Per one tech forum this week: “Google has quietly installed an app on all Android devices called ‘Android System SafetyCore’. It claims to be a ‘security’ application, but whilst running in the background, it collects call logs, contacts, location, your microphone, and much more making this application ‘spyware’ and a HUGE privacy concern. It is strongly advised to uninstall this program if you can. To do this, navigate to 'Settings’ > 'Apps’, then delete the application.”

  • @SavageCoconut@lemmy.world
    link
    fedilink
    English
    11920 days ago

    Google says that SafetyCore “provides on-device infrastructure for securely and privately performing classification to help users detect unwanted content. Users control SafetyCore, and SafetyCore only classifies specific content when an app requests it through an optionally enabled feature.”

    GrapheneOS — an Android security developer — provides some comfort, that SafetyCore “doesn’t provide client-side scanning used to report things to Google or anyone else. It provides on-device machine learning models usable by applications to classify content as being spam, scams, malware, etc. This allows apps to check content locally without sharing it with a service and mark it with warnings for users.”

    But GrapheneOS also points out that “it’s unfortunate that it’s not open source and released as part of the Android Open Source Project and the models also aren’t open let alone open source… We’d have no problem with having local neural network features for users, but they’d have to be open source.” Which gets to transparency again.

    • @FauxLiving@lemmy.world
      link
      fedilink
      English
      1020 days ago

      Graphene could easily allow for open source solutions to emulate the SafetyCore interface. Like how it handles Google’s location services.

      There’s plenty of open source libraries and models for running local AI, seems like this is something that could be easily replicated in the FOSS world.

    • @ad_on_is@lemm.eeOP
      link
      fedilink
      English
      3920 days ago

      if there was something that could run android apps virtualized, I’d switch in a heartbeat

      • Refurbished Refurbisher
        link
        fedilink
        English
        9
        edit-2
        20 days ago

        There are two solutions for that. One is Waydroid, which is basically what you’re describing. Another is android_translation_layer, which is closer to WINE in that it translates API calls to more native Linux ones, although that project is still in the alpha stages.

        You can try both on desktop Linux if you’d like. Just don’t expect to run apps that require passing SafetyNet, like many banking apps.

        • @ad_on_is@lemm.eeOP
          link
          fedilink
          English
          419 days ago

          I know about WayDroid, but never heard of ATL.

          So yeah, while we have the fundamentals, we still don’t have an OS that’s stable enough as a daily driver on phones.

          And this isn’t a Linux issue. It’s mostly because of proprietary drivers. GrapheneOS already has the issue that it only works on Pixel phones.

          I can imagine, bringing a Linux only mobile OS to life is even harder. I wish android phones were designed in a way, that there is a driver layer and an OS layer, with standerdized APIs to simply swap the OS layer for any unix-like system.

          • Refurbished Refurbisher
            link
            fedilink
            English
            119 days ago

            Halium is basically what you’re talking about. It uses the Android HAL to run Linux.

            The thing is, that also uses the Android kernel, meaning that there will essentially never be a kernel update since the kernel patches by Qualcomm have a ton of technical debt. The people working on porting mainline Linux to SoCs are essentially rewriting everything from scratch.

      • @bdonvr@thelemmy.club
        link
        fedilink
        English
        520 days ago

        Every one of them can, AFAIK. I have a second cheap used phone I picked up to play with Ubuntu Touch and it has a system called Waydroid for this. Not quite seamless and you’ll want to use native when possible but it does work.

        SailfishOS, PostmarketOS, Mobian, etc all also can use Waydroid or a similar thing

        • @ad_on_is@lemm.eeOP
          link
          fedilink
          English
          120 days ago

          not necessarily… I mean If they run under the same VM, I’d be fine with that as well…but having a sandboxed wrapper would for sure be nice.

      • @deadcade@lemmy.deadca.de
        link
        fedilink
        English
        120 days ago

        I have used Waydroid, mainly with FOSS apps, and although it has some rough edges, it does often work for just having one or two Android apps functionality.

        Linux on mobile as a whole isn’t daily driver ready yet in my opinion. I’ve only tried pmOS on a OP6, but that seems to be a leading project on a well-supported phone (compared to the rest).

