Live data from Hacker News

Facebook scans system libraries on Android and uploads them to their server

twitter.com

51–60 of 188 posts

Re: Facebook scans system libraries on Android and uploads them to their server

#51

Earlier quoted context omitted.

It would be less creepy if they actually asked the user if they want to upload those system files before uploading them.

I wonder how many users would understand what these files are, why Facebook might want them, and what the risks are associated with sending these.

That's why telemetry uploads metadata, not actual binaries. If you don't upload other's files, you don't need to ask permission to do so.

Re: Facebook scans system libraries on Android and uploads them to their server

#52
post #28
post #24

Aside from fingerprinting, what other nefarious uses could this have in theory?

You can identify devices with vulnerable libraries and do targeted attacks.

This.

This is the biggest one for me. Anyone who has that data is capable of playing back the 0-days that affect android. How many android phones are kept out of date?

As other user mentioned, the Android ecosystem is like the Wild West. Given there's a report for 2.5B active devices, how many can be affected by such an attack?

1% would affect 25M devices, around the population of Australia. 10% - 250 million devices. 40% - 1 billion devices...

Re: Facebook scans system libraries on Android and uploads them to their server

#54

How does the internal culture at FB come to grips with the world's vision of them as creepy and amoral and still do stuff like this anyway?

That culture has been built up over years. And probably most of the people they hire don't have the life experiences that would give them pause and allow them to consider or even recognize if what they're tasked to do is creepy or not.

Re: Facebook scans system libraries on Android and uploads them to their server

#55

Earlier quoted context omitted.

It would be less creepy if they actually asked the user if they want to upload those system files before uploading them.

I wonder how many users would understand what these files are, why Facebook might want them, and what the risks are associated with sending these.

> what the risks are associated with sending these.

What are the risks?

Re: Facebook scans system libraries on Android and uploads them to their server

#56

I was going to say this isn’t a big deal but copying and uploading the libraries is actually illegal (copyright violation) and users likely can’t even consent to this even if it is in the Facebook ToS as many android phones contain proprietary libraries not licensed for redistribution. The creators of those various libraries should have a valid legal case against Facebook here, if they want to exercise it. I doubt an…

[deleted]

Re: Facebook scans system libraries on Android and uploads them to their server

#57
post #18
post #9

Which android permission does this fall under I wonder?

None, libraries are readable by any process, as they should.

Reading yes, executing yes, reading for the sole purpose to upload to a remote server?.... barf and egregious

Re: Facebook scans system libraries on Android and uploads them to their server

#58

How does the internal culture at FB come to grips with the world's vision of them as creepy and amoral and still do stuff like this anyway?

Seems like people assume FB employees are 'gifted' they are technically capable, and emotionally and philosophically infantile.

Re: Facebook scans system libraries on Android and uploads them to their server

#59
post #30

i was looking around to find lore regarding sandboxing android apps, so far i found this interesting: https://www.reddit.com/r/androidapps/comments/5n7ak9/any_app... And this too: https://www.gtricks.com/android/how-to-sandbox-android-apps-...

As other commenters have mentioned, traditional sandboxing mechanisms would do little here. Applications are always given read access to system libraries because they need them to function.

im thinking about how we get to non traditional sandboxing

Re: Facebook scans system libraries on Android and uploads them to their server

#60

I was going to say this isn’t a big deal but copying and uploading the libraries is actually illegal (copyright violation) and users likely can’t even consent to this even if it is in the Facebook ToS as many android phones contain proprietary libraries not licensed for redistribution. The creators of those various libraries should have a valid legal case against Facebook here, if they want to exercise it. I doubt an…

Some older android devices running newer lineage/AICP/etc builds include a few libraries I wrote (in their entirety) for compatibility of old vendor prebuilts with new android versions - libdgv1 & libdmitry. Maybe I should C&D FB for laughs?

Yes please!
Post reply on HN