Live data from Hacker News

OnePlus Is Again Sending User Data to a Chinese Company Without User Consent

twitter.com

11–20 of 47 posts

Re: OnePlus Is Again Sending User Data to a Chinese Company Without User Consent

#11
post #8
post #6

Earlier quoted context omitted.

Don't worry, the GDPR is coming. Now you're going to war with the Royal Navy in a nuclear armed ruber dinghy 4% revenue per timeframe in which privacy rights were violated, or 20 million. EUR, whichever is larger, is absolutely nothing to ignore anymore.

If you're in the UK. Some of us Yanks aren't too happy with the state of things either, and don't have people looking out for us. /rant

*EU, the UK won't be part of the GDPR for long enough that it'd have relevant effects.

Re: OnePlus Is Again Sending User Data to a Chinese Company Without User Consent

#12

And what penalty will the company suffer? Virtually none.

Wirecutter removed them as a recommendation. Others will probably as well. This should affect sales somewhat and since smart phone margins are so slim it could have a drastic affect.

Re: OnePlus Is Again Sending User Data to a Chinese Company Without User Consent

#13
post #6

Any fight for privacy in the modern technology environment is such an extreme case of power asymmetry that I'm starting to think it's hopeless. On the one side you have individuals that don't want their private information to be revealed without their consent. On the other are device manufacturers, advertisers, startups, and giants like Google and Facebook. Often, maintaining privacy while viewing a single website re…

Don't worry, the GDPR is coming. Now you're going to war with the Royal Navy in a nuclear armed ruber dinghy 4% revenue per timeframe in which privacy rights were violated, or 20 million. EUR, whichever is larger, is absolutely nothing to ignore anymore.

That sounds nice in theory, but in a global setting, how will it really work?

Per GP comment, there is a whole tech stack of N providers, each piece made or running in a different country, pushing data to servers in another country, which data is bought by interests in a third country, for M destinations. Then you get the providers who intentionally don't store data in GDPR countries specifically so they can avoid these rules. Look at what Uber already does to skirt the authorities. So you have at least MxN countries possibly involved or whatever. If your data is released, it'll rattle around in a pachinko machine of jurisdiction debate for years against well funded, malicious corporations.

It doesn't seem like any rule is enforceable in practice.

Re: OnePlus Is Again Sending User Data to a Chinese Company Without User Consent

#14

Why does it matter whether the company is Chinese or not? Isn't it bad enough that there's a background process running, unbeknownst to the user, and presumably uncontrollable by the user, that monitors the device's clipboard and has methods like containsBankAccount(String)?

One reason is court jurisdiction. A domestic company is subject to, and therefore vulnerable to, court action/rulings/judgements. Suing a foreign company (especially one in China) is hopeless.

Re: OnePlus Is Again Sending User Data to a Chinese Company Without User Consent

#15

Why does it matter whether the company is Chinese or not? Isn't it bad enough that there's a background process running, unbeknownst to the user, and presumably uncontrollable by the user, that monitors the device's clipboard and has methods like containsBankAccount(String)?

Because China's government has been known to lean on manufacturers in the past to include malware and backdoors.

Re: OnePlus Is Again Sending User Data to a Chinese Company Without User Consent

#16

Why does it matter whether the company is Chinese or not? Isn't it bad enough that there's a background process running, unbeknownst to the user, and presumably uncontrollable by the user, that monitors the device's clipboard and has methods like containsBankAccount(String)?

Sure it's bad but there are a couple of reasons why it matters that it's a Chinese company.

1. It feeds into the suspicion many have that many (most? all?) large Chinese companies are effectively controlled by the Chinese government. This could go as far as having backdoors in, say, Huawei routing equipment.

2. Effectively disclosing a user's personal information to the Chinese government could, in some cases, imperil their liberty, even their life. I'm talking about people the Chinese governments views as "dissidents". The same would be true if it were a Russian, North Korean, Iranian, Syrian or Sudanese company.

Re: OnePlus Is Again Sending User Data to a Chinese Company Without User Consent

#17
post #13
post #6

Earlier quoted context omitted.

Don't worry, the GDPR is coming. Now you're going to war with the Royal Navy in a nuclear armed ruber dinghy 4% revenue per timeframe in which privacy rights were violated, or 20 million. EUR, whichever is larger, is absolutely nothing to ignore anymore.

That sounds nice in theory, but in a global setting, how will it really work? Per GP comment, there is a whole tech stack of N providers, each piece made or running in a different country, pushing data to servers in another country, which data is bought by interests in a third country, for M destinations. Then you get the providers who intentionally don't store data in GDPR countries specifically so they can avoid th…

The GDPR applies extraterritorially.

If a company even stores a record of a single EU citizen, the GDPR applies to it, and the EU has the right to seize the assets of the company for the purpose of enforcing it.

Re: OnePlus Is Again Sending User Data to a Chinese Company Without User Consent

#18
Notice how there is actually no proof at all in these tweets. The author admits that they could not observe any network requests being made:

> I didn't manage to trigger the network communications to the teddymobile servers but I will continue later.

It looks to me like this person is cherrypicking random SDK methods that may seem suspicious out of context and making very wild assumptions of their purposes.

For example, they show a function that checks if a string contains a bank account number (https://twitter.com/fs0c131y/status/956649951056064513). Somehow they then jump to the conclusion that copied text is run through this function and uploaded to some server! But where is the proof? They could check where this method is used and show this supposed data upload happening.

In fact, since these methods are coming from some third party SDK and not the app itself, they could be completely unused.

Re: OnePlus Is Again Sending User Data to a Chinese Company Without User Consent

#19

Why does it matter whether the company is Chinese or not? Isn't it bad enough that there's a background process running, unbeknownst to the user, and presumably uncontrollable by the user, that monitors the device's clipboard and has methods like containsBankAccount(String)?

One reason is court jurisdiction. A domestic company is subject to, and therefore vulnerable to, court action/rulings/judgements. Suing a foreign company (especially one in China) is hopeless.

https://abovethelaw.com/2016/03/suing-chinese-companies-in-u...

Re: OnePlus Is Again Sending User Data to a Chinese Company Without User Consent

#20

Why does it matter whether the company is Chinese or not? Isn't it bad enough that there's a background process running, unbeknownst to the user, and presumably uncontrollable by the user, that monitors the device's clipboard and has methods like containsBankAccount(String)?

Very good question indeed. European smartphones send tons of data to US companies with are known to proactively cooperate with the NSA and consors, which is the same kind of problem. But for some reasons this seems to be fine for our rulers whereas it’s becoming an issue when China or Russia is involved. Not that I what a free pass for these two countries; on the contrary I would like to see more regulations for every non EU companies.
Post reply on HN