Live data from Hacker News

The FBI considers FaceApp to be a potential counterintelligence threat [pdf]

democrats.senate.gov

41–50 of 136 posts

Re: The FBI considers FaceApp to be a potential counterintelligence threat [pdf]

#41
post #21

Earlier quoted context omitted.

By "non-jailbroken" you should mean "jailbreakable": it is the existence of the vulnerability that makes the phone insecure, not the user having used an exploit to leverage that vulnerability to do something for them. Like, for no avoidance of doubt: if you are running a version of iOS for which you can download an app-based jailbreak (which has been all jailbreaks for current phones that have been released for years…

Just to be clear, you’re saying that FaceApp has a yet unfound component that lets them remotely jailbreak an otherwise un-jailbroken Phone via a published AppStore app? and that they’ve done this in the open on one of the most politically criticized apps short of Facebook?

1) I am saying that your assertion that "There is no threat model for an iPhone app to do nefarious things in an App Store distributed app on a non-jailbroken phone." is a misleading statement that is making a very broad and entirely inaccurate claim about something that I personally don't want anyone confused about (the safety of users jailbreaking their own phone, particularly on these newer devices where the jailbreak developer has very limited ability to mess with the sandbox).

However, 2) I would imagine the probability that FaceApp does not have a vulnerability in it somewhere is extremely low, as in my experience essentially every single app has security flaws in them; the problem in your mental model is that you think someone would "find" a "component" that would be a smoking gun of some form, whereas only an idiot would make a back door something other than a security vulnerability (as essentially every single app has security vulnerabilities). Were any placed there on purpose? No one would ever know.

Re: The FBI considers FaceApp to be a potential counterintelligence threat [pdf]

#42
post #9

Plenty of chinese apps under "utility" category is flooding the us consumers...

Notably ES File Explorer was recently removed form the Google play store because of suspicious behavior. One of the most popular Android file managers.

Aw man, I had no idea! Time to delete. :(

Re: The FBI considers FaceApp to be a potential counterintelligence threat [pdf]

#43

I wonder how many people with a profile picture of their face on their Twitter/Facebook accounts are seriously concerned about this

I wouldn't be surprised if this app collected much less data than the Facebook cancer. Facebook is not only stalking you through its main app but its other brands (Insta, WhatsApp, etc which a lot of people don't even know they're owned by FB) as well as unrelated third-party apps & websites that embed their malicious SDKs. Facebook is an industrial-scale stalking operation. I doubt FaceApp (or frankly any government…

The difference is which government the spyware corp is controlled by.

Re: The FBI considers FaceApp to be a potential counterintelligence threat [pdf]

#44

Earlier quoted context omitted.

Yes, I am sure that's all it can grab (on the iphone). Anyone telling you otherwise is fear-mongering Edit: Obligatory “why are you booing me, I’m right?”

Why are you sure that’s all it can grab? That seems mistaken on a technical level. “Can’t” and “doesn’t” is an important distinction. We have seen lots of examples of ad analytics SDKs that push the iPhone beyond its intended sandbox. Most of them have been banned, but some operated for years before getting banned. It would be a disservice to brush away those concerns as fearmongering.

By that logic, very app should be designated “a counterintelligence threat”

Re: The FBI considers FaceApp to be a potential counterintelligence threat [pdf]

#45

The best measure would be for “good actors” (universities, government research agencies, the New York Times) to provide a free FaceApp-type app. It’s like a weekend-hackathon of work and can be prioritized by the app stores.

Alternative idea: spend that effort on something more worthwhile than a stupid toy. Like cancer research. Or clean energy. Or simply go outside and clean the beaches. NYT office ain’t that far from the ocean.

Re: The FBI considers FaceApp to be a potential counterintelligence threat [pdf]

#46
Russian laws obligates all companies and individuals to provide government access to any data, hardware or applications upon initial request or better have backdoor. All information must be stored for minimum 5 years and provided in un-encrypted form or decryption mechanisms must be supplied.

Re: The FBI considers FaceApp to be a potential counterintelligence threat [pdf]

#47
post #26

Earlier quoted context omitted.

It's certainly better than giving your face to sketchy apps from Russia or China.

It's not better to have your face or other data in a database within reach of your own government. Your government has power over you, other governments do not.

Other governments absolutely have power over you, just not always legally.

Re: The FBI considers FaceApp to be a potential counterintelligence threat [pdf]

#48

Russian laws obligates all companies and individuals to provide government access to any data, hardware or applications upon initial request or better have backdoor. All information must be stored for minimum 5 years and provided in un-encrypted form or decryption mechanisms must be supplied.

0-10 how naive are you?

Re: The FBI considers FaceApp to be a potential counterintelligence threat [pdf]

#49
post #5

Looks like the FBI designated FaceApp as a threat because of its crazy data policy and its Russian origin. Even though I think it's a really shady app, that's a pretty low bar.

policy standpoint that's a low bar

but from a counter intelligence standpoint that's finger painting bar

Re: The FBI considers FaceApp to be a potential counterintelligence threat [pdf]

#50

The best measure would be for “good actors” (universities, government research agencies, the New York Times) to provide a free FaceApp-type app. It’s like a weekend-hackathon of work and can be prioritized by the app stores.

That works in this particular case but is not a general solution. It's not feasible to have "good actors" rewrite clean versions of software written by "bad actors"
Post reply on HN