Live data from Hacker News

Samsung embeds IronSource spyware app on phones across WANA

smex.org

281–290 of 500 posts

Re: Samsung embeds IronSource spyware app on phones across WANA

#281

Earlier quoted context omitted.

Because Apple blocks everybody else from spying on you but Apple themselves are still perfectly spying on you. And not just that, by disallowing all other apps to get their hands on your data you even tell Apple which data it can sell for a higher price because it's only available via Apple and noons else... Let that sink in.

Let what sink in? Your completely unprovable/unproven conspiracy theory? You are suggesting that Apple is actively tracking you in other apps (apps that aren’t allowed to track you themselves). I find that completely preposterous and a huge risk for Apple to take given their marketing. > Because Apple blocks everybody else from spying on you but Apple themselves are still perfectly spying on you. Extraordinary claims…

I never said they monitor you in 3rd party apps. Don't put words into my mouth.

https://www.apple.com/privacy/labels/

Re: Samsung embeds IronSource spyware app on phones across WANA

#282

I suspect a strong link between mass surveillance (by corporations for advertising or by states for intelligence purposes) and the very recent targeting of the senior Iranian nuclear scientist and military officers at their homes in Iran. Wherever you are from or whatever side of the conflict you are on, I think we can all agree that it’s never been easier to infer so much about a person from “semi-public” sources su…

If you're a valuable enough target, like these Iranians generals/scientists they just need to find you once and then they can continuously track your movements via satellite. They don't need much precision, just which building to level

Re: Samsung embeds IronSource spyware app on phones across WANA

#283

I suspect a strong link between mass surveillance (by corporations for advertising or by states for intelligence purposes) and the very recent targeting of the senior Iranian nuclear scientist and military officers at their homes in Iran. Wherever you are from or whatever side of the conflict you are on, I think we can all agree that it’s never been easier to infer so much about a person from “semi-public” sources su…

I suspect Israel has backdoor access to most CPUs. Here is how Pegasus seems: - China has 1.5 billion people, lots of resources, would profit a lot economically if they found a way to hack iOS, etc. But yet couldn't hack it. - Israel with its 7 million people, not only hacks iOS multiple times, but does it to spy on its allies. Now I've seen the threads analysing Pegasus' complexity, I don't know if it's been reprodu…

> China has 1.5 billion people, lots of resources, would profit a lot economically if they found a way to hack iOS, etc. But yet couldn't hack it.

What makes you think China can't hack iOS?

Re: Samsung embeds IronSource spyware app on phones across WANA

#284

Earlier quoted context omitted.

> There should be a "maintenance mode", but the onus of responsibility for breakage should be on the user for system update compatibility without the user being held hostage Isn’t this just a second device? How can you hold a manufacturer liable if the user was given unsupervised time as root?

"How can you hold a manufacturer liable if the user was given unsupervised time as root?" PCs had root access by default, so why wasn't it a significant problem for them? Banking is possible on a PC without a banking app. As Noam Chomsky has said, as in politics, manufacturers and OS vendors such as Google and Microsoft have been deliberately "manufacturing concent" — a widespread belief in the population of users th…

Manufactured consent requires media complicity to achieve acceptance of Hobson's choice Accept or Don't Use EULAs and corporate, technofeudal non-ownership and the "shame" of specialized knowledge, tinkering, and modifying things. Nerds were frowned upon until electronics and software people became billionaires in the 80's, and technical vocations are still frowned upon in socially most of America.

PS: While he maybe in effectively hospice now, at least he outlived Kissinger.

Re: Samsung embeds IronSource spyware app on phones across WANA

#285
post #219

Earlier quoted context omitted.

4. Apps with special security needs are allowed to detect whether a device is unlocked and can either disable themselves or go into a mode that shifts ALL related liability onto the user. It's not the bank's fault if the user disabled protections and some spyware logs the online banking password or something like that.

