Live data from Hacker News

Samsung embeds IronSource spyware app on phones across WANA

smex.org

201–210 of 500 posts

Re: Samsung embeds IronSource spyware app on phones across WANA

#201

Because the link is down: https://web.archive.org/web/20250506145643/https://smex.org/... The article leaves out quite a lot about what AppCloud is, but it's essentially how Samsung monetizes their non-flagship device users and can do things like insert installation advertisements into the notification tray, and silently install apps. Personally, if I found this on my device it'd be the final straw to grit my teeth a…

Just buy a 5 year old iPhone - it's likely to be still better than the cheapo phone, and will get longer support as well, while being sold at rock bottom prices.

I just replaced my iPhone XS, not out of necessity, but I wanted to see what the new ones were like. The 16 is barely better and I was suprised to find just how little the old one was worth second hand, considering it still runs circles around most midrange Android handsets.

Re: Samsung embeds IronSource spyware app on phones across WANA

#202

I suspect a strong link between mass surveillance (by corporations for advertising or by states for intelligence purposes) and the very recent targeting of the senior Iranian nuclear scientist and military officers at their homes in Iran. Wherever you are from or whatever side of the conflict you are on, I think we can all agree that it’s never been easier to infer so much about a person from “semi-public” sources su…

Europol now argues that privacy is not a right and that we need to “think of the children”. EU is now pushing some abhorrent policies and legislation to demand backdoors.

We, the people, need to demand and force our politicians to work for us.

Re: Samsung embeds IronSource spyware app on phones across WANA

#204

Earlier quoted context omitted.

Not having verified boot is not a security downside for most people. Unless your threat model includes the evil maid attack, which it doesn't for thr vaaaaaast majority of people, verified boot is just another DRM anti-feature.

Verified Boot isn't merely to thwart Evil Maids, but by and large provide what's known as "Trusted Computing Base". And yes, given the proliferation of smartphones and the nature of sensitive applications built on top, most people, even if they don't realise it, need it.

but by and large provide what's known as "Trusted Computing Base".

In other words, DRM.

https://en.wikipedia.org/wiki/Trusted_Computing#Criticism

(I knew from the beginning that this was known as the Palladium project, and until recently, a search for "Palladium TCG" would find plenty of information about that history, yet now references to that group and its origins in DRM have seemingly disappeared from Google. Make of that what you will...)

Re: Samsung embeds IronSource spyware app on phones across WANA

#205
post #120

it's now a case of choosing between who you least care about spying on you - think I'll choose a Chinese phone next time, at least they're not currently engaged in genociding children

They're currently engaged in doing all kinds of awful things that we know about, and no doubt lots of even worse things that we don't. Try looking up Xinjiang, Tibet, or the Falun Gong for a taste.

There are no innocent world superpowers.

Re: Samsung embeds IronSource spyware app on phones across WANA

#206
post #90

Samsung currently has an unremovable spyware app on North American phones that pastes (records) everything copied to the clipboard by any app. It is the Samsung Keyboard app. It cannot be removed. It doesn't matter if you're using any other keyboard app. Samsung Keyboard pastes (records) everything that gets copied to the clipboard by any app. The Samsung Keyboard app cannot even be disabled from Android. As an aside…

Every day it feels like regulators need to increase enforcement by an order of magnitude. For every fine they dish out, 10 more abuses go unnoticed.

The regulators work for the same governments and intelligence agencies that are making companies add such clandestine spyware.

Re: Samsung embeds IronSource spyware app on phones across WANA

#207

making it nearly impossible for regular users to uninstall it without root access, which voids warranties and poses security risks Stop parroting the corporate propaganda that put us into this stupid situation in the first place. Having root access on devices you own should be a fundamental right, as otherwise it's not ownership.

The current legal reality might be corporate propaganda, but not exclusively corporate propaganda, it's the current legal reality as well. "root access voids warranties" is a fact in many jurisdictions, regardless of how it came to be. Hence, it's not as much parroting propaganda, as in furthering a cause, but just stating it how it is.

Re: Samsung embeds IronSource spyware app on phones across WANA

#208
post #8

The "unremovable" part is inaccurate. While you can't completely remove it because it resides on the system partition, you most probably can still disable it with an adb command: adb shell pm uninstall --user 0 com.package.name This command is very powerful as it works for any app, even those that have "disable" greyed out in the settings. I disabled the Galaxy Store on my S9 this way for example.

Words don't just have a literal, technical meaning. If the phone itself doesn't allow a straightforward, user friendly happy-path for removal, it might as well be "unremovable" in a sense that it is indeed unremovable for most users. "adb shell etc" implies that one has a PC with this tool correctly installed, and many people don't even have a PC in the first place. Then comes the case of installing adb, setting it up correctly, and having a cable to connect the two, enabling debug mode, and doing the thing. This is much more like a service thing, than a do it yourself at home thing. Not much unlike "chip tuning" for cars.

Re: Samsung embeds IronSource spyware app on phones across WANA

#209
post #7

In my experience, Samsung is a label that means "stay far, far away." From the Galaxy Note fiasco to my microwave to my dishwasher to ... Probably at least three other products before I learned my lesson. I even refuse to buy QD-OLED monitors out of indignation that Samsung makes the panels. Maybe I'm alone but maybe one day we'll boycott lousy companies out of business.

In favor of what? The Android ecosystem is pretty lousy. Which manufacturers allow you to easily migrate to a new phone (Samsung has Smart Switch) and have, let's say, 4+ years of security updates? Genuine question. In my case I also wanted an SD card slot so it was slim slim pickings indeed. (And still there are some misfits who insist that there is no such thing as progress!)

Pixel of course. And yeah the Androids suck mostly. Pixels suck too in some ways, for example, they are quite bulky, and heat up a bunch. But overall, by far the best Android experience in my opinion. No SD slot though.

Re: Samsung embeds IronSource spyware app on phones across WANA

#210

Earlier quoted context omitted.

Didn't we backslide hard enough at this point that it is now architecturally ensured that there is a security downside to rooting? Prevents verified boot for example, since the attestation is tied to said corporations, and not you.

AFAIK that's true for many vendors but for example Pixels (and IIRC also OnePlus at least a few years ago) you can relock the bootloader with other keys. The crazy thing is that on all the devices I've had AVB is implemented on top of secureboot. Being able to set your own secureboot keys is bog standard on corporate laptops. The entire situation makes absolutely no sense. Also for the record I think it's a silly att…

> A normal person does not have secret agents attempting to flash malicious images to his phone while he's in the shower.

No, but millions of women have controlling partners or friends who betray their trust and, for example, many people going through U.S. Customs are being asked to surrender control of their devices so they can be used without their knowledge. There’s a well-funded malware industry with a lot of customers now.

Post reply on HN