Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's fascinating to me that gyroscope and accelerometer data don't seem to require permissions or explicit user opt-in on smartphones (at least that was true a few years ago and still seems true from a quick Google search, although I'm not sure if things have changed). As a side-channel, I've read about them being used for: - This. - Audio recordings of users (https://arxiv.org/pdf/1907.05972.pdf) - Keystrokes (https://medium.com/@tomasreimers/axolotl-a-keylogger-for-iph..., this one is shameless self-promotion and also why I'm interested in the topic)

To me it seems that there are so few legitimate use-cases for device motion (mostly fitness related and https://www.cyberdefinitions.com/definitions/SMTH.html) that it's almost shocking you can access them by default.



Indeed. I myself have hit significant roadblocks trying to block access to my device's compass. Between storage in a magnetic-clasp case and its car mount not facing directly toward the direction of travel, bad compass data significantly interferes with the ability of my navigation apps to tell the direction my car is going. I wish I could just force them to orient based on my direction of travel.


Permission requirement should be generalized to all sensors, if not all sources of data such as the file system and internet.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: