Package: gnome
Version: 1:3.30+1
Severity: serious
Tags: security
Justification: 5

Dear Maintainer,

It became apparent that despite explicit settings of gnome desktop environment 
"Settings -> All Settings -> Privacy -> Location Services" set to "OFF", 
package 'geoclue-2.0' along with packages depending on it, such as 
'gnome-clocks' ignore settings and continue to send requests via networking 
stack to identify hosts geographical location. 

Could some one from Debian security team review this bug and hopefully provide 
a work around to stop gnome desktop environment along with packages 
'gnome-clocks' & 'geoclue-2.0' from contacting remote services over the 
network, tracing the hosts geo-location?

Any help to stop geo-location tracing/checking/calculating/guestimating - would 
be greatly appreciated.

PS: Debian Dev Team, please note, nether package 'gnome-clocks' or 
'geoclue-2.0' have NO man pages available, and therefore there is no way for a 
user of the host to find out how to disable geo-tracing functionality.

Per Debian regulations:

... Section 5(o) - 'Packages must have a useful extended description.' there 
should be some sort of a documentation that would informed a user of the host 
what options are available to modify unwanted, and this case, privacy related 
behavior to be changes or stopped.

At the same time, while explicit settings for privacy gui element of a GNOME 
environment exist, they appear to be meaningless in terms geo location tracing 
of the host.


-- System Information:
Debian Release: 10.0
  APT prefers stable
  APT policy: (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 4.19.0-5-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), 
LANGUAGE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

