Live data from Hacker News

Massachusetts health notifications app installed without users’ knowledge

play.google.com

101–110 of 407 posts

Re: Massachusetts health notifications app installed without users’ knowledge

#101

Well well well. Looks like all my fears have been fully realized. Please tell me more about how unrootable devices are for my own good.

Bootloader unlockable is sufficient to replace the OS. Rooting is likely to die in the near future now that Google hired the Magisk dev.

Re: Massachusetts health notifications app installed without users’ knowledge

#102

I wonder if this is the same functionality some carriers use to install their management app on your phone. For example, I've recently bought a second hand Samsung tablet. I've reset it to factory settings and put in a Vodafone SIM. The next time I looked though the installed apps I saw some Vodafone Services app that I didn't install. It couldn't be removed either. So clearly, either Google with play services or the…

LineageOS without Google Play services (and if you want with microG) would not install anything from Google automaticly.

Other comments mention embedded Java in SIM cards, that's possible, but I'm not sure.

Re: Massachusetts health notifications app installed without users’ knowledge

#103
post #22
post #4

Here is an official page for the same app. Interesting what is the whole story. https://www.mass.gov/info-details/enable-massnotify-on-your-...

Why do this at this late date? A year ago it would have been useful. Now, 59% of Massachusetts's population has been fully vaccinated. About 70% have at least one shot. A bit more pushing and they'll hit 80%, which seems to be about where the epidemic dies out for lack of new carriers.

Isn't contact tracing actually more useful when the number of cases are reasonably low?

Re: Massachusetts health notifications app installed without users’ knowledge

#104
post #84

Earlier quoted context omitted.

This sounds worse to me? Rather than violation of a relatively small privacy (phone number), you instead get timestamp social graph interactions in the physical world. This seems like fat more extreme an invasion than the former.

Read up on how the contact tracing apps work. They do not upload your data to the cloud. Phones broadcast a rolling random identifier, other phones collect received identifiers, and only on confirmed infection does the person's phone upload its last two weeks of broadcast IDs to the cloud, where other phones can grab them and cross-check. Having someone's phone number allows you (via the phone company) to trace their…

Just because protocol is theoretically safe does not imply it is safe in actual practice or that it is not possible to exploit it.

Re: Massachusetts health notifications app installed without users’ knowledge

#105

It is obvious that we need better legislation to deal with all the new possibilities that technologies have opened. The installation of this app, even done with good intent, open a lot of questions on what should be possible or not to be done by government and corporations. When you get a device with pre-installed, uninstallable, or auto-installed apps. What are the rules? > "By enabling this service, you can be quic…

> It is obvious that we need better legislation to deal with all the new possibilities that technologies have opened.

How about applying common sense?

Re: Massachusetts health notifications app installed without users’ knowledge

#106
post #82

Google is fucking evil nowadays. The "Don't be evil" days are far gone. https://en.wikipedia.org/wiki/Don%27t_be_evil

Calling installing a contact tracing app (which really is just a small wrapper over the existing Exposure Notification API) as "fucking evil" seems like bit over the top...

Re: Massachusetts health notifications app installed without users’ knowledge

#107
post #79

It is obvious that we need better legislation to deal with all the new possibilities that technologies have opened. The installation of this app, even done with good intent, open a lot of questions on what should be possible or not to be done by government and corporations. When you get a device with pre-installed, uninstallable, or auto-installed apps. What are the rules? > "By enabling this service, you can be quic…

> In this case it seems that the same goal could have been better achieved by SMS that do not depend on the brand of your phone. The dependency on proprietary app stores and OSs seems a risk for the continuation of a free and reliable communications. While installing an app without users consent can be as questionable as you want, the point about these apps are not the notifications itself but about the contact traci…

Would it not be possible to send everyone currently in the state an SMS? I personally would be okay with the government having access to this type of PSA.

Re: Massachusetts health notifications app installed without users’ knowledge

#108

Earlier quoted context omitted.

Edit: Surely we can come up with a more approachable explanation for less technical folks, though? Here's an attempt: "Contact tracing respects your privacy and does not send your location to the cloud. Instead, your phone makes up a new random name every 15 minutes and broadcasts it to nearby phones. It remembers the last two weeks of names it used, as well as the last two weeks of names it heard from other phones.…

Ahh apologies. It's not the wording of your paragraph, I understood both very well, they are well written. It's a more fundamental understanding of stuff that's hard by those who are most at risk. The old, the vulnerable etc. It's the old digital divide idea. My neighbor doesn't have any internet connected devices, for example. But she would benefit much more from the app than 40 of her mask wearing, young, self isol…

I didn't want to imply you didn't understand it; I was trying to come up with a more accessible explanation that might help others do so and help drive adoption.

You're right that it's not easy to explain, but surely we can come up with something that gets the idea across? :)

Re: Massachusetts health notifications app installed without users’ knowledge

#109

Earlier quoted context omitted.

That doesn't fix the issue ISPs mandate certain capabilities of the cellular modem + the simcards (remember java cards? that ran java? they still exist as simcards!) Government RCE is still 100% on the table regardless of whatever software your phone is running

Do any of the privacy oriented custom ROMs protect against that? I can't imagine their maintainers seeing code that just installs any app the ISP wants and be okay with it.

The problem is, its usually cheaper the more things you can shove into the 1 hardware item, so you have your cellular hardware in the same chip as your CPU and GPU. Not much a ROM can do about this unless the chip itself supports disabling direct memory across the two items, + does it correctly, + doesn't allow it to be reversed from the other side, + you would also need the datasheet to find out how to implement this.

Generally why privacy roms don't support more than 1 or 2 brands total, I guess.

There are also platforms with strict division between the seperate parts of hardware, la pinephone and the librem5

Re: Massachusetts health notifications app installed without users’ knowledge

#110
post #96

Earlier quoted context omitted.

The factual basis of your assertion is absolutely true, but your attitude is unhelpful and defeatist. There is a chasm between "a state actor throws an 0day at you" and "Google remotely installs an app on your phone". The latter is done at scale. The former is expensive, risky, and used relatively rarely. If you're organizing a protest movement, it's totally reasonable to factor government 0days into your threat mode…

its not exactly a 0day if the ISP is communicating (through an intermediary) to a card the ISP gave you, that's just normal, unexpensive And this is like, literally a state actor installing an app in this case?

[deleted]
Post reply on HN