Grapheneos with Google play services (sandboxed) only send 12 packets per hour, instead of around 350.
That’s great, but the sandboxed Google play services are by default set to normal in battery usage. Meaning it’s subject to dooze and other ways to artificially limit its background activity.
You neee to set the battery usage to unrestricted to reliably revive notification.
I wonder what the packet count would have been with unrestricted Google play services.
I'm less interested in the quantity, and more in the content of those packets. Do they contain my GPS movement history? A list of installed and opened apps? My contacts list, messaging text log, and list of visited websites?
The data I really care about protecting would fit into a few kilobytes, so knowing the phone sends, for example, a minuscule 2 MB/day, brings me no comfort.
Google play services on ‘stock’ android has access to absolutely everything. Including list of apps.
Obviously they send back this data to Google, for legitimate and advertising reasons. For instance, how would they backup apps you have installed if they didn’t know what you installed in the first place.
On grapheneos, it doesn’t have access to this data, but it can still gather a lot of data (just as regular apps on Android). Location (even without location permission), WiFi devices around, Gyroscope so they know if you are standing, driving or else, etc…
This isn’t new. The disgraced Lunduke did this same test nearly a decade ago and observed the same results. Android is malware disguised as a consumer operating system.
I looked around the thread and there was nothing notable there at all.
The being political thing just makes sense considering the majority of Linux is hard leftist and bans people from their forums and wiki's if you politically disagree with them, just do a Google search for GNOME, Arch Linux or NixOS and how what they did to XLibre.
Doesn't really work for me. It's just a site likely checking what the browser tells it any the system. Meanwhile I have a VPN blocking most connections and every Google app is either uninstalled or disabled.
Was there any TLS interception in place? Mind you, that can be detected and ignored...
Cause the (obviously AI generated) page is fairly ambiguous in this regard. In one section it claims certain pieces of info were sent outright. In others, it refers to them as "Privacy Threat Vector" items. Were they possibly sent or were they actually sent? Why is this left unclear? Why is transmission alone counted as evidence of later misuse? What data is technically necessary to send as part of a protocol?
I'm really quite tired of the run of the mill "privacy minded" folks thinking they're the hot shit because they can launch WireShark, and gawk at packets flying about. Like no, various corporate SNIs appearing in a chatty network log is not evidence for illegal or unethical corporate espionage/surveillance, especially not a clear one. Nor is the network log being chatty any evidence one way or another. Do you really think that surveillence is a more likely explanation for them than just regular enterprise sprawl?
If you're bringing receipts, bring them whole, disclaimers and limitations included. Any analysis that stops before decrypting the traffic is deeply unserious, and only serves to discredit actual research findings & real violations of privacy.
So i wanted to know what an Android phone actually transmits when you aren't touching it most articles say "Google collects a lot of data" but nobody knows to what extent and publishes some proof lets say some packet captures
Stock Android 16 averaged 348.4 requests/hour to Alphabet ASN 15169 endpoints turning off location and usage diagnostics in settings still left 194.2 requests/hour active mostly checkin.gstatic.com Wi-Fi BSSID surveys. Running GrapheneOS with Sandboxed Play Services dropped traffic to 12.1 requests/hour, while pure GrapheneOS registered zero.
LineageOS does not come with Google Play services, so it's a lot quieter. It should also be possible to find all instances of outbound requests in its source.
That being said, I ran tcpdump on my router for about 10 minutes with no background applications and didn't observe any traffic. There's a (weekly? forgot the default) update check that's enabled by default, everything else is disabled.
> LineageOS does not come with Google Play services, so it's a lot quieter
... Than stock android. Graphene doesn't come with Play either, so Lineage doesn't have Graphene beat here.
Graphene also allows changing (or disabling) connections to Google via their proxy for: Widevine checks, Internet Connectivity checks, certificate transparency, PSDS, and SUPL. I do not believe Lineage has this.
Soulless LLM-ese. The content is needlessly stretched to occupy space, paragraphs, and tables. Any actual insights could have been condensed and conveyed with 80% less text.
