Follow

OSMAnd is spyware that leaks your travel history to the OSMAnd developers, even if you have analytics/telemetry turned off!

github.com/osmandapp/OsmAnd/is

github.com/osmandapp/OsmAnd-iO

This unethical and consent-violating data leak exists in both the iOS and Android versions. It's not an accident - they are deliberately phoning home with a unique identifier.

@sneak This kind of shit is what makes me leery about going to meetups cause you know people bring their phones, ntm most new cars have some means of being tracked by intel agencies inbuilt.
@sneak I thank the good Lord above for making me so lazy a piece of shit that I put off setting up OsmAnd for about seven years. Also, chalk another W up for Team "Android is fucking dead please someone make the Pinephone usable I beg you."

@sneak @coolboymew valid concern, but your wording makes it sound as if they added this for the sole purpose of tracking individuals and don't intend to do anything about it. Let's give them some time to respond before starting drama.

@sneak This from having a particular app downloaded or this baked in shit off the OS?
@sneak Also I just noticed that the iPhone version is written in Objective C(++)
That's cool I thought they nuked anything other than Swift because Apple.

@sneak I have analytics disabled and it pings download.osmand.org on ios privacy report. It happens during a live update or download - it should not be sending IDs (but I havent checked with a proxy to inspect https). Can't wait to hear back from them though, as I've been a long time fan of OsmAnd and a premium subscriber... 😬

@lambdagoat the lead dev says it doesnt require consent because it's just a random id. he doesn't get it.

@sneak thanks for the update, that really sucks. I will rethink my subscription then

@trashcatt the lead dev thinks that it doesnt need consent because it is just a random id lol

@sneak Unfortunately OSMAnd+ is, at least for me, still unbeatable as I can configure it to navigate me exactly like I want it. It does not impose onto me a specific set of routing calculations

@sneak It looks like it only happens when downloading maps for later offline use, not continuously? So it could track the maps you're interested in, and maybe where you are while planning a trip, but not where you actually go?

Long thread, but that claim seems far fetched.

@hans it sends a unique and permanent tracking id on every map download.

@sneak That doesn't imply it "leaks your travel history", that's what is far fetched. It can "track" which maps you download, that's not travel history, is it?

@hans client ip is city level geolocation. when you send a persistent unique id from changing client ips over time, i know which cities you were in, and when.

@sneak I've downloaded a lot of maps of areas I've never been to. So unless they actually follow my GPS coordinates, I don't see it as "leaking travel history".

@hans this has nothing to do with which maps you download. you don't seem to understand ip geolocation.

@sneak I've read the thread on Github, and I think I understand enough to know that this kind of "tracking" isn't a problem. I don't wear a mask and pay with cash only while doing groceries because the cashier could track my purchases either.

Sure, maybe OsmAnd could work without that ID, but again, I find your claim far fetched.

@hans it’s fine if you don’t care about your own personal privacy but that doesn’t give anyone license to track people who do (and don’t consent to such tracking)

@sneak Again, I don't see this as tracking. I have a serious problem with online tracking, that's why I never visit sites like Google or Facebook, but an enterprise setting an ID do check the number of maps I download and nothing else, is not a privacy concertn. Not for me, at least.

It's a good thing that you told the world about this, so that people have a choice. Not going to be easy, I think, because every alternative that I know of is a far bigger privacy risk, but hey. But telling the world by calling it "spyware" and "leaking travel history" is a bridge too far, I think.

@hans that's because you don't understand tracking. it is objectively tracking regardless of whether you comprehend it as such or not. the idea that it needs informed consent is your clue.

@sneak

that's because you don't understand tracking.



Yeah, let's go with that.

@hans if it weren't literally designed to discern one user from another, no unique identifier would be necessary.

@sneak holly molly I will read about it tomorrow. I use this app for cycling tracking.

@sneak years ago they had a weird response against a request to allow showing tagged surveillance cameras in OSMAnd

@sneak it seems to have been fixed back in October, which is great since I use it a lot

@sneak well I read this and I came up with:

"Sneak: you are wrong. It is time to admit you came to wrong conclusions and time to publicly show you are able to learn when presented with new facts. Thank you."

github.com/osmandapp/OsmAnd/is

@sneak if you read the github thread it sounds like this isn't quite accurate and you seem to be mischaracterizing what's actually going on.
Sign in to participate in the conversation
Mastodon

The social network of the future: No ads, no corporate surveillance, ethical design, and decentralization! Own your data with Mastodon!