Live data from Hacker News

Nokia phones sent identifiable data to Chinese server

translate.google.com

161–170 of 191 posts

Re: Nokia phones sent identifiable data to Chinese server

#161
post #27

Earlier quoted context omitted.

People inside China are very aware of it; most just don't care that much. They (willingly, if not happily) trade what westerners might consider pillars of freedom for widespread prosperity. When you consider the progress China has made over the last 50 years from the perspective of a typical Chinese citizen, you can see why they make that bargain.

I hear this often, but it kinda implies they prospered because they had this obnoxious rules, i fail to see if this is actually true. Wouldn't they still be better without this tyranical bullshit?

From a viewpoint of a person that was able to move from the poor dirty village to the city, get a well-paid job at the factory and get a mortgage for an apartment in a 40-floor building, the government is doing everything right. Also this person has probably to work all over the clock to repay the mortgage so he has not much time to think about politics.

Re: Nokia phones sent identifiable data to Chinese server

#162
post #28

This has to be fixed by HMD and I hope for an official investigation as most other manufacturers are probably doing the same. In the meantime, I recommend the following: 1. Remove any unnecessary packages through ADB ( https://www.xda-developers.com/uninstall-carrier-oem-bloatwa... ) 2. Use Shelter ( https://f-droid.org/en/packages/net.typeblog.shelter/ ) 3. Use a VPN-Firewall such as NetGuard ( https://f-droid.org/e…

You suggest installing userspace apps to control system software that might run in a privileged context. NoRoot Firewall, for example, doesn't control iptables, it just pretends to be a VPN server and privileged software, I assume, can bypass it.

Yes, I'm fully aware of this. There's also the problem of having a closed source baseband processor in pretty much every device.

But bypassing these mechanisms is a decision they had to make. If they're just lazy or incompetent, these userspace apps should be sufficient as a mitigation.

Check this out for a more sophisticated way: https://privacyinternational.org/node/2732

Re: Nokia phones sent identifiable data to Chinese server

#163
post #9

It is kind of ironic for me to think my perception of Android as same as Windows as major malware distributor despite it is based on Linux. Android is now fast becoming Windows XP of mobile.

My Android phone came with a weather app preinstalled. The app cannot be uninstalled, is full of translation errors and some links redirect to Chinese websites. Who knows what data my phone constantly sends there? Adding to that the fact that I don't receive system updates anymore, I have absolutely no trust in my phone. My next phone will be an iPhone, for the lack of better alternative.

Oneplus preinstalled weather app doesn't work at all without access to my contacts and to device storage (media). I'm also more and more thinking about switching to Apple, and paying premium for no hardware advantage, only due to fact that Apple collects and sells less information about me. Not because it will change anything substantially but on principle.

Re: Nokia phones sent identifiable data to Chinese server

#164

Earlier quoted context omitted.

You're right. My Android One Nokia 7.1 comes with at least 64 evenwell/HMDGlobal apps, albeit behind the scenes. There's no docs on any of them as far as I can tell so you can only guess from the name what they do. https://pastebin.com/LehzyCMU That said I've not noticed anything obviously suspicious when I use a firewall to monitor it. I only did it as a test so I might have missed something. Also I'm in the UK, if…

I've got a Nokia 8 (also bought in the UK) with the Evenwell system apps as well, and I haven't noticed any unusual domains in my Pi-hole logs at home. I wonder if it's only specific country builds that display this behaviour?

These apps can freely choose to only use the cellular modem for communication and thus communication may not show up in your firewall / proxy. In addition to this, your carrier can't distinguish legitimate traffic generated by you from malicious traffic generated by these applications.

Re: Nokia phones sent identifiable data to Chinese server

#165
post #28

This has to be fixed by HMD and I hope for an official investigation as most other manufacturers are probably doing the same. In the meantime, I recommend the following: 1. Remove any unnecessary packages through ADB ( https://www.xda-developers.com/uninstall-carrier-oem-bloatwa... ) 2. Use Shelter ( https://f-droid.org/en/packages/net.typeblog.shelter/ ) 3. Use a VPN-Firewall such as NetGuard ( https://f-droid.org/e…

Google should revoke their use of the AndroidOne trademark over these shenanigans.

Re: Nokia phones sent identifiable data to Chinese server

#167

Earlier quoted context omitted.

How can I check it? I bought Xiaomi Mi A2 recently and I didn't find any non-Google software, it looks pretty authentic. Here's pm list: https://pastebin.com/HjQED9fr (I installed few applications myself)

You have the problematic application: com.qualcomm.qti.autoregistration, also some stuff from Goodix that I'm not sure if you installed yourself...

> You have the problematic application: com.qualcomm.qti.autoregistration

Could you explain why this is problematic?

Re: Nokia phones sent identifiable data to Chinese server

#168

Earlier quoted context omitted.

You have the problematic application: com.qualcomm.qti.autoregistration, also some stuff from Goodix that I'm not sure if you installed yourself...

> You have the problematic application: com.qualcomm.qti.autoregistration Could you explain why this is problematic?

"security researcher Dirk Wetter reported that the culprit could be an APK package named “com.qualcomm.qti.autoregistration.apk.”"

https://www.androidauthority.com/nokia-7-plus-user-info-9679...

Re: Nokia phones sent identifiable data to Chinese server

#169
post #29

Earlier quoted context omitted.

Happens with a lot of posts, if they don't reach a critical mass of upvotes early on. In this case probably nobody could verify, if the claims were correct.

There is a new feature on HN these days to fix this: If a post get upvotes later, it will often be given a second chance to ‘try to shine’ to the front page. With this comment I think it was to hard for people to understand in the first place.

It's not if a post gets upvotes later, but rather if a moderator or a small number of story reviewers notice that it was a good post that didn't get attention. We've been doing it for quite a while now https://news.ycombinator.com/item?id=11662380. The long term plan is still to open this up to all users, not just a few, but we still haven't figured out a good way to do that.

Re: Nokia phones sent identifiable data to Chinese server

#170
post #128

Earlier quoted context omitted.

Why do you assume it's simply laziness? Regardless, it's not good.

Why is there a Chinese flag in the article and not a Finnish flag? Because it gives more attention. The real story here is that the venerable brand of Nokia now is being used to sell sub-quality phones.

Because the service and server in question are in China? Look I understand being skeptical of the narrative, but that's where the data was going.

Nokia isn't being shielded in the article.

Post reply on HN