Live data from Hacker News

Massachusetts health notifications app installed without users’ knowledge

play.google.com

301–310 of 407 posts

Re: Massachusetts health notifications app installed without users’ knowledge

#301
post #197

Most of the comments on that app as well as here are probably wrong. I'd suspect that everyone who had the app "installed without their permission" opted into the Android COVID-19 Exposure Notification program. This was deployed by Google as part of an update to Google Play Services. When you go to your phone's settings with this update, there's an option to enable COVID-19 Exposure Notifications. When you turn it on…

I don't know what kind of proof you want, but I just looked at my phone settings after reading your comment. The exposure notification option is there and it's off. The region selection is grayed out because of it. Yet I got the app (uninstalled it after I saw this on hacker news). I did get a notification when it got installed but I thought it was just a push similar to amber alerts. I didn't realize it installed so…

Same here. Never opted in, just checked and that hasn't changed. I hadn't even selected a region, so it shouldn't even know which invasive app to install, but I still got it.

Re: Massachusetts health notifications app installed without users’ knowledge

#302
post #37

I think the real question is what mechanism allows them to push a random app to some phones? google play services is actively listening for remote installation requests? that's essentially a remote-code-execution backdoor to all android phones?

I thought this was well-known, Android is not private at all until you degoogle. Unlock your bootloader then install a ROM without Google Play Services such as GrapheneOS, CalyxOS or LineageOS. You can consider installing microG also as an open-source minimal implementation of Google Play Services if some of it's functionality is absolutely necessary for you to keep.

A core issue is that building Android ROMs is very difficult to do so in a simple and accessible manner. The build systems generally all require enterprise server level of memory and a build can easily take hours. Every device has a unique configuration, imagine if every brand of laptop ran their own variant of Ubuntu. For most "ROMs" that you find on obscure places like XDA, the builds by random people across the globe are a much greater security risk than good first-party updates.

Re: Massachusetts health notifications app installed without users’ knowledge

#303

Most of the comments on that app as well as here are probably wrong. I'd suspect that everyone who had the app "installed without their permission" opted into the Android COVID-19 Exposure Notification program. This was deployed by Google as part of an update to Google Play Services. When you go to your phone's settings with this update, there's an option to enable COVID-19 Exposure Notifications. When you turn it on…

You can be concerned by reading the top comment on this HN thread.

Re: Massachusetts health notifications app installed without users’ knowledge

#304

Fellow humans, there are alternatives! Your neck need not be under FAANG's boot! You don't even need to give up any functionality: CalyxOS: https://calyxos.org/ Privacy-respecting Android distribution that replaces Google spyware with MicroG, so you can have your cake and eat it too. Most everything will work as you're used to, but it does still talk to Google to make that happen. GrapheneOS: https://grapheneos.org/…

Even with Graphene OS you’re still using a phone that has a proprietary modem which has its own hidden CPU that acts like a black box. Who knows what it does or if it can read main memory.

Don't let perfect be the enemy of good and always evaluate solutions against your threat model.

Re: Massachusetts health notifications app installed without users’ knowledge

#305
post #104

Earlier quoted context omitted.

Read up on how the contact tracing apps work. They do not upload your data to the cloud. Phones broadcast a rolling random identifier, other phones collect received identifiers, and only on confirmed infection does the person's phone upload its last two weeks of broadcast IDs to the cloud, where other phones can grab them and cross-check. Having someone's phone number allows you (via the phone company) to trace their…

Just because protocol is theoretically safe does not imply it is safe in actual practice or that it is not possible to exploit it.

Even if it is perfectly safe with no potential for abuse, I deserve to make the decision to opt-in, not have it silently downloaded and installed. If the government thinks I am too stupid to understand how safe it is or that I should just trust them more, that is totally on them. They either need to communicate well or fix the trust issues.

Re: Massachusetts health notifications app installed without users’ knowledge

#306
post #261

I was reading about this yesterday and confirmed that I did not have gov.ma.covid19.exposurenotifications.v3 nor gov.ma.covid19.exposurenotifications installed. I turned off auto-updates in the Play store (Settings -> Network preferences -> Auto update apps -> Don't auto update apps) and went to sleep. This morning I woke up with a cheerful notification that Google can help with COVID notifications and gov.ma.covid19…

It's pure madness that Play Services comes with this sort of backdoor. This is clearly what I would consider a deliberate RCE vulnerability.