    • @ilinamorato@lemmy.world
      link
      fedilink
      English
      29
      edit-2
      20 days ago

      The Firefox Phone should’ve been a real contender. I just want a browser in my pocket that takes good pictures and plays podcasts.

      • @StefanT@lemmy.world
        link
        fedilink
        English
        1920 days ago

        Unfortunately Mozilla is going the enshittification route more and more. Or good in this case that the Firefox Phone did not take of.

      • @Ledericas@lemm.ee
        link
        fedilink
        English
        520 days ago

        too bad firefox is going through the way like google, they are updating thier privacy terms of usage.

        • @ilinamorato@lemmy.world
          link
          fedilink
          English
          419 days ago

          Yep. I’m furious at Mozilla right now. But when the Firefox Phone was in development, they were one of the web’s heroes.

          • @Ledericas@lemm.ee
            link
            fedilink
            English
            219 days ago

            it says its only for LLM? as long as they dont try to expand the “privacy” in any case i download alternatives to the browsers anyways.

    • @DegenerateSupreme@lemmy.zip
      link
      fedilink
      English
      119 days ago

      I just gave up and pre-ordered the Light Phone 3. Anytime I truly need a mobile app, I can just use an old iPhone and a WiFi connection.

    • @hector@sh.itjust.works
      link
      fedilink
      English
      3920 days ago

      Thanks for the link, this is impressive because this really has all the trait of spyware; apparently it installs without asking for permission ?

      • @Moose@moose.best
        link
        fedilink
        English
        3120 days ago

        Yup, heard about it a week or two ago. Found it installed on my Samsung phone, it never asked for permissions or gave any info that it was added to my phone.

      • @Ledericas@lemm.ee
        link
        fedilink
        English
        320 days ago

        yea i found it as soon as this article said it was on your phone spying on you, ALSO many people, like myself noticed the battery draining pretty fast too, this is probalby the cause, if it installs without your knowledge, i doubt the app is excluded from your "app battery usage logs to, like it doesnt show up how much power its using.

    • @lka1988@lemmy.dbzer0.com
      link
      fedilink
      English
      720 days ago

      Thanks. Uninstalled and reported. Hopefully they’ll get the hint. I love my Android, but this is pushing me towards Graphene/Calyx.

    • @x4740N@lemm.ee
      link
      fedilink
      English
      118 days ago

      Apparently I’m a beta tester for it, don’t recall signing up for beta tests with it

  • @Armand1@lemmy.world
    link
    fedilink
    English
    66
    edit-2
    20 days ago

    For people who have not read the article:

    Forbes states that there is no indication that this app can or will “phone home”.

    Its stated use is for other apps to scan an image they have access to find out what kind of thing it is (known as "classification"). For example, to find out if the picture you’ve been sent is a dick-pick so the app can blur it.

    My understanding is that, if this is implemented correctly (a big ‘if’) this can be completely safe.

    Apps requesting classification could be limited to only classifying files that they already have access to. Remember that android has a concept of “scoped storage” nowadays that let you restrict folder access. If this is the case, well it’s no less safe than not having SafetyCore at all. It just saves you space as companies like Signal, WhatsApp etc. no longer need to train and ship their own machine learning models inside their apps, as it becomes a common library / API any app can use.

    It could, of course, if implemented incorrectly, allow apps to snoop without asking for file access. I don’t know enough to say.

    Besides, you think that Google isn’t already scanning for things like CSAM? It’s been confirmed to be done on platforms like Google Photos well before SafetyCore was introduced, though I’ve not seen anything about it being done on devices yet (correct me if I’m wrong).

    • Ulrich
      link
      fedilink
      English
      3420 days ago

      Forbes states that there is no indication that this app can or will “phone home”.

      That doesn’t mean that it doesn’t. If it were open source, we could verify it. As is, it should not be trusted.

        • @FauxLiving@lemmy.world
          link
          fedilink
          English
          420 days ago

          The Graphene devs say it’s a local only service.

