Trinity College in Dublin has done a few studies in this area over the years. Here's a Forbes article about them (apologies in advance if it is paywalled).
Switching to open source, privacy-respecting apps is the most important part of obtaining privacy on Android and it sounds like you've done that. Whether you need to have the absolute highest level of protection against Google is really something only you can determine. For me, "stock" Android with as many FOSS replacements as possible is good enough.
Google play service have unstoable access to everything on they have like root rights + vendors spyware like on miui there are dozens of bad system apps
Not so sure about the signal messages if they're stored properly encrypted by the app. But yeah, technically they could probably take screenshots. You could do a MiTM with a https proxy and look at wireshark to see what it sends.
You could do a MiTM with a https proxy and look at wireshark to see what it sends.
Surely a professional must have looked into this by now?
Also I don't see how Google wouldn't be able to read Signal messages if they have full unstoppable access to everything? If the user can read it, surely Google can too?
Your location, contacts, nearby devices, nearby WiFi, search history, voice query recordings, which apps you install and use and when, a log of activity on your phone, your advertising profile, which accounts you set up on the phone, possibly facial recognition for photos you take, who you call and message (if using default apps) including which phone numbers you connect to, events in your calendar, browsing history (if using default browser) and YouTube activity (if using the YouTube app).
Those are the main ones that are usually mentioned in articles about this. Some of it won't apply if you use only open source apps and no Google apps. But some of it is baked into the OS and the Play Services, and difficult or impossible to avoid.
Thank you! Location and search history are particularly troubling especially when a user is not even using Google to search. Can Google still see contacts if not using their contacts app?
Location and search history are particularly troubling especially when a user is not even using Google to search.
I dont think that's what is happening. You said "no precautions", so they gave you a list of what is collected by default. Google is the default search browser used by the default Google Assistant and the default browser (Chrome, Samsung Internet, etc all use Google Search).
Can Google still see contacts if not using their contacts app?
Probably. Android has a contacts database with which your contacts app interacts. And Google Play Services, which you can't disable in stock Android, has access to everything, including this database.
Plus they can use location to see who you meet up with, and get their info and their contacts' info from their phones. One way or another, Google can build up a pretty thorough profile of your social circle.
after removing OEM and Google bloats with Universal ADB Debloater, practically none. There are some stuff occasionally like google connectivity check, so you gotta use something like rethinkdns or afwall and only enable net access for apps you need.
There's not really a stock Android though. Every manufacturer has its own flavor, so unless you go out of your way to build AOSP for your device, it could be anything.
Yes, as I understand it, by "stock" Android OP meant any of these OEM-supplied Android installations as opposed to a custom version you'd install yourself. Although the "stock" Androids are different from one another, they all share the same relatively poor baseline privacy because they all send data to Google, on top of which they may also send data to the phone manufacturer and the cell network provider and possibly other organizations. This contrasts with custom versions of Android like GrapheneOS which are designed to be better for privacy and send less data to Google.
21 Comments
Ilandar@lemmy.today · 31 pts · 288d
Trinity College in Dublin has done a few studies in this area over the years. Here's a Forbes article about them (apologies in advance if it is paywalled).
Switching to open source, privacy-respecting apps is the most important part of obtaining privacy on Android and it sounds like you've done that. Whether you need to have the absolute highest level of protection against Google is really something only you can determine. For me, "stock" Android with as many FOSS replacements as possible is good enough.
flork@lemy.lol · 5 pts · 288d
Yes that's what I'm trying to determine lol but I haven't been able to know what it is Google has the power to do with stock android.
Thank you for the link to the article!
anon5621@lemmy.ml · 20 pts · 288d
Google play service have unstoable access to everything on they have like root rights + vendors spyware like on miui there are dozens of bad system apps
flork@lemy.lol · 8 pts · 288d
Understood (I think) so just to be clear, you are saying Google has the power to collet:
Is that accurate?
northernlights@lemmy.today · 7 pts · 288d
Not so sure about the signal messages if they're stored properly encrypted by the app. But yeah, technically they could probably take screenshots. You could do a MiTM with a https proxy and look at wireshark to see what it sends.
flork@lemy.lol · 4 pts · 288d
Surely a professional must have looked into this by now?
Also I don't see how Google wouldn't be able to read Signal messages if they have full unstoppable access to everything? If the user can read it, surely Google can too?
limerod@reddthat.com · 2 pts · 287d
Signal uses E2E encryption. Unless, google can capture the screen displaying the message. It cannot read encrypted signal messages.
pr06lefs@lemmy.ml · 1 pts · 287d
google text entry and AI assist/training
floofloof@lemmy.ca · 9 pts · 288d
What are your "other precautions"?
flork@lemy.lol · 5 pts · 288d
Let's say the user is taking no other precautions. What information is being shared to Google with stock android?
floofloof@lemmy.ca · 4 pts · 288d
Your location, contacts, nearby devices, nearby WiFi, search history, voice query recordings, which apps you install and use and when, a log of activity on your phone, your advertising profile, which accounts you set up on the phone, possibly facial recognition for photos you take, who you call and message (if using default apps) including which phone numbers you connect to, events in your calendar, browsing history (if using default browser) and YouTube activity (if using the YouTube app).
Those are the main ones that are usually mentioned in articles about this. Some of it won't apply if you use only open source apps and no Google apps. But some of it is baked into the OS and the Play Services, and difficult or impossible to avoid.
flork@lemy.lol · 4 pts · 288d
Thank you! Location and search history are particularly troubling especially when a user is not even using Google to search. Can Google still see contacts if not using their contacts app?
Ilandar@lemmy.today · 2 pts · 288d
I dont think that's what is happening. You said "no precautions", so they gave you a list of what is collected by default. Google is the default search browser used by the default Google Assistant and the default browser (Chrome, Samsung Internet, etc all use Google Search).
flork@lemy.lol · 1 pts · 288d
To be clear I said "using F-Droid for all apps".
floofloof@lemmy.ca · 1 pts · 288d
Probably. Android has a contacts database with which your contacts app interacts. And Google Play Services, which you can't disable in stock Android, has access to everything, including this database.
Plus they can use location to see who you meet up with, and get their info and their contacts' info from their phones. One way or another, Google can build up a pretty thorough profile of your social circle.
hexagonwin@lemmy.sdf.org · 2 pts · 286d
after removing OEM and Google bloats with Universal ADB Debloater, practically none. There are some stuff occasionally like google connectivity check, so you gotta use something like rethinkdns or afwall and only enable net access for apps you need.
limerod@reddthat.com · -2 pts · 288d
Depends. Can you share the device name in question? Also, if you use the default OS or a custom rom with/without play services.
floofloof@lemmy.ca · 4 pts · 288d
OP explicitly says stock Android, not a Custom ROM.
Hoimo@ani.social · 3 pts · 288d
There's not really a stock Android though. Every manufacturer has its own flavor, so unless you go out of your way to build AOSP for your device, it could be anything.
floofloof@lemmy.ca · 2 pts · 287d
Yes, as I understand it, by "stock" Android OP meant any of these OEM-supplied Android installations as opposed to a custom version you'd install yourself. Although the "stock" Androids are different from one another, they all share the same relatively poor baseline privacy because they all send data to Google, on top of which they may also send data to the phone manufacturer and the cell network provider and possibly other organizations. This contrasts with custom versions of Android like GrapheneOS which are designed to be better for privacy and send less data to Google.
6nk06@sh.itjust.works · -4 pts · 288d
Google Android, no. Custom ROM, yes.