I'm pretty sure I'm against this. I could be convinced otherwise by documentation of significant fraud involving compromised devices (especially Android phones) that would have been stopped by a device attestation scheme. I should note Google has such an attestation scheme, and there are reliable defeats for it in most situations given root access. Apps have been able to insist on hardware-backed attestation which ha…

Also, online banking has been a thing for so long on PCs which never had that kind of remote attestation. I also do not believe the security argument, but I believe that the banks believe it.

Re: Samsung embeds IronSource spyware app on phones across WANA

#286

Earlier quoted context omitted.

"How can you hold a manufacturer liable if the user was given unsupervised time as root?" PCs had root access by default, so why wasn't it a significant problem for them? Banking is possible on a PC without a banking app. As Noam Chomsky has said, as in politics, manufacturers and OS vendors such as Google and Microsoft have been deliberately "manufacturing concent" — a widespread belief in the population of users th…

> PCs had root access by default, so why wasn't it a significant problem for them? They weren't networked. They were notoriously buggy. And most importantly, they weren't warrantied [1]. Root should always be an option. But once you root, it's fair for the warranty to be voided. > OS vendors such as Google and Microsoft have been deliberately "manufacturing concent" Nitpick, the propaganda model [2] attempts to descr…

My PCs were homebuilt and networked in 1994. All warranties void, except the hardware. Windows 3.1 and Netscape over 28.8 sucked, but it worked.

Re: Samsung embeds IronSource spyware app on phones across WANA

#288

Because the link is down: https://web.archive.org/web/20250506145643/https://smex.org/... The article leaves out quite a lot about what AppCloud is, but it's essentially how Samsung monetizes their non-flagship device users and can do things like insert installation advertisements into the notification tray, and silently install apps. Personally, if I found this on my device it'd be the final straw to grit my teeth a…

I can assure you that they do the same thing with flagship phones, especially carrier versions of the phones -- speaking from first hand experience. I have seen notifications from apps I have never heard of multiple times.

That's what I have been thinking recently -- given that Samsung is quietly doing these shady things with my phone, and other annoyances like Samsung forcing Galaxy AI on me (try selecting some texts in a browser or webview) which cannot be uninstalled and the terrible Samsung Pay interface, I am questioning my device choice every day.

Re: Samsung embeds IronSource spyware app on phones across WANA

#289

Earlier quoted context omitted.

We need regulation which defines that any hardware device capable of running software developed by a third party different from the hardware manufacturer qualifies as a general purpose computing device, and that any such device is disallowed to put cryptographic or other restrictions on what software the user wants to execute. This pertains to all programmable components on the device, including low-level hardware co…

I agree, but I think three extra conditions would need to be added here. 1. Devices should be allowed to display a different logo at boot time depending on whether the software is manufacturer-approved or not. That way, if somebody sells you an used device with a flashed firmware that steals all your financial data, you have a way to know. 2. Going from approved to unapproved firmware should result in a full device w…

> Devices should be allowed to display a different logo at boot time depending on whether the software is manufacturer-approved or not.

Another thought on that point: Why of all things is manufacturer approval so important? We know manufacturers often don't work for - or even work against - the interests of their end users. Manufacturer approval is not an indicator for security - as evidenced by the OP article.

If anything, we need independent third parties that can vet manufacturer and third party software and can attach their own cryptographic signatures as approval.

Re: Samsung embeds IronSource spyware app on phones across WANA

#290

Earlier quoted context omitted.

Almost all of Iran's cell network system was originally installed by S. Korean firms. They've changed some to Chinese brands, but apparently the compromised S. Korean brands are still around.

Changing from SK to CN is a trade from intentional vulnerability to unintentional vulnerability. I’ve yet to see a secure piece of software come out of China in my 30+ years of coding.

When a security analysis was done of Chinese parts of the Dutch mobile network, that was pretty much the conclusion: Chinese vendors deliver software and components full of vulnerabilities, but none of them seem to be intentional.

Since then there has been a movement to reduce Chinese vendors in general our if security concerns, as well as to improve the security posture of the mobile networks by doing things like "encrypting connections" and "switching away from telnet".

On the other hand, the Chinese managed to break into the US wiretapping system, so it's not like other networks aren't vulnerable either.

Post reply on HN