Live data from Hacker News

Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

mobile.nytimes.com

101–110 of 170 posts

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#101

Earlier quoted context omitted.

Where did you buy that phone from and what brand was it? I was under the impression that US does not allow selling of Android phones from most Chinese brands due to the reasons you mentioned, and for those that all allowed, they have strict vetting procedures to prevent phones with such capabilities from reaching the US market?

Have you not heard of OnePlus?

Yes, I know. I mean most brands, notably ZTE and Huawei. I am sure OnePlus is an exception here and does not fall into the category of phones with such capabilities otherwise it would have faced similar destinies as ZTE and Huawei. Anyway, I edited my comment to reflect that.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#102
post #91

I have a chinese Android phone. Instead of connecting it to the Internet I connected it to my computer over bluetooth and started monitoring the traffic it tried to send. There were attempts to connect to Google servers and chinese manufacturer's servers. The data sent to China was supposed to contain sensitive information like phone number or SIM card identifier. It also has an auto-update (read: backdoor) feature t…

As a consumer I am very disappointed and feel being deceived by Google. Why Google and not the maker of the phone? They're the ones that wrote the backdoor that sent stuff to China. You're not suggesting that Google helped with that, are you?

And Google advertises Android as free, open source, linux-based OS. "open" is supposed to mean I can do whatever I want with it but in fact I cannot even access the iptables.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#103

Earlier quoted context omitted.

Where did you buy that phone from and what brand was it? I was under the impression that US does not allow selling of Android phones from most Chinese brands due to the reasons you mentioned, and for those that all allowed, they have strict vetting procedures to prevent phones with such capabilities from reaching the US market?

The manufacturer's name is Shenzhen Huafurui Technology if it tells you anything. The brand name is Cubot. I do not live in US but one can buy such kind of phone on Amazon (if you search manufacturer's name there you can find it is even cheaper now). It is good to hear that in some countries importing such phones is not allowed.

Sorry to hear your experience. Next time you'd be better off buying from a more established brand if you going to buy a phone of Chinese brand. Chances are, if they are officially selling outside China, they would have met some the requirements from the respective countries. I know Europe and US has strict privacy laws and that's why you can't buy such phones through official channels.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#104

Earlier quoted context omitted.

Where did you buy that phone from and what brand was it? I was under the impression that US does not allow selling of Android phones from most Chinese brands due to the reasons you mentioned, and for those that all allowed, they have strict vetting procedures to prevent phones with such capabilities from reaching the US market?

The manufacturer's name is Shenzhen Huafurui Technology if it tells you anything. The brand name is Cubot. I do not live in US but one can buy such kind of phone on Amazon (if you search manufacturer's name there you can find it is even cheaper now). It is good to hear that in some countries importing such phones is not allowed.

Is there any real difference between buying on Amazon with an non-major brand and buying at Alibaba?

Seems like for items that involve things you care about (kids, your personal data), you take your chances buying from a vendor who might be an fly-by-night and in a jurisdiction that doesn't care about your local country's laws.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#105

I have a chinese Android phone. Instead of connecting it to the Internet I connected it to my computer over bluetooth and started monitoring the traffic it tried to send. There were attempts to connect to Google servers and chinese manufacturer's servers. The data sent to China was supposed to contain sensitive information like phone number or SIM card identifier. It also has an auto-update (read: backdoor) feature t…

You feel deceived by Google for buying a cheap Chinese made phone? What other things do you feel deceived by Google? Buying a car from Ford that always breaks down?

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#106
post #85
post #26

H guys, I'm one of the researchers with kryptowire if you have any questions

Hey duked. I just returned from Hong Kong (on vacation) and used two BLU Advance 5.0 phones as burners for use while in-country. I take precautions whenever I travel overseas. I've got two phones here that were used during my trip there. I was wondering if you had any tips for figuring out of they were compromised or otherwise owned while I was out there.

You can start by not buying cheap Chinese Android phones and hoping for the best.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#107

What's the big deal? Google does this on a much bigger scale and of course shares its data with the US government when asked. Why is it suddenly scary when a Chinese company does the same?

That's cute. You make it sound as if Apple doesn't share your data with the US government when asked. Oh, look what do we have here:

>In one of the leaked emails sent by Apple Environment, Policy and Social Initiatives Vice President Lisa Jackson to Podesta, the Apple team clearly stated that the current methods of encryption in place allows the firm to essentially send an unlimited amount of personal and sensitive user data to law enforcement.

>Jackson further emphasized that Apple already has a 24-hour live team established for the sole purpose of handling law enforcement and government requests. “Thousands of times every month, we give governments information about Apple customers and devices, in response to warrants and other forms of legal process,” Jackson stated. “We have a team that responds to those requests 24 hours a day. Strong encryption does not eliminate Apple’s ability to give law enforcement meta-data or any of a number of other very useful categories of data.”

You have to love that 24 hour live team whose sole purpose is to provide customer data to law enforcement and government people.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#108
post #91

Earlier quoted context omitted.

As a consumer I am very disappointed and feel being deceived by Google. Why Google and not the maker of the phone? They're the ones that wrote the backdoor that sent stuff to China. You're not suggesting that Google helped with that, are you?

And Google advertises Android as free, open source, linux-based OS. "open" is supposed to mean I can do whatever I want with it but in fact I cannot even access the iptables.

Jailbreak a phone and you can surely do whatever you want on it. Other than that it's not Google's fault how a manufacturer customizes the software.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#109

I have a chinese Android phone. Instead of connecting it to the Internet I connected it to my computer over bluetooth and started monitoring the traffic it tried to send. There were attempts to connect to Google servers and chinese manufacturer's servers. The data sent to China was supposed to contain sensitive information like phone number or SIM card identifier. It also has an auto-update (read: backdoor) feature t…

I'm not sure what device you have, but there is a better than even chance that simply changing your rom will remove the spyware.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#110

Elephant in the room is of course the amount of data that is sent to the u.s. from phones in the rest of the world. Hardly a surprise that China is getting in on the action too.

Exactly. When an address book is sent to every company that makes an app it's business!

When the same is sent to China, it's outrage?

Ditto with auto-updates.

I'd be glad if I could control much more of my data exposure. But business.

Post reply on HN