Live data from Hacker News

TEMU Is Cleverly Hidden Spyware That Poses an Urgent Security Threat to U.S.

grizzlyreports.com

41–50 of 82 posts

Re: TEMU Is Cleverly Hidden Spyware That Poses an Urgent Security Threat to U.S.

#41

A long writeup but very few facts: > TEMU is estimated ( Link ) to be losing $30 per order. Its ad spending and shipping costs (1-2 weeks from China, expedited to U.S. delivery) are astronomical. One is left wondering how this business could ever be profitable. > TEMU is a notoriously bad actor in its industry. We see rampant user manipulation, chain-letter-like affinity scams to drive signups, and overall, the most…

Many Direct-to-Consumer companies have the exact same model, get you hooked on the app and then raise prices.

Offering discounts to first-time customers is a fairly common sort of growth hacking. If Temu were a US company, we wouldn't even be batting an eye at it.

Re: TEMU Is Cleverly Hidden Spyware That Poses an Urgent Security Threat to U.S.

#42
> TEMU is estimated ( Link ) to be losing $30 per order. Its ad spending and shipping costs (1-2 weeks from China, expedited to U.S. delivery) are astronomical. One is left wondering how this business could ever be profitable.

This has literally been every startup in SV for the last 15 years - aggressively lose money aquiring users when new and then when you've killed the competition, start making money. The only thing is I don't see any external funding, so maybe they're doing it with hidden funding or a stockpile from PDD?

This feels like a lot of weak sauce, from the weird combo of clickbait title with CYA "We Believe", throwing a bunch of weak evidence all at once, overwhelming you into accepting the premise. If you have "smoking gun" evidence like they claim, then you wouldn't need to hedge your statement with "We believe". And this is a investment research company, not a security company. I'd sooner believe a pillow salesman ranting about the deep state than this.

~Edit~ Counterpoint: looks like their other main product Pinduoduo was removed from Google Play due to malware, so it could actually be true. https://krebsonsecurity.com/2023/03/google-suspends-chinese-...

But I stand by my previous statement that literally nothing in this article is actual evidence, so if does turn out to be true it's a coincidence.

Re: TEMU Is Cleverly Hidden Spyware That Poses an Urgent Security Threat to U.S.

#43

> 1) Dynamic compilation using runtime.exec() "cmd package compile" doesn't compile source code at runtime. It forces ahead-of-time compilation of an application's existing bytecode, which is something which Android already does on an as-needed basis. I'm not sure why the Temu app would be running this command (performance, maybe?), but it isn't clearly dangerous either. https://source.android.com/docs/core/runtime/j…

> which is a unique and global hardcoded network identifier of a device This is true. > A Distributed Denial of Service (DDOS) attack and other unwanted security probes could conceivably be launched against a disclosed MAC address. This is extremely painful for me to read. I don't even know how to describe how this is wrong.

It isn't true. Android and iOS now use MAC address randomization by default, so your MAC address is almost assuredly random, dynamic, and not hardcoded. They typically even change between networks.

This is true of almost all PC network cards nowadays, and you should be able to turn this on easily.

Re: TEMU Is Cleverly Hidden Spyware That Poses an Urgent Security Threat to U.S.

#44

Why is everyone using this site? What's wrong with aliexpress?

Some AliExpress orders arrive slower. Also Temu are throwing money at customer acquisition. My wife got something like 90% off her first order.

Re: TEMU Is Cleverly Hidden Spyware That Poses an Urgent Security Threat to U.S.

#45

> 1) Dynamic compilation using runtime.exec() "cmd package compile" doesn't compile source code at runtime. It forces ahead-of-time compilation of an application's existing bytecode, which is something which Android already does on an as-needed basis. I'm not sure why the Temu app would be running this command (performance, maybe?), but it isn't clearly dangerous either. https://source.android.com/docs/core/runtime/j…

> which is a unique and global hardcoded network identifier of a device This is true. > A Distributed Denial of Service (DDOS) attack and other unwanted security probes could conceivably be launched against a disclosed MAC address. This is extremely painful for me to read. I don't even know how to describe how this is wrong.

