Earlier quoted context omitted.
Why do you assume it's simply laziness? Regardless, it's not good.
Why is there a Chinese flag in the article and not a Finnish flag? Because it gives more attention. The real story here is that the venerable brand of Nokia now is being used to sell sub-quality phones.
Nokia phones sent identifiable data to Chinese server
151–160 of 191 posts
Re: Nokia phones sent identifiable data to Chinese server
#152Very nice of the Chinese military to choose a .cn domain so even the Norwegians can see what is going on ...
It is obviously a bug / lazy programmer / broken project management. A phone with most of it components bought from China and in one of the many configurations just copied from the supplier's examples there was an URL which was supposed to be changed but didn't. In other words - a non-story or at most a story about quality issues at the reborn Nokia. But luckily the URL pointed to China ... so we can make the story a…
On the off chance that you're a native Chinese speaker, are you able to figure out what the purpose of device self-registration is? My Chinese is unfortunately not good enough to easily find information on it.
Re: Nokia phones sent identifiable data to Chinese server
#153It's shameful of Google (but totally expected) that they don't supervise the Android One program AT ALL. All of the Android One mobiles appear on the top list of their Android One microsite and I'm sure most of them contain malware built-in. https://www.android.com/one/ Having said this, I never expected Nokia to be doing that, too. Both Nokia and HMD are Finnish, do they really need to outsource the creation of the…
Here's pm list: https://pastebin.com/HjQED9fr (I installed few applications myself)
Re: Nokia phones sent identifiable data to Chinese server
#154Personally for me Google is an opposite of privacy.
Re: Nokia phones sent identifiable data to Chinese server
#155It's shameful of Google (but totally expected) that they don't supervise the Android One program AT ALL. All of the Android One mobiles appear on the top list of their Android One microsite and I'm sure most of them contain malware built-in. https://www.android.com/one/ Having said this, I never expected Nokia to be doing that, too. Both Nokia and HMD are Finnish, do they really need to outsource the creation of the…
How can I check it? I bought Xiaomi Mi A2 recently and I didn't find any non-Google software, it looks pretty authentic. Here's pm list: https://pastebin.com/HjQED9fr (I installed few applications myself)
Re: Nokia phones sent identifiable data to Chinese server
#156For example, many apps, especially messenger and social network apps secretly or openly export contact lists from devices. Not only this is highly unethical, it might be a violation under GDPR because the information in the contact list is personal information and you must obtain the permission of that person for transferring the data abroad, not only the permission of the phone owner.
Almost every mobile app collects IMEI, a hardware identifier that allows governments and mobile companies to track the precise location of your phone. While such data are highly sensitive, they collect it without any second thought. Even a simple keyboard app was collecting all the data it could grab [2].
I can remember how Google was collecting WiFi data, without permission from access point owners. It was also collecting the traffic sent over WiFi [1].
It seems like the companies in every country have similar interests for users' data.
Also, I have a noname Chinese phone and when I examined its traffic with Wireshark, it was attempting to send data with IMEI to Chinese servers (luckily I had no SIM card inserted so it couldn't get a phone number). It was sending data to Google servers as well, but sadly they were encrypted with SSL and even installing a self-signed root certificate on the device didn't help to decode the contents.
So I think there should be better regulation of data collection. The general rule ("not a single byte" rule) should be that no data can be sent anywhere without explicit user's consent (not a phrase somewhere in the EULA). Also I think the manufacturers should put large warnings on the boxes, like the ones on the cigarette packs, like "This device sends all your private data to country X", "This IoT device will spy on you 24 hours a day", "This device uses a cloud in country Y", etc. So that the consumers better know who will spy on them.
[1] https://www.wired.com/2012/05/google-wifi-fcc-investigation/
[2] https://www.zdnet.com/article/popular-virtual-keyboard-leaks...
Re: Nokia phones sent identifiable data to Chinese server
#157I did some research on zzhc.vnet.cn and what its purpose might be. Zzhc is probably an abbreviation of 自注册, meaning self-registration. There is plenty of documentation (in Chinese) on how to implement it (e.g. [1]), but so far I haven't been able to figure out what it's actually good for. You can find implementations by Qualcomm and Mediatek on GitHub, the Mediatek one even comes with a minimal README [2]. That seems…
Though that doesn't explain why CT wants that data.
Re: Nokia phones sent identifiable data to Chinese server
#158Earlier quoted context omitted.
It is obviously a bug / lazy programmer / broken project management. A phone with most of it components bought from China and in one of the many configurations just copied from the supplier's examples there was an URL which was supposed to be changed but didn't. In other words - a non-story or at most a story about quality issues at the reborn Nokia. But luckily the URL pointed to China ... so we can make the story a…
I agree with your assessment that this was likely unintentional, although it doesn't seem like they forgot to change the URL, but rather that the whole component should have been disabled. https://news.ycombinator.com/item?id=19451772 On the off chance that you're a native Chinese speaker, are you able to figure out what the purpose of device self-registration is? My Chinese is unfortunately not good enough to easily…
Re: Nokia phones sent identifiable data to Chinese server
#159This has to be fixed by HMD and I hope for an official investigation as most other manufacturers are probably doing the same. In the meantime, I recommend the following: 1. Remove any unnecessary packages through ADB ( https://www.xda-developers.com/uninstall-carrier-oem-bloatwa... ) 2. Use Shelter ( https://f-droid.org/en/packages/net.typeblog.shelter/ ) 3. Use a VPN-Firewall such as NetGuard ( https://f-droid.org/e…
Re: Nokia phones sent identifiable data to Chinese server
#160Shouldn't this be something that the NSA looks into and prevents? The NSA works with US companies to secure their systems from espionage. Shouldn't the NSA be analyzing consumer electronics to make sure they don't spy on US citizens, some of which will have sensitive information or trade secrets on their phones?
[1] https://www.wired.com/2013/10/nsa-hacked-yahoo-google-cables...