Live data from Hacker News

Samsung embeds IronSource spyware app on phones across WANA

smex.org

181–190 of 500 posts

Re: Samsung embeds IronSource spyware app on phones across WANA

#181

Earlier quoted context omitted.

> PCs had root access by default, so why wasn't it a significant problem for them? They weren't networked. They were notoriously buggy. And most importantly, they weren't warrantied [1]. Root should always be an option. But once you root, it's fair for the warranty to be voided. > OS vendors such as Google and Microsoft have been deliberately "manufacturing concent" Nitpick, the propaganda model [2] attempts to descr…

Uh? My PCs and corporate PCs I've been responsible for are networked including the internet (they always have been). Moreover, they were warranted with no conditions about what software was run on them. Where on earth did you get that notion from? Just because some vendor [your links] has conned the unfortunate client into an unacceptable contract doesn't mean it's commonplace or ever was.

> Were on earth did you get that notion from?

Literally cited the source.

> My PCs and corporate PCs I've been responsible for were networked including the internet

These came later, in the mid 90s. If you have a source for any PC having been "warranted with no conditions about what software was run on them," I'd love to see it. Practically every warranty for PCs voided if you e.g. overclocked the CPU. And almost all PC warranties were limited warranties, not the no-questions-asked up-to accidental-damage common today.

Re: Samsung embeds IronSource spyware app on phones across WANA

#182

AppCloud, developed by the controversial Israeli-founded company ironSource (now owned by the American company Unity) Yes the Unity 3D engine company wow.

The weirdest part of that merger was Unity paid $4.4billion for IronSource.

Re: Samsung embeds IronSource spyware app on phones across WANA

#183

I suspect a strong link between mass surveillance (by corporations for advertising or by states for intelligence purposes) and the very recent targeting of the senior Iranian nuclear scientist and military officers at their homes in Iran. Wherever you are from or whatever side of the conflict you are on, I think we can all agree that it’s never been easier to infer so much about a person from “semi-public” sources su…

Almost all of Iran's cell network system was originally installed by S. Korean firms. They've changed some to Chinese brands, but apparently the compromised S. Korean brands are still around.

It's a mistake to assume that a very capable country can't get into a network that uses Chinese equipment/software.

Re: Samsung embeds IronSource spyware app on phones across WANA

#184
post #57

I suspect a strong link between mass surveillance (by corporations for advertising or by states for intelligence purposes) and the very recent targeting of the senior Iranian nuclear scientist and military officers at their homes in Iran. Wherever you are from or whatever side of the conflict you are on, I think we can all agree that it’s never been easier to infer so much about a person from “semi-public” sources su…

> I suspect a strong link between mass surveillance [...] and the very recent targeting of the senior Iranian nuclear scientist and military officers at their homes in Iran. We all like to imagine this super cool clandestine hacking operation using peoples mobile phones to secretly track people who visit nuclear facilities back to their homes. The much more logical explanation is someone approached a low level employ…

Israel, like any other state, must be using a variety of methods including good old "human intelligence" so it's not either-or.

In addition, saying that

> someone approached a low level employee at the MEAF who turned over a USB stick with the governments org charts and payroll records in exchange for their kids getting a full ride to a prestigious foreign university

is an oversimplification on multiple levels:

1. Low-level employees typically don't have access to sensitive information.

2. With human intelligence, there is always a risk that the person you (e.g. Israel) are in touch with (e.g. an Iranian officer) who pretends to be a "double agent" (e.g. leaking info to Israel), is in fact a "triple agent" (e.g. actually working for Iran to mislead Israel).

3. You can send your kids to foreign universities but not your siblings, your parents, your wife's family, and so on... Some of your beloved ones are almost certain to suffer the consequences of your actions. High treason is no joke.

Re: Samsung embeds IronSource spyware app on phones across WANA

#185

Earlier quoted context omitted.

In favor of what? The Android ecosystem is pretty lousy. Which manufacturers allow you to easily migrate to a new phone (Samsung has Smart Switch) and have, let's say, 4+ years of security updates? Genuine question. In my case I also wanted an SD card slot so it was slim slim pickings indeed. (And still there are some misfits who insist that there is no such thing as progress!)

>Which manufacturers allow you to easily migrate to a new phone (Samsung has Smart Switch) and have, let's say, 4+ years of security updates? Pixel phones get 7 years of OS and security updates. Do you consider Pixel phones to allow you to easily migrate to a new phone? Disclosure: I work at Google, but not on Android or Pixel.

Pixel phones have been awful hardware since the 5. So there is that. The tensor chip is a dud and can't be fixed. I'm done with Samsung for good after my current phone which I bought a few months ago. I'll probably replace it with an Oppo or something again, never going back to Samsung.

Re: Samsung embeds IronSource spyware app on phones across WANA

#186

Earlier quoted context omitted.

Didn't we backslide hard enough at this point that it is now architecturally ensured that there is a security downside to rooting? Prevents verified boot for example, since the attestation is tied to said corporations, and not you.

Not having verified boot is not a security downside for most people. Unless your threat model includes the evil maid attack, which it doesn't for thr vaaaaaast majority of people, verified boot is just another DRM anti-feature.

