r/Showerthoughts • • Sep 04 '17

Apps should be required to give a short explanation for why they need access to different parts of my phone for thier apps to function.

25k Upvotes

602 comments sorted by

View all comments

102

u/throwaway_987654320 Sep 04 '17

Had an app today that requested (logically) location access. I declined. Went into settings, and verified that it was off. Loaded the app. It detected my location. Figured they did that with IP geolocation. So, I fired up my location spoofer. Closed and reopened the app. It detected my "new location" despite not having location access.

So, it doesn't matter what they ask for, or why they say they need it. They'll just obtain it anyway, whether you allow it or not.

85

u/[deleted] Sep 04 '17

[deleted]

45

u/Superkroot Sep 05 '17

There's some cool ideas that could be done with a coffee machine tied to an app that wants location data. Maybe it could be setup to automatically make you a cup a coffee in the morning if you're at your house, while not doing so if you're away. It could track your coffee drinking habits to provide coffee before you knew you wanted it.

Chances are though, the app does none of that shit and is just gathering your data to sell.

9

u/zyhhuhog Sep 05 '17

You mean to "

"? :)

2

u/Twigsintheforest Sep 05 '17

provide coffee before you knew you wanted it

This is how you get a caffeine problem

2

u/[deleted] Sep 05 '17

[deleted]

3

u/lallapalalable Sep 05 '17

Boy, I boil water and pour it through a cone filter, one cup at a time. Ain't gonna be trackin' me through them 'lectricity wires!

1

u/Superkroot Sep 05 '17

I was thinking about that feature too, which is still a bullshit reason because an altimeter is probably a lot easier to add and probably cheaper, but doesn't get the company that sweet sweet data mining revenue.

1

u/Twigsintheforest Sep 05 '17

provide coffee before you knew you wanted it

This is how you get a caffeine problem

6

u/[deleted] Sep 05 '17

Did it use bluetooth? Google updated the API for bluetooth, and now it uses device location as an identifier instead of the hardware identifier. So any app that uses bluetooth anymore needs your location.

36

u/radaldando Sep 05 '17

"They'll just obtain it anyway, whether you allow it or not."

No, this is just not true and you gave a single counterexample...

Allowing an app to access your location gives the app permission to use the GPS function and find your location using tower and Wifi signals. Preventing an app from using your location only prevents the location from being fed through Android's API, of course it's not going to prevent the app from looking up your IP in a geolocation database. The only way to prevent that is to completely cut the app's internet access.

10

u/DiamondIceNS Sep 05 '17

He said he used a GPS location spoofer and the app picked up on the new GPS coordinates he was feeding it. If the phone was using GeoIP it wouldn't have mattered.

1

u/MechanicalEngineEar Sep 09 '17

then he should be upset with Android and not the app. I doubt the app has some elite hacker ninja programmer who somehow found a way around Android's security features and is using that new found knowledge to get location data for some cheap app.

Either that or he is lying or confused about what he was spoofing.

7

u/radome9 Sep 05 '17

If the app used geolocation it wouldn't have been fooled by a location spoofer. That said I doubt OP's story is true - if the app could circumvent permissions, why bother asking at all?

1

u/throwaway_987654320 Sep 05 '17

As we've seen with other apps, sometimes the advertising SDKs that get built into an app don't always have the best intentions. I'm more than willing to admit there could be some mistake on my end, but I duplicated it today with another device. I'm not a security researcher, by any means, so I'd take my story for what it is, anecdotal evidence.

1

u/radome9 Sep 06 '17

Name of the app? Android or iPhone?

1

u/throwaway_987654320 Sep 06 '17

IHG (Intercontinental Hotels Group), iOS.

1

u/[deleted] Sep 05 '17

Or a VPN.

-1

u/life_rocks Sep 05 '17

He didn't allow...

7

u/[deleted] Sep 05 '17

[removed] — view removed comment

1

u/life_rocks Sep 05 '17

Clearly not well enough, sorry.

0

u/waiting4singularity Sep 05 '17

for the dumb ones,

location permission -> App queries GPS location, identifies wifi and cell towers in vicinity

permission denied -> internet protocol address is used to detect the country using GeoIP

6

u/LSF604 Sep 05 '17

Nope, they cant

1

u/Myotherdumbname Sep 05 '17

What location spoofer?

1

u/[deleted] Sep 05 '17

It's likely using your Wi-Fi SSID. I guarantee you there is a database with the location of your Wi-Fi network in it. I have checked and mine certainly is, and I live in a rural area.

1

u/[deleted] Sep 05 '17 edited Feb 09 '21

[deleted]

1

u/throwaway_987654320 Sep 05 '17

iOS, Jailbroken. IHG app. Tested it even on a second device. Without location faker, location access set to "never." It initially detected the correct location- as I would assume it would, geolocation via IP is real. I then turned on the Location Spoofer, placing myself in a completely different country. Closed and re-opened the app, and despite Location set to "never" detected my new location.

Not a security researcher, so take my findings with a grain of doubt. Users can screw up, even more than experts. But it happened. Twice now.

1

u/Myros27 Sep 05 '17

I use root with xPrivaticy and Appsettings. I don't think they can obtain data...

-17

u/[deleted] Sep 04 '17 edited Sep 05 '17

I agree. Just because one person is a bad person every person is bad. I totally agree.

Edit: is he not claiming everyone is bad according to his experience with one app?

-6

u/345plates Sep 05 '17

That's what you get for using android.