Earlier quoted context omitted.
Or just don't get Samsung? I guess I don't know for sure that my phone brand doesn't do anything similar, but it at least hasn't hit the news yet.
All Android phone but pixel ones have bloatware preinstalled. Some are worst, like Xiaomi. If you don’t want bloatware (spyware), it’s either pixel or iPhone.
Samsung embeds IronSource spyware app on phones across WANA
291–300 of 500 posts
Re: Samsung embeds IronSource spyware app on phones across WANA
#292Earlier quoted context omitted.
I'm pretty sure I'm against this. I could be convinced otherwise by documentation of significant fraud involving compromised devices (especially Android phones) that would have been stopped by a device attestation scheme. I should note Google has such an attestation scheme, and there are reliable defeats for it in most situations given root access. Apps have been able to insist on hardware-backed attestation which ha…
Also, online banking has been a thing for so long on PCs which never had that kind of remote attestation. I also do not believe the security argument, but I believe that the banks believe it.
Re: Samsung embeds IronSource spyware app on phones across WANA
#293Earlier quoted context omitted.
Verified Boot isn't merely to thwart Evil Maids, but by and large provide what's known as "Trusted Computing Base". And yes, given the proliferation of smartphones and the nature of sensitive applications built on top, most people, even if they don't realise it, need it.
but by and large provide what's known as "Trusted Computing Base". In other words, DRM. https://en.wikipedia.org/wiki/Trusted_Computing#Criticism (I knew from the beginning that this was known as the Palladium project, and until recently, a search for "Palladium TCG" would find plenty of information about that history, yet now references to that group and its origins in DRM have seemingly disappeared from Google. Mak…
If I want my device to be secure, I want this trust. If I want to sell a copy of my virtual asset to only be used in ways I approve of, I want this trust. You can't have only one of these at the same time, either your device can provide this trust or it cannot. That's not the battle in my view. The battle is to implement this appropriately, such that e.g. if we're representing access control, identity, and ownership, then that representation should match reality. So if I'm said to own a device, the device can and will attest so, and behave accordingly. It's just that instead of that, I'm always somehow just being loaned these things, only have some specified amount of control over these things, and am just a temporary user somehow. That's the issue. And that these systems are not reimplementable, and as such entitlements do not carry around.
Re: Samsung embeds IronSource spyware app on phones across WANA
#294The "unremovable" part is inaccurate. While you can't completely remove it because it resides on the system partition, you most probably can still disable it with an adb command: adb shell pm uninstall --user 0 com.package.name This command is very powerful as it works for any app, even those that have "disable" greyed out in the settings. I disabled the Galaxy Store on my S9 this way for example.
On my 2025 Motorola RAZR 5G, in /product/etc/nondisable are a series of XML files listing carrier and activation apps for Dish Wireless, Tracfone/Verizon Value, T-Mobile, the Amazon App Manager, and two apps provided for finance providers PayJoy (who lock and disable phones for financial product recovery) and one for Claro internally (that operates similar to Payjoy).
Re: Samsung embeds IronSource spyware app on phones across WANA
#295I suspect a strong link between mass surveillance (by corporations for advertising or by states for intelligence purposes) and the very recent targeting of the senior Iranian nuclear scientist and military officers at their homes in Iran. Wherever you are from or whatever side of the conflict you are on, I think we can all agree that it’s never been easier to infer so much about a person from “semi-public” sources su…
The truth is far outside the Overton window. Yes, privacy is a question of civil defense in the drone age. But the existing crop of states will never acknowledge that; their structure and institutions presume precisely the kind of mass databases of PII that create this vulnerability, as well as institutional transparency for public accountability. This makes them structurally vulnerable to insurgencies that expropria…
Re: Samsung embeds IronSource spyware app on phones across WANA
#296Because the link is down: https://web.archive.org/web/20250506145643/https://smex.org/... The article leaves out quite a lot about what AppCloud is, but it's essentially how Samsung monetizes their non-flagship device users and can do things like insert installation advertisements into the notification tray, and silently install apps. Personally, if I found this on my device it'd be the final straw to grit my teeth a…
Their stock android is fine. If you want more privacy, installing e/OS/ is trivial. It blows my mind that anyone is concluding Samsung stuff is worth buying under any circumstances.
Re: Samsung embeds IronSource spyware app on phones across WANA
#297Earlier quoted context omitted.
Changing from SK to CN is a trade from intentional vulnerability to unintentional vulnerability. I’ve yet to see a secure piece of software come out of China in my 30+ years of coding.
When a security analysis was done of Chinese parts of the Dutch mobile network, that was pretty much the conclusion: Chinese vendors deliver software and components full of vulnerabilities, but none of them seem to be intentional. Since then there has been a movement to reduce Chinese vendors in general our if security concerns, as well as to improve the security posture of the mobile networks by doing things like "e…
Plausible deniability.
Re: Samsung embeds IronSource spyware app on phones across WANA
#298Earlier quoted context omitted.
All Android phone but pixel ones have bloatware preinstalled. Some are worst, like Xiaomi. If you don’t want bloatware (spyware), it’s either pixel or iPhone.
The trick is to define "bloatware". Is that known knowns (stuff that's visible), known unknowns (stuff that's added that's not visible), and/or unknown unknowns (stuff added we are pretty sure is there but can't prove)? Apple adds all kinds of carrier-specific crap on every phone, but it's not readily discoverable. Android mfgrs must also because of carrier contracts and country-specific regulatory approval requireme…
Re: Samsung embeds IronSource spyware app on phones across WANA
#299Earlier quoted context omitted.
Almost all of Iran's cell network system was originally installed by S. Korean firms. They've changed some to Chinese brands, but apparently the compromised S. Korean brands are still around.
Changing from SK to CN is a trade from intentional vulnerability to unintentional vulnerability. I’ve yet to see a secure piece of software come out of China in my 30+ years of coding.
Re: Samsung embeds IronSource spyware app on phones across WANA
#300I suspect a strong link between mass surveillance (by corporations for advertising or by states for intelligence purposes) and the very recent targeting of the senior Iranian nuclear scientist and military officers at their homes in Iran. Wherever you are from or whatever side of the conflict you are on, I think we can all agree that it’s never been easier to infer so much about a person from “semi-public” sources su…