Live data from Hacker News

Massachusetts health notifications app installed without users’ knowledge

play.google.com

211–220 of 407 posts

Re: Massachusetts health notifications app installed without users’ knowledge

#211
Interesting. I started getting the COVID exposure opt-in message a few days ago. I've declined both times it's popped up (it's already too late to be contact tracing, no need). This app is already installed on my phone apparently despite declining to opt-in.

Re: Massachusetts health notifications app installed without users’ knowledge

#212
post #192

Most of the comments on that app as well as here are probably wrong. I'd suspect that everyone who had the app "installed without their permission" opted into the Android COVID-19 Exposure Notification program. This was deployed by Google as part of an update to Google Play Services. When you go to your phone's settings with this update, there's an option to enable COVID-19 Exposure Notifications. When you turn it on…

There's even a standard for mobile operators to control the setting in your modem and update/install apps: https://en.wikipedia.org/wiki/OMA_Device_Management I reverse engineered what this does in practice on pinephone modem (Quectel EG25G), for example, and there are pre-compiled binaries there for tmobile and vodafone that process their particular OMA DM flavors, download some configuration and code from internet…

Can one use pinephones to collect these blobs, and then try to run them on Android simulator or whatever for more specific knowledge about operators' practices?

Re: Massachusetts health notifications app installed without users’ knowledge

#214

Most of the comments on that app as well as here are probably wrong. I'd suspect that everyone who had the app "installed without their permission" opted into the Android COVID-19 Exposure Notification program. This was deployed by Google as part of an update to Google Play Services. When you go to your phone's settings with this update, there's an option to enable COVID-19 Exposure Notifications. When you turn it on…

I have no memory of opting in to this, but it was installed on my phone. Updated to add: well I'll be, an hour after this comment and seeing the link show me that Mass Notification was installed, I was prompted to opt-in appropos of nothing.

If it makes you feel better (or worse) I specifically opted out and this app is installed

Re: Massachusetts health notifications app installed without users’ knowledge

#216
post #94

Earlier quoted context omitted.

Yes, but RCE is typically shorthand for “RCE by someone other than the owner of the device”

When I buy a phone, I'd like to think that I am the owner. I haven't rented it from the vendor or something.

That’s exactly what the vendor who owns it wants you to think…

Re: Massachusetts health notifications app installed without users’ knowledge

#217

Interesting. I started getting the COVID exposure opt-in message a few days ago. I've declined both times it's popped up (it's already too late to be contact tracing, no need). This app is already installed on my phone apparently despite declining to opt-in.

I don't think it will happen or that we particularly need to do it, but at this point, contact tracing (I'm talking about in the US) would be cheap and effective.

Especially if it traced back to likely exposure events.

Re: Massachusetts health notifications app installed without users’ knowledge

#219

From what I've read (I don't live in Massachusetts), the app is installed via the auto update channel, but it explicitly asks permission to activate. If you think this is bad, the commercial apps that have been auto-installing for years, without notifying the user , should have you throwing a conniption.

I live in MA, i had no prompt asking me to activate this at all. it was silently installed without any notice. this isn't an auto update, this was an unsolicited app install.

Same here.

Re: Massachusetts health notifications app installed without users’ knowledge

#220
post #43

Earlier quoted context omitted.

... you trust Google ?

Everyone trusts Google, whether they like it or not. This is the definition of trust that security operations use: A trusts B if B is capable of doing something nasty to A. Google has a heck-load of money. They could pay a disreputable aggregate company to deliver a load of tonne-bags of gravel to my front garden, blocking my car in, and generally destroying the landscaping. I trust them not to do this, and the reaso…

This is a bad example.

Putin or Kim Jong Il or Brad Pitt could also pay to get gravel delivered to your address. You have not taken any specific 100% effective steps to prevent them, any more than you’ve done with Google, right?

Post reply on HN