this post was submitted on 18 Jul 2024
51 points (100.0% liked)
Free and Open Source Software
18066 readers
1 users here now
If it's free and open source and it's also software, it can be discussed here. Subcommunity of Technology.
This community's icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
And your phone’s GPS wouldn’t work for all of those cases because…?
GNSS does work, but it can take a pretty long time to acquire an initial location without PSDS and SUPL. It also uses much more battery. This can especially become an issue if you want to share your live location with somebody, or record your workout over a longer period of time. There are technologies like A-GNSS (Assisted GNSS) that use SUPL (Secure User Plane Location) and PSDS (Predicted Satelite Data Service), but these also require you to send your location to a third party (the default SUPL service on Android is supl.google.com, which is definitely much worse for your privacy than any NLP). GrapheneOS hosts a proxy at supl.grapheneos.org, which is much more private (see GrapheneOS's privacy policy for all their network services: https://grapheneos.org/faq#privacy-policy). PSDS isn't much better, as it's usually provided by the manufacturer of your phone's SoC (e.g. Qualcomm, Broadcom or Samsung). PSDS also sends a lot of data to the service, including SoC serial number and information on the phone including manufacturer, brand and model. GrapheneOS improves the privacy of PSDS (you can read more about all of this at https://grapheneos.org/faq#default-connections), but I still don't see how this would be better than a privacy-friendly network location provider. beaconDB is still in a pretty early phase of development, but it's likely going to be used by GrapheneOS when it becomes more stable. It's also likely, that the GrapheneOS project will either host their own proxy for the public beaconDB service, or their own server using beaconDB data. That way, it would be even more private, and it would be covered under Graphene's privacy-policy, which is essentially just the EFF's privacy-friendly Do Not Track (DNT) policy.
Thanks for the explanation. I really do appreciate it. We seem to have a fundamental disagreement about whether this can be truly private and, indeed, whether it's necessary at all. It still seems to me a non-private solution in search of a problem.
It really is as private as it can be, and the developer is really dedicated to improve user privacy. Other solutions (SUPL, PSDS) aren't much better in terms of privacy. And it's definitely not a solution in search of a problem, as pure GNSS is really slow and consumes a lot of battery. You can try this out yourself if you use GrapheneOS, by going into the location settings and disabling both SUPL and PSDS. I tried it, and I can tell you that it's bad (in my opinion unusable).