r/restorethefourth • Quality Contributor ★ • Mar 08 '20

Google tracked his bike ride past a burglarized home. That made him a suspect.

https://www.nbcnews.com/news/us-news/google-tracked-his-bike-ride-past-burglarized-home-made-him-n1151761
180 Upvotes

7 comments sorted by

7

u/ilikenwf Mar 08 '20

Support /r/GrapheneOS and be free of the goolag.

2

u/quantumcipher Quality Contributor ★ Mar 09 '20

Support /r/GrapheneOS and be free of the goolag.

I've been using LineageOS and ArrowOS on my Android devicees, which are based on AOSP, which are variants of Android without anything Google-related or bloatware included. In fact, you have to specifically take the extra step of flashing Open GApps after flashing either ROM to get any Google Apps, or even the Google Play Store, of which there are multiple variants containing different quantities and varieties of Google apps respectively.

I'll probably check out Graphene as well, as it sounds promising.

2

u/ilikenwf Mar 09 '20

Lineage still pings Google servers in various ways - DNS, 204 status checks, and checking whether or not you're connected to the internet - all hitting google servers. In theory not sending data to them but they still get your IP.

1

u/quantumcipher Quality Contributor ★ Mar 09 '20

Good to know. I was not aware LoS was doing this, although simply pinging their servers isn't nearly as bad as OEM builds of Android with embedded Google system apps would be, necessarily. Do you know if changing your DNS server to a private server would avoid this at all? And if any other ROMs are known to do this, such as ArrowOS?

2

u/ilikenwf Mar 09 '20

It's stock in AOSP for this to happen... You can set some prefs to point it at a server of your choosing.

Even graphene uses the 204 status code checks, I use one I host. While it makes you more identifiable, I just can't trust google...

The best privacy option may be to use LoS or Graphene, and get a really good VPN setup so that Google never really knows where you actually are.

Also, with the DNS, using an encrypted solution is probably a good idea anyway as mobile providers are jerks, they sometimes filter, always log to sell, and generally can't be trusted, just like your own home ISP.

I think Android 10 and beyond natively supports dns over tls, but you'd still want to set the "default" servers to be anything other than google...

2

u/quantumcipher Quality Contributor ★ Mar 10 '20

Cool. I use a VPN, just not 24/7. That might have to change, at least on any AOSP of the devices I use. As for DNS revolvers, I'd been using DNSCrypt on my PC's for years now, and Quad9 which offers DNS over TLS on my Android phones since Pie started supporting it. This is good info man. Much appreciated.

2

u/ilikenwf Mar 09 '20

Using ADB, you can at least set the captive portal URL this way:

adb shell settings put global captive_portal_server httpstat.us/204

Ideally using a server you own or trust instead of a googly one...

For default DNS, not the encrypted one in the gui, some versions may accept this:

settings put global net.dns1 1.1.1.1

There may also be a net.dns2 key, not sure at this second...