Per one tech forum this week: “Google has quietly installed an app on all Android devices called ‘Android System SafetyCore’. It claims to be a ‘security’ application, but whilst running in the background, it collects call logs, contacts, location, your microphone, and much more making this application ‘spyware’ and a HUGE privacy concern. It is strongly advised to uninstall this program if you can. To do this, navigate to 'Settings’ > 'Apps’, then delete the application.”

top 50 comments

sorted by: hot top controversial new old
[–] 222 points 2 years ago (20 children)

SafetyCore Placeholder so if it ever tries to reinstall itself it will fail due to signature mismatch.

  • source
  • hideshow 20 child comments
  • [–] 43 points 2 years ago (14 children)

    I struggle with GitHub sometimes. It says to download the apk but I don't see it in the file list. Anyone care to point me in the right direction?

  • source
  • parent
  • hideshow 14 child comments
  • load more comments (5 replies)
  • load more comments (5 replies)
    [–] 120 points 2 years ago (1 child)

    Google says that SafetyCore “provides on-device infrastructure for securely and privately performing classification to help users detect unwanted content. Users control SafetyCore, and SafetyCore only classifies specific content when an app requests it through an optionally enabled feature.”

    GrapheneOS — an Android security developer — provides some comfort, that SafetyCore “doesn’t provide client-side scanning used to report things to Google or anyone else. It provides on-device machine learning models usable by applications to classify content as being spam, scams, malware, etc. This allows apps to check content locally without sharing it with a service and mark it with warnings for users.”

    But GrapheneOS also points out that “it’s unfortunate that it’s not open source and released as part of the Android Open Source Project and the models also aren’t open let alone open source… We’d have no problem with having local neural network features for users, but they’d have to be open source.” Which gets to transparency again.

  • source
  • hideshow 1 child comment
  • load more comments (1 reply)
    [+] 120 points 2 years ago* (last edited 1 year ago) (24 children)
  • [–] 29 points 2 years ago* (last edited 2 years ago) (9 children)

    The Firefox Phone should've been a real contender. I just want a browser in my pocket that takes good pictures and plays podcasts.

  • source
  • parent
  • hideshow 9 child comments
  • load more comments (4 replies)
  • load more comments (1 reply)
    [–] 82 points 2 years ago (12 children)
  • load more comments (6 replies)
    [–] 66 points 2 years ago* (last edited 2 years ago) (23 children)

    For people who have not read the article:

    Forbes states that there is no indication that this app can or will "phone home".

    Its stated use is for other apps to scan an image they have access to find out what kind of thing it is (known as "classification"). For example, to find out if the picture you've been sent is a dick-pick so the app can blur it.

    My understanding is that, if this is implemented correctly (a big 'if') this can be completely safe.

    Apps requesting classification could be limited to only classifying files that they already have access to. Remember that android has a concept of "scoped storage" nowadays that let you restrict folder access. If this is the case, well it's no less safe than not having SafetyCore at all. It just saves you space as companies like Signal, WhatsApp etc. no longer need to train and ship their own machine learning models inside their apps, as it becomes a common library / API any app can use.

    It could, of course, if implemented incorrectly, allow apps to snoop without asking for file access. I don't know enough to say.

    Besides, you think that Google isn't already scanning for things like CSAM? It's been confirmed to be done on platforms like Google Photos well before SafetyCore was introduced, though I've not seen anything about it being done on devices yet (correct me if I'm wrong).

  • source
  • hideshow 23 child comments
  • load more comments (16 replies)
    [–] 44 points 2 years ago (19 children)
  • [–] 32 points 2 years ago (10 children)

    To quote the most salient post

    The app doesn't provide client-side scanning used to report things to Google or anyone else. It provides on-device machine learning models usable by applications to classify content as being spam, scams, malware, etc. This allows apps to check content locally without sharing it with a service and mark it with warnings for users.

