Live data from Hacker News

Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

mobile.nytimes.com

121–130 of 170 posts

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#121

You cannot have privacy and security without free/libre software. While such doesn't doesn't guarantee privacy or security, operating systems that make an effort to build the system entirely from source without any proprietary components are much less likely to have a problem like this slip through the cracks of a large, active development community. Unfortunately, currently the only Android operating system to do th…

Regarding more secure versions of Android, what are your (or anyone's) thoughts on the following?

* CopperheadOS

* OmniROM

* PrivatOS, on Silent Circle Blackphones AFAIK

* The version on Blackberry Priv phones

.

I've also come across these, but don't know much about them:

* Cryptogenmod: I'm not sure this project ever went anywhere

* Chamelephon: http://chamelephon.com/

* GuardianROM: Discontinued?

* KeyROM by Mocana: Seems aimed at businesses that need secure Android. https://www.mocana.com/iot-security/keyrom

* Privacy phone by FreedomPOP: https://www.freedompop.com/theprivacyphone

.

And a couple probably not available to the public:

* OK:Android by General Dynamics: http://gdmissionsystems.com/cyber/products/trusted-computing...

* The OS on Boeing Black smartphones: http://www.boeing.com/defense/boeing-black/index.page

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#122

You cannot have privacy and security without free/libre software. While such doesn't doesn't guarantee privacy or security, operating systems that make an effort to build the system entirely from source without any proprietary components are much less likely to have a problem like this slip through the cracks of a large, active development community. Unfortunately, currently the only Android operating system to do th…

That's the old open source argument. And while many things could most certainly be discovered by extensive, costly audits, that someone has to pay for... OS code bases are huge. How difficult would it be to hide functionality like this in some obscure code that's camouflaged as something else? How hard would it be to automatically install an app that does this after first boot, disguised as some self updating or anal…

> That's the old open source argument.

Indeed, so it's unfortunate that it doesn't get more discussion in situations such as these.

> How difficult would it be to hide functionality like this in some obscure code that's camouflaged as something else?

More difficult than it would be with proprietary software, where anyone at any time can add malicious code that may never even be discovered over the lifetime of the device.

Free software doesn't prevent malicious actors from contributing malicious code, but it certainly improves chances. It also makes such a move very risky. Just as laws are a deterrent for many crimes, so is public scrutiny.

> How hard would it be to automatically install an app that does this after first boot, disguised as some self updating or analytics feature?

In a fully free OS, this app would have been built from source. So the same arguments apply.

> If someone puts an Android fork online, who has the time to go through the changes to discover something like this?

Again, it improves changes. Here's a good example from Replicant:

http://redmine.replicant.us/projects/replicant/wiki/SamsungG...

> Also, such features could even easily be placed on a tiny, dedicated chip inside the phone, completely apart from the OS.

Sure, but that's not an excuse to throw our hands up and not worry about the security of the software running on it. The OS might even be able to itself mitigate certain things (e.g. the Samsung backdoor mentioned above).

This issue also exists on PCs:

https://libreboot.org/faq/#intelme

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#123

I have a chinese Android phone. Instead of connecting it to the Internet I connected it to my computer over bluetooth and started monitoring the traffic it tried to send. There were attempts to connect to Google servers and chinese manufacturer's servers. The data sent to China was supposed to contain sensitive information like phone number or SIM card identifier. It also has an auto-update (read: backdoor) feature t…

> Instead of connecting it to the Internet I connected it to my computer over bluetooth and started monitoring the traffic it tried to send

How did you set that up? I'd be interested in knowing how to redirect/proxy cellular connections to something local, in a way I could read and monitor the data (is it encrypted?).

Based on what you say, maybe you proxied Internet connections through Bluetooth - do you have a way to know whether there was any leakage? For example, I've read, but can't confirm, that Android makes connections during bootup and before any firewall takes affect.

> I ended up making a linux-based whitelist firewall to access the Internet but it is pretty inconvinient because I have to manually enable every new host. And I can use it only at home.

A VPN with a firewall might be easier.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#124

Earlier quoted context omitted.

Unless you've purchased phones from all the "more established" brands and verified whether they're sending data, this is hardly sound advice. "More established" brands have a history of leaving secret backdoors and phoning home just the same as the Chinese devices. One was discovered in a range of Samsung devices just a couple years ago. Lenovo, same story, spyware and garbage hidden deep within their gadgets. The on…

That seems rather pessimistic. If you really don't trust any brands, what's wrong with directly buying from the tech companies instead of the manufacturers? Like Google Nexus (Pixel), Microsoft Windows Phone and iPhone. They are supposed to the industrial standards for how to do privacy correctly.

