Live data from Hacker News

Nokia phones sent identifiable data to Chinese server

translate.google.com

121–130 of 191 posts

Re: Nokia phones sent identifiable data to Chinese server

#121

Allegedly hacked entire OPM database, Marriot and other orgs. This allows them to potentially blackmail key personnel they want to control. Imagine what they can accomplish with the deployment of Huawei 5G.

All this 5G panic is ridiculous. If our protocols were properly end to end encrypted then it doesn't matter who makes the router.

The real reason is that 5G is not secure by design, just like 4G and 3G and GSM before. But the NSA wants to have the keys only for themselves.

Re: Nokia phones sent identifiable data to Chinese server

#122
post #119

Earlier quoted context omitted.

Huh? It's more than just that; the Android build comes littered with software from an unscrupulous source, even on phones that are supposed to be close to a clean version of Android.

Why do you assume they (the presumely Chinese provider of the component) are unscrupulous? To me it is obvious that it is Nokia that is sloppy and having quality issues.

Why do you assume it's simply laziness? Regardless, it's not good.

Re: Nokia phones sent identifiable data to Chinese server

#123
post #45

It's shameful of Google (but totally expected) that they don't supervise the Android One program AT ALL. All of the Android One mobiles appear on the top list of their Android One microsite and I'm sure most of them contain malware built-in. https://www.android.com/one/ Having said this, I never expected Nokia to be doing that, too. Both Nokia and HMD are Finnish, do they really need to outsource the creation of the…

Yeah, Android One is a bit of a joke really. I got a Nokia 7 Plus on the promise that it would have fast updates, be bug free, and not contain any OEM modifications. None of those have really been true. Admittedly, updates are still a bit faster than the likes of Samsung and other big OEMs, but the process has shown that it's not as simple as Google rolling out the updates.

OEMs still make changes to it, and it still seems dependent on carriers pushing through the changes - despite buying a SIM free phone, I waited 2 months longer for updates, which seemed to be the case with everyone on the same network in the UK.

It's far from bug free, with a few updates in the last few months introducing new bugs. Again, it shows that this isn't an update coming directly from Google, it is at least in some part developed and tweaked by OEMs. In this particular case, the process showed that HMD/Nokia is severely lacking in development and QA expertise, as there have been ongoing issues for months with no fix.

They also introduced their own battery optimisation software a few months ago, which massively changed how the phone handled multitasking and background applications (effectively, it killed them all). And then this news that they're sending unencrypted identifiable information to a third party? These things shouldn't be possible if Android One did what it claimed.

I avoid OEMs like Samsung because of all the bloat and junk that they add on top of Android, but Android One is clearly not a solution to that. I would still prefer it in theory in the alternatives, but I'll do more research next time - if a company doesn't have a proven track record, then Android One isn't going to solve that.

One minor point - Nokia the company isn't involved in the Nokia Android phones. HMD is just a small company that licenses the brand. Admittedly, a small company that was founded by ex-Nokia folk and based across the road from Nokia's HQ, but it's evidently not a company with Nokia's resources or much of their expertise.

Re: Nokia phones sent identifiable data to Chinese server

#124

Earlier quoted context omitted.

I have a Nokia 3 and a Nokia 7.0 Plus, both had a bunch of com.evenwell.* packages installed. I think all HMD devices have those packages.

Would love to speak to you about this. Can you send me an email? henrik.lied [at] nrk.no

Send you a mail from a newly created mail account.

Re: Nokia phones sent identifiable data to Chinese server

#126

Side note: I didn't notice the page was translated from another language until after I finished reading it and noticed the title bar. Machine translation between European languages has really come a long way.

Oh wow me neither. Just one word (ombudsman) stood out to me, but I thought it could exist in English. It does in my native language so I did understand it :p That's a nice translation!

It does exist in English.

Re: Nokia phones sent identifiable data to Chinese server

#127
Pretty much every phone in the U.S goes through the hands of a singular distribution point. This company (who I'm not going to name) is responsible for putting the custom image for the cellular provider. The basic phone that arrives from the manufacturer is going to be wiped, and re-imaged.

For something like this to survive that, it's either 100% known about (U.S side) or chip based.

Re: Nokia phones sent identifiable data to Chinese server

#128
post #119

Earlier quoted context omitted.

Why do you assume they (the presumely Chinese provider of the component) are unscrupulous? To me it is obvious that it is Nokia that is sloppy and having quality issues.

Why do you assume it's simply laziness? Regardless, it's not good.

Why is there a Chinese flag in the article and not a Finnish flag?

Because it gives more attention.

The real story here is that the venerable brand of Nokia now is being used to sell sub-quality phones.

Re: Nokia phones sent identifiable data to Chinese server

#129
post #21

I knew of that 9 months ago, but nobody was interested so I dropped it. https://news.ycombinator.com/item?id=17329825

I wonder how often this kind of comments fall through the cracks like this. Happened to me too with something privacy related about one of the big Corps that then was noticed by everyone else a few weeks later... I agree with others, better open a "Tell HN" in this cases.

I've found that sometimes a "why was this downvoted" response to an irrationally downvoted question can turn it from grayed out to black again.

Herd mentality for sure.

Re: Nokia phones sent identifiable data to Chinese server

#130
post #55

Please don't assume this is a one-time event, or that it is specific to this brand or even to Chinese manufacturers. Nokia could actually be in the best half on that aspect, just got unlucky. Most of such info leaks are hidden. I've already witnessed several OEM firmwares sending informations to many different parties. Too often, this is done through http, with payload encrypted. But it's always symmetrical encryptio…

> raises an advertisement company in Israel Out of curiosity, what "advertisement" company would that be?

Digital Turbine
Post reply on HN