Live data from Hacker News

A Hacker Has Wiped a Spyware Company’s Servers

motherboard.vice.com

11–20 of 120 posts

Re: A Hacker Has Wiped a Spyware Company’s Servers

#11

They stored the master key to their entire data store in a publicly distributed app? > ...we have been taking steps to enhance our data security measures. Sharing details of security measures could only serve to potentially compromise those efforts. Maybe they used ROT13 on the API key twice this time!

[deleted]

Re: A Hacker Has Wiped a Spyware Company’s Servers

#12

I see no reason to praise the hacker. He destroyed a legitimate company's private data for no purpose other than his flawed moral reasoning. The company provides a way for parents to monitor their children and other legitimate business practices. Obviously, the software can be used for nefarious purposes but so can almost any other software. U.S. representatives and senators try to ban encryption using the same exact…

They also store extensive sensitive data and media about/from/with children with piss poor security. Is that not unambiguously bad?

Re: A Hacker Has Wiped a Spyware Company’s Servers

#13

I see no reason to praise the hacker. He destroyed a legitimate company's private data for no purpose other than his flawed moral reasoning. The company provides a way for parents to monitor their children and other legitimate business practices. Obviously, the software can be used for nefarious purposes but so can almost any other software. U.S. representatives and senators try to ban encryption using the same exact…

I see a legitimate business opportunity, a phone walking service. You collect the children's phones and take them to the mall, the library or wherever teenagers go these days, and meanwhile the kids can enjoy life without parental surveillance.

You do wonder what the 24-hour panopticon does to adolescents' mental health and to the health of the parent-child relationship.

Re: A Hacker Has Wiped a Spyware Company’s Servers

#14

How is this even possible that a 3rd party application can intercept all text messages, call history, and photos and still get published to the Android Play Store? Ins't Google supposed to be reviewing the apps?

Isn't Google supposed to be reviewing the apps? The real question is: who gets to say in what someone's phone is going to be doing: the programmer, the manufacturer or the phone's owner. Most everyone would agree that the owner should have a word in it, and that the manufacturer should have no say at all. Germany takes another approach: no one gets to do surveillance outside strict limits, privacy is highly regarded…

Unfortunately most phone owners are unaware of technical details, security, and privacy implications. I'd argue Apple has the right approach with their heavy handed reviews and security model.

Re: A Hacker Has Wiped a Spyware Company’s Servers

#15

How is this even possible that a 3rd party application can intercept all text messages, call history, and photos and still get published to the Android Play Store? Ins't Google supposed to be reviewing the apps?

Whenever I would publish my app (or an update) on the Android Play Store, it seemed like it would be available almost immediately, which hints at the absence of review process.

Also, I've never had to have a discussion with any "reviewer" about my app on Android. For iOS, I've always had to do quite a few back and forth interactions with the "Resolution Center".

Android seems to be a pass through, perhaps after some automated checks are passing.

As mentioned by others, you don't necessarily have to publish to the Play Store: apps can be side-loaded on Android.

Re: A Hacker Has Wiped a Spyware Company’s Servers

#16

How is this even possible that a 3rd party application can intercept all text messages, call history, and photos and still get published to the Android Play Store? Ins't Google supposed to be reviewing the apps?

This is by design. For the apps on Google Play Store, Google wouldn't look at these because it's been possible to do all these and more using the APIs provided by the Android OS all along, even before the granular runtime permission model came with Android 6 (Marshmallow).

I always dread the thought of people not understanding these permissions and letting apps have all kinds of permissions — access to all text messsages, privilege to send text messages, access to call history and privilege to make calls. Many apps read the text messages to process one time passwords/codes sent as text messages, thus avoiding the user having to enter them manually.

These privileges have never been available in iOS for third party apps, and I appreciate Apple deciding to err on this side of the privacy equation (though Apple could still do a lot more on app permissions). Taking the same example as above, iOS apps that need one time passwords/codes depend on the user to enter them manually.

Re: A Hacker Has Wiped a Spyware Company’s Servers

#18

How is this even possible that a 3rd party application can intercept all text messages, call history, and photos and still get published to the Android Play Store? Ins't Google supposed to be reviewing the apps?

Isn't Google supposed to be reviewing the apps? The real question is: who gets to say in what someone's phone is going to be doing: the programmer, the manufacturer or the phone's owner. Most everyone would agree that the owner should have a word in it, and that the manufacturer should have no say at all. Germany takes another approach: no one gets to do surveillance outside strict limits, privacy is highly regarded…

A better question is how can we give the owner a say without the typical owner getting pwned roughly 100% of the time? Which is what's happening on Android at the moment.

Re: A Hacker Has Wiped a Spyware Company’s Servers

#19

I see no reason to praise the hacker. He destroyed a legitimate company's private data for no purpose other than his flawed moral reasoning. The company provides a way for parents to monitor their children and other legitimate business practices. Obviously, the software can be used for nefarious purposes but so can almost any other software. U.S. representatives and senators try to ban encryption using the same exact…

By default all tech companies to me are bad actors with the exception of companies like Watsi and a few others.

Re: A Hacker Has Wiped a Spyware Company’s Servers

#20

I see no reason to praise the hacker. He destroyed a legitimate company's private data for no purpose other than his flawed moral reasoning. The company provides a way for parents to monitor their children and other legitimate business practices. Obviously, the software can be used for nefarious purposes but so can almost any other software. U.S. representatives and senators try to ban encryption using the same exact…

Well, I side with that hacker for this, taken from this article — "I don't want to live in a world where younger generations grow up without privacy."

While parents make a lot of decisions for children in their best interests, this certainly wasn't one of them. The fact that children might later suffer for no fault of theirs and live with something for life because of such a company makes me a lot more angry. It's becoming far too easy to push people into such a situation now.

Post reply on HN