What standards are you talking about? I don't know of any. AFAIK, the standard is to monitor users and collect as much data on them as possible. The whole Internet runs on that model.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#125

Earlier quoted context omitted.

The big market and financial strength is one important factor but I believe that there are quite a few other forces at work which are not so obvious.

Do you have any hypothesis on the potential forces at work?

Sorry, I can't provide you with any good hypothesis. I'm just looking at what is known assuming that if something is of statistical significance without an obvious cause, that there is probably something going on that we don't see. Yet, correlation is no proof auf causation.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#126

Earlier quoted context omitted.

Sounds great! Does Android 7 run smoothly and stable-y on this device?

Custom roms never run stable from my experience and that is why I have stuck with Google Nexus devices in the past. Maybe if the phone is past its supported update lifespan then I would consider custom roms, otherwise I don't want to have to deal with these frustrations on a brand new device.

Funny that, my experience is quite the opposite.

Nexus 6P (Marshmallow); any time I lost phone signal the messaging app would get itself stuck in a tight loop until it had to be force stopped. You'd think they would have tested that on a brand new device..

Cyanogen Mod has been great in the past, as you say, to extend the life of old phones. Quite stable too.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#127

Earlier quoted context omitted.

And Google advertises Android as free, open source, linux-based OS. "open" is supposed to mean I can do whatever I want with it but in fact I cannot even access the iptables.

Jailbreak a phone and you can surely do whatever you want on it. Other than that it's not Google's fault how a manufacturer customizes the software.

If it is an Android phone with Google Play store then it is definitely Google's fault. Maybe Google should stop manufacturers from installing Android on their phones when they are doing things like this.

You want me to tell you why Google won't do anything, because Google doesn't give a crap about what manufacturers do as long as they keep installing Android on as many phones as possible and in return they get more advertising dollars.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#128

Elephant in the room is of course the amount of data that is sent to the u.s. from phones in the rest of the world. Hardly a surprise that China is getting in on the action too.

I am also a little curious about what the manufacturer (or by extension the PRC government) could do with data from a phone in the US? I actually prefer my backdoors to open to Beijing... they aren't likely to share, and they aren't in a position to do anything to me (I would obviously feel differently if I was a Chinese citizen).

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#129

Earlier quoted context omitted.

Unless you've purchased phones from all the "more established" brands and verified whether they're sending data, this is hardly sound advice. "More established" brands have a history of leaving secret backdoors and phoning home just the same as the Chinese devices. One was discovered in a range of Samsung devices just a couple years ago. Lenovo, same story, spyware and garbage hidden deep within their gadgets. The on…

That seems rather pessimistic. If you really don't trust any brands, what's wrong with directly buying from the tech companies instead of the manufacturers? Like Google Nexus (Pixel), Microsoft Windows Phone and iPhone. They are supposed to the industrial standards for how to do privacy correctly.

When a simple Google search reveals the exact pattern mentioned occurring again and again, not just with phones but with networking gear, laptops, TV's, IoT devices, CDs (Sony rootkit anyone?), and websites loaded to the max with trackers and secret downloads onto people's machines, it moves from pessimism to "this is just how it works."

The price of freedom is eternal vigilance. You want crap free gadgets, make them sell crap free gadgets by ratting them out when they sell gadgets loaded with crap.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#130

I have a chinese Android phone. Instead of connecting it to the Internet I connected it to my computer over bluetooth and started monitoring the traffic it tried to send. There were attempts to connect to Google servers and chinese manufacturer's servers. The data sent to China was supposed to contain sensitive information like phone number or SIM card identifier. It also has an auto-update (read: backdoor) feature t…

"And I can use it only at home."

In other words you can use it only on a network you control.

In other words, at home you can use your own router; you can set the gateway as a computer that you control.

Correct?

What if you had a portable gateway, one that could travel with you?

We now have Apple devices, Google/Android devices, Microsoft devices, and the majority of apps all phoning home. It is routine. No one cares. Right.

We may not be able to run the latest device purchased from major retail sources using open source, user-installed OS (UNIX).

But what we can do with UNIX is build our own routers from inexpensive hardware, including older hardware, and use these as our gateways.

To do this, no one needs Apple, Google or Microsoft's assistance. We have what we need.

It is easy to do at home, but what I would like to see is more travel-sized routers which can be driven by user chosen and user installed bootloader and user chosen UNIX-like kernel.

The aim with these efforts is control, not impressive hardware specs.

Proprietary hardware and locked bootloaders will always have the most impressive hardware specs on their side.

But to get those things, the user has to sacrafice some control.

Post reply on HN