Fauxx is an open-source Android privacy tool that poisons data broker and ad-tech profiles by generating continuous, plausible, off-demographic synthetic activity from your device. The goal is simple: make your real behavioral signal statistically indistinguishable from noise.

Not my project, but though this is really cool and worth sharing.

  • acido ( acido@feddit.it ) 
    link
    fedilink
    arrow-up
    6
    ·
    5 months ago

    started using it today, it still is in early stages of development and it’s pretty bugged, but it’s very cool.

    the main doubt I have now is if it would be more useful of you could fake activity coherent with your location, for example, because being in EU and faking visits to US gov sites doesn’t exactly sound as stealth.

    I could be wrong though.

  • leoj ( leoj@piefed.zip ) 
    link
    fedilink
    English
    arrow-up
    5
    ·
    5 months ago

    I wonder if you could set up a second phone that is logged in with all your accounts, then use it for FAUXX, currently concerned about battery usage / background usage of device.

    Like, does it need to be running continuously ALL DAY to effectively poison? Or is sometimes usage helpful? Second phone idea solid?

    Anyone understand the data collection better have thoughts?

    • Em Adespoton ( adespoton@lemmy.ca ) 
      link
      fedilink
      arrow-up
      10
      ·
      5 months ago

      This method wouldn’t combat device fingerprinting, so it would be trivial for everyone but the aggregate data brokers to filter out as noise.

      For a strategy like this to work, your legitimate traffic needs to be indistinguishable from the random traffic.

        • f3nyx ( f3nyx@lemmy.ml ) 
          link
          fedilink
          arrow-up
          2
          ·
          5 months ago

          not necessarily. if ‘you’ are sending traffic, i (someone interested in your data) don’t really care where it comes from. Em is correct that it’s trivial to filter out, but it’s also another data point that is interesting and potentially relevant for them, so in practice they won’t.

          tracking has gotten to the point where they can infer connections based off of users that have no interaction but otherwise share a location for a period of time (think coffee shop wifi, work). you have things in common with those people. maybe not a lot, but enough to be relevant in someone’s dataset somewhere.

          so no, it doesn’t have to be running on your primary device to be relevant. i’d argue that it simply being on your home network would be enough.

  • MonkderVierte ( MonkderVierte@lemmy.zip ) 
    link
    fedilink
    arrow-up
    5
    ·
    edit-2
    4 months ago

    Ok, but how does it work? Not the faux data generation part detailed on the git (which OP didn’t link btw) but how it injects/intercepts the data.
    There are magisk modules for this kind of thing, because what can be faked is severely limited without the ability to mess with other apps or the system.

    Does it put a local VPN or what?

  • comrade_twisty ( comrade_twisty@feddit.org ) 
    link
    fedilink
    English
    arrow-up
    2
    ·
    edit-2
    5 months ago

    This is great! I wanted something like this for a long time.

    Any suggestions for something similar that runs on a linux desktop?

    I used TrackMeNot extension for Firefox in the past, but it has been abandoned and not updated in close to 10 years.

  • crow ( crow@leminal.space ) 
    link
    fedilink
    arrow-up
    1
    ·
    edit-2
    5 months ago

    Interesting, how useful is it if I’m always behind a VPN and browse privately (hardened browser, ad blocker, no-script, never logged in etc.)?

    May be wrong but the way I see it it doesn’t help me much?

    • f3nyx ( f3nyx@lemmy.ml ) 
      link
      fedilink
      arrow-up
      8
      ·
      5 months ago

      i only did a quick readthrough so my understanding of how it works is probably flawed. that said:

      you could consider split-tunneling a browser outside of your normal stack for fauxx to pollute. that way your real activity remains as close to “ghost” as possible, and gives your device a fake fingerprint that will fool anyone not directly targeting you.

      the reason I’d suggest doing it that way is that nobody’s personal device hygiene is perfect. flooding with synthetic data is a great way to help conceal when you slip up.

      • crow ( crow@leminal.space ) 
        link
        fedilink
        arrow-up
        3
        ·
        5 months ago

        nobody’s personal device hygiene is perfect

        fair point. guess I’ll try to understand a bit better how everything works before making a decision

        side note: I like how in this thread we have a crow, a f3nyx and a raccoon lol