Live data from Hacker News

TEMU Is Cleverly Hidden Spyware That Poses an Urgent Security Threat to U.S.

grizzlyreports.com

1–10 of 82 posts

Re: TEMU Is Cleverly Hidden Spyware That Poses an Urgent Security Threat to U.S.

#2
I'm not exactly an Android expert but... android.permission.INSTALL_PACKAGES, getRuntime.exec()... these basically are permissions for remote code execution, are they not?

I think this blogpost is hyperbolic in its discussion and that's a bit unhelpful. But this does look like a serious problem on my first glance. I'd like to see what a real Android-developer thinks about these permissions though.

Re: TEMU Is Cleverly Hidden Spyware That Poses an Urgent Security Threat to U.S.

#3

I'm not exactly an Android expert but... android.permission.INSTALL_PACKAGES, getRuntime.exec()... these basically are permissions for remote code execution, are they not? I think this blogpost is hyperbolic in its discussion and that's a bit unhelpful. But this does look like a serious problem on my first glance. I'd like to see what a real Android-developer thinks about these permissions though.

I did find the table comparing its permissions to others in the space...enlightening.

My kid bought something from Temu recently and it was ridiculously low-priced. I told him the quality must be terrible...and I was wrong. I was kind of shocked and wondered what the "catch" was.

Of course, I hadn't installed the app but wow, now I have the heebie-jeebies just thinking about it.

Re: TEMU Is Cleverly Hidden Spyware That Poses an Urgent Security Threat to U.S.

#7
A bit off topic, but this website has some of the most draconian TOS I've ever seen

> You agree that the information on this website is copyrighted, and you therefore agree not to distribute this information (whether the downloaded _le, copies / images / reproductions, or the link to these _les) in any manner other than by providing the following link: http://GRIZZLYREPORTS.COM

So this HN submission is in violation of their (probably unenforceable) TOS just by virtue of linking to a path other than the root path of the domain.

> If you have obtained research published by Grizzly Research LLC in any manner other than by download from that link, you may not read such research without going to that link and agreeing to the Terms of Use on the Grizzly Research LLC designated website.

Quite ridiculous to expect that you can enforce a directive (don't read this article) on someone who hasn't visited your site and is therefore probably unaware that your TOS even exist.

Re: TEMU Is Cleverly Hidden Spyware That Poses an Urgent Security Threat to U.S.

#9

I'm not exactly an Android expert but... android.permission.INSTALL_PACKAGES, getRuntime.exec()... these basically are permissions for remote code execution, are they not? I think this blogpost is hyperbolic in its discussion and that's a bit unhelpful. But this does look like a serious problem on my first glance. I'd like to see what a real Android-developer thinks about these permissions though.

How did they even get the android.permission.INSTALL_PACKAGES permission approved on the play store?

Google clearly states that:

To use this permission, your app’s core functionality must include:

Sending or receiving app packages, AND Enabling user-initiated installation of app packages. If your app does not meet the requirements for acceptable use below, you must remove it from your app's manifest in order to comply with Google Play policy. Suggestions for policy-compliant alternative implementations are also detailed below.

Which surely doesn’t seem the case for a shopping app?

Re: TEMU Is Cleverly Hidden Spyware That Poses an Urgent Security Threat to U.S.

#10
Interesting. Recently ordered from them for giggles just because the pricing was crazy yet people seem to be getting their stuff. Even mentioned to a friend that something feels very off commercially here - like something is aggressively subsidised.

Also Noticed that they were specifically pushing in app purchases hard with discounts etc.

…but didn’t connect the dots between those two odd things.

Post reply on HN