I captured 72 hours of idle Android packets behind pfSense
A team of researchers placed three new Google Pixel 8 smartphones on a private Wi-Fi network for 72 hours. The phones remained untouched and connected to the network. The Wi-Fi router was attached to a pfSense firewall that captured all packets. The investigation revealed the phones transmitted over 8,300 background requests per day without user interaction.
The data included timestamps, device builds, IP addresses, and byte payloads. The phones broadcast Wi-Fi details, device serial numbers, and background telemetry to Alphabet data centers. Even with GPS off, Google Play Services continued to upload unique MAC addresses of nearby Wi-Fi routers. The phones also transmitted carrier configuration profiles, SIM card hashes, and hardware fingerprints.
Push notifications were maintained through a persistent socket to mtalk.google.com. Android background tasks included syncing with Google Photos and pre-downloading search suggestions. The research highlights key Google services that emit telemetry, such as Google Play Services, Google Photos, and search-related domains. Users can block these domains using tools like Pi-hole, AdGuard Home, or NextDNS to limit data leaks.
The dataset is available under Creative Commons Attribution 4.0 (CC BY 4.0) for further analysis and citation.
Written by urgent.news from Hacker News's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.