Live data from Hacker News

Nokia phones sent identifiable data to Chinese server

translate.google.com

181–190 of 191 posts

Re: Nokia phones sent identifiable data to Chinese server

#181

FWIW, I have a recently purchased Nokia 7.1 which is part of the Android One scheme (running Android Pie). This was through a legit high-stret UK retailer so not grey-import or anything. I installed NoRoot Firewall as suggested in another comment here. So far NoRoot Firewall has not detected any activity from anything unusual running in the background (either idle, screen-on, or charging). What was weird though was t…

So 24 hours later and still nothing odd going on according to NoRoot Firewall on a UK retail Nokia 7.1.

I'll keep running foir a few more days (I cant use my usual VPN at the same time as NoRoot Firewall so dont want to run indefinitely) and udpate if anything else happens.

Re: Nokia phones sent identifiable data to Chinese server

#182
post #9

It is kind of ironic for me to think my perception of Android as same as Windows as major malware distributor despite it is based on Linux. Android is now fast becoming Windows XP of mobile.

... and it is probably going to be even worse with BSD/MIT/Apache-licensed eventual Android replacement in development called Fuchsia. More modifications by vendors and manufacturers, more preinstalled malware and bloatware, less customizations allowed. :)

Re: Nokia phones sent identifiable data to Chinese server

#183

Shouldn't this be something that the NSA looks into and prevents? The NSA works with US companies to secure their systems from espionage. Shouldn't the NSA be analyzing consumer electronics to make sure they don't spy on US citizens, some of which will have sensitive information or trade secrets on their phones?

NSA is the world-wide espionage agency. They welcome these leaks. That's why security bugs found in Windows are first sent to NSA and later eventually to Microsoft to fix. Read more about Snowden's leaks, read stallman.org.

Re: Nokia phones sent identifiable data to Chinese server

#184

Statement from HMD Global We have analyzed the case and can confirm that there has been an error in the packing process of software in a single batch of a telephone model, which by mistake attempted to send activation data to a foreign server. The data was never processed and no personal information was shared with third parties or authorities. This has now been fixed and almost any device affected by this error has…

"takes the safety and privacy of our customers seriously" - so far every company said that.

Re: Nokia phones sent identifiable data to Chinese server

#185
post #137

I did some research on zzhc.vnet.cn and what its purpose might be. Zzhc is probably an abbreviation of 自注册, meaning self-registration. There is plenty of documentation (in Chinese) on how to implement it (e.g. [1]), but so far I haven't been able to figure out what it's actually good for. You can find implementations by Qualcomm and Mediatek on GitHub, the Mediatek one even comes with a minimal README [2]. That seems…

More articles about "补贴", from same user, https://www.jianshu.com/u/3bff037f7a8b . I assume the android implementation was done in China, then many requirements are related with "补贴", it is just part of them to submit some data to zzhc.vnet.cn. But didn't get deleted when they are making EU variants.

Thanks for the links. Actually, I had seen one of those articles before, but didn't understand it well enough.

My understanding now is that some 4G deployments are subsidized, and to correctly compute the amounts to be paid, China Telecom needs to collect more data than is usually available, so they came up with the idea of sending the data to zzhc.vnet.cn.

Still pretty hacky, but it kind of makes sense from a perspective of doing the minimum necessary to fulfill the requirements.

Re: Nokia phones sent identifiable data to Chinese server

#186

Earlier quoted context omitted.

> It is kind of scary to use a banking app on this thing. My wife, who is not a tech person at all, flatly refuses to run any banking or financial apps on her Android phone. She knows just enough about the technology to know that most Android devices are cesspools of spyware and malware, even her Galaxy phone. She doesn't like iPhones though, so I doubt she will ever go over to that side even for security's sake.

Please have her order a Librem 5 for banking etc!

No thank you, I lost faith in Purism after they continually misled their customers about the Librem 15 laptop.

https://www.reddit.com/r/linux/comments/3anjgm/on_the_librem...

Re: Nokia phones sent identifiable data to Chinese server

#187

Earlier quoted context omitted.

Please have her order a Librem 5 for banking etc!

No thank you, I lost faith in Purism after they continually misled their customers about the Librem 15 laptop. https://www.reddit.com/r/linux/comments/3anjgm/on_the_librem...

To be fair, they did get Coreboot working after about 2 years from the time of that post but it's still not ideal, compared to a older Libreboot based system, performance not withstanding.

Re: Nokia phones sent identifiable data to Chinese server

#188

Earlier quoted context omitted.

No thank you, I lost faith in Purism after they continually misled their customers about the Librem 15 laptop. https://www.reddit.com/r/linux/comments/3anjgm/on_the_librem...

To be fair, they did get Coreboot working after about 2 years from the time of that post but it's still not ideal, compared to a older Libreboot based system, performance not withstanding.

They did, but they never once apologized or admitted they misled customers about the laptop launching with Coreboot working and ME removed (in fact their initial promise was that they somehow got Intel to make a ME-free chipset "just for them" which was a flat out lie).

Lie to me and I'm done with you, especially over something as important as privacy and freedom. It may now be closer to what they originally promised, but I no longer trust them.

Re: Nokia phones sent identifiable data to Chinese server

#190

Earlier quoted context omitted.

To be fair, they did get Coreboot working after about 2 years from the time of that post but it's still not ideal, compared to a older Libreboot based system, performance not withstanding.

They did, but they never once apologized or admitted they misled customers about the laptop launching with Coreboot working and ME removed (in fact their initial promise was that they somehow got Intel to make a ME-free chipset "just for them" which was a flat out lie). Lie to me and I'm done with you, especially over something as important as privacy and freedom. It may now be closer to what they originally promised…

That's fair, and even "I" as a "partial supporter" think they need to tune down the marketing machine a bit.

It's a shame because they're really the only company doing what their doing (a fighting a chance at open source (as possible) and secure hardware)

Post reply on HN