Source" for this web page, and I stopped counting.

          If you're really worried about "two holes unde

      • What has that to do with the topic?

        Your phone provider collects YOUR calls and only YOUR calls to bill you according to your plan

        And after 90 days: the data is deleted!!

  • by WaffleMonster ( 969671 ) on Tuesday March 22, 2022 @07:57PM (#62381831)

    Picked up a new phone a few months ago and couldn't believe just how evil and rotten Google had become. Just for grins while waiting for OEM unlock...

    Tried disabling "Google play" and was treated to a hilarious infinite nag fest of basically every app in the system whining in unison. Yes I'm not kidding even the fucking calculator app popped up an enable Google play notice and was using data to boot. Yes the calculator is spying on you. No messaging, no phone, no keyboard, no basic component without Google and all constantly spying using your data and battery to do it.

    Between the phone and adb you can disable or remove most of it and install alternatives yet this is labor intensive and simply isn't an option for mortals.

    It's easier just to install LineageOS than to replace everything individually. Going that route you at least get the ability to firewall apps which is huge and bypass carrier fuckery but honestly this too is a big pain and beyond the reach of mortals.

    The whole thing is intentionally designed with the upmost contempt and disrespect.

    • by Luckyo ( 1726890 )

      This isn't actually about google, but about app makers. Google offers a lot of libraries as a part of Play package. App makers can use these libraries, or include their own.

      Most choose the convenience of well tested and well maintained play libraries of Google Play over having to do the work of including their own.

      • That's why there's microG. [microg.org] They've managed to replace a lot of these libraries, so the handful of closed-source apps I don't want to give up can still work without any Google apps on my phone.
        Last week I bought a Moto G7 Plus, and yesterday I installed LineageOS for microG [microg.org] on it. The last time I did this, there were a few apps that wouldn't work, but they've come a long way since 2019. So far everything I want to do is working great!

        • by Luckyo ( 1726890 )

          That's great news if true. The only microG app I use is youtube vanced, and that is sadly going away. But I've seen problems that people who root their phone and install another version of android without Google Play have all kinds of compatibility problems.

          If microG has solved most of the library related issues with phones that don't have Google Play, it makes Google less dominant on android. Which is a good thing.

    • Yes the calculator is spying on you.

      No it's not. Google Play Services provides programming APIs as well as update management for apps. Just because you tried disabling a core part of the OS and apps which depend on it complained doesn't mean the app is spying on you.

      Also the "using the battery" comment just shows how out of touch you really are. Core system services consume basically no battery these days compared to using the screen on. I don't even charge my phone over night knowing fully well that it'll still be at 99% when I wake up.

      Pleas

      • No it's not. Google Play Services provides programming APIs as well as update management for apps. Just because you tried disabling a core part of the OS and apps which depend on it complained doesn't mean the app is spying on you.

        GPS is not a core part of android. Hence the reason android continues to work without it. Neither is the above the reason for my assertion. The reason I said calculator is spying on you is because the calculator app is using data. Either the calculator is offloading basic arithmetic "to the cloud" or it is collecting usage data.

        Just look at the permissions on Google play for their calculator app:

        full network access
        prevent device from sleeping

    • by AmiMoJo ( 196126 )

      Many Android apps rely on a common set of services, normally supplied by Google. However, you can replace them, e.g. with microg.

      https://microg.org/ [microg.org]

  • This means the default SMS app and default phone call app on Samsung Galaxy etc. phones, right?

  • If you use Signal already, try it for the default SMS app. As a bonus you get message backup-and-restore too.

    • Does Signal play nice with dual SIM in the mean time? That's what made it unusable for SMS for me some time ago...
  • It's been a while since I upgraded, but when bought a phone with Android 11.

    I was surprised to see whilst exchanging SMS messages with people, I was receiving notifications when the other person was drafting a SMS message to me, like I was using messenger or whatsapp. Obviously this isn't supported by SMS, I had to be receiving push notifications from google, and the other person's phone must have been sending information as the other person was drafting an SMS notifying google of who they were messaging.

    • by Luckyo ( 1726890 )

      Yes. I'm shocked that this isn't included in TOS and this metadata isn't sent as a result of data request from Google Takeout. This seems like a really, really stupid oversight on part of Google that's just asking to get fined by data protection authorities in EU.

  • I'm so scared of my communications being spied on, I wiped all the Google apps from my life, installed a third-party OS, and posted on TikTok and Facebook all about how to free yourself from the evil spies! /s

Remember to say hello to your bank teller.

Working...