Hmm, this thread and the reports of shady practices make me wonder if this will affect the partnership with GrapheneOS[1]. It seems that such things shouldn't really happen on a device where security is a top priority, whether intentional or not. 1: https://news.ycombinator.com/item?id=47214645
I was just wondering that... GrapheneOS team consider Fairphone to be infosec plebs, but instead partner with a company that intentionally harms users' privacy for profit?
Motorola phones have started hijacking the Amazon app to insert affiliate codes
121–130 of 240 posts
Re: Motorola phones have started hijacking the Amazon app to insert affiliate codes
#122Earlier quoted context omitted.
I can understand it's hard to defend against plausibly deniable errors that create backdoors, etc. But this would show a complete lack of code review, no?
Code review just means you need an accomplice. It makes it harder, not impossible.
Humans reading code is so "legacy"...
Re: Motorola phones have started hijacking the Amazon app to insert affiliate codes
#123> In further digging, we noticed that the URL the phone opens up is “kira-abboud.com,” a website that references fashion influencer “@kirasfashionfinds.” Notably, this exact URL isn’t listed anywhere on Abboud’s social media, and the affiliate codes don’t match up either. The redirect coming from Motorola phones is using Amazona affiliate code “sramz-kff-008-20” which is completely different from any of the codes we…
My guess is a rogue employee who hopes they can get away with this stuff for years till caught... That employees cousin probably does social media for Abboud...
Re: Motorola phones have started hijacking the Amazon app to insert affiliate codes
#124Think how bad the market got. Today we have preinstalled garbage apps like LinkedIn, garbage apps mandated to be preinstalled by the government, ads, cloud accounts, notifications spam, telemetry. This is not only Chinese smartphones, for example Samsung also plays this game. I assume there are Chinese backdoors, American backdoors and national government backdoors on almost every phone. And there seems to be no way…
The paranoia is completely warranted, but there is a solution. Just root your Android phone and put a custom ROM like LineageOS etc If you want a stretch goal try and de-Google yourself, I have tried but failed twice now.
We only got in by installing the app on my Sony and him signing into his account. They charge a fee now to get paper tickets from the box office.
Re: Motorola phones have started hijacking the Amazon app to insert affiliate codes
#125Think how bad the market got. Today we have preinstalled garbage apps like LinkedIn, garbage apps mandated to be preinstalled by the government, ads, cloud accounts, notifications spam, telemetry. This is not only Chinese smartphones, for example Samsung also plays this game. I assume there are Chinese backdoors, American backdoors and national government backdoors on almost every phone. And there seems to be no way…
The paranoia is completely warranted, but there is a solution. Just root your Android phone and put a custom ROM like LineageOS etc If you want a stretch goal try and de-Google yourself, I have tried but failed twice now.
Re: Motorola phones have started hijacking the Amazon app to insert affiliate codes
#126Earlier quoted context omitted.
"Seriously, get a Pixel and install..." Ah, the Google tax. They can turn the lock of that door (bootloader) when they choose to do so.
But they haven't yet, and if you refuse to give Google money directly there's always the secondhand market.
Re: Motorola phones have started hijacking the Amazon app to insert affiliate codes
#127Earlier quoted context omitted.
Not sure what timescale you're referring to when you're talking about "how bad the market got" and "today", but back around 2012 I got my first and last Samsung smartphone, must have been a Galaxy 3 or something, that had all of those problematic things too. It seems like this starting to happen as soon as apps were installable on phones, even iPhones came (and still comes) with a ton of apps you cannot remove regard…
You can delete almost all apps on iOS except the obviously core apps that are necessary for it to function.
Re: Motorola phones have started hijacking the Amazon app to insert affiliate codes
#128Earlier quoted context omitted.
In the past I often tend to replace stock Android with LineageOS but in today's world with so many attack vectors like for example malware in supply chains etc. I choose to stay with stock OS. I also have my bank apps and lot of my clients data/credentials stored on my accounts.
How do you imagine that protects you? If anything I'm inclined to trust the LineageOS supply chain more than the OEM on account of being a smaller target, having less bloat, and being 100% open from start to finish. For a particularly sensitive context I'd want to build the ROM myself on an appropriately secured machine running one of the major distros.
I just have no time and knowledge to build ROM myself. 100% open projects also suffer supply chain attacks.
Re: Motorola phones have started hijacking the Amazon app to insert affiliate codes
#129Earlier quoted context omitted.
The paranoia is completely warranted, but there is a solution. Just root your Android phone and put a custom ROM like LineageOS etc If you want a stretch goal try and de-Google yourself, I have tried but failed twice now.
I recently spent twenty minutes sitting outside of an MLB stadium because MLB decided they needed the same level of play protection as a foreign banking app and it refused to work on my friend's LineageOS phone. We only got in by installing the app on my Sony and him signing into his account. They charge a fee now to get paper tickets from the box office.
Re: Motorola phones have started hijacking the Amazon app to insert affiliate codes
#130Earlier quoted context omitted.
The paranoia is completely warranted, but there is a solution. Just root your Android phone and put a custom ROM like LineageOS etc If you want a stretch goal try and de-Google yourself, I have tried but failed twice now.
I recently spent twenty minutes sitting outside of an MLB stadium because MLB decided they needed the same level of play protection as a foreign banking app and it refused to work on my friend's LineageOS phone. We only got in by installing the app on my Sony and him signing into his account. They charge a fee now to get paper tickets from the box office.