News: 1647895522

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Android's Messages, Dialer apps quietly sent text, call info to Google

(2022/03/21)


Google's Messages and Dialer apps for Android devices have been collecting and sending data to Google without specific notice and consent, and without offering the opportunity to opt-out, potentially in violation of Europe's data protection law.

According to a research paper, "What Data Do The Google Dialer and Messages Apps On Android Send to Google?"

[1]PDF

, by Trinity College Dublin computer science professor Douglas Leith, Google Messages (for text messaging) and Google Dialer (for phone calls) have been sending data about user communications to the Google Play Services Clearcut logger service and to Google's Firebase Analytics service.

"The data sent by Google Messages includes a hash of the message text, allowing linking of sender and receiver in a message exchange," the paper says. "The data sent by Google Dialer includes the call time and duration, again allowing linking of the two handsets engaged in a phone call. Phone numbers are also sent to Google."

[2]

The timing and duration of other user interactions with these apps has also been transmitted to Google. And Google offers no way to opt-out of this data collection.

[3]Zoom agrees privacy conditions, gets low-risk rating from Netherlands

[4]Meta sued for 'aiding and abetting' crypto scammers

[5]Ireland: Meta fined $18.6m for breaking EU's GDPR

[6]EU, US close to replacing defunct Privacy Shield II

Google Messages (com.google.android.apps.messaging) is installed on over a billion Android handsets. It's offered by AT&T and T-Mobile on Android phones in the US and comes preloaded on recent handsets from Huawei, Samsung, and Xiaomi. Similarly, Google Dialer (also known as Phone by Google, com.google.android.dialer) has the same reach.

Both pre-installed versions of these apps, the paper observes, lack app-specific privacy policies that explain what data gets collected – something Google requires from third-party developers. And when a request was made through Google Takeout for the Google Account data associated with the apps used for testing, the data Google provided did not include the telemetry data observed.

[7]

[8]

Both apps presently have links on Google Play to Google's [9]consumer privacy policy , which is not app-specific and not necessarily evident to those who receive the apps preinstalled.

From the Messages app, Google takes the message content and a timestamp, generates a SHA256 hash, which is the output of an algorithm that maps the human readable content to an alphanumeric digest, and then transmits a portion of the hash, specifically a truncated 128-bit value, to Google's Clearcut logger and Firebase Analytics.

[10]

Hashes are designed to be difficult to reverse, but in the case of short messages, Leith said he believes some of these could be undone to recover some of the message content.

"I’m told by colleagues that yes, in principle this is likely to be possible," Leith said in an email to The Register today. "The hash includes a hourly timestamp, so it would involve generating hashes for all combinations of timestamps and target messages and comparing these against the observed hash for a match – feasible I think for short messages given modern compute power."

The Dialer app likewise logs incoming and outgoing calls, along with the time and the call duration.

[11]

As the paper states, Google Play services discloses that data gets collected for security and fraud prevention, to maintain Google Play Services APIs and core services, and to provide Google services like bookmark and contact syncing. It does not, however, detail or explain its collection of message content or of callers and call recipients.

"I was surprised to see this data being collected by these Google apps," said Leith.

Leith disclosed his findings to Google last November and said he has had several conversations with Google's engineering director for Google Messages about suggested changes.

The paper describes nine recommendations made by Leith and six changes Google has already made or plans to make to address the concerns raised in the paper. The changes Google has agreed to include:

Revising the app onboarding flow so that users are notified they're using a Google app and are presented with a link to Google’s consumer privacy policy.

Halting the collection of the sender phone number by the CARRIER_SERVICES log source, of the 5 SIM ICCID, and of a hash of sent/received message text by Google Messages.

Halting the logging of call-related events in Firebase Analytics from both Google Dialer and Messages.

Shifting more telemetry data collection to use the least long-lived identifier available where possible, rather than linking it to a user's persistent Android ID.

Making it clear when caller ID and spam protection is turned on and how it can be disabled, while also looking at way to use less information or fuzzed information for safety functions.

Google confirmed to The Register on Monday that the paper's representations about its interactions with Leith are accurate. "We welcome partnerships – and feedback – from academics and researchers, including those at Trinity College," a Google spokesperson said. "We've worked constructively with that team to address their comments, and will continue to do so."

The paper raises questions about whether Google's apps comply with GDPR but cautions that legal conclusions are out of scope for what is a technical analysis. We asked Google whether it believes its apps meet GDPR obligations but we received no reply.

We've worked constructively with that team to address their comments, and will continue to do so

Leith said it's not clear whether Google's commitments fully address the concerns he has raised.