          Open source would be better (and I can easily see open source alternatives being made if you’re not locked into a Google Android-based phone), but the idea is sound and I can deny network privileges to the app with Graphene so it doesn’t matter if it does decide to one day try to phone home… so I’ll give it a shot.

          • @Armand1@lemmy.world
            link
            fedilink
            English
            820 days ago

            God I wish I could completely deny internet access to some of my apps on stock android. It’s obvious why they don’t allow it though.

            • @xspurnx@lemmy.dbzer0.com
              link
              fedilink
              English
              320 days ago

              Check out Netguard. It’s an app that pretends to be a VPN client so most of your traffic has to go through it - and then you can deny/allow internet access per app. Even works without root.

    • @Opinionhaver@feddit.uk
      link
      fedilink
      English
      1520 days ago

      Doing the scanning on-device doesn’t mean that the findings cannot be reported further. I don’t want others going thru my private stuff without asking - not even machine learning.

    • @ZILtoid1991@lemmy.world
      link
      fedilink
      English
      1120 days ago

      Issue is, a certain cult (christian dominionists), with the help of many billionaires (including Muskrat) have installed a fucking dictator in the USA, who are doing their vow to “save every soul on Earth from hell”. If you get a porn ban, it’ll phone not only home, but directly to the FBI’s new “moral police” unit.

    • @lepinkainen@lemmy.world
      link
      fedilink
      English
      -4
      edit-2
      19 days ago

      This is EXACTLY what Apple tried to do with their on-device CSAM detection, it had a ridiculous amount of safeties to protect people’s privacy and still it got shouted down

      I’m interested in seeing what happens when Holy Google, for which most nerds have a blind spot, does the exact same thing

      EDIT: from looking at the downvotes, it really seems that Google can do no wrong 😆 And Apple is always the bad guy in lemmy

      • Noxy
        link
        fedilink
        English
        2020 days ago

        it had a ridiculous amount of safeties to protect people’s privacy

        The hell it did, that shit was gonna snitch on its users to law enforcement.

        • @lepinkainen@lemmy.world
          link
          fedilink
          English
          -319 days ago

          Nope.

          A human checker would get a reduced quality copy after multiple CSAM matches. No police was to be called if the human checker didn’t verify a positive match

          Your idea of flooding someone with fake matches that are actually cat pics wouldn’t have worked

          • Noxy
            link
            fedilink
            English
            519 days ago

            That’s a fucking wiretap, yo

      • Natanael
        link
        fedilink
        English
        17
        edit-2
        20 days ago

        Apple had it report suspected matches, rather than warning locally

        It got canceled because the fuzzy hashing algorithms turned out to be so insecure it’s unfixable (easy to plant false positives)

        • @Clent@lemmy.dbzer0.com
          link
          fedilink
          English
          020 days ago

          The official reason they dropped it is because there were security concerns. The more likely reason was the massive outcry that occurs when Apple does these questionable things. Crickets when it’s Google.

          The feature was re-added as a child safety feature called “Comminication Saftey” that is optional on a child accounts that will automatically block nudity sent to children.

        • @lepinkainen@lemmy.world
          link
          fedilink
          English
          019 days ago

          They were not “suspected” they had to be matches to actual CSAM.

          And after that a reduced quality copy was shown to an actual human, not an AI like in Googles case.

          So the false positive would slightly inconvenience a human checker for 15 seconds, not get you Swatted or your account closed

          • Natanael
            link
            fedilink
            English
            3
            edit-2
            19 days ago

            Yeah so here’s the next problem - downscaling attacks exists against those algorithms too.

            https://scaling-attacks.net/

            Also, even if those attacks were prevented they’re still going to look through basically your whole album if you trigger the alert

            • @lepinkainen@lemmy.world
              link
              fedilink
              English
              019 days ago

              And you’ll again inconvenience a human slightly as they look at a pixelated copy of a picture of a cat or some noise.

              No cops are called, no accounts closed

              • Natanael
                link
                fedilink
                English
                219 days ago

                The scaling attack specifically can make a photo sent to you look innocent to you and malicious to the reviewer, see the link above

      • @lka1988@lemmy.dbzer0.com
        link
        fedilink
        English
        16
        edit-2
        20 days ago

        I have 5 kids. I’m almost certain my photo library of 15 years has a few completely innocent pictures where a naked infant/toddler might be present. I do not have the time to search 10,000+ pics for material that could be taken completely out of context and reported to authorities without my knowledge. Plus, I have quite a few “intimate” photos of my wife in there as well.

