Permission Denied

Almost every day I see posts cautioning people against bringing smart technology owned by our Big Tech overlords into their home. These posts warn people to be careful of Alexa and Google Home devices, even Smart TVs. While I agree, the device that really knows the most about you is likely in your hand or your pocket right now: Your phone. 

Your phone has access to your location, social media, email, your private text messages, your purchasing habits, bank account information, search history, what content ignites your political fury and what turns you on, and how often you replayed that one song at 2AM. I could go on for pages. There are probably people who you love and trust who know less about you than your phone does. This month I want to walk you through the process of protecting yourself against your biggest threat – you. 

Know Thyself

Time for a digital detox. The first step is identifying what apps you consistently use on your phone and which ones you don’t. Remove anything you don’t use, because chances are these apps are just sitting there and with each update sneaking more and more data off your phone. Especially if you already gave the app all the permissions it needs when you first installed it. 

Try not to put every app that you do use on your phone. For example, do you really need to be gaming on your phone, or do you have an old tablet you can use just to run your games? Personally, most of my games are on my iPad along with the software that I use to create my art. Only one game I play consistently gets to live on my phone. I pay attention whenever it’s updated and regularly review what it can access.

This might take some time, but it’s the first big, necessary step. If you spend a lot of time on your phone like most people do these days, you’ll be surprised at how uninstalling apps can feel like decluttering your life. That’s because that’s exactly what you’re doing. 

Your Calculator Doesn’t Need Microphone Access

By that, I mean check that the apps that you do use only have permission to do what you want them to do. Why would a calculator app need to use your microphone? It doesn’t, and it shouldn’t ask you for it. Keep this rule in mind when installing anything new, too. Ask yourself why an app is asking for permission to use or access something on your phone and if you can’t understand why it needs that thing, don’t give it that thing.

Treat apps with a pesky behavior of asking for the kitchen sink like a telemarketer or scam caller asking for your Social Security Number. What could they possibly need that for? 

In the case of apps that do ask for your permission to use things like your location or camera for a seemingly legitimate reason, make sure they can only use them for as long as they need to and revoke their access when not in use. If you give that app constant access to everything it asks for, you might never get to experience privacy again. 

Look out for one sneaky thing, apps that run silently in the background. Sometimes you’ll notice an app running like this because your battery is draining faster than it should and your phone feels like lava. Your phone might ask you to put some apps into “deep sleep” and you’ll find yourself questioning why those apps were “awake” in the first place. If you’re anything like me, you can take that as a sign to uninstall those apps since you haven’t used them in what seems like forever.  

There’s No Perfectly Safe App

Don’t trust anything that tells you it’s 100% secure or private. Security is constantly changing and evolving and so are threats to that security. Give apps the bare minimum. Take Signal Private Messenger for example. It doesn’t need your real phone number, so don’t give it that. Don’t use your legal first or last name as your username. Unless you plan on sending images or documents, it doesn’t need access to your storage, and why on earth would you need to use their Story feature? You can just use it for one basic function like I do, to text or chat, and 99% of the time I have vanishing messages enabled. If you use Signal like you use every other social media app, you might find that it doesn’t matter how secure an app is if you’re leaving breadcrumbs in stories or in your profile bio that attackers can use to piece together information on who you really are. You still need to practice good OPSEC, something that many hyperaware security experts I’ve met struggle with at times. We’ll get into what that means in more detail in the future, but basically, you need to be quiet on the creek. 

You Don’t Need the Latest Tech

You don’t need to buy the hottest new thing because it’s new. You can upgrade when your devices are on their last legs, when you are unable to personally repair them with what you have, or if you do not have the means to have them repaired elsewhere. You don’t need to stress over what new iPhone your friends have, because you don’t know how that new device will handle your data and how it might be engineered to ask for more. I’m not talking about some one-off hack, I’m referring to the data Apple pulls and the amount of information that every single app that comes preinstalled on the device requests from you. Do you know for certain how much access these apps will have to personal information on your phone? What they can see and report back?

The same goes for any Android phone, including any of Google’s devices. I’d be concerned about data harvest, usage, and retention of any new device I acquire. I pick a new device when I need to, get used to it, lock it down as much as I can, and then I don’t get rid of it until I absolutely need to. When it comes to their personal device, people are quick to trade in their phones for the latest shiny model and seem to forget about the 4Rs: Reduce, Reuse, Recycle, Repurpose! At the very least, you can refuse to knowingly contribute to the way Big Tech exploits the Democratic Republic of Congo by not upgrading to the newest, shiny device every year. 

No, I’m not just telling you this because I repair devices as a small source of income, I think you should learn to repair your own device before bringing it to me if you can. My main point here is that if you don’t know how the shiny new thing operates, don’t bring it into your home and give it access to your life unless you want to unknowingly feed the beast. That’s literally the plot point of 1984’s Gremlins. 