"In particular, they say they will introduce a toggle within the Messages app to allow users to opt out of data collection but that this opt out will not cover data that Google considers to be 'essential' i.e. they will continue to collect some data even when users opt out," he said. "In my tests I had already opted out of Google data collection by disabling the Google 'Usage and diagnostics' option in the handset Settings, and so the data I reported on was already judged to be somehow essential by Google. I think we’ll have to wait and see."

Leith said there are two larger matters related to Google Play Service, which is installed on almost all Android phones outside of China.

"The first is that the logging data sent by Google Play Services is tagged with the Google Android ID which can often be linked to a person’s real identity – so the data is not anonymous," he said. "The second is that we know very little about what data is being sent by Google Play Services, and for what purpose(s). This study is the first to cast some light on that, but it's very much just the tip of the iceberg." ®

Get our [12]Tech Resources



[1] https://www.scss.tcd.ie/doug.leith/privacyofdialerandsmsapps.pdf

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YjkDn@QzVYCUpaLHBsF9ZAAAAEs&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.theregister.com/2022/03/21/zoom_dpia/

[4] https://www.theregister.com/2022/03/18/meta_sued_over_scam_celebrity_crypto_ads/

[5] https://www.theregister.com/2022/03/16/meta_gdpr_fine/

[6] https://www.theregister.com/2022/03/02/new_hope_for_privacy_shield/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YjkDn@QzVYCUpaLHBsF9ZAAAAEs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YjkDn@QzVYCUpaLHBsF9ZAAAAEs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[9] https://policies.google.com/privacy

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YjkDn@QzVYCUpaLHBsF9ZAAAAEs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YjkDn@QzVYCUpaLHBsF9ZAAAAEs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[12] https://whitepapers.theregister.com/



Why not just let people flag and report spam?

ecarlseen

Is the easy and obvious solution that difficult?

Re: Why not just let people flag and report spam?

Gene Cash

They do, actually. You can go into your call log, tap a recent call and "Block/Report Spam"

Google is in bed with the NSA

VoiceOfTruth

Everything you think is your information, they think is their information.

Re: Google is in bed with the NSA

b0llchit

They do not "think" it is their information. They assure it becomes their information by all means necessary.

The "smart" in these phones is how smart the controlling parties (*) have been to get their fingers in any and all possible information for analysis.

(*) controlling parties include google and apple but there are many more. The commercial entities may just be a front for more nefarious parties like NSA and other secret services.

Re: Google is in bed with the NSA

Jellied Eel

The law seems strange. So I have an android with a Verizon contract. They need call logs. A local app would so it could show it to me. Google doesn't need to know, especially their Play organ.

I'm also curious about the legality. Most countries have legislation covering lawful intercept that attempts to regulate things like wire taps. There have been plenty of prosecutions in the past where people have illegally installed call & data loggers.

So why not prosecute, if the basic activity is fundamentally unlawful? Which may also be a consent issue because I think it gets legally tricky to consent to something illegal.

Re: Google is in bed with the NSA

b0llchit

But any redress would require you to sue google. Then, in a class action, you can get maybe one million people in the class to get 500 Megabucks in a settlement. The lawyers take 50% of that and then you get vouchers for $250, which you may spend at the google play store.

Your data is still abused and you cannot get it back. Your data is used in aggregates, probably anonymized in a reversible way, and will never get deleted anyway. The three letter agencies from all over the world have copies of the data and you will never ever get them to admit to anything.

All in all, you are fucked over, regardless how illegal the actions have been. That is the problem with this digital data in the hands of anybody else than yourself. You can never get effective redress.

That rogue programmer again

Dan 55

Let me guess, he put the data collection in the apps and forgot the opt-in toggles.

Bet that rogue programmer has a Sailfish phone.

Re: That rogue programmer again

b0llchit

No, it was the same programmer as the one from microsoft who also accidentally implemented the advertising code in that file explorer.

These programmers... They always move between jobs and employers. That is how all these accidents happen, you know. But some programmers are a little more accident-prone than others. Here we see an expert in both advertisement visualization and information gathering for direct targeting. I'm almost sure this guy is getting at least two paychecks each month.

GDPR

Woodnag

I don't understand the weaseling around.

This very clearly violates the GDPR... intimate surveillance, undisclosed and therefore without opt-in (the legal requirement) let alone opt out.

Re: GDPR

Ian Mason

I would not be surprised to find that this falls within criminal stalking legislation in some jurisdictions.

Power corrupts. And atomic power corrupts atomically.