        I refuse to consent to a corporation searching through my device on the basis of “well just in case”, as the ramifications of false positives can absolutely destroy someone’s life. The unfortunate truth is that “for your security” is a farce, and people who are actually stupid enough to intentionally create that kind of material are gonna find ways to do it regardless of what the law says.

        Scanning everyone’s devices is a gross overreach and, given the way I’ve seen Google and other large corporations handle reports of actually-offensive material (i.e. they do fuck-all), I have serious doubts over the effectiveness of this program.

      • @Modern_medicine_isnt@lemmy.world
        link
        fedilink
        English
        020 days ago

        Overall, I think this needs to be done by a neutral 3rd party. I just have no idea how such a 3rd party could stay neutral. Some with social media content moderation.

    • @kattfisk@lemmy.dbzer0.com
      link
      fedilink
      English
      3219 days ago

      To quote the most salient post

      The app doesn’t provide client-side scanning used to report things to Google or anyone else. It provides on-device machine learning models usable by applications to classify content as being spam, scams, malware, etc. This allows apps to check content locally without sharing it with a service and mark it with warnings for users.

      Which is a sorely needed feature to tackle problems like SMS scams

      • @desktop_user@lemmy.blahaj.zone
        cake
        link
        fedilink
        English
        519 days ago

        if the cellular carriers were forced to verify that caller-ID (or SMS equivalent) was accurate SMS scams would disappear (or at least be weaker). Google shouldn’t have to do the job of the carriers, and if they wanted to implement this anyway they should let the user choose what service they want to perform the task similar to how they let the user choose which “Android system WebView” should be used.

        • @Aermis@lemmy.world
          link
          fedilink
          English
          419 days ago

          Carriers don’t care. They are selling you data. They don’t care how it’s used. Google is selling you a phone. Apple held down the market for a long time for being the phone that has some of the best security. As an android user that makes me want to switch phones. Not carriers.

        • @kattfisk@lemmy.dbzer0.com
          link
          fedilink
          English
          118 days ago

          No, that wouldn’t make much difference. I don’t think I’ve seen a real world attack via SMS that even bothered to “forge” the from-field. People are used to getting texts from unknown numbers.

          And how would you possibly implement this supposed “caller-id” for a field that doesn’t even have to be set to a number?

          • @desktop_user@lemmy.blahaj.zone
            cake
            link
            fedilink
            English
            -118 days ago

            caller id is the thing that tells you the number. it isn’t cheap to forge, but it’s the only way a scan could reasonably effect anyone with more than half a brain. there is never a reason to send information to an unknown SMS number, or click on a link from a text message from an unknown number.

      • @throwback3090@lemmy.nz
        link
        fedilink
        English
        519 days ago

        Why do you need machine learning for detecting scams?

        Is someone in 2025 trying to help you out of the goodness of their heart? No. Move on.

        • @Aermis@lemmy.world
          link
          fedilink
          English
          519 days ago

          If you want to talk money then it is in businesses best interest that money from their users is being used on their products, not being scammed through the use of their products.

          Secondly machine learning or algorithms can detect patterns in ways a human can’t. In some circles I’ve read that the programmers themselves can’t decipher in the code how the end result is spat out, just that the inputs will guide it. Besides the fact that scammers can circumvent any carefully laid down antispam, antiscam, anti-virus through traditional software, a learning algorithm will be magnitudes harder to bypass. Or easier. Depends on the algorithm

          • @throwback3090@lemmy.nz
            link
            fedilink
            English
            119 days ago

            I don’t know the point of the first paragraph…scams are bad? Yes? Does anyone not agree? (I guess scammers)

            For the second we are talking in the wild abstract, so I feel comfortable pointing out that every automated system humanity has come up with so far has pulled in our own biases and since ai models are trained by us, this should be no different. Second, if the models are fallible, you cannot talk about success without talking false positives. I don’t care if it blocks every scammer out there if it also blocks a message from my doctor. Until we have data on consensus between these new algorithms and desired outcomes, it’s pointless to claim they are better at X.