Take the Extra Step

It might seem extra, but if you ever find yourself in a position where someone has access to your phone, these tips could suddenly seem like the bare minimum and you might end up wishing you had locked things down a little tighter. 

  1. Opt for a password over a pin or pattern

Consider a complex (full alphanumeric - both uppercase and lowercase letters, plus numbers) password to unlock your phone instead of a pin or pattern. If you choose to use a pin, opt for using six digits instead of four. Typically, making something like a password more complex helps to keep things locked down and harder to unlock. Don’t just use six zeros, change the numbers, don’t just use something easy to guess like a birthday or pet’s name. A complex password or longer pin will make your phone harder to break into than a common pattern or shorter pin. 

  1. Remove biometric login, don’t use your fingerprint or face to unlock your device

There has been at least one instance of an individual being taken into custody and law enforcement using their fingerprint or face to gain access to their device without permission (without a warrant!) The cost of convenience could be your life. What would you do if someone planted evidence against you on your own phone? How would you go about proving it? Before you tell me that you think Apple is more secure, consider what all someone could have access to if all they had was your iCloud password. 

  1. Change what settings are available before you even unlock your phone

Some mobile devices have a limited amount of settings that a user can access before their phone is unlocked. If someone malicious wants to abduct you and make you harder to track, they don’t need to unlock your phone to turn off every setting, or even turn your phone off. They can turn on Airplane Mode and take you offline for a while. Navigate to your settings and turn off Control Center access when your phone is locked, or if you’re on an Android device, edit the Quick Settings panel to remove the Airplane Mode toggle. Sure, your phone can still be tossed into a Faraday bag, but at least try to make things a bit harder for anyone with malicious intent. This isn’t to shame you, I just want you to be safe! You can take shortcuts, but the easier you make it for yourself in the now, the harder it might get for you in the when. 

  1. Turn off your bluetooth when you’re not using it

I can’t tell you the amount of times I tried to get away with wearing bluetooth headphones at a Cybersecurity conference only for someone to either disconnect my headphones or, on at least one occasion, blast whatever they wanted straight to my eardrums. In my opinion, those hackers were being cute and I got off easy with a nonverbal warning of “hey, doofus! Don’t do that.” Anyways, bluetooth access can go from being a digital game of “ding-dong ditch” to “let’s see what all I can trick you into letting me have access to.”

  1. No coffee shop wifi

Don’t connect to free wifi wherever you go, and at the very least please use a VPN. That stands for Virtual Private Network, a service that creates a secure, encrypted connection between your device and the internet, hiding your online activity and masking your IP address. Think of your IP address as a digital fingerprint. There’s still quite a bit that an attacker can do to make your life harder with just your IP address. 

  1. Take physical precautions

A privacy screen can protect you from someone shoulder surfing, but you also need to be aware of the fact that you shouldn’t just connect to any charging cable you find out in the wild. Otherwise your phone will be our phone. I’m just kidding. Mostly. 

This isn’t even every step you can take to make your phone just a little bit more secure, these are the baby steps. Initially, I had written a column walking users through switching to Graphene, a security and privacy focused mobile OS. However, I realized that it would likely exclude many readers as Graphene is exclusively designed to run on Google Pixel devices. You could also benefit from utilizing a panic app. If a user enters a preconfigured "duress password" under threat, a panic app can fire a hidden command to instantly wipe a device or activate a full system lockout. I don’t usually suggest these to everyone, because there is always a possibility that a user will accidentally and unintentionally wipe their phone or lock themselves out. 

Not Everyone Needs to Know Everything About You, Including Your Phone.

As queer folk, we need to be aware of where our data is going, what is being reported on when it comes to our personhood, and who we allow to access this data. Having a large, uncontrolled digital footprint as a targeted minority can land you a role as doxxing target-practice or the next lolcow sensation. I’m speaking as someone with experience as both target and attacker. It only gets worse when you consider that deepfakes have already entered the chat. I don’t want to take you down a depressing spiral of a rabbit hole. Just know that if you’ve already thought about locking down your phone, it’s not too late. Maybe the best time was yesterday when you first had that thought, but the second best time is today. You can still choose to play it safe. 

In the future, I’ll walk you through what to do if you’ve already had your information spread across the internet. Sometimes less really is more, including to an attacker, and effective protection can at times look like hypervisibility and information overload, rather than locking down every aspect of your life from the public eye. We’ll weave a web of disinformation together. For now, though, please turn off biometric login on your phone. 


Thanks for reading The Lavender Newsletter! If you like what you see, consider supporting your local queer publication <3

You received this because you are subscribed to The Lavender Newsletter. If a friend forwarded this to you, sign up here to get more Lavender!

HOW ARE WE DOING?

We’re always trying to get better and would love your feedback on how The Lavender Newsletter could serve you better. Email your thoughts, suggestions, or complaints to: thelavendernewsletter@gmail.com.

Reading Between the Algorithms #4

by Lavender Tech Columnist Squid