Live data from Hacker News

Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

mobile.nytimes.com

111–120 of 170 posts

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#112
post #85
post #26

H guys, I'm one of the researchers with kryptowire if you have any questions

Hey duked. I just returned from Hong Kong (on vacation) and used two BLU Advance 5.0 phones as burners for use while in-country. I take precautions whenever I travel overseas. I've got two phones here that were used during my trip there. I was wondering if you had any tips for figuring out of they were compromised or otherwise owned while I was out there.

Hi, our findings are specific to the BLU R1HD. What you can do is have man in the middle proxy for your device and look at the traffic. Funny enough we actually bought the R1HD for the same reason as you... We had a conference in Taiwan and wanted a burner and BLU looked awesome for the price ;)

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#113

What's the big deal? Google does this on a much bigger scale and of course shares its data with the US government when asked. Why is it suddenly scary when a Chinese company does the same?

Despite its many flaws, the US government is still held accountable for its actions by voting citizens.

How do I, as a non-US but otherwise voting citizen, hold the US government accountable?

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#114
post #48

Earlier quoted context omitted.

> I'm in the market for a new Android phone. Find a phone which has a large community around it, and lots of custom ROMs available. An official Cyanogenmod release is a good sign. It's also a sign that your phone will have a longer usable life than whatever the manufacturer promises you now. Custom ROMs have a long history of extending the life of phones. For example the HTC G1 was abandoned by Google at Donut (1.6)…

I spent a day battling with getting a custom ROM on my Redmi 3 and gave up. In case anyone reads this: Xioami make amazing phones for the price. This $120 USD phone outperforms my S3. But getting a custom ROM on a Xioami is getting increasingly difficult - you have to ask for permission, jump through hoops to unlock the phone and sometimes it just does not work. Xioami is the Apple of China - great UI but increasingl…

It took me couple hours to get an unlock granted, then the unlock was done in couple minutes - it does require to read the instructions though.

After the unlock:

fastboot flash recovery twrp.img

fastboot boot twrp.img

Same as Nexus.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#115

Earlier quoted context omitted.

So you didn't tell the Federal Trade Commission, even though they previously investigated (and punished) HTC for doing something similar?

Curious, do security researchers typically liaise with the FTC when vulnerabilities are discovered? This and your parent comment seem to imply a 'yes' but this doesn't seem like an obvious connection (to me at least). I would expect the first point of contact at DHS to flag this for other agencies' attention if they felt it was necessary. Should DHS feel territorial about this and be reluctant to contact outside agen…

DHS is a law enforcement agency, which regularly uses surveillance techniques, some of which exploit security flaws in devices and software. When you share information about security flaws with DHS, you're sharing them with ICE and the Secret Service.

The FTC, in contrast, is a consumer protection agency. They don't kick down doors and they don't arrest people.

And yes, many security researchers have shared their prepublication research with the FTC.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#116

Question for HN: I'm in the market for a new Android phone. If I want to avoid this sort of thing, are there manufacturers I should steer clear of?

All of them except phones made/designed/whatever by Google. That leaves you the Nexus and Pixel lines only. There's a fair bit more oversight there and no shady third-party ROM with 'helpful' spying applications shipped by default (and often uninstallable). Nor do carriers get to modify the ROM themselves or install their own apps. Android is pretty much a wasteland outside of the Nexus/Pixel line. Ignoring security…

Pixel ? The phone which advertises/ships with a data collection assistant ?

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#117
post #53

Earlier quoted context omitted.

I think that's because market is more mature and people adopt thing quicker, so it's easier to sell more at the beginning of a business.

The big market and financial strength is one important factor but I believe that there are quite a few other forces at work which are not so obvious.

Do you have any hypothesis on the potential forces at work?

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#118

Earlier quoted context omitted.

The manufacturer's name is Shenzhen Huafurui Technology if it tells you anything. The brand name is Cubot. I do not live in US but one can buy such kind of phone on Amazon (if you search manufacturer's name there you can find it is even cheaper now). It is good to hear that in some countries importing such phones is not allowed.

Sorry to hear your experience. Next time you'd be better off buying from a more established brand if you going to buy a phone of Chinese brand. Chances are, if they are officially selling outside China, they would have met some the requirements from the respective countries. I know Europe and US has strict privacy laws and that's why you can't buy such phones through official channels.

Unless you've purchased phones from all the "more established" brands and verified whether they're sending data, this is hardly sound advice.

"More established" brands have a history of leaving secret backdoors and phoning home just the same as the Chinese devices.

One was discovered in a range of Samsung devices just a couple years ago. Lenovo, same story, spyware and garbage hidden deep within their gadgets.

The only solution is to take a chance, buy a device, test it. If it's backdoored, return it if you can, and call them out on HN/Amazon reviews, etc.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#119

Earlier quoted context omitted.

Sorry to hear your experience. Next time you'd be better off buying from a more established brand if you going to buy a phone of Chinese brand. Chances are, if they are officially selling outside China, they would have met some the requirements from the respective countries. I know Europe and US has strict privacy laws and that's why you can't buy such phones through official channels.

Unless you've purchased phones from all the "more established" brands and verified whether they're sending data, this is hardly sound advice. "More established" brands have a history of leaving secret backdoors and phoning home just the same as the Chinese devices. One was discovered in a range of Samsung devices just a couple years ago. Lenovo, same story, spyware and garbage hidden deep within their gadgets. The on…

That seems rather pessimistic. If you really don't trust any brands, what's wrong with directly buying from the tech companies instead of the manufacturers? Like Google Nexus (Pixel), Microsoft Windows Phone and iPhone. They are supposed to the industrial standards for how to do privacy correctly.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#120
post #30

Earlier quoted context omitted.

> 990 EUR Before taxes (VAT, etc.) So this is the threshold I'll have to pass to get a chance for true privacy? A throw-away phone without ID bound to it would be my way to go then.

We have to start somewhere. I am asking anyone who can to go for it (I have no connection to this company). We can hope that later it will become more affordable.

I wish you luck. For all of us :)
Post reply on HN