        • @kattfisk@lemmy.dbzer0.com
          link
          fedilink
          English
          418 days ago

          Blaming the victim solves nothing.

          Scamming is a rapidly growing industry that is becoming more professional and specialized all the time. Anyone can be scammed.

      • @cley_faye@lemmy.world
        link
        fedilink
        English
        -119 days ago

        You don’t need advanced scanning technology running on every device with access to every single bit of data you ever seen to detect scam. You need telco operator to stop forwarding forged messages headers and… that’s it. Cheap, efficient, zero risk related to invasion of privacy through a piece of software you did not need but was put there “for your own good”.

        • @zlatko@programming.dev
          link
          fedilink
          English
          419 days ago

          I will perhaps be nitpicking, but… not exactly, not always. People get their shit hacked all the time due to poor practices. And then those hacked things can send emails and texts and other spam all they want, and it’ll not be forged headers, so you still need spam filtering.

    • Spaniard
      link
      fedilink
      English
      819 days ago

      If the app did what op is claiming then the EU would have a field day fining google.

    • @dan@upvote.au
      link
      fedilink
      English
      419 days ago

      So is this really just a local AI model? Or is it something bigger? My S25 Ultra has the app but it hasn’t used any battery or data.

    • @throwback3090@lemmy.nz
      link
      fedilink
      English
      -5
      edit-2
      19 days ago

      graphene folks have a real love for the word misinformation (and FUD, and brigading). That’s not you under there👻, Daniel, is it?

      After 5 years of his antics hateful bullshit lies, I think I can genuinely say that word triggers me.

      • @teohhanhui@lemmy.world
        link
        fedilink
        English
        919 days ago

        Please, read the links. They are the security and privacy experts when it comes to Android. That’s their explanation of what this Android System SafetyCore actually is.

      • @loics2@lemm.ee
        link
        fedilink
        English
        519 days ago

        Have you even read the article you posted? It mentions these posts by GrapheneOS

  • @mctoasterson@reddthat.com
    link
    fedilink
    English
    4320 days ago

    People don’t seem to understand the risks presented by normalizing client-side scanning on closed source devices. Think about how image recognition works. It scans image content locally and matches to keywords or tags, describing the person, objects, emotions, and other characteristics. Even the rudimentary open-source model on an immich deployment on a Raspberry Pi can process thousands of images and make all the contents searchable with alarming speed and accuracy.

    So once similar image analysis is done on a phone locally, and pre-encryption, it is trivial for Apple or Google to use that for whatever purposes their use terms allow. Forget the iCloud encryption backdoor. The big tech players can already scan content on your device pre-encryption.

    And just because someone does a traffic analysis of the process itself (safety core or mediaanalysisd or whatever) and shows it doesn’t directly phone home, doesn’t mean it is safe. The entire OS is closed source, and it needs only to backchannel small amounts of data in order to fuck you over.

    Remember the original justification for clientside scanning from Apple was “detecting CSAM”. Well they backed away from that line of thinking but they kept all the client side scanning in iOS and Mac OS. It would be trivial for them to flag many other types of content and furnish that data to governments or third parties.

    • @danciestlobster@lemm.ee
      link
      fedilink
      English
      1419 days ago

      I also reported it as hostile and inappropriate. I am sure Google will do fuck all with that report but I enjoy being petty sometimes

    • @woobat@midwest.social
      link
      fedilink
      English
      619 days ago

      thank you for posting this. it’s not yet installed on my phone for some reason, but i will be checking this page every couple days to make sure it stays that way.

  • @Ilovethebomb@lemm.ee
    link
    fedilink
    English
    3220 days ago

    I’ve just given it the boot from my phone.

    It doesn’t appear to have been doing anything yet, but whatever.

  • @variouslegumes@reddthat.com
    link
    fedilink
    English
    3020 days ago

    I switched over to GrapheneOS a couple months ago and couldn’t be happier. If you have a Pixel the switch is really easy. The biggest obstacle was exporting my contacts from my google account.

