Greetings, friends. I am trying to wrap my brain around the de-Googled concept of /e/.
For example, suppose I install an app from the /e/ App that discloses they Google analytics. What I think this means is that data goes from my phone to the service provider of that app. And then that app service provider crunches my numbers with Google analytics. (i.e. Google has my data. But I have authorized that transaction.)
What /e/ has does is not allow data to go directly from my device to Google. (Such as relay the number of times I pick up my phone, the orientation of my phone, my location, my acceleration, heartbeat, etc.)
So data does not flow from my device to Google. But that does not stop the app service provider from sending my data to Google.
Is this correct or incorrect? If correct, is there more to the story?
No, it goes straight forward to the tracker owner, so Google if it’s a Firebase Analytics tracker.
What /e/ does for now is preventing any data connection to Google (except through MicroG) by the system. But /e/ doesn’t do anything against bad user apps. It’s a long term goal to implement an ad/tracker blocker in /e/, but for now you could use Blokada for instance.
Worst of it all: they can access your IMEI and, if this phone has had a Google account in a previous life, cross-reference everything and link it to your personal profile. Without that, it’s just a bunch of almost-anonymous data.
BTW I remember in 1999 when the Pentium III came out, and it was the first consumer device ever to include a personal tracking number that could be used to identify you. There was a HUGE backslash against Intel because of this. See https://en.wikipedia.org/wiki/Pentium_III#Controversy_about_privacy_issues
Nowadays every phone comes with an IMEI and nobody complains. I think IMEI access should be a restricted permission in Android, but just like account access it’s allowed without asking. AOSP is very permissive about this kind of thing (obviously it was the intended design to not obstruct user tracking).
Isn’t it the case with recent Android versions (10 or 11) ? (I thought the IMEI wasn’t available without the phone permission but don’t know where this idea comes from).
You’re right. I just run into this page explaining the changes with Android 10.
READ_PHONE_STATE permission, which of course doesn’t apply to Google Play Services. It’s funny how concerned they are with protecting user privacy but only from 3rd parties. I guess they don’t like competition
Anyway when it comes to degoogled/microg phones I’m very happy to see this changed