Live data from Hacker News

I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

404media.co

71–80 of 132 posts

Re: I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

#71
post #47

Earlier quoted context omitted.

Integrating everything into USB has been great at physical simplification, but it really opened up the attack surface. First party malware is the worst.

From the photos, this looks like a Lightning cable, not a USB cable.

They're referring to the USB protocol, which lightning uses.

Re: I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

#72
post #14

So from my reading, the shitty behaviour is from the app, not the cable. Have I misread it? What happens if you try to use the cable without downloading the app? I for one would assume that my cable was defective, if it needed an app to work. I realize that HDMI cables are weird, and that like quite a lot of modern interconnect are not a monolithic standard, but come with multiple support levels; I wish that would st…

The adapter flashes a QR code on your monitor. It's not plug-n-play.

I think I've come across this specific screen. In my case, this was its equivalent of "No Signal" screen, and the app was only needed to update the firmware if needed, not to connect. It seemed to exploit AirPlay somehow and therefore finicky unlike official dongles.

Re: I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

#73

I have an impression that covid enabled widespread acceptation of QR codes, and now every app is excused to request camera and photo access because "we need to scan a QR code".

I don't know for iOS but on Android they are not excused, just register intent for your url and let the system camera app/qr code scanner pass it.

Effectively you can expect it to work for Android 8+ as the previous versions don't necessarily have a QR code scanner.

Re: I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

#74
post #53

Earlier quoted context omitted.

Requiring the use of an app, in order to use some kind of adapter cable? I must be getting old, feel like I've just crawled from under a rock... :-) That would also mean this cable becomes useless the moment URL encoded in the QR disappears? As for the app: even if it's total crap, if only 50% of cable-buyers proceed to install the app, that 50% is still gained as potentially spied-upon subjects. There's a new please…

It's not really an adapter cable. It's got a little SOC in there that streams your iPhone's display from the app to the HDMI port. Meanwhile, your personal data is being streamed back to China...

The official Apple HDMI adapter does the same thing with an SoC in there. The difference is native iOS support instead of a 3rd party app needed to support it.

Re: I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

#75
post #7

The saluspa from "bestway" demands your location before allowing you to setup wifi remote control of the portable hot tub on the android app. I wonder how on android I can spoof the location used by an app, or if anyone figured out if you can control it without the app. I set it up away from my house and use a separate wifi network but it pissed me off.

I tried to use Fanduel last night to place some bets for my friend in prison. It requires your location. You have to install some horrible app that installs a Windows Service and has no UI. It still won't work. After a lot of digging around, I discovered you cannot use Fanduel if you have a wired device. The app _requires_ you to connect to your router by Wifi or it will not work. WTF.

Maybe it's for compliance reasons? in other words they really want to know you're in a jurisdiction that allows gambling, and not using a VPN or whatever.

Re: I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

#76
post #70

Earlier quoted context omitted.

Before Android required that permission, there were marketing companies selling malls the ability to see who was around by the ID of their Bluetooth beacon.

But pairing work well without the app involved, we could just give a permission to a specific already-paired devices and keep location for apps that actually need to scan.

Again - That still sends out a beacon. Searching for already-paired bluetooth devices still sends a bluetooth frame with your bluetooth MAC address, (which has to be consistent, because that's how bluetooth devices identify each other).

Re: I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

#77
post #15

Given that the device is plugged in, trusted, shows up as a computer, and requires external power, it has all the connections it needs spy on the screen (at minimum) and remote control the victim iPhone without permission in the worst case. (it has video feed, and can emulate USB keyboard and mouse) Yikes!

Integrating everything into USB has been great at physical simplification, but it really opened up the attack surface. First party malware is the worst.

Can't wait for the consumer keyboard that saves everything that was typed to it and/or executes things on its own

Re: I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

#78

I say the big 404 and instinctively bounced. I can’t be the only one. I went back to find their 404 page and am quite satisfied with what I found: https://www.404media.co/i-te/

I’ve seen a few 404 Media articles on here as of late and I’ve been pleasantly surprised by the high quality of the content.

Re: I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

#79
post #63
post #55

Earlier quoted context omitted.

That’s intended for selecting a pre-taken photo without giving an app library access. You’d have to get the user to take the picture then come back to your app. What you really need is a system dialogue that pops up the camera and only returns the QR code to the app, the way the photo picker can see the whole library but only gives the app the one selected photo.

Pretty sure Android has this. You can make an app without camera permissions, send an intent that opens the built-in camera to take a picture and you are given access to only that picture. It means you cannot record things in the background all the time, and users don't need to make a decision about a sensitive permission.

iOS may have that as well. I think it’s part of that same photo picker interface.

But that’s not what I was imagining. I was thinking of something in the system that did the QR code scanning for you so that you could just point the camera and as soon as it recognized one the app would get the data. That way the user doesn’t have to frame it and take the picture and select that it’s OK to use in the app.

That’s how adding HomeKit devices work. You hit the add device button in the Home app and a view of the camera comes up. The instant it sees one of the HomeKit QR codes it goes away and starts doing its thing. It’s a great user experience.

But third parties can’t do that without requesting camera access first to get access to the live camera view. A system library could provide it.

Re: I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

#80
post #53

Earlier quoted context omitted.

It's not really an adapter cable. It's got a little SOC in there that streams your iPhone's display from the app to the HDMI port. Meanwhile, your personal data is being streamed back to China...

The official Apple HDMI adapter does the same thing with an SoC in there. The difference is native iOS support instead of a 3rd party app needed to support it.

I still find it hilarious that that’s how the old cable worked, the iPhone encoded an H.264 video stream and sent it to the dongle, which decoded it and sent it down HDMI.

Now that iPhones have USB-C they no longer need a custom adapter. A standard USB-C to HDMI cable is supposed to work. I believe.

Post reply on HN