Most of the comments on that app as well as here are probably wrong. I'd suspect that everyone who had the app "installed without their permission" opted into the Android COVID-19 Exposure Notification program. This was deployed by Google as part of an update to Google Play Services. When you go to your phone's settings with this update, there's an option to enable COVID-19 Exposure Notifications. When you turn it on…
This is a great explanation for whats occurring. I'll be interested to see what comes of all of this. So far what I guess is: - This is likely a government action via telco and not something done via Google* (*Unless they've opted into a program like the one you stated) - These phones being affected COULD BE all Carrier Locked phones which have specific terms to allow such behavior. To me, this is pretty clear cut vi…
Massachusetts health notifications app installed without users’ knowledge
321–330 of 407 posts
Re: Massachusetts health notifications app installed without users’ knowledge
#322Fellow humans, there are alternatives! Your neck need not be under FAANG's boot! You don't even need to give up any functionality: CalyxOS: https://calyxos.org/ Privacy-respecting Android distribution that replaces Google spyware with MicroG, so you can have your cake and eat it too. Most everything will work as you're used to, but it does still talk to Google to make that happen. GrapheneOS: https://grapheneos.org/…
I've been thinking about getting away from proprietary Google Services and their backdoors, but the one thing that's holding me back is Google Pay (NFC payments). It's way too convenient and I'm unwilling to give it up. Is there an open-source replacement/reimplementation maybe, or something like a way to run the original proprietary app with MicroG? What about other apps that require SafetyNet? (Important note: I'm…
Re: Massachusetts health notifications app installed without users’ knowledge
#323Some have speculated that this may only be happening to people who mistakenly (or purposefully) turned on the COVID-19 Exposure Notifications in the Google Settings. But I confirmed that that setting is turned off on my phone and the app still installed silently on my device anyway.
Re: Massachusetts health notifications app installed without users’ knowledge
#324Most of the comments on that app as well as here are probably wrong. I'd suspect that everyone who had the app "installed without their permission" opted into the Android COVID-19 Exposure Notification program. This was deployed by Google as part of an update to Google Play Services. When you go to your phone's settings with this update, there's an option to enable COVID-19 Exposure Notifications. When you turn it on…
Re: Massachusetts health notifications app installed without users’ knowledge
#325Earlier quoted context omitted.
Would it not be possible to send everyone currently in the state an SMS? I personally would be okay with the government having access to this type of PSA.
I'm not sure I get your point. The notifications are sent when system detects you were in contact with a person that tested positive, so mass messages don't make that much sense. Unless you are referring to using the sms as a marketing way to encourage people to install the application...
Re: Massachusetts health notifications app installed without users’ knowledge
#326I was reading about this yesterday and confirmed that I did not have gov.ma.covid19.exposurenotifications.v3 nor gov.ma.covid19.exposurenotifications installed. I turned off auto-updates in the Play store (Settings -> Network preferences -> Auto update apps -> Don't auto update apps) and went to sleep. This morning I woke up with a cheerful notification that Google can help with COVID notifications and gov.ma.covid19…
You can understand it with an OS update. It's the new shiny thing that comes with bunch of stuff and this new one has this new app.
However, getting it without action on our own part feels very wrong. Even with games, you would receive a pack or something that you can take action to activate. When it's happening without our action, it messes up with our sense of control and continuity.
Re: Massachusetts health notifications app installed without users’ knowledge
#327I was reading about this yesterday and confirmed that I did not have gov.ma.covid19.exposurenotifications.v3 nor gov.ma.covid19.exposurenotifications installed. I turned off auto-updates in the Play store (Settings -> Network preferences -> Auto update apps -> Don't auto update apps) and went to sleep. This morning I woke up with a cheerful notification that Google can help with COVID notifications and gov.ma.covid19…
It's pure madness that Play Services comes with this sort of backdoor. This is clearly what I would consider a deliberate RCE vulnerability.
Re: Massachusetts health notifications app installed without users’ knowledge
#328Hi [my name],
In order for MassNotify to be available to users in their phone’s settings, an update was made by Google that resulted in some users seeing MassNotify appear in their app list in the Google Play Store. Apologies if this caused any confusion.
The appearance of MassNotify in the app list does not mean that MassNotify is enabled on your phone. The presence of the app merely means that MassNotify has been made available as an option in your phone's settings if you wish to enable it. For more information about this, please see this help center article from Google: https://support.google.com/android/answer/10775533
You can see whether MassNotify is active by going to Settings -> Google -> COVID-19 Exposure Notifications. The “Use Exposure Notifications” toggle at the top of the page will show you whether MassNotify is active or not. From this screen, you can also enable or disable MassNotify at any time.
If you have any further questions about this, or anything else related to MassNotify, please don’t hesitate to reach out and we’ll be happy to help.
Regards,
[name]
MassNotify Help Desk Team
www.mass.gov/massnotify
For information about MA COVID-19 resources visit www.mass.gov/isolate
Re: Massachusetts health notifications app installed without users’ knowledge
#329Earlier quoted context omitted.
My guess is that it's the Play Store app itself that does this (con.android.vending). That app is responsible for both updating itself regularly and installing/updating other apps. One possible way: There is a daily job run in the Play Store called "daily hygiene" that performs various configured tasks based on device state and device targeting. It would not be difficult to add some code to install this app for MA us…
They don't have to add any code or push a Play Store update or wait for a daily cronjob. Listening for remote installation requests is a core feature of Google Play Services. It is not a mystery how this was done.
Re: Massachusetts health notifications app installed without users’ knowledge
#330Earlier quoted context omitted.
That doesn't fix the issue ISPs mandate certain capabilities of the cellular modem + the simcards (remember java cards? that ran java? they still exist as simcards!) Government RCE is still 100% on the table regardless of whatever software your phone is running
It's hard to get good info on what capabilities it does have. Here's what I've gathered though I'd like to learn more: Modems are often isolated by being connected via USB, or if on your SoC the modem has DMA then it's isolated via IOMMU groups. SIM cards have to implement the E911 feature which allows 911 operators to toggle a cell phone into "stay online no matter what" mode. Some SIM cards have additional apps ins…
1) http://ramtin-amin.fr/#nvmepcie, http://ramtin-amin.fr/#nvmedma (the two articles are separate but the first provides incidental context for the second) the iPhone 6 kinda maybe sorta didn't dot the Is and cross the Ts with the MMU side of things. So, USB is awesome in that the failure state is "probably can't RCE".
2) I read a comment on here, which I should be able to re-find, but hn.algolia is not cooperating, suggesting that the system design of a particular AGPS implementation (a few years ago) interposed the GPS in between the CPU and the cellular radio such that the GPS SoC could do HTTP requests to grab its almanac that all of Android, down to the kernel, had no idea about.
IMHO this level of security paranoia is at the end of the day a micro-optimization. For any given device, you're looking at maybe two or three dozen Things Containing ALUs™ (often buried inside subcomponents buried inside other things); one or two concentrations of several billion transistors; and an unknown proportion of manglement, incompetence, cost-cutting, internal compromise (because guarantee there's none), and Agreements™. Honestly: give up, and declare that whatever makes you feel better is enough.