Live data from Hacker News

Samsung embeds IronSource spyware app on phones across WANA

smex.org

161–170 of 500 posts

Re: Samsung embeds IronSource spyware app on phones across WANA

#161

Earlier quoted context omitted.

Or just don't get Samsung? I guess I don't know for sure that my phone brand doesn't do anything similar, but it at least hasn't hit the news yet.

All Android phone but pixel ones have bloatware preinstalled. Some are worst, like Xiaomi. If you don’t want bloatware (spyware), it’s either pixel or iPhone.

That's incorrect. Zenphone is a bliss.

Re: Samsung embeds IronSource spyware app on phones across WANA

#162

Earlier quoted context omitted.

Didn't we backslide hard enough at this point that it is now architecturally ensured that there is a security downside to rooting? Prevents verified boot for example, since the attestation is tied to said corporations, and not you.

AFAIK that's true for many vendors but for example Pixels (and IIRC also OnePlus at least a few years ago) you can relock the bootloader with other keys. The crazy thing is that on all the devices I've had AVB is implemented on top of secureboot. Being able to set your own secureboot keys is bog standard on corporate laptops. The entire situation makes absolutely no sense. Also for the record I think it's a silly att…

> AFAIK that's true for many vendors but for example [on] Pixels you can relock the bootloader with other keys

Oh that's pretty cool, wasn't aware.

> The crazy thing is that on all the devices I've had AVB is implemented on top of secureboot. Being able to set your own secureboot keys is bog standard on corporate laptops. The entire situation makes absolutely no sense.

Hold on, could you elaborate a bit on this? I thought it was an either/or type deal cause they do the same thing.

Re: Samsung embeds IronSource spyware app on phones across WANA

#163

Earlier quoted context omitted.

We need regulation which defines that any hardware device capable of running software developed by a third party different from the hardware manufacturer qualifies as a general purpose computing device, and that any such device is disallowed to put cryptographic or other restrictions on what software the user wants to execute. This pertains to all programmable components on the device, including low-level hardware co…

While I agree in theory, this is never going to happen. There's too much DRM in use for it to work out.

Repeal and outlaw drm. It was a mistake that violates everyone's constitutional rights.

Re: Samsung embeds IronSource spyware app on phones across WANA

#164

making it nearly impossible for regular users to uninstall it without root access, which voids warranties and poses security risks Stop parroting the corporate propaganda that put us into this stupid situation in the first place. Having root access on devices you own should be a fundamental right, as otherwise it's not ownership.

How is the security risk propaganda?

It's not (only) propaganda. Rooting disables or bypasses verified boot, allowing exploits to persist across a reboot.

Re: Samsung embeds IronSource spyware app on phones across WANA

#165
post #7

In my experience, Samsung is a label that means "stay far, far away." From the Galaxy Note fiasco to my microwave to my dishwasher to ... Probably at least three other products before I learned my lesson. I even refuse to buy QD-OLED monitors out of indignation that Samsung makes the panels. Maybe I'm alone but maybe one day we'll boycott lousy companies out of business.

In favor of what? The Android ecosystem is pretty lousy. Which manufacturers allow you to easily migrate to a new phone (Samsung has Smart Switch) and have, let's say, 4+ years of security updates? Genuine question. In my case I also wanted an SD card slot so it was slim slim pickings indeed. (And still there are some misfits who insist that there is no such thing as progress!)

>Which manufacturers allow you to easily migrate to a new phone (Samsung has Smart Switch) and have, let's say, 4+ years of security updates?

Pixel phones get 7 years of OS and security updates. Do you consider Pixel phones to allow you to easily migrate to a new phone?

Disclosure: I work at Google, but not on Android or Pixel.

Re: Samsung embeds IronSource spyware app on phones across WANA

#166

Earlier quoted context omitted.

