Live data from Hacker News

TEMU Is Cleverly Hidden Spyware That Poses an Urgent Security Threat to U.S.

grizzlyreports.com

11–20 of 82 posts

Re: TEMU Is Cleverly Hidden Spyware That Poses an Urgent Security Threat to U.S.

#11
A long writeup but very few facts:

> TEMU is estimated ( Link ) to be losing $30 per order. Its ad spending and shipping costs (1-2 weeks from China, expedited to U.S. delivery) are astronomical. One is left wondering how this business could ever be profitable.

> TEMU is a notoriously bad actor in its industry. We see rampant user manipulation, chain-letter-like affinity scams to drive signups, and overall, the most aggressive and questionable techniques to manipulate large numbers of people to install the app.

> TEMU is demonstrably more dangerous than TikTok. The app should be removed from the Google and Apple app stores.

Grizzly Reports (https://twitter.com/ResearchGrizzly) is "focused on producing differentiated research insights on publicly traded companies through in-depth due diligence."

This seems like low quality junk to me.

Re: TEMU Is Cleverly Hidden Spyware That Poses an Urgent Security Threat to U.S.

#12

I'm not exactly an Android expert but... android.permission.INSTALL_PACKAGES, getRuntime.exec()... these basically are permissions for remote code execution, are they not? I think this blogpost is hyperbolic in its discussion and that's a bit unhelpful. But this does look like a serious problem on my first glance. I'd like to see what a real Android-developer thinks about these permissions though.

I did find the table comparing its permissions to others in the space...enlightening. My kid bought something from Temu recently and it was ridiculously low-priced. I told him the quality must be terrible...and I was wrong. I was kind of shocked and wondered what the "catch" was. Of course, I hadn't installed the app but wow, now I have the heebie-jeebies just thinking about it.

It's likely cheap because it's made with forced labor: https://apnews.com/article/temu-shein-forced-labor-china-de7...

Re: TEMU Is Cleverly Hidden Spyware That Poses an Urgent Security Threat to U.S.

#13

I'm not exactly an Android expert but... android.permission.INSTALL_PACKAGES, getRuntime.exec()... these basically are permissions for remote code execution, are they not? I think this blogpost is hyperbolic in its discussion and that's a bit unhelpful. But this does look like a serious problem on my first glance. I'd like to see what a real Android-developer thinks about these permissions though.

It’s likely they use runtime exec because they are doing in app sideloading of features so they don’t need to wait for App Store approval. TEMU feels kinda like a superapp like wechat.

I think TEMU is a super shady company but I don’t think the app is the vector to worry about.

Re: TEMU Is Cleverly Hidden Spyware That Poses an Urgent Security Threat to U.S.

#15
post #7

A bit off topic, but this website has some of the most draconian TOS I've ever seen > You agree that the information on this website is copyrighted, and you therefore agree not to distribute this information (whether the downloaded _le, copies / images / reproductions, or the link to these _les) in any manner other than by providing the following link: http://GRIZZLYREPORTS.COM So this HN submission is in violation o…

And also the button for not accepting it does nothing lol

Re: TEMU Is Cleverly Hidden Spyware That Poses an Urgent Security Threat to U.S.

#16

Is it me or is this an over the top not very trust worthy article designed to move the stock market?

It's a market research firm, probably also a hedge fund that takes a short position specifically before posting these articles to make money on a short position. (See also Muddy Waters (https://www.muddywatersresearch.com/).

So yes, it's designed to move the stock market. That doesn't mean it's wrong, though.

Re: TEMU Is Cleverly Hidden Spyware That Poses an Urgent Security Threat to U.S.

#17

A long writeup but very few facts: > TEMU is estimated ( Link ) to be losing $30 per order. Its ad spending and shipping costs (1-2 weeks from China, expedited to U.S. delivery) are astronomical. One is left wondering how this business could ever be profitable. > TEMU is a notoriously bad actor in its industry. We see rampant user manipulation, chain-letter-like affinity scams to drive signups, and overall, the most…

> aggressive and questionable techniques to manipulate large numbers of people to install the app.

So basically like facebook?

Re: TEMU Is Cleverly Hidden Spyware That Poses an Urgent Security Threat to U.S.

#18

Earlier quoted context omitted.

I did find the table comparing its permissions to others in the space...enlightening. My kid bought something from Temu recently and it was ridiculously low-priced. I told him the quality must be terrible...and I was wrong. I was kind of shocked and wondered what the "catch" was. Of course, I hadn't installed the app but wow, now I have the heebie-jeebies just thinking about it.

It's likely cheap because it's made with forced labor: https://apnews.com/article/temu-shein-forced-labor-china-de7...

Ugh.

Re: TEMU Is Cleverly Hidden Spyware That Poses an Urgent Security Threat to U.S.

#19
Surprisingly, for almost all the things that I've bothered to compare, Amazon is actually cheaper than Temu. Even cheap toys from China that I thought would be Temu's bread and butter. And of course the shipping is no contest. The deals look good in their app but try searching for the same item on Amazon and I bet you will be surprised.

Temu sometimes gives you more flexibility to order a single copy of small items while Amazon might only have bundles. But then Temu has a minimum order size you must meet while Amazon doesn't. So I haven't found any reason to use Temu after their ridiculous free money coupon for new users is gone.

Re: TEMU Is Cleverly Hidden Spyware That Poses an Urgent Security Threat to U.S.

#20

I'm not exactly an Android expert but... android.permission.INSTALL_PACKAGES, getRuntime.exec()... these basically are permissions for remote code execution, are they not? I think this blogpost is hyperbolic in its discussion and that's a bit unhelpful. But this does look like a serious problem on my first glance. I'd like to see what a real Android-developer thinks about these permissions though.

I did find the table comparing its permissions to others in the space...enlightening. My kid bought something from Temu recently and it was ridiculously low-priced. I told him the quality must be terrible...and I was wrong. I was kind of shocked and wondered what the "catch" was. Of course, I hadn't installed the app but wow, now I have the heebie-jeebies just thinking about it.

You could send a postcard here with your thanks for the great deal:

    General Office of the Central Committee of the Chinese Communist Party
    West Building
    Zhongnanhai
    Beijing
    People's Republic of China
Post reply on HN