Live data from Hacker News

Samsung embeds IronSource spyware app on phones across WANA

smex.org

271–280 of 500 posts

Re: Samsung embeds IronSource spyware app on phones across WANA

#271

Earlier quoted context omitted.

Spoken like someone who knew no one other than fellow practitioners in the field. My God, the 2000s were the Wild West in every kind of way - were you even there to see it? I note you do not say that you were.

That's fine if they weren't. Probably not cool to attack them personally though.

[dead]

Re: Samsung embeds IronSource spyware app on phones across WANA

#272

Earlier quoted context omitted.

Changing from SK to CN is a trade from intentional vulnerability to unintentional vulnerability. I’ve yet to see a secure piece of software come out of China in my 30+ years of coding.

Supermicro IPMI comes to mind. If it was compromised we would have known by now.

Not only is Supermicro headquartered in USA, but it's operations are in Taiwan, which they would very much like you to acknowledge is not the same as mainland China.

Re: Samsung embeds IronSource spyware app on phones across WANA

#273
post #215

Earlier quoted context omitted.

I agree, but I think three extra conditions would need to be added here. 1. Devices should be allowed to display a different logo at boot time depending on whether the software is manufacturer-approved or not. That way, if somebody sells you an used device with a flashed firmware that steals all your financial data, you have a way to know. 2. Going from approved to unapproved firmware should result in a full device w…

> Devices should be allowed to display a different logo at boot time depending on whether the software is manufacturer-approved or not. Not sure how to phase this legally, but please also add a provision against manufacturers making the "custom firmware" logo hideously ugly on purpose to discourage rooting - like e.g.Microsoft did for Surface tablets. > 3. Users should have the ability to opt themselves into cryptogr…

Someone with the motivation to install custom firmware would consider the bootsplash aesthetic a deal breaker?

Re: Samsung embeds IronSource spyware app on phones across WANA

#274

Earlier quoted context omitted.

>almost no one uses desktop for critical stuff like payment or finance. I'm not saying this is wrong (in fact I assume it is accurate), but relative to my life experience this is crazy to me.

Worked on some financial stuff before, and dashboards showed the opposite of your experience, if I’ll be honest. An average user is very different from us.

Financially savvy people are much more likely to have a desktop, I would think.

Mu mother-in-law does not have a laptop or desktop. She barely uses her iPad. If it’s not on the phone, it might as well not exist. My father-in-law has a PC at work and a Mac laptop, but he uses them only for work - his casual internet use is entirely on the phone. My wife uses multiple iPads and her phone, but only uses a desktop at work or when working at home.

Most people I know don’t actually own personal computers other than their phone or tablet.

Re: Samsung embeds IronSource spyware app on phones across WANA

#275
post #215

Earlier quoted context omitted.

> Devices should be allowed to display a different logo at boot time depending on whether the software is manufacturer-approved or not. Not sure how to phase this legally, but please also add a provision against manufacturers making the "custom firmware" logo hideously ugly on purpose to discourage rooting - like e.g.Microsoft did for Surface tablets. > 3. Users should have the ability to opt themselves into cryptogr…

Someone with the motivation to install custom firmware would consider the bootsplash aesthetic a deal breaker?

If you want to promote alternative bootloaders or OSes for wider, nontechnical audiences (like LineageOS etc), then absolutely.

I think it's a difference in mindset whether you view custom firmware as a grudging exception for techies (with the understanding that "normal" people should have a device under full control of their respective vendor), or whether you want an open OS ecosystem for everyone.

Re: Samsung embeds IronSource spyware app on phones across WANA

#276
post #180

Earlier quoted context omitted.

Computer usage and consequently threat landscape went through a crazy change from 40/50 years ago. Desktops are a minority of devices. If you take personal devices even more so. Most people in the world with a computer have just a pocket one. Especially in WANA countries discussed If you talk to regular non IT savvy people many of them don't bother and correctly assume that at some point it will "get a virus" or some…

> almost no one uses desktop for critical stuff like payment or finance What? This makes no sense. For something where security matters, using the desktop is the only rational choice. I never, ever, allow any sensitive information through the phone since it is not a trusted device.

And yet it is the truth.

Re: Samsung embeds IronSource spyware app on phones across WANA

#277
post #215

Earlier quoted context omitted.

> Devices should be allowed to display a different logo at boot time depending on whether the software is manufacturer-approved or not. Not sure how to phase this legally, but please also add a provision against manufacturers making the "custom firmware" logo hideously ugly on purpose to discourage rooting - like e.g.Microsoft did for Surface tablets. > 3. Users should have the ability to opt themselves into cryptogr…

Someone with the motivation to install custom firmware would consider the bootsplash aesthetic a deal breaker?

Yes -- bootsplash showing "DANGER! YOUR SECURITY AT RISK! HACKERS CAN NOW STEAL YOUR GIRLFRIEND AND SHUFFLE YOUR PAIRS OF SOCKS!" in big bold red letters only because you enabled root to remove manufacturer malware (which if anything likely _increases_ your security) is a deal breaker, because it will frighten most users from doing it .

Re: Samsung embeds IronSource spyware app on phones across WANA

#278

Earlier quoted context omitted.

We need regulation which defines that any hardware device capable of running software developed by a third party different from the hardware manufacturer qualifies as a general purpose computing device, and that any such device is disallowed to put cryptographic or other restrictions on what software the user wants to execute. This pertains to all programmable components on the device, including low-level hardware co…

While I agree in theory, this is never going to happen. There's too much DRM in use for it to work out.

What there are is many people utterly convinced that this brings some security to end-users. See the other messages in this thread. DRM is only a fraction of the problem.

Re: Samsung embeds IronSource spyware app on phones across WANA

#279

Earlier quoted context omitted.

It creates a Hobson's choice of no tinkering and less malware, or tinkering and greater risks from malware. There should be a "maintenance mode", but the onus of responsibility for breakage should be on the user for system update compatibility without the user being held hostage. This is a false choice and ostensible customizability. If the manufacturer wants to add an "OS warranty void sticker" flag because things m…

It is my experience that this is what Google does with their Pixel phones. It is really quite simple to unlock the bootloader and do whatever you want on a Google Pixel you own (i.e unlocked, no carrier). They even give you this really handy Android flash tool which uses WebUSB to fully restore your device when you mess up. Heck, custom ROMs like GrapheneOS and CalyxOS are even able to sign their own images and allow…

Nice. I wish Pixels (and recent iPhones Pros) were more repairable. Pixels are the least repairable phone around, so don't drop it at least not without a rugged case. ;)

Re: Samsung embeds IronSource spyware app on phones across WANA

#280
post #229

This article has basically no technical details and scant evidence for the claims made by the authors. It's rage bait that is intended for emotional reaction rather than a curious and intelligent analysis.

I think this is an open letter addressed to Samsung, not an article trying to convince readers... Perhaps, the takeaway can be the call for transparency as a minimum ?
Post reply on HN