this post was submitted on 17 Jan 2025
138 points (98.6% liked)

Cybersecurity

5995 readers
112 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] rumba@lemmy.zip 5 points 4 days ago (1 children)

apps rather than the phones themselves,

In this case, they took it from a marketing agency, who collected it from apps, who got it from the phones.

The "app" adds location services as a permission requirement. Then they add the API for the advertiser. When they app runs, it calls the API which gathers location data.

So you'd think you can just disable location services for the app.

But what happens when they end up stealing it from Waze, or Tile, or Apple. What happens when google just sells it to people?

The only reasonable option is to turn it off at the phone level. But even then, aGPS knows. Your Carrier knows.

To stop this from being a thing, it needs to be done from the ground up with a privacy respecting OS run by a privacy respecting company, serviced by a privacy respecting server.

so basically never.

[–] homesweethomeMrL@lemmy.world 3 points 4 days ago (1 children)

But what happens when they end up stealing it from Waze, or Tile, or Apple. What happens when google just sells it to people?

Indeed.

To stop this from being a thing, it needs to be done from the ground up with a privacy respecting OS run by a privacy respecting company, serviced by a privacy respecting server.

Same as it ever was.

[–] boonhet@lemm.ee 1 points 3 days ago

Google, Apple, etc selling the data is actually unlikely. They don't want other advertisers data to be as competitive as their own.

The smaller players though, get more profit selling data because they'll never compete with the giants on the targeted ads front.