‹ BackHN Continuity

Thread

Big Tech ruined the cloud, so we're renaming ours

212 points · 108 comments · 2sf5

  1. paimapi · · focus · HN ↗
    I'll wait for someone to do a network call audit before I trust something like this

    I've been working on a small project running mitmproxy on a lot of 'privacy-focused' baby-tracking apps and only one of the ones I've tested doesn't send back a bevy of analytics data (none of which they openly promise to anonymize)

    some of the worst culprits had things like the Facebook SDK and Google Ads installed and sending data in spite of literally promising not to generate an Ad ID and three (Baby+, Nanit, and Pregnancy+) straight up had Microsoft Clarity sending data (ie basically screen recordings and full input logs)

    1. Jimpulse · · focus · HN ↗
      Which one didn't send back a ton of analytics?

      Also, surprised with Nanit, Microsoft Clarity was found on the phone app?

      With the whole LG fiasco I wouldn't be surprised if the camera itself was doing network fingerprinting and data collection.

      1. paimapi · · focus · HN ↗
        one open-source, locally hosted one (that&#x27;s slightly inconvenient if you don&#x27;t have a home server that can sync logs) - <a href="https:&#x2F;&#x2F;github.com&#x2F;babybuddy&#x2F;babybuddy" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;babybuddy&#x2F;babybuddy

        and a really obscure and clearly vibe-designed one (that still works fine) that only fired off a single Firebase call noting an install: <a href="https:&#x2F;&#x2F;play.google.com&#x2F;store&#x2F;apps&#x2F;details?id=com.mimiapp.mimilog&amp;hl=en_US&amp;pli=1">https:&#x2F;&#x2F;play.google.com&#x2F;store&#x2F;apps&#x2F;details?id=com.mimiapp.mi...

        one caveat is that I haven&#x27;t done anything like longterm use testing - just account setup and a handful of inputs like a specific feed time and amount, etc. if these apps are firing off data with delayed intervals, I wouldn&#x27;t have captured it

        re Nanit, yes, it sent a request to <a href="https:&#x2F;&#x2F;r.clarity.ms&#x2F;collect" rel="nofollow">https:&#x2F;&#x2F;r.clarity.ms&#x2F;collect with a 1.1KB payload after only a few seconds of use. everything I&#x27;ve read about MS Clarity and MS in general around their data practices makes me extremely wary that such a popular app collects this much data

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.