    • @Kbobabob@lemmy.world
      link
      fedilink
      English
      720 days ago

      GrapheneOS — an Android security developer — provides some comfort, that SafetyCore “doesn’t provide client-side scanning used to report things to Google or anyone else. It provides on-device machine learning models usable by applications to classify content as being spam, scams, malware, etc. This allows apps to check content locally without sharing it with a service and mark it with warnings for users.”

  • @AWittyUsername@lemmy.world
    link
    fedilink
    English
    2319 days ago

    Google says that SafetyCore “provides on-device infrastructure for securely and privately performing classification to help users detect unwanted content

    Cheers Google but I’m a capable adult, and able to do this myself.

  • Zier
    link
    fedilink
    2220 days ago

    My question is, does it install as a stand alone app? Or is it part of a Google Play update chunk that you only find out after Play has updated? My system does not auto update (by design) so I’d like to know where it sources from.

    • ThePowerOfGeek
      link
      fedilink
      English
      -220 days ago

      I went to it on the Okay Store and uninstalled it. It didn’t commission and so far all phone functionality is working funny. It seems like an addon that’s not tightly bound to core OS components.

  • @CaptKoala@lemmy.ml
    link
    fedilink
    English
    2020 days ago

    Thanks for bringing this up, first I’ve heard of it. Not present on my GrapheneOS pixel, present on stock.

    I suppose I should encourage pixel owners to switch from stock to graphene, I know which decide I rather spend time using. GrapheneOS one of course.

    • @SayNaughtOfIt@feddit.org
      link
      fedilink
      English
      320 days ago

      I’ve got a Pixel 8 Pro and I’m currently using the stock OS. Anything in particular that you miss with Graphene OS?

      • @praechaox@lemmy.dbzer0.com
        link
        fedilink
        English
        219 days ago

        I switched from a Samsung to a Pixel a couple years ago. I instantly installed GrapheneOS and have loved it ever since. It generally works perfectly normally with the huge background benefit of security and privacy. The only issues I have had is one of my banking apps doesn’t work (but the others work fine) and lack of RCS (but I’m sure it’s coming). In short, highly highly recommend. I will be sticking with GOS for the long term!

      • @CaptKoala@lemmy.ml
        link
        fedilink
        English
        117 days ago

        I still use a stock pixel for work related and daily usage, but the alternatives I’ve found between F-Droid and Aurora store I’ve never felt lacking.

        Maybe I’ll finish the switch fully in the coming months.

    • @Flying_Hellfish@lemmy.world
      link
      fedilink
      English
      320 days ago

      I’ve looked into it.l briefly. Did you have any issues switching? I’m concerned about how some apps I need would function.

      • @praechaox@lemmy.dbzer0.com
        link
        fedilink
        English
        319 days ago

        I switched from a Samsung to a Pixel a couple years ago. I instantly installed GrapheneOS and have loved it ever since. It generally works perfectly normally with the huge background benefit of security and privacy. The only issues I have had is one of my banking apps doesn’t work (but the others work fine) and lack of RCS (but I’m sure it’s coming). In short, highly highly recommend. I will be sticking with GOS for the long term!

      • @CaptKoala@lemmy.ml
        link
        fedilink
        English
        320 days ago

        I did a fair amount of research before the switch to find alternatives to Google services, some I’ve replaced, others I felt were too much of a hassle for my phone usage.

        I’ve kept my original pixel stock, the hardest part about switching this one over was plugging it in and following the instructions.

        I’m hoping to get rid of my stock OS pixel soon, it would appear my bank hasn’t blocked it’s app on Graphene, unlike Uber.

        For the rest I’ll either buy a cheap af shitbox to use purely for banking and Uber (if it comes to that).

        If you’ve any other questions I’m happy to help find then answers with you, feel free to DM me.

    • @Maxxie@lemmy.blahaj.zone
      link
      fedilink
      English
      219 days ago

      I’m traumatized by trying to use banking apps on lineage… don’t think I’ll risk it until I get a backup phone

  • Lanske
    link
    fedilink
    English
    2019 days ago

    Thnx for this, just uninstalled it, google are arseholes