The "Complete 72-Hour Raw CSV Dataset" CSV contains 13 records. That incomplete data is formatted incorrectly: rows 6 and 11 are missing payload_bytes, so their description shows in the wrong column.
The "How DeGoogled Are You" section is mostly a separate issue from the test described in the article, and it has no place being at the top. The article is about how Android phones are passively phoning home. For example, switching from Chrome to Brave won't reduce idle phone-home, as Android users can't uninstall Chrome, and the idle activity was not related to Chrome. The same goes for most of the other recommendations in that widget.
of which: Nearby Wi-Fi Routers (Location Triangulation)
is 84.2 pings/hr
So a stock (idle!) pixel 8 is checking where you are more than once per second (without maps running, without asking for directions) and asking what you're doing almost five times a second.
Is there any slope at all? Like, does it ask more frequently in the beginning and less after an hour+ of idle, or is it fairly static?
Would be very curious to see what adding social media and voice assistants does to this, especially with a controls against a silent room and a room with a radio/movies/TV/pure music playing.
Does the voice assistant send more data in the conversational context? How much more? If it is indeed more, how much voice is theoretically being transmitted given the average words per bitrate?
It could also be interesting to see if the stock device transmits more in a conversational environment. Like, if the device is idle, why would it be transmitting more while sitting in an office instead of a quiet lab?
Grapheneos with Google play services (sandboxed) only send 12 packets per hour, instead of around 350.
That’s great, but the sandboxed Google play services are by default set to normal in battery usage. Meaning it’s subject to dooze and other ways to artificially limit its background activity.
You neee to set the battery usage to unrestricted to reliably revive notification.
I wonder what the packet count would have been with unrestricted Google play services.
I'm less interested in the quantity, and more in the content of those packets. Do they contain my GPS movement history? A list of installed and opened apps? My contacts list, messaging text log, and list of visited websites?
The data I really care about protecting would fit into a few kilobytes, so knowing the phone sends, for example, a minuscule 2 MB/day, brings me no comfort.
Google play services on ‘stock’ android has access to absolutely everything. Including list of apps.
Obviously they send back this data to Google, for legitimate and advertising reasons. For instance, how would they backup apps you have installed if they didn’t know what you installed in the first place.
On grapheneos, it doesn’t have access to this data, but it can still gather a lot of data (just as regular apps on Android). Location (even without location permission), WiFi devices around, Gyroscope so they know if you are standing, driving or else, etc…
Android is rotten to the core.
This isn’t new. The disgraced Lunduke did this same test nearly a decade ago and observed the same results. Android is malware disguised as a consumer operating system.
> The disgraced Lunduke
What makes him disgraced?
I wasn't sure either: https://www.reddit.com/r/linux/comments/muc18q/whats_the_dea...
tldr he became very political.
I looked around the thread and there was nothing notable there at all. The being political thing just makes sense considering the majority of Linux is hard leftist and bans people from their forums and wiki's if you politically disagree with them, just do a Google search for GNOME, Arch Linux or NixOS and how what they did to XLibre.
Doesn't really work for me. It's just a site likely checking what the browser tells it any the system. Meanwhile I have a VPN blocking most connections and every Google app is either uninstalled or disabled.
Shockingly bad, any move away from big tech is a good one in my opinion. And I’ve got a lot of moving to do!
Care to run the same experiment for an iPhone?
If you turn the WiFi/mobile off with airplane mode (and ensure wifi is off) this should go away right?
Fun fact, they track you via GPS even harder and upload that once it can
Is there anything we can do? I'm on pixel phone and I love the hardware - very neutral on the software tbh
You've got the ideal hardware to move to GrapheneOS
https://grapheneos.org/
Thank you!
How does iOS compare?
Was there any TLS interception in place? Mind you, that can be detected and ignored...
Cause the (obviously AI generated) page is fairly ambiguous in this regard. In one section it claims certain pieces of info were sent outright. In others, it refers to them as "Privacy Threat Vector" items. Were they possibly sent or were they actually sent? Why is this left unclear? Why is transmission alone counted as evidence of later misuse? What data is technically necessary to send as part of a protocol?