AFAIK that's true for many vendors but for example Pixels (and IIRC also OnePlus at least a few years ago) you can relock the bootloader with other keys. The crazy thing is that on all the devices I've had AVB is implemented on top of secureboot. Being able to set your own secureboot keys is bog standard on corporate laptops. The entire situation makes absolutely no sense. Also for the record I think it's a silly att…

> AFAIK that's true for many vendors but for example [on] Pixels you can relock the bootloader with other keys Oh that's pretty cool, wasn't aware. > The crazy thing is that on all the devices I've had AVB is implemented on top of secureboot. Being able to set your own secureboot keys is bog standard on corporate laptops. The entire situation makes absolutely no sense. Hold on, could you elaborate a bit on this? I th…

Many devices if you load up fastboot mode (is that the right name?) it will give you chipset and other information and it will have secureboot info there. It's permanently locked to chain into the AVB image. AVB is a much more complicated beast that specifies the existence of multiple partitions including (IIRC) one for storing authorized keys, one for the recovery, and a bunch of other stuff.

It's possible this has changed or was never widespread in the first place. I have a very limited (and historic) sample size.

Re: Samsung embeds IronSource spyware app on phones across WANA

#167

making it nearly impossible for regular users to uninstall it without root access, which voids warranties and poses security risks Stop parroting the corporate propaganda that put us into this stupid situation in the first place. Having root access on devices you own should be a fundamental right, as otherwise it's not ownership.

I'm pretty sure the recent switch 2 "license to use the hardware" has entirely killed any notion that you actually own the hardware and are free to do anything with it. Especially in Africa, where privacy and consumer rights are probably less relevant than the US/EU.

""license to use the hardware"…."

Well, then it's high time the laws of ownership in just about evey country in the world were updated.

As it stands, if I buy something then I own it.

Re: Samsung embeds IronSource spyware app on phones across WANA

#168
post #60

Earlier quoted context omitted.

How?

By following the principle of least privilege. Like with apps the user should only have privileges for what they are allowed to control and nothing more. So if the user should have privilege to disable apps, then the settings app could expose a way for the user to do so. Yes, this is kind of approach of coming up with a design to security instead of going with the easy route of everything being allowed is harder to d…

I believe that the top-level comment you replied to is making the point that there should not be any authority that either allows or disallows what a user can do with the device they own. Purchasing a device should make one that authority, free to decide how much security to trade for how much privilege.

Re: Samsung embeds IronSource spyware app on phones across WANA

#169

making it nearly impossible for regular users to uninstall it without root access, which voids warranties and poses security risks Stop parroting the corporate propaganda that put us into this stupid situation in the first place. Having root access on devices you own should be a fundamental right, as otherwise it's not ownership.

Didn't we backslide hard enough at this point that it is now architecturally ensured that there is a security downside to rooting? Prevents verified boot for example, since the attestation is tied to said corporations, and not you.

Not having verified boot is not a security downside for most people. Unless your threat model includes the evil maid attack, which it doesn't for thr vaaaaaast majority of people, verified boot is just another DRM anti-feature.

Re: Samsung embeds IronSource spyware app on phones across WANA

#170

Earlier quoted context omitted.

> There should be a "maintenance mode", but the onus of responsibility for breakage should be on the user for system update compatibility without the user being held hostage Isn’t this just a second device? How can you hold a manufacturer liable if the user was given unsupervised time as root?

"How can you hold a manufacturer liable if the user was given unsupervised time as root?" PCs had root access by default, so why wasn't it a significant problem for them? Banking is possible on a PC without a banking app. As Noam Chomsky has said, as in politics, manufacturers and OS vendors such as Google and Microsoft have been deliberately "manufacturing concent" — a widespread belief in the population of users th…

> PCs had root access by default, so why wasn't it a significant problem for them?

They weren't networked. They were notoriously buggy. And most importantly, they weren't warrantied [1].

Root should always be an option. But once you root, it's fair for the warranty to be voided.

> OS vendors such as Google and Microsoft have been deliberately "manufacturing concent"

Nitpick, the propaganda model [2] attempts to describe traditional mass media. Two of its five pillars (ownership and sourcing) fall apart in a world with smartphones and social media.

[1] https://www.studocu.com/ph/document/university-of-rizal-syst...

[2] https://en.wikipedia.org/wiki/Propaganda_model#Criticism

Post reply on HN