Live data from Hacker News

Malware Found Pre-Installed on Xiaomi, Huawei, Lenovo Phones [pdf]

public.gdatasoftware.com

11–20 of 22 posts

Re: Malware Found Pre-Installed on Xiaomi, Huawei, Lenovo Phones [pdf]

#11

This seems to be the report referred to in the linked article: https://public.gdatasoftware.com/Presse/Publikationen/Malwar...

Thanks. We changed the URL from http://au.idigitaltimes.com/malware-found-pre-installed-xiao..., which points to this.

Re: Malware Found Pre-Installed on Xiaomi, Huawei, Lenovo Phones [pdf]

#13
post #11

This seems to be the report referred to in the linked article: https://public.gdatasoftware.com/Presse/Publikationen/Malwar...

Thanks. We changed the URL from http://au.idigitaltimes.com/malware-found-pre-installed-xiao... , which points to this.

Cool thanks dang!

Re: Malware Found Pre-Installed on Xiaomi, Huawei, Lenovo Phones [pdf]

#14
When I worked for a company that distributed malware (mostly desktop, but trying to break into mobile), we had relationships with a few people who would buy up android devices in bulk and then charge money to companies like ours to have our apps pre-installed. You could pay extra to have the app baked into a custom rom to make it non-removable.

The business model from our end is we'd find app developers who are willing to pay X amount per install (a conversion was usually tracked by the first time an end user opens the app), and then we pay Y amount per install to a shady phone re-seller to bake that app into the rom of their latest batch of phones. As long as X is sufficiently higher than Y to account for whatever our conversion rate is, we make our money back plus profits as the app developer pays us for conversions.

The shady re-sellers would take their phones with new roms and either sell direct to consumer or, in the case of the bigger guys, move those phones on to a big-box retailer.

Re: Malware Found Pre-Installed on Xiaomi, Huawei, Lenovo Phones [pdf]

#15
post #14

When I worked for a company that distributed malware (mostly desktop, but trying to break into mobile), we had relationships with a few people who would buy up android devices in bulk and then charge money to companies like ours to have our apps pre-installed. You could pay extra to have the app baked into a custom rom to make it non-removable. The business model from our end is we'd find app developers who are willi…

instead of paying 10? 30% of your sleazy revenue to the middle man, why not offer one payment to QA manager at the factory?

ironically, the same economics that make it worthwhile to manufacture in country X, also makes it very cheap to bribe in country X (e.g. the guy that would drive to eastern europe to buy pez dispensers at the factory for collectors)

Re: Malware Found Pre-Installed on Xiaomi, Huawei, Lenovo Phones [pdf]

#17

Well, this is a whitepaper from a company that wants to sell you mobile AV software... so IMO some independent verification (or better proof than what's in this PDF) would be good. Not that I doubt this goes on.

The comment above ("Rudism") appears to be exactly that.

Re: Malware Found Pre-Installed on Xiaomi, Huawei, Lenovo Phones [pdf]

#18
post #17

Well, this is a whitepaper from a company that wants to sell you mobile AV software... so IMO some independent verification (or better proof than what's in this PDF) would be good. Not that I doubt this goes on.

The comment above ("Rudism") appears to be exactly that.

A random comment is not an "independent verification"

Re: Malware Found Pre-Installed on Xiaomi, Huawei, Lenovo Phones [pdf]

#20
post #5

Earlier quoted context omitted.

It's interesting that the report states "The G DATA security experts are certain that the manufacturers are not the perpetrators in the majority of cases. Renowned companies will not risk their reputation by distributing malware in the firmware." Manufacturers have no qualms about installing bloatware and even spyware onto laptops. It would be interesting to know what standards, if any are used to sift out the malwar…

Clearly the author does not consider Lenovo to be a "Renowned company" given that they have form for doing that very act. Twice.

While SuperFish was a security risk it wasn't a "malware", there is a difference between various really stupid and blatant backdoors and other security risks and actual malware.

Lenovo didn't use it to steal user's data they could care less about it, but some one could abuse it to compromise users both through compromising SuperFish it self and by exploiting the fact that SuperFish will issue certificates to SSL websites even if the original certificate isn't really valid which will allow attackers to MITM SSL connections.

Sony also had distributed software that could be classified as backdoors or rootkits in it's CD's as DRM, many other companies also had similar incidents.

While it's a stupid practice and quite unfair to your customers you can't really call it malicious since they didn't really used it for that just never thought it quite true or didn't care enough in the first place.

The packages in this case seem to be actual malware and not some adware/unwanted software installed by the vendors which while might be a security risk wasn't intended to actually compromise the user.

Post reply on HN