Live data from Hacker News

Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

mobile.nytimes.com

141–150 of 170 posts

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#141

Earlier quoted context omitted.

When a simple Google search reveals the exact pattern mentioned occurring again and again, not just with phones but with networking gear, laptops, TV's, IoT devices, CDs (Sony rootkit anyone?), and websites loaded to the max with trackers and secret downloads onto people's machines, it moves from pessimism to "this is just how it works." The price of freedom is eternal vigilance. You want crap free gadgets, make them…

I am okay with the skepticism you have here but is there really a reason to create two throwaway accounts just to reply to me? Do you happen to know me in real life? I can't think of another reason for this.

No one should have to justify wanting to remain private/anonymous.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#142

Earlier quoted context omitted.

Have you not heard of OnePlus?

Is OnePlus a good phone? Been wanting an Android phone but can't seem to settle on one

Yes. I replaced my Nexus6 with a OnePlus3 ($400) because paying the Pixel's price ($950) would have made me feel like a sucker. The screen is excellent, and there is a wide variety of ROMs to choose from.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#143
post #65
post #28

Earlier quoted context omitted.

How can someone detect if their phone has this backdoor installed?

The thing is these are system apps so not easy to analyze unless you're root. What you can do is use observe your device traffic and see if any of these domains are pinged: bigdata.adups.com (primary) bigdata.adsunflower.com bigdata.adfuture.cn bigdata.advmob.cn Then check the content of the POST request (usually to url/mobileupload.do )

Sir, this is HN. You may assume we are root.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#144

Earlier quoted context omitted.

Because Google has no incentive to fix the issue.

It's not their issue to fix. Do you demand Microsoft take action because say Lenovo installs superfish? You make Lenovo fix it instead of a tangentially related company like Microsoft. Same thing here. It's not a Google issue.

Microsoft has to address the amount of crapware vendors ship and the permissions they have and deffinitely plays some games of chicken with them to try to keep windows market share.

While it makes sense to hit the vendors directly to the extent possible, it also costs these platforms trust when most of the ways users end up with them have them compromised from day one. I.e. do I give relatives a list of vendors I think might be safe to use without a complete wipe and fresh install? For windows that is impossible.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#145
post #130

I have a chinese Android phone. Instead of connecting it to the Internet I connected it to my computer over bluetooth and started monitoring the traffic it tried to send. There were attempts to connect to Google servers and chinese manufacturer's servers. The data sent to China was supposed to contain sensitive information like phone number or SIM card identifier. It also has an auto-update (read: backdoor) feature t…

"And I can use it only at home." In other words you can use it only on a network you control. In other words, at home you can use your own router; you can set the gateway as a computer that you control. Correct? What if you had a portable gateway, one that could travel with you? We now have Apple devices, Google/Android devices, Microsoft devices, and the majority of apps all phoning home. It is routine. No one cares…

> In other words, at home you can use your own router; you can set the gateway as a computer that you control.

Yes.

> What if you had a portable gateway, one that could travel with you?

I can rent a VPS and connect through it using "Always-on VPN" option (I did it once and it worked). But then I have to pay for a server monthly in addition to the mobile plan. It is not that expensive but I would prefer just having access to iptables and being able to install my firewall on a phone.

I might be wrong but on Windows you can at least install a firewall. At least you could on earlier versions.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#146

Earlier quoted context omitted.

Jailbreak a phone and you can surely do whatever you want on it. Other than that it's not Google's fault how a manufacturer customizes the software.

If it is an Android phone with Google Play store then it is definitely Google's fault. Maybe Google should stop manufacturers from installing Android on their phones when they are doing things like this. You want me to tell you why Google won't do anything, because Google doesn't give a crap about what manufacturers do as long as they keep installing Android on as many phones as possible and in return they get more a…

The phone has Google Services including Play Store (which I never used because it needs a Google Account, so I download software either from F-droid or from apkpure). But I don't know if it is licensed. It is noname chinese manufacturer that probably doesn't care much about american copyright (and GPL too because I could not find any links to linux kernel source code at their website).

> You want me to tell you why Google won't do anything, because Google doesn't give a crap about what manufacturers do as long as they keep installing Android on as many phones as possible

Google could allow controlling firewall on Android (and getting root access). The only reason they don't do it is because then users will be able to block tracking and advertisement.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#147

Earlier quoted context omitted.

Because Google has no incentive to fix the issue.

It's not their issue to fix. Do you demand Microsoft take action because say Lenovo installs superfish? You make Lenovo fix it instead of a tangentially related company like Microsoft. Same thing here. It's not a Google issue.

Unlike Google (that "is not evil") Microsoft allows user to gain administrator access and install firewall on Windows.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#148
post #100

Earlier quoted context omitted.

