Live data from Hacker News

Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

mobile.nytimes.com

21–30 of 170 posts

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#21

Huawei routers used in Indian govt offices were found to be sending data to China. They were banned after the discovery. Wont be surprised if cellular components that are made in China send back data quietly.

People at HN would appreciate the corresponding links...

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#22
post #3

Earlier quoted context omitted.

Get a phone that supports CyanogenMod. Sure, baseband still remains a blackbox and possibly backdoored, but at least you can get rid of most spyware/adware that comes preinstalled with Android. While we don't have fully open source OS with open drivers for smartphones, you cannot trust any manufacturer.

Or simply skip that step and get a phone that comes with CyanogenOS installed.

How do you know then that CyanogenOS itself was not modified to include unwanted software?

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#23
post #14

Earlier quoted context omitted.

> I'm in the market for a new Android phone. Find a phone which has a large community around it, and lots of custom ROMs available. An official Cyanogenmod release is a good sign. It's also a sign that your phone will have a longer usable life than whatever the manufacturer promises you now. Custom ROMs have a long history of extending the life of phones. For example the HTC G1 was abandoned by Google at Donut (1.6)…

"If your threat model includes a three letter agency, then don't use Android. Full stop. The iPhone is the ecosystem you want." I wouldn't count on that either.. It depends on how "interesting" you are for them, given their reach, I would be really surprised if some of these agencies doesn't have zero-days and/or backdoors stockpiled for high value targets.

Heck, or they even have cooperation from Apple. Apple claims they dont have a backdoor, and the FBI moans that they can't hack current iPhones.

But honestly, who can ensure to me that there is no national security letter (or other mechanism I don't know about) forcing Apple to cooperate, with a gag order forcing them to keep silent?

Who can ensure me that the NSA et al have are not bribing, blackmailing, or using court orders on the three or four vocal security experts I can name (like Bruce Schneier, tptacek, Moxie Marlinspike, ...). Everything they say on this topic might be manipulated, who knows.

There could be backdoors everywhere, in apps, hardware, routers, lamps, whatever. Occam's razor suggests that this is crazy, but then people found spam sending wifi chips in clothes irons, so I guess nothing is too far fetched.

If you suspect "they" might be out to get you, the only thing you can really do is to stay under the radar, and hope they don't notice you and target you individually.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#24

Earlier quoted context omitted.

> I'm in the market for a new Android phone. Find a phone which has a large community around it, and lots of custom ROMs available. An official Cyanogenmod release is a good sign. It's also a sign that your phone will have a longer usable life than whatever the manufacturer promises you now. Custom ROMs have a long history of extending the life of phones. For example the HTC G1 was abandoned by Google at Donut (1.6)…

Sounds great! Does Android 7 run smoothly and stable-y on this device?

Custom roms never run stable from my experience and that is why I have stuck with Google Nexus devices in the past.

Maybe if the phone is past its supported update lifespan then I would consider custom roms, otherwise I don't want to have to deal with these frustrations on a brand new device.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#29
Does anyone regularly audit devices and apps with something similar to a web proxy, to see where they talk to during the course of normal usage? This seems like a decent low-hanging fruit (well, relatively speaking).

I also remember there used to be application firewalls in windows that kept track of the connections that each application made and if any of them contacted a new server, they'd ask you for permission. I don't think most folks used them because in the end they kept asking a lot of questions that the users didn't necessarily know how to answer, but I wonder if it wasn't such a bad idea after all, and whether the "default" choice could be mined from other users' settings.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#30

Question for HN: I'm in the market for a new Android phone. If I want to avoid this sort of thing, are there manufacturers I should steer clear of?

The only good choice may be https://neo900.org .

> 990 EUR Before taxes (VAT, etc.)

So this is the threshold I'll have to pass to get a chance for true privacy?

A throw-away phone without ID bound to it would be my way to go then.

Post reply on HN