We captured 72 hours of idle Android network packets behind a hardware firewall: 348 outbound requests/hour to Alphabet servers vs GrapheneOS. Raw CSV & blocklist.

45 points•youngmanyk•11 days ago•27 comments•

27 comments

aucisson_masque11 days ago
Grapheneos with Google play services (sandboxed) only send 12 packets per hour, instead of around 350.

That’s great, but the sandboxed Google play services are by default set to normal in battery usage. Meaning it’s subject to dooze and other ways to artificially limit its background activity.

You neee to set the battery usage to unrestricted to reliably revive notification.

I wonder what the packet count would have been with unrestricted Google play services.

like_any_other11 days ago
I'm less interested in the quantity, and more in the content of those packets. Do they contain my GPS movement history? A list of installed and opened apps? My contacts list, messaging text log, and list of visited websites?

The data I really care about protecting would fit into a few kilobytes, so knowing the phone sends, for example, a minuscule 2 MB/day, brings me no comfort.

aucisson_masque10 days ago
Google play services on ‘stock’ android has access to absolutely everything. Including list of apps.

Obviously they send back this data to Google, for legitimate and advertising reasons. For instance, how would they backup apps you have installed if they didn’t know what you installed in the first place.

On grapheneos, it doesn’t have access to this data, but it can still gather a lot of data (just as regular apps on Android). Location (even without location permission), WiFi devices around, Gyroscope so they know if you are standing, driving or else, etc…

Android is rotten to the core.

VCFundedGenYer11 days ago
This isn’t new. The disgraced Lunduke did this same test nearly a decade ago and observed the same results. Android is malware disguised as a consumer operating system.
KetoManx6411 days ago
> The disgraced Lunduke

What makes him disgraced?

safeimp10 days ago
I wasn't sure either: https://www.reddit.com/r/linux/comments/muc18q/whats_the_dea...

tldr he became very political.

skeledrew11 days ago
Doesn't really work for me. It's just a site likely checking what the browser tells it any the system. Meanwhile I have a VPN blocking most connections and every Google app is either uninstalled or disabled.
perching_aix11 days ago
Was there any TLS interception in place? Mind you, that can be detected and ignored...

Cause the (obviously AI generated) page is fairly ambiguous in this regard. In one section it claims certain pieces of info were sent outright. In others, it refers to them as "Privacy Threat Vector" items. Were they possibly sent or were they actually sent? Why is this left unclear? Why is transmission alone counted as evidence of later misuse? What data is technically necessary to send as part of a protocol?

I'm really quite tired of the run of the mill "privacy minded" folks thinking they're the hot shit because they can launch WireShark, and gawk at packets flying about. Like no, various corporate SNIs appearing in a chatty network log is not evidence for illegal or unethical corporate espionage/surveillance, especially not a clear one. Nor is the network log being chatty any evidence one way or another. Do you really think that surveillence is a more likely explanation for them than just regular enterprise sprawl?

If you're bringing receipts, bring them whole, disclaimers and limitations included. Any analysis that stops before decrypting the traffic is deeply unserious, and only serves to discredit actual research findings & real violations of privacy.

grebc11 days ago
Shockingly bad, any move away from big tech is a good one in my opinion. And I’ve got a lot of moving to do!

Care to run the same experiment for an iPhone?

Read the full thread on Hacker News →

Related stories