Google could provide easy ways to control Internet traffic and to gain root access. For example, they could grant access to builtin linux iptables which doesn't cost anything to implement. And Google is easier to influence than noname chinese company. Or they could not to sell Android license to companies not repecting consumer's privacy. Even if I got refunded, what would I buy instead? Free market doesn't work here…

> Google could provide easy ways to control Internet traffic and to gain root access. For example, they could grant access to builtin linux iptables which doesn't cost anything to implement. And Google is easier to influence than noname chinese company. And the manufacturer could simply unroot the phone and lock its bootloader. At the end of the day it's the phone manufacturer that controls the product, even if Googl…

My phone has an option to unlock a bootloader. But it would take time to find or build a custom ROM and install it and solve all kinds of problems with drivers and hardware.

And generally it is pretty decent model. It sends some data home but at least it doesn't have preinstalled adware like another chinese tablet I saw (that displays an ad over browser window and tries to disguise it as a part of a web page).

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#149

I have a chinese Android phone. Instead of connecting it to the Internet I connected it to my computer over bluetooth and started monitoring the traffic it tried to send. There were attempts to connect to Google servers and chinese manufacturer's servers. The data sent to China was supposed to contain sensitive information like phone number or SIM card identifier. It also has an auto-update (read: backdoor) feature t…

> Instead of connecting it to the Internet I connected it to my computer over bluetooth and started monitoring the traffic it tried to send How did you set that up? I'd be interested in knowing how to redirect/proxy cellular connections to something local, in a way I could read and monitor the data (is it encrypted?). Based on what you say, maybe you proxied Internet connections through Bluetooth - do you have a way…

I used Windows laptop with bluetooth and linux machine in VirtualBox (that also provides a virtual internal network). I physically disconnected a laptop from the Internet and used standard Windows "share Internet connection" feature to "share" virtual network via bluetooth. So Windows thought that linux VM is an Internet gateway and provided DHCP service to bluetooth network. The phone connected via bluetooth, got an IP address and all its traffic was redirected to a virtual machine by Windows. Once you get traffic to go to linux machine everything gets easy (if your host OS is linux you could skip some steps and obviously you don't need VirtualBox).

I used Wireshark on Windows to check that everythink is set up correctly and to see what kind of requests the phone makes.

You can use WiFi instead of bluetooth the same way. You only need to use "hotspot" option and provide DHCP to a phone and set your linux machine as a gateway. Probably you can do that with a router too, for example if you connect its WAN port to your linux machine or set up traffic redirection.

On linux I redirected traffic from phone to localhost with ports 53 (DNS), 80/443 (HTTP) and rejected any other traffic (there were some requests to time servers, that were sent by drm component of Android). I also ran a DNS server (dnsmasq) and Squid HTTP proxy that can process redirected traffic (Squid can also generate certificates to decrypt HTTPS traffic which was very useful though it took some time to find correct settings). I set up dnsmasq and squid to serve requests based on white and black lists.

After I did some tests I found another, easier way to capture traffic from Android phone. Android has a useful "Always-on VPN" feature that sends all traffic through specified host (and doesn't allow any network access until VPN connection is set up). You only need to set up ipsec on a linux box (I used strongswan). I used "Always-on VPN" feature to redirect traffic to my VPS while using mobile internet connection.

> Based on what you say, maybe you proxied Internet connections through Bluetooth - do you have a way to know whether there was any leakage?

I physically disconnected a laptop from the Internet and monitored the traffic on a bluetooth interface with Wireshark. The phone did not have a SIM card inside so it could not connect to a mobile network.

> For example, I've read, but can't confirm, that Android makes connections during bootup and before any firewall takes affect.

This can be detected using my setup. But if software is programmed to send some data only via mobile network and not via WiFi/bluetooth then it is more difficult to detect. You would need to set up a fake BTS (using OpenBTS for example) to capture that traffic. You would need special (not very expensive) SDR hardware in this case.

> A VPN with a firewall might be easier.

I ended up with the same idea. I even wrote a simple PHP app to manage black and white lists and view logs.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#150

Earlier quoted context omitted.

The manufacturer's name is Shenzhen Huafurui Technology if it tells you anything. The brand name is Cubot. I do not live in US but one can buy such kind of phone on Amazon (if you search manufacturer's name there you can find it is even cheaper now). It is good to hear that in some countries importing such phones is not allowed.

Sorry to hear your experience. Next time you'd be better off buying from a more established brand if you going to buy a phone of Chinese brand. Chances are, if they are officially selling outside China, they would have met some the requirements from the respective countries. I know Europe and US has strict privacy laws and that's why you can't buy such phones through official channels.

Even if I bought a Samsung (that is established brand, isn't it) or Apple phone I still would have to trust the manufacturer that it would not spy on me even if requested by NSA. I know that Samsung adds additional software into Android, they might have some kind of analytics too.
Post reply on HN