Verified Boot isn't merely to thwart Evil Maids, but by and large provide what's known as "Trusted Computing Base". And yes, given the proliferation of smartphones and the nature of sensitive applications built on top, most people, even if they don't realise it, need it.

Re: Samsung embeds IronSource spyware app on phones across WANA

#187

Earlier quoted context omitted.

Having your vehicle serviced by someone other than the dealer could void your warranty and poses a safety risk. Cooking animal products at home poses a health risk. You should be sure to only ever consume animal products prepared by a duly licensed establishment. The chauffeur's union would like to take this opportunity to remind you that amateurs operating their own motor vehicles risk serious injury and even death.…

You make an interesting point here. While “rooting your phone can void your warranty and pose a security risk“ may be a factually true statement, we must also consider some entirely unrelated and possibly untrue statements that could be theoretically uttered in another reality. We can get so bogged down with “things that are real” and “exist in this universe” that we completely fail to focus on the vital stuff like “…

On the contrary. My statements bear equivalent accuracy to yours in our current reality. My statements are also very obviously FUD. So is yours.

Or do you dispute that you could be hospitalized for salmonella if you botch cooking poultry at home? Or perhaps you feel that there is no straightforward way to inadvertently endanger your life by servicing your vehicle incorrectly?

Re: Samsung embeds IronSource spyware app on phones across WANA

#188

Earlier quoted context omitted.

This is a good point. While there is nothing factually incorrect in the statement “rooting your phone can void your warranty and pose a security risk”, if you imagine factual statements are the same thing as value judgments it becomes very problematic. Similarly it is pretty messed up when people say stuff like “fire can burn you if you aren’t careful” because so many people rely on fire for food and warmth.

In fact there is a lot factually incorrect. For starters, in most places, warranty is a legal requirement and the manufacturer isn't allowed to void it for whatever reason they want. If my phone's battery starts getting really hot in normal use, or I start getting dead pixels on my screen or whatever else, the fact I have a custom OS on my phone isn't relevant to the warranty claim any more than having it in a case o…

>For starters, in most places, warranty is a legal requirement and the manufacturer isn't allowed to void it for whatever reason they want.

This only makes the statement untrue if you use “can” and “will” interchangeably.

>More importantly, rooting is only a security risk in the sense that it increases the attack surface for exploits.

This is a good point. What even is “attack surface” anyway? Does anybody actually consider it when “evaluating security posture”? If I simply choose not to care about attack surface because I don’t want to, then doesn’t it simply become a factual nonissue? There are no answers to these questions

Re: Samsung embeds IronSource spyware app on phones across WANA

#189
post #160

Earlier quoted context omitted.

It is my experience that this is what Google does with their Pixel phones. It is really quite simple to unlock the bootloader and do whatever you want on a Google Pixel you own (i.e unlocked, no carrier). They even give you this really handy Android flash tool which uses WebUSB to fully restore your device when you mess up. Heck, custom ROMs like GrapheneOS and CalyxOS are even able to sign their own images and allow…

>banks and the like have a say in how I choose to access their more convenient services I disagree. I don't understand how it's fine that I can access my banking services with my Gentoo machine, with everything compiled from source by myself, but it's somehow a problem when I'm not using either Apple or Google certified OS on my phone. I'm sure they want to prevent the first scenario, like various streaming cartels a…

What kind of actions can gentoo do with your financial accounts, and what levels of user authentication does it use to do it? My phone can effectively act as a bank card with contactless payment or I can transfer up to a daily allowance (that would be painful to me if it was misused) of thousands with biometric auth. Similar to the OS if you're doing that with any browser with a web login you could potentially compile it to behave how you like or lie about what it's doing

Because it's a bank there's going to be insurance behind the scenes to cover them if something goes wrong, and I assume part of that is ticking off enough points to be confident a transaction is secure or different payment limits on confidence levels.

Re: Samsung embeds IronSource spyware app on phones across WANA

#190

Earlier quoted context omitted.

In favor of what? The Android ecosystem is pretty lousy. Which manufacturers allow you to easily migrate to a new phone (Samsung has Smart Switch) and have, let's say, 4+ years of security updates? Genuine question. In my case I also wanted an SD card slot so it was slim slim pickings indeed. (And still there are some misfits who insist that there is no such thing as progress!)

>Which manufacturers allow you to easily migrate to a new phone (Samsung has Smart Switch) and have, let's say, 4+ years of security updates? Pixel phones get 7 years of OS and security updates. Do you consider Pixel phones to allow you to easily migrate to a new phone? Disclosure: I work at Google, but not on Android or Pixel.

Going from a phone with a Snapdragon SoC to a Pixel with the Tensor SoC was a big downgrade for me. It gets hotter quicker when doing more demanding tasks, battery drains faster if network conditions are not perfect, etc.

We've been having some warm weather (~30ºC) around here and the other day my Pixel 8 Pro started warning me about the phone being too hot when I tried to record a video.

I like Google's Android skin and their long support periods, but Tensor holds these newer Pixels back.

Post reply on HN