Your phone is careful about some things. Open an app that wants the camera, the microphone, or your location, and you get a prompt. You can say no. You can revoke it later. You can see, in settings, exactly which apps have it.
Now here is the part nobody tells you. Your phone contains roughly a dozen other sensors, and most of them are not behind any permission at all. The accelerometer, the gyroscope, the magnetometer, the ambient light sensor, the proximity sensor, on stock Android these are what researchers call zero-permission sensors. Any app you install can read them silently, with no prompt, forever. So can a web page you merely visit, through ordinary JavaScript in the browser. There is no toggle, no notification, no way to even know it is happening.
For years everyone assumed that was fine, because what could a motion sensor possibly reveal? It turns out: a startling amount.
What the “harmless” sensors actually leak
Your PIN. Researchers demonstrated, in a project called TouchSignatures, that the motion and orientation data a website can read from your phone, no app, no permission, just a web page, is enough to infer the PIN you type. The tiny tilts and accelerations of each tap are distinctive. A separate study showed the ambient light sensor alone, reacting to the shadow of your finger, could narrow a four-digit PIN down enough to guess it correctly about eighty percent of the time within ten tries. Sensors you did not know were on, reading the passcode you thought was private.
Your conversations. This one is genuinely unsettling. The accelerometer is sensitive enough to pick up the vibrations produced by your phone’s own loudspeaker. In an attack researchers named Spearphone, they used those vibrations to partially reconstruct speech, the voice on the other end of a speakerphone call, or your voice assistant’s replies. In effect, the accelerometer becomes a crude microphone, and it is one you never granted access to, because it does not ask. Leave your phone face-up on a table during a speaker call and a rogue app can listen without ever touching the mic permission.
Your identity, across every device you own. The manufacturing process leaves tiny, permanent imperfections in each phone’s motion sensors, so no two accelerometers behave exactly alike. That makes the sensor output a fingerprint. An app or website can read it and recognize your specific device again later, across different apps, and even after a factory reset or behind a VPN, because it is identifying the physical hardware, not an ID you can change. It is one of the few tracking identifiers you cannot reset your way out of.
Your life, in the aggregate. From motion sensors alone, software can read your gait, your typing rhythm, when you are walking, driving, or asleep. The barometer reveals your altitude, which floor of a building you are on. And the radios that are always scanning for nearby devices, for AirDrop, Find My, and location features, quietly build a map of your movements and the people around you, even when you are not using any of it.
Why this is worse than the camera and mic
The camera and the microphone get all the paranoia, and they should be respected. But you can see when an app requests them, you can deny them, and modern phones even show you an indicator light when they are active. The zero-permission sensors get none of that scrutiny precisely because the system treats them as harmless. There is no prompt to deny, no indicator, no list in settings showing which apps are reading your accelerometer right now. It is the single largest surveillance surface on your phone that nobody is watching, hiding in plain sight behind the assumption that a motion sensor is boring.
Regulators are only now waking up to this. There are active investigations in the US and Europe into how much motion, proximity, and Bluetooth data companies collect and whether users can meaningfully control it. The honest security advice for a stock phone is thin: review the permissions you can see, use a USB data blocker, keep the OS updated, and, in one memorable Spearphone mitigation, do not set your phone on a hard surface during speaker calls. That last tip tells you everything. When the best defense is “put your phone on a soft cushion,” you are working around a design flaw, not fixing it. As one survey of the field put it plainly, this class of leak is hard for an individual to protect against on a normal phone.
The fix is putting the sensors behind a door you control
The real solution is straightforward, and it is exactly the kind of thing a stock phone will not give you: put every sensor behind a permission you control, including the ones the platform leaves wide open, and let you disable them outright.
That is a feature of the hardened builds we work with. There is a genuine sensors permission, so you can deny an app access to all the motion, light, and proximity sensors that stock Android would have handed over silently. Now the accelerometer is treated like the camera: something an app has to ask for, that you can refuse, and that you can see. And where a use case calls for it, sensors can be disabled at the operating-system level entirely, so there is simply nothing for a rogue app or a malicious web page to read. The zero-permission hole gets closed, because on a device built this way, no sensor is zero-permission.
This connects to the broader point we keep coming back to: your apps are the leak, and the permission model on a stock phone was written to keep the ecosystem happy, not to keep you in control. A phone that lets you gate every sensor is a phone where “deny” actually means deny, across the whole device, not just the three sensors the manufacturer decided to guard.
Who this is for
Anyone typing a PIN, having a private conversation near their phone, or who would rather not carry a hardware fingerprint that follows them across every app and reset, which is everyone, but especially people whose threat model includes targeted apps, hostile web pages, or an adversary who would love a microphone that never had to ask. If the idea that a website can read your accelerometer while you enter a passcode bothers you, and it should, the answer is not a cushion under your phone. It is a device where you decide which apps touch which sensors, all of them.
If you want a phone where every sensor is behind a door you hold the key to, that is what we build. Email hello@spicycorp.com, or book a call.
SovereignOS is a hardened, de-Googled phone, set up the way we would build one we had to rely on ourselves. One-time price, no subscription, no account required.
See SovereignOSRecent Posts
- Your Phone, Laptop, and TV Are One Profile. Here’s How They Got Linked.
- Your Advertising ID Is a Tracking Number. Here’s How to Actually Kill It.
- Surveillance Capitalism in Plain English (You’re Not the Product, Your Future Is)
- Does iPhone Lockdown Mode Actually Work? (Yes, and Here’s Where It Stops.)
- Your Data Just Leaked. Here’s the First 48 Hours.
Recent Comments
Post Widget
Why Your VPN Isn’t Hiding Your IMEI
Should You Trust Signal?
Social Media Widget
Customer service
Real people, ready to help. Reach our team anytime at hello@spicycorp.com.
Fast Free Shipping
Get free shipping on orders of $150 or more (within the US)
Returns & Exchanges
We offer free returns and exchanges within 30 days of purchase.