I'm really quite tired of the run of the mill "privacy minded" folks thinking they're the hot shit because they can launch WireShark, and gawk at packets flying about. Like no, various corporate SNIs appearing in a chatty network log is not evidence for illegal or unethical corporate espionage/surveillance, especially not a clear one. Nor is the network log being chatty any evidence one way or another. Do you really think that surveillence is a more likely explanation for them than just regular enterprise sprawl?
If you're bringing receipts, bring them whole, disclaimers and limitations included. Any analysis that stops before decrypting the traffic is deeply unserious, and only serves to discredit actual research findings & real violations of privacy.
So i wanted to know what an Android phone actually transmits when you aren't touching it most articles say "Google collects a lot of data" but nobody knows to what extent and publishes some proof lets say some packet captures
Stock Android 16 averaged 348.4 requests/hour to Alphabet ASN 15169 endpoints turning off location and usage diagnostics in settings still left 194.2 requests/hour active mostly checkin.gstatic.com Wi-Fi BSSID surveys. Running GrapheneOS with Sandboxed Play Services dropped traffic to 12.1 requests/hour, while pure GrapheneOS registered zero.
Data is uploaded here : https://doi.org/10.5281/zenodo.22848749
I'd be curious how LineageOS stacks up against GrapheneOS.
Also, anyone know if there are downsides to blocking checkin.static.com?
LineageOS does not come with Google Play services, so it's a lot quieter. It should also be possible to find all instances of outbound requests in its source.
That being said, I ran tcpdump on my router for about 10 minutes with no background applications and didn't observe any traffic. There's a (weekly? forgot the default) update check that's enabled by default, everything else is disabled.
When connecting to a network, HTTP and HTTPS requests are sent to Google-owned domains for the captive portal check; you can configure a custom URL instead: https://gist.github.com/edwardw/cb99236a592900c4f26fb0d8f474....
> LineageOS does not come with Google Play services, so it's a lot quieter
... Than stock android. Graphene doesn't come with Play either, so Lineage doesn't have Graphene beat here.
Graphene also allows changing (or disabling) connections to Google via their proxy for: Widevine checks, Internet Connectivity checks, certificate transparency, PSDS, and SUPL. I do not believe Lineage has this.
[dead]
please share your thoughts if i should have done things differently
Soulless LLM-ese. The content is needlessly stretched to occupy space, paragraphs, and tables. Any actual insights could have been condensed and conveyed with 80% less text.
The "Complete 72-Hour Raw CSV Dataset" CSV contains 13 records. That incomplete data is formatted incorrectly: rows 6 and 11 are missing payload_bytes, so their description shows in the wrong column.
The "How DeGoogled Are You" section is mostly a separate issue from the test described in the article, and it has no place being at the top. The article is about how Android phones are passively phoning home. For example, switching from Chrome to Brave won't reduce idle phone-home, as Android users can't uninstall Chrome, and the idle activity was not related to Chrome. The same goes for most of the other recommendations in that widget.
Seems like you used AI to steal the results from the same experiment done a decade ago to be honest. Heard this story in a YouTube video long ago.
Stock Pixel 8 (Default Settings)-> 348.4 req/hr
of which: Nearby Wi-Fi Routers (Location Triangulation) is 84.2 pings/hr
So a stock (idle!) pixel 8 is checking where you are more than once per second (without maps running, without asking for directions) and asking what you're doing almost five times a second.
Is there any slope at all? Like, does it ask more frequently in the beginning and less after an hour+ of idle, or is it fairly static?
Would be very curious to see what adding social media and voice assistants does to this, especially with a controls against a silent room and a room with a radio/movies/TV/pure music playing.
Does the voice assistant send more data in the conversational context? How much more? If it is indeed more, how much voice is theoretically being transmitted given the average words per bitrate?
It could also be interesting to see if the stock device transmits more in a conversational environment. Like, if the device is idle, why would it be transmitting more while sitting in an office instead of a quiet lab?
Your maths is wrong...
eh, off by one
You could not have posted AI slop, and written your own thoughts as if you were an actual human being with something to say in their own voice.