Re: Massachusetts health notifications app installed without users’ knowledge

#307
post #84
post #79

Earlier quoted context omitted.

> In this case it seems that the same goal could have been better achieved by SMS that do not depend on the brand of your phone. The dependency on proprietary app stores and OSs seems a risk for the continuation of a free and reliable communications. While installing an app without users consent can be as questionable as you want, the point about these apps are not the notifications itself but about the contact traci…

This sounds worse to me? Rather than violation of a relatively small privacy (phone number), you instead get timestamp social graph interactions in the physical world. This seems like fat more extreme an invasion than the former.

[deleted]

Re: Massachusetts health notifications app installed without users’ knowledge

#308

Fellow humans, there are alternatives! Your neck need not be under FAANG's boot! You don't even need to give up any functionality: CalyxOS: https://calyxos.org/ Privacy-respecting Android distribution that replaces Google spyware with MicroG, so you can have your cake and eat it too. Most everything will work as you're used to, but it does still talk to Google to make that happen. GrapheneOS: https://grapheneos.org/…

I've been thinking about getting away from proprietary Google Services and their backdoors, but the one thing that's holding me back is Google Pay (NFC payments). It's way too convenient and I'm unwilling to give it up. Is there an open-source replacement/reimplementation maybe, or something like a way to run the original proprietary app with MicroG? What about other apps that require SafetyNet?

(Important note: I'm not from US)

(Google's data collection isn't much of a concern for me anyway because I block all ads and analytics — so even if they do collect something, they have no way of showing me ads)

Re: Massachusetts health notifications app installed without users’ knowledge

#309
post #263

Earlier quoted context omitted.

If you think legislation is the answer, I’ve got a bridge to sell you. Who do you think writes the legislation and hands it to X representative? How niave... HN crowd has fallen pretty far. Used to be WE build the things that make our lives better and now the top comment is calling for some ethemeral they to come up with legislation? That’s BS. And, antithetical to any builder/havker ethic. We build the world we want…

This defeatist attitude toward legislating is self-perpetuating. We can at least hold our representatives accountable.

> This defeatist attitude toward legislating is self-perpetuating. We can at least hold our representatives accountable.

What can we do? I have no confidence that Congress will act in my best interest. Congress has some "partisan deadlock" but somehow I feel confident Intel's payday will go through without a bumpy ride

> U.S. senators propose 25% tax credit for semiconductor manufacturing (reuters.com)

https://news.ycombinator.com/item?id=27561238

We can't even get a modest broadband Internet infrastructure bill passed.

> Widespread fiber-to-the-home deployment would make a bigger difference for more Internet users than Starlink. President Joe Biden pledged to lower prices and deploy "future-proof" broadband to all Americans, but he's already scaled back his plan in the face of opposition from Republicans and incumbent ISPs. AT&T has been lobbying against nationwide fiber and funding for municipal networks, and AT&T CEO John Stankey expressed confidence last week that Congress will steer legislation in the direction that AT&T favors.

https://arstechnica.com/information-technology/2021/06/starl...

> Biden's pitch to build "future-proof" broadband technology is also facing opposition from broadband providers who don't want to build fiber-to-the-home networks in rural areas. Just before Biden announced his plan, AT&T said it opposes subsidizing fiber-to-the-home deployment across the US, arguing that rural people don't need fiber and should be satisfied with Internet service that provides only 10Mbps upload speeds.

https://arstechnica.com/tech-policy/2021/05/biden-cuts-35b-f...

I have not met a single programmer / computer scientist who seriously defends the CFAA and yet we cannot find the votes in Congress to repeal it.

Re: Massachusetts health notifications app installed without users’ knowledge

#310
post #132
post #37

I think the real question is what mechanism allows them to push a random app to some phones? google play services is actively listening for remote installation requests? that's essentially a remote-code-execution backdoor to all android phones?

>google play services is actively listening for remote installation requests? Uh, yes? That is and always has been core functionality. You can click "install" on the Google Play website on your laptop and the app will magically appear on your phone, if both devices are signed in to Google. I triggered this behavior accidentally a good 10 years ago when I got my first Android phone, and it gave me the shivers - it rea…

That's not the behaviour of what happened here, where an app was downloaded without user initiation or intervention. There was no authorization from the user of the actions that were taken by Google or the app's vendor.
Post reply on HN