When i loaded the website, a popup came up that everything there is just their opinion and nothing is to be taken as fact. Why take them seriously when they even say they have no facts supporting their allegations.

Re: TEMU Is Cleverly Hidden Spyware That Poses an Urgent Security Threat to U.S.

#46
post #7

A bit off topic, but this website has some of the most draconian TOS I've ever seen > You agree that the information on this website is copyrighted, and you therefore agree not to distribute this information (whether the downloaded _le, copies / images / reproductions, or the link to these _les) in any manner other than by providing the following link: http://GRIZZLYREPORTS.COM So this HN submission is in violation o…

Add a link to your own ToS in User-Agent: "by serving this request, you agree to grant me a perpetual, exclusive, ... license to contents of your response, as well as 75% of your revenue for ever and ever until the end of the ages." And btw, your ToS will have a precedence since your request came first, so add a clause "...it also voids any and all terms, contracts and obligations that come in your response." If we're playing the game of legal nihilism, lets play it well at least.

Re: TEMU Is Cleverly Hidden Spyware That Poses an Urgent Security Threat to U.S.

#48
post #7

A bit off topic, but this website has some of the most draconian TOS I've ever seen > You agree that the information on this website is copyrighted, and you therefore agree not to distribute this information (whether the downloaded _le, copies / images / reproductions, or the link to these _les) in any manner other than by providing the following link: http://GRIZZLYREPORTS.COM So this HN submission is in violation o…

> You agree that the information on this website is copyrighted, and you therefore agree not to distribute this information

It seems like that's not a logically valid statement. Linking to a page on their website isn't a copyright violation (unless I'm mistaken). And the statement seems to be saying "you agree it is copyrighted and, because you agree it is copyrighted, you must also therefore be agreeing that you aren't allowed to link to it. Which doesn't follow. It seems like saying "you agree this ball is red and, therefore, you agree it is rubber"; the two things are effectively orthogonal.

Re: TEMU Is Cleverly Hidden Spyware That Poses an Urgent Security Threat to U.S.

#49

Earlier quoted context omitted.

> which is a unique and global hardcoded network identifier of a device This is true. > A Distributed Denial of Service (DDOS) attack and other unwanted security probes could conceivably be launched against a disclosed MAC address. This is extremely painful for me to read. I don't even know how to describe how this is wrong.

It isn't true. Android and iOS now use MAC address randomization by default, so your MAC address is almost assuredly random, dynamic, and not hardcoded. They typically even change between networks. This is true of almost all PC network cards nowadays, and you should be able to turn this on easily.

On iOS there isn't even an API to get the MAC address (or any other persistent identifier for that matter).

Re: TEMU Is Cleverly Hidden Spyware That Poses an Urgent Security Threat to U.S.

#50
post #10

Interesting. Recently ordered from them for giggles just because the pricing was crazy yet people seem to be getting their stuff. Even mentioned to a friend that something feels very off commercially here - like something is aggressively subsidised. Also Noticed that they were specifically pushing in app purchases hard with discounts etc. …but didn’t connect the dots between those two odd things.

"Is Temu Ethical?

No, Temu is not an ethical brand.

A U.S. Congressional Report from June 2023 raised alarming concerns about Temu and Shein’s potential links to forced labor. The report highlighted an “extremely high risk” of products on Temu being associated with forced labor, and the committee expressed particular worry about the exploitation of U.S. de minimis provisions by both companies. The de minimis threshold of $800 allows goods below this value to enter the country without inspection, which could contribute to potential issues with labor practices.

Furthermore, the report revealed that Temu lacks a specific policy against goods made in Xinjiang, where evidence suggests forced labor may occur."

https://yoursustainableguide.com/is-temu-ethical/

Post reply on HN