    Which is a sorely needed feature to tackle problems like SMS scams

  • source
  • parent
  • hideshow 10 child comments
  • load more comments (10 replies)
  • load more comments (8 replies)
    [–] 43 points 2 years ago

    People don't seem to understand the risks presented by normalizing client-side scanning on closed source devices. Think about how image recognition works. It scans image content locally and matches to keywords or tags, describing the person, objects, emotions, and other characteristics. Even the rudimentary open-source model on an immich deployment on a Raspberry Pi can process thousands of images and make all the contents searchable with alarming speed and accuracy.

    So once similar image analysis is done on a phone locally, and pre-encryption, it is trivial for Apple or Google to use that for whatever purposes their use terms allow. Forget the iCloud encryption backdoor. The big tech players can already scan content on your device pre-encryption.

    And just because someone does a traffic analysis of the process itself (safety core or mediaanalysisd or whatever) and shows it doesn't directly phone home, doesn't mean it is safe. The entire OS is closed source, and it needs only to backchannel small amounts of data in order to fuck you over.

    Remember the original justification for clientside scanning from Apple was "detecting CSAM". Well they backed away from that line of thinking but they kept all the client side scanning in iOS and Mac OS. It would be trivial for them to flag many other types of content and furnish that data to governments or third parties.

  • source
  • [–] 35 points 2 years ago (2 children)

    I didn't have it in my app drawer but once I went to this link, it showed as installed. I un-installed it ASAP.

    https://play.google.com/store/apps/details?id=com.google.android.safetycore&hl=en-US

  • source
  • hideshow 2 child comments
  • load more comments (1 reply)
    [–] 32 points 2 years ago (1 child)

    I've just given it the boot from my phone.

    It doesn't appear to have been doing anything yet, but whatever.

  • source
  • hideshow 1 child comment
  • load more comments (1 reply)
    [–] 30 points 2 years ago (5 children)

    I switched over to GrapheneOS a couple months ago and couldn't be happier. If you have a Pixel the switch is really easy. The biggest obstacle was exporting my contacts from my google account.

  • source
  • hideshow 5 child comments
  • load more comments (5 replies)
    [–] 23 points 2 years ago

    Google says that SafetyCore “provides on-device infrastructure for securely and privately performing classification to help users detect unwanted content

    Cheers Google but I'm a capable adult, and able to do this myself.

  • source
  • [–] 22 points 2 years ago (3 children)

    My question is, does it install as a stand alone app? Or is it part of a Google Play update chunk that you only find out after Play has updated? My system does not auto update (by design) so I'd like to know where it sources from.

  • source
  • hideshow 3 child comments
  • load more comments (3 replies)
    [–] 22 points 2 years ago (1 child)

    Thank you was able to find and uninstall the app with no issues

  • source
  • hideshow 1 child comment
  • load more comments (1 reply)
    [–] 20 points 2 years ago

    Thnx for this, just uninstalled it, google are arseholes

  • source
  • [–] 20 points 2 years ago (9 children)

    Thanks for bringing this up, first I've heard of it. Not present on my GrapheneOS pixel, present on stock.

    I suppose I should encourage pixel owners to switch from stock to graphene, I know which decide I rather spend time using. GrapheneOS one of course.

  • source
  • hideshow 9 child comments
  • load more comments (9 replies)
    [–] 19 points 2 years ago (7 children)

    I just un-installed it

    Anyone know what Android System Intelligence does? Should that be un-installed as well?

  • source
  • hideshow 7 child comments
  • load more comments (7 replies)
    [–] 17 points 2 years ago (6 children)

    Don't use Google Play. Prefer Obtanium, F-Droid or Aurora Store.

  • source
  • hideshow 6 child comments
  • load more comments (6 replies)
    [–] 15 points 2 years ago (3 children)

    Even with the latest update from Samsung, I am not seeing this app. My OnePlus did get it with the February update and I had to remove it.

  • source
  • hideshow 3 child comments
  • load more comments (3 replies)
    [–] 15 points 2 years ago (1 child)

    Well then I hope they like seeing my butthole.

  • source
  • hideshow 1 child comment
  • load more comments (1 reply)
    [–] 13 points 2 years ago (7 children)

    I'd that what's killing my fucking battery like crazy lately?

  • source
  • hideshow 7 child comments
  • load more comments (7 replies)
    load more comments
    view more: next ›