Live data from Hacker News

Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

mobile.nytimes.com

151–160 of 170 posts

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#151

Earlier quoted context omitted.

That seems rather pessimistic. If you really don't trust any brands, what's wrong with directly buying from the tech companies instead of the manufacturers? Like Google Nexus (Pixel), Microsoft Windows Phone and iPhone. They are supposed to the industrial standards for how to do privacy correctly.

What standards are you talking about? I don't know of any. AFAIK, the standard is to monitor users and collect as much data on them as possible. The whole Internet runs on that model.

The market could be driving that. If you don't spy on a user then your competitor would do and get ahead of you (and get additional profit from selling the data or showing relevant advertisement).

Microsoft didn't have any telemetry in earlier days. Now they turned to a dark side.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#152

I have a chinese Android phone. Instead of connecting it to the Internet I connected it to my computer over bluetooth and started monitoring the traffic it tried to send. There were attempts to connect to Google servers and chinese manufacturer's servers. The data sent to China was supposed to contain sensitive information like phone number or SIM card identifier. It also has an auto-update (read: backdoor) feature t…

I'm not sure what device you have, but there is a better than even chance that simply changing your rom will remove the spyware.

I am considering this but is would take time to find and configure all necessary drivers and build the ROM.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#153

I have a chinese Android phone. Instead of connecting it to the Internet I connected it to my computer over bluetooth and started monitoring the traffic it tried to send. There were attempts to connect to Google servers and chinese manufacturer's servers. The data sent to China was supposed to contain sensitive information like phone number or SIM card identifier. It also has an auto-update (read: backdoor) feature t…

You feel deceived by Google for buying a cheap Chinese made phone? What other things do you feel deceived by Google? Buying a car from Ford that always breaks down?

Google is developing software for cars so maybe soon it will be inside Ford cars too. Of course with Google Analytics preinstalled.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#154

Earlier quoted context omitted.

> Instead of connecting it to the Internet I connected it to my computer over bluetooth and started monitoring the traffic it tried to send How did you set that up? I'd be interested in knowing how to redirect/proxy cellular connections to something local, in a way I could read and monitor the data (is it encrypted?). Based on what you say, maybe you proxied Internet connections through Bluetooth - do you have a way…

I used Windows laptop with bluetooth and linux machine in VirtualBox (that also provides a virtual internal network). I physically disconnected a laptop from the Internet and used standard Windows "share Internet connection" feature to "share" virtual network via bluetooth. So Windows thought that linux VM is an Internet gateway and provided DHCP service to bluetooth network. The phone connected via bluetooth, got an…

Thanks for such a helpful and detailed response; I really appreciate it and I bet I'm not the only one.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#155
post #14

Earlier quoted context omitted.

"If your threat model includes a three letter agency, then don't use Android. Full stop. The iPhone is the ecosystem you want." I wouldn't count on that either.. It depends on how "interesting" you are for them, given their reach, I would be really surprised if some of these agencies doesn't have zero-days and/or backdoors stockpiled for high value targets.

Heck, or they even have cooperation from Apple. Apple claims they dont have a backdoor, and the FBI moans that they can't hack current iPhones. But honestly, who can ensure to me that there is no national security letter (or other mechanism I don't know about) forcing Apple to cooperate, with a gag order forcing them to keep silent? Who can ensure me that the NSA et al have are not bribing, blackmailing, or using cou…

I keep wondering the same. And I keep thinking that by the time I became privacy conscious, I am already like 20-30 years late...

What can we do?

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#156

Earlier quoted context omitted.

And Google advertises Android as free, open source, linux-based OS. "open" is supposed to mean I can do whatever I want with it but in fact I cannot even access the iptables.

"Open" means the re-distributor can do whatever they want with it, as long as they pass along the source under the same license. Software licenses with strings attached like "you must let end-users access the iptables" are emphatically nonfree.

Upvoting because you are absolutely 100% correct (and because I'm trying to help prevent HN from becoming more like Reddit where everyone "downvotes to oblivion" statements they don't like).

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#157

What's the big deal? Google does this on a much bigger scale and of course shares its data with the US government when asked. Why is it suddenly scary when a Chinese company does the same?

That's cute. You make it sound as if Apple doesn't share your data with the US government when asked. Oh, look what do we have here: >In one of the leaked emails sent by Apple Environment, Policy and Social Initiatives Vice President Lisa Jackson to Podesta, the Apple team clearly stated that the current methods of encryption in place allows the firm to essentially send an unlimited amount of personal and sensitive u…

That's not at all what I meant, but whatever.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#158

Question for HN: I'm in the market for a new Android phone. If I want to avoid this sort of thing, are there manufacturers I should steer clear of?

All of them except phones made/designed/whatever by Google. That leaves you the Nexus and Pixel lines only. There's a fair bit more oversight there and no shady third-party ROM with 'helpful' spying applications shipped by default (and often uninstallable). Nor do carriers get to modify the ROM themselves or install their own apps. Android is pretty much a wasteland outside of the Nexus/Pixel line. Ignoring security…

I will have to disagree. AFAIK, the recent Qualcomm exploits don't affect Samsung's Exynos SoC. I have an Exynos S7 Edge and it ships with a feature to disallow (read: kill) apps trying to work in the background. After I fine-tuned this list, the phone's battery life improved noticeably.

Battery life has actually been slowly and steadily improving after each update by Samsung. I imagine this is a sign of Samsung not liking Google's spyware very much and trying their best to limit background activity.

None of us has solid proof of course, but judging by observable facts (and by the pretty awful battery life of the Nexus 6P and the Pixels -- compared to the Exynos S7 Edge at least), I'd say mine aren't that crazy.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#159
post #130

Earlier quoted context omitted.

"And I can use it only at home." In other words you can use it only on a network you control. In other words, at home you can use your own router; you can set the gateway as a computer that you control. Correct? What if you had a portable gateway, one that could travel with you? We now have Apple devices, Google/Android devices, Microsoft devices, and the majority of apps all phoning home. It is routine. No one cares…

> In other words, at home you can use your own router; you can set the gateway as a computer that you control. Yes. > What if you had a portable gateway, one that could travel with you? I can rent a VPS and connect through it using "Always-on VPN" option (I did it once and it worked). But then I have to pay for a server monthly in addition to the mobile plan. It is not that expensive but I would prefer just having ac…

> I can rent a VPS and connect through it using "Always-on VPN" option...

Still though, you have to worry that the hosting provider is taking adequate measures to protect your data, as well as also not secretly spying on you. I've worked with enough hosting sysops making trivial errors with their OVZ/KVM setups to realize that some VPS providers are about as secure and resilient as a power grid made from discarded toasters with forks shoved in them.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#160

Earlier quoted context omitted.

And Google advertises Android as free, open source, linux-based OS. "open" is supposed to mean I can do whatever I want with it but in fact I cannot even access the iptables.

"Open" means the re-distributor can do whatever they want with it, as long as they pass along the source under the same license. Software licenses with strings attached like "you must let end-users access the iptables" are emphatically nonfree.

Actually, licenses like the GPLv3 have been actively trying to prevent this in certain cases [1]

[1]: https://en.wikipedia.org/wiki/Tivoization

Post reply on HN