Live data from Hacker News

Nokia phones sent identifiable data to Chinese server

translate.google.com

131–140 of 191 posts

Re: Nokia phones sent identifiable data to Chinese server

#131
post #28

This has to be fixed by HMD and I hope for an official investigation as most other manufacturers are probably doing the same. In the meantime, I recommend the following: 1. Remove any unnecessary packages through ADB ( https://www.xda-developers.com/uninstall-carrier-oem-bloatwa... ) 2. Use Shelter ( https://f-droid.org/en/packages/net.typeblog.shelter/ ) 3. Use a VPN-Firewall such as NetGuard ( https://f-droid.org/e…

This should be fixed at an even higher level, and have Google force manufacturers to not add or alter the base OS for any data-gathering reasons in Android One and deny them from using the Android One brand if they do, or people will lose faith about the Android One program.

Re: Nokia phones sent identifiable data to Chinese server

#132
Shouldn't this be something that the NSA looks into and prevents?

The NSA works with US companies to secure their systems from espionage.

Shouldn't the NSA be analyzing consumer electronics to make sure they don't spy on US citizens, some of which will have sensitive information or trade secrets on their phones?

Re: Nokia phones sent identifiable data to Chinese server

#133
post #98
post #55

Please don't assume this is a one-time event, or that it is specific to this brand or even to Chinese manufacturers. Nokia could actually be in the best half on that aspect, just got unlucky. Most of such info leaks are hidden. I've already witnessed several OEM firmwares sending informations to many different parties. Too often, this is done through http, with payload encrypted. But it's always symmetrical encryptio…

> On Samsung Galaxy S9+ simply listing apps that can install apps silently (which is the master of all permissions Wait... what? Why is there such a permission in the first place?

As mentioned, there are updates, but then you could have an upgrade-specific permission (there isn't one).

But even when simply installing, check the workflow that the play store currently have: When you click "install" in the play store, you don't really want interactions far in the future about it. So the apps' permissions are asked right away. Without this silent install permission, you would have a pop-up at the end of the download (which can be between few seconds after clicking "install" to several hours if you're unlucky and downloading a big app), asking you to confirm the installation.

Re: Nokia phones sent identifiable data to Chinese server

#134

Statement from HMD Global We have analyzed the case and can confirm that there has been an error in the packing process of software in a single batch of a telephone model, which by mistake attempted to send activation data to a foreign server. The data was never processed and no personal information was shared with third parties or authorities. This has now been fixed and almost any device affected by this error has…

If that's an official statement, it should probably come with a link to a corresponding press release.

Random hacker news comments aren't the most trustworthy.

Re: Nokia phones sent identifiable data to Chinese server

#136
post #131
post #28

This has to be fixed by HMD and I hope for an official investigation as most other manufacturers are probably doing the same. In the meantime, I recommend the following: 1. Remove any unnecessary packages through ADB ( https://www.xda-developers.com/uninstall-carrier-oem-bloatwa... ) 2. Use Shelter ( https://f-droid.org/en/packages/net.typeblog.shelter/ ) 3. Use a VPN-Firewall such as NetGuard ( https://f-droid.org/e…

This should be fixed at an even higher level, and have Google force manufacturers to not add or alter the base OS for any data-gathering reasons in Android One and deny them from using the Android One brand if they do, or people will lose faith about the Android One program.

That, my friend, would be abusing their monopoly position.

Google hoovers up all the data and tells their partners they can't do this too? The antitrust regulators would have a field day.

Re: Nokia phones sent identifiable data to Chinese server

#137
I did some research on zzhc.vnet.cn and what its purpose might be. Zzhc is probably an abbreviation of 自注册, meaning self-registration. There is plenty of documentation (in Chinese) on how to implement it (e.g. [1]), but so far I haven't been able to figure out what it's actually good for.

You can find implementations by Qualcomm and Mediatek on GitHub, the Mediatek one even comes with a minimal README [2]. That seems to indicate that it's gated by a feature flag "MTK_CT4GREG_APP" and is only supposed to be active when explicitly selected while the phone is in developer mode. That makes it likely that sending the data was only due to a misconfiguration.

Considering the long list of manufacturers starting at page 10 of [1], it's also possible that others are leaking data in the same way.

[1] https://wenku.baidu.com/view/c2eaa9fc5022aaea998f0f7f.html

[2] https://github.com/griffins-testing-ground/android_vendor_mt...

Re: Nokia phones sent identifiable data to Chinese server

#138
post #56

Earlier quoted context omitted.

Yeah, I recently switched from iPhone to Samsung Galaxy S10. I don't have a previous experience so my reasoning was "well it's Samsung, at worst they'll have some shitty branded apps and some cruft". But I don't have an idea what these dozens of preinstalled apps running on my phone doing. Almost none of them can be uninstalled and only a handful can be disabled. It is kind of scary to use a banking app on this thing…

> It is kind of scary to use a banking app on this thing. My wife, who is not a tech person at all, flatly refuses to run any banking or financial apps on her Android phone. She knows just enough about the technology to know that most Android devices are cesspools of spyware and malware, even her Galaxy phone. She doesn't like iPhones though, so I doubt she will ever go over to that side even for security's sake.

Please have her order a Librem 5 for banking etc!

Re: Nokia phones sent identifiable data to Chinese server

#139
post #45

It's shameful of Google (but totally expected) that they don't supervise the Android One program AT ALL. All of the Android One mobiles appear on the top list of their Android One microsite and I'm sure most of them contain malware built-in. https://www.android.com/one/ Having said this, I never expected Nokia to be doing that, too. Both Nokia and HMD are Finnish, do they really need to outsource the creation of the…

You're right. My Android One Nokia 7.1 comes with at least 64 evenwell/HMDGlobal apps, albeit behind the scenes. There's no docs on any of them as far as I can tell so you can only guess from the name what they do.

https://pastebin.com/LehzyCMU

That said I've not noticed anything obviously suspicious when I use a firewall to monitor it. I only did it as a test so I might have missed something. Also I'm in the UK, if that makes a difference.

Re: Nokia phones sent identifiable data to Chinese server

#140
post #84
post #81

Earlier quoted context omitted.

So then maybe they aren't so "happy" to make the trade, but afraid for their status and lives if they don't obey?

Happy, probably not. Content? Most likely. And what makes most people happy is having a rich personal life, rather than achieving their political goals, I've found.

Bread and circuses stave off revolution.
Post reply on HN