Live data from Hacker News

Massachusetts health notifications app installed without users’ knowledge

play.google.com

131–140 of 407 posts

Re: Massachusetts health notifications app installed without users’ knowledge

#131
post #37

I think the real question is what mechanism allows them to push a random app to some phones? google play services is actively listening for remote installation requests? that's essentially a remote-code-execution backdoor to all android phones?

No different than, say, "Windows Update". The entire "updates" culture is essentially RCE backdoor (botnet) functionality for "trusted" tech companies. Consent, where it is actually explicitly obtained, never rises to the level of "informed". That's because even if a user "consents", she still cannot see what is in each update.

WU allows hardware manufacturers to silently install literally anything based on hardware ID matching and the only way to prevent that is to disable WU driver updates entirely (via GPC/registry).

In my case the maker of my motherboard installed a persistent “self-repairing” (i.e. difficult to uninstall) from yet another third party. Naturally, I will not buy a product from them (MSI) again.

Another way to put this is: windows update will install malware w/o user approval in the background.

Re: Massachusetts health notifications app installed without users’ knowledge

#132
post #37

I think the real question is what mechanism allows them to push a random app to some phones? google play services is actively listening for remote installation requests? that's essentially a remote-code-execution backdoor to all android phones?

>google play services is actively listening for remote installation requests?

Uh, yes? That is and always has been core functionality. You can click "install" on the Google Play website on your laptop and the app will magically appear on your phone, if both devices are signed in to Google. I triggered this behavior accidentally a good 10 years ago when I got my first Android phone, and it gave me the shivers - it really drove home the point that Google had root on my phone, not me.

In fact, this entire behavior is so normalized on phones we now have a special word for the process of downloading an app and installing it manually, the way we do on PCs: "sideloading".

Re: Massachusetts health notifications app installed without users’ knowledge

#133

Earlier quoted context omitted.

> It is obvious that we need better legislation to deal with all the new possibilities that technologies have opened. How about applying common sense?

Common sense is not so common.

“Common sense is the best distributed commodity in the world, for every man is convinced that he is well supplied with it.”

― René Descartes, Discourse on Method

Re: Massachusetts health notifications app installed without users’ knowledge

#134
post #118

It is obvious that we need better legislation to deal with all the new possibilities that technologies have opened. The installation of this app, even done with good intent, open a lot of questions on what should be possible or not to be done by government and corporations. When you get a device with pre-installed, uninstallable, or auto-installed apps. What are the rules? > "By enabling this service, you can be quic…

> instead of the silent install the government could have spend money in advertisement campaigns This absolutely does not work. Here, the NL gov tried this and almost nobody installed the app, despite it using the privacy-safe google/apple API.

[deleted]

Re: Massachusetts health notifications app installed without users’ knowledge

#135
post #37

I think the real question is what mechanism allows them to push a random app to some phones? google play services is actively listening for remote installation requests? that's essentially a remote-code-execution backdoor to all android phones?

No different than, say, "Windows Update". The entire "updates" culture is essentially RCE backdoor (botnet) functionality for "trusted" tech companies. Consent, where it is actually explicitly obtained, never rises to the level of "informed". That's because even if a user "consents", she still cannot see what is in each update.

I think the difference is that I chose to install Chrome/Firefox etc, so I don't mind the automatic updates.

In this case nobody actually installed this app by choice!

Re: Massachusetts health notifications app installed without users’ knowledge

#136
post #43

Earlier quoted context omitted.

... you trust Google ?

Everyone trusts Google, whether they like it or not. This is the definition of trust that security operations use: A trusts B if B is capable of doing something nasty to A. Google has a heck-load of money. They could pay a disreputable aggregate company to deliver a load of tonne-bags of gravel to my front garden, blocking my car in, and generally destroying the landscaping. I trust them not to do this, and the reaso…

In this case you also probably trust the legal system to let you sue Google when they do this.

Re: Massachusetts health notifications app installed without users’ knowledge

#137
post #130

Earlier quoted context omitted.

"Arbitrary" is doing a lot of sneaky work here. You're implying that the law would somehow allow Google to manipulate investigators. But the law has broad allowances and exceptions in lots of areas, and competing permissions/denials that together weave specific allowances. There's little reason to think that the law couldn't allow app installation in general and also disallow either targeting of individuals or collec…

Another question worth asking is "what is the governing law?" It is almost certainly contract law via Google's ToS. Government phones probably have different ToS, but government employee' personal phones have the same ToS we have. If Google is asserting non-contractual rights, I'd like to know what they are. Edit: I edited this comment because it was rude, and that was not my intent.

[Edit: the comment originally said their question wasn't implying anything] Of course you're implying something. If nothing else, you're implying the one might imply the other, and that the implication is worth attention.

The governing law that would protect people is a lot of things, and ToS is the least of it. The Wiretap Act applies, for example.

Re: Massachusetts health notifications app installed without users’ knowledge

#138
post #87

This is very inconsiderate. For example, depending on your cell phone plan, data transfer may incur high costs, especially when roaming etc. Therefore, owners of cell phones may be interested in limiting it to the absolute minimum. As I see it, this consideration by itself already should have prevented this automatic installation.

Automatic app installation and updates will only trigger when charging, not in active use for >90 minutes, and on a wifi network that's not set as metered

[deleted]

Re: Massachusetts health notifications app installed without users’ knowledge

#139
post #79

Earlier quoted context omitted.

> In this case it seems that the same goal could have been better achieved by SMS that do not depend on the brand of your phone. The dependency on proprietary app stores and OSs seems a risk for the continuation of a free and reliable communications. While installing an app without users consent can be as questionable as you want, the point about these apps are not the notifications itself but about the contact traci…

Would it not be possible to send everyone currently in the state an SMS? I personally would be okay with the government having access to this type of PSA.

I'm not sure I get your point. The notifications are sent when system detects you were in contact with a person that tested positive, so mass messages don't make that much sense. Unless you are referring to using the sms as a marketing way to encourage people to install the application...

Re: Massachusetts health notifications app installed without users’ knowledge

#140
Most of the comments on that app as well as here are probably wrong. I'd suspect that everyone who had the app "installed without their permission" opted into the Android COVID-19 Exposure Notification program. This was deployed by Google as part of an update to Google Play Services.

When you go to your phone's settings with this update, there's an option to enable COVID-19 Exposure Notifications. When you turn it on, it prompts you for your location and will download your region's app that uses your phone's new capabilities to connect to the appropriate health authorities.

Massachusetts just opted into this program in the last couple of weeks. I'm honestly not sure why they did it so late - this would have been helpful earlier. Apple iPhones also have this capability, including interoperability with Android phones, and iPhone users in Massachusetts are also able to turn on this setting.

Now, if someone can actually prove that they didn't opt into the COVID-19 Exposure Notifications, then I'd be concerned. But my guess is they opted in when it came out, but there was no app for their region, so nothing was downloaded and the feature did nothing. Then, Massachusetts rolled out the app now and lots of people who configured their phones earlier in the pandemic got a new app. They granted permission for it, perhaps months ago.

Post reply on HN