Live data from Hacker News

Samsung embeds IronSource spyware app on phones across WANA

smex.org

301–310 of 500 posts

Re: Samsung embeds IronSource spyware app on phones across WANA

#301

Earlier quoted context omitted.

> if I buy something then I own it. That's the point: you can't buy it, only license.

I've never had to license hardware I've bought, only software. There's no way I do so.

I'm not saying it's a good thing. But we shouldn't hide from the fact that door has been opened and I see no practical reason we won't see more of it.

The minute Apple sees a clear path to get away with it, iPhone will essentially become licensed devices.

Then other phone makers will jump through the opening, at some point it becomes the standard, and we'll laugh at the "voting with your wallet" joke again.

> software

We're already full in licensing books, as truly the most pragmatic choice. Amazon opened the door, and many other ebook stores have jumped on the bandwagon.

Re: Samsung embeds IronSource spyware app on phones across WANA

#302
post #182

AppCloud, developed by the controversial Israeli-founded company ironSource (now owned by the American company Unity) Yes the Unity 3D engine company wow.

The weirdest part of that merger was Unity paid $4.4billion for IronSource.

ironsource was the owner and runner of the largest sleazy game ad network, which was unity specific

unity was dying for lack of revenue

Re: Samsung embeds IronSource spyware app on phones across WANA

#303
post #251

Earlier quoted context omitted.

The truth is far outside the Overton window. Yes, privacy is a question of civil defense in the drone age. But the existing crop of states will never acknowledge that; their structure and institutions presume precisely the kind of mass databases of PII that create this vulnerability, as well as institutional transparency for public accountability. This makes them structurally vulnerable to insurgencies that expropria…

I used to feel this way until I learned about counter-UAS tech.

That's wishful thinking. Flying drones aren't the only threat, or the main threat, and there isn't such a thing as "counter-UAS tech", only counter-yesterday's-UAS tech. Radio jamming was "counter-UAS tech" until the mass production of fiber-optic-controlled FPV drones starting five months ago, for example. You can still find vendors marketing it as such.

30 milligrams of high explosive is enough to open your daughter's skull, or, more relevantly, your commanding officer's daughter's skull, and there are a thousand ways to deliver it to her if she can be tracked: in pager batteries, crawling, swimming, floating, waiting for ambush, hitchhiking on migratory birds, hitchhiking on car undercarriages, in her Amazon Prime deliveries, falling from a hydrogen balloon in the mesosphere, and so on. And if 30mg is too much, 2mg of ricin on a mechanical ovipositor will do just as well.

All of this is technically possible today without any new discoveries. At this point it's a straightforward systems development exercise. And you can be sure that there are bad people working for multiple different countries' spy agencies who know this; they don't need me to tell them.

Re: Samsung embeds IronSource spyware app on phones across WANA

#304

I suspect a strong link between mass surveillance (by corporations for advertising or by states for intelligence purposes) and the very recent targeting of the senior Iranian nuclear scientist and military officers at their homes in Iran. Wherever you are from or whatever side of the conflict you are on, I think we can all agree that it’s never been easier to infer so much about a person from “semi-public” sources su…

I suspect Israel has backdoor access to most CPUs. Here is how Pegasus seems: - China has 1.5 billion people, lots of resources, would profit a lot economically if they found a way to hack iOS, etc. But yet couldn't hack it. - Israel with its 7 million people, not only hacks iOS multiple times, but does it to spy on its allies. Now I've seen the threads analysing Pegasus' complexity, I don't know if it's been reprodu…

> Here is how Pegasus seems: - China has 1.5 billion people, lots of resources, would profit a lot economically if they found a way to hack iOS, etc. But yet couldn't hack it.

That you know of. Maybe they just don't indiscriminately sell the results to anybody who shows they have money. Or maybe they have different strategies for spying.

> - Israel with its 7 million people, not only hacks iOS multiple times,

NSO and friends find zero-days or buy them on the open market (not just from Israel). Citizen Lab has identified specific vulnerabilities used to install Pegasus. The exploits don't require or use CPU back doors.

... and you think Israel's smaller population somehow translates into better infiltrators than China has, but not better hackers than China has? Israel also makes better halva than China, by the way.

That kind of "logic" is what turns you into a loony raving on a street corner somewhere.

> but does it to spy on its allies.

Everybody spies on their allies, at least opportunistically. But Pegasus is a commercial product, sold to basically every government and mostly used to spy on normal people, not other governments. The people writing it have ties to Israeli spies, and I'm sure it's been used by Israeli spies, but it's general-purpose.

> Israel has a lot of silicon fabs

As far as I can tell, Israel has one facility capable of making remotely serious CPUs. It's owned by Intel. There are no phones using Intel processors.

The processors in iPhones are "Designed by Apple in Cupertino" and fabbed by TSMC in Taiwan. The processors in basically all other phones are ARM, and most of them also come from TSMC. Pegasus does not run on Intel processors, ever.

> And I compared the dates of when intel started putting the Intel Management Engine in all of their CPU and the date of which they built their biggest fab in Israel

So the fab somehow reached out into the rest of Intel and retroactively caused it to develop a heavily advertised feature?

Re: Samsung embeds IronSource spyware app on phones across WANA

#305
post #230

making it nearly impossible for regular users to uninstall it without root access, which voids warranties and poses security risks Stop parroting the corporate propaganda that put us into this stupid situation in the first place. Having root access on devices you own should be a fundamental right, as otherwise it's not ownership.

Even though you seem to have a lot of support on Hacker News, I don't think making root access a fundamental right is preferable. Historically, computers have not granted you access to everything. Most home computers used to have ROM cartridges, which could not be modified, at least not by an average user. Also, when using unrestricted operating systems, such as as MS-DOS, a simple virus could wipe all your hard work…

Why? What is the reason root would be dangerous, if it's not the default? People can be scammed to activate it, but those same people can be scammed to click links and give passwords and personal data. Any action requiring root would need a warning and raise suspicion, or put behind an activation mechanism that's complex enough.

Anything else and you lose freedom, and the whole ethos that enabled the advanced IT landscape of today.

Re: Samsung embeds IronSource spyware app on phones across WANA

#306
post #199

making it nearly impossible for regular users to uninstall it without root access, which voids warranties and poses security risks Stop parroting the corporate propaganda that put us into this stupid situation in the first place. Having root access on devices you own should be a fundamental right, as otherwise it's not ownership.

My grandma should not have root on her phone and a lot of younger people as well. Making it easy to root phone makes it easy for scammers to ask people to unlock it. It should not void warranty if you unlock the phone. But security concerns are real. Mobile banking apps refuse to run on rooted phones.

The same people can be scammed to give passwords, click links, perform any human action, so what's the difference besides giving up yet another freedom?

Re: Samsung embeds IronSource spyware app on phones across WANA

#307

Earlier quoted context omitted.

"How can you hold a manufacturer liable if the user was given unsupervised time as root?" PCs had root access by default, so why wasn't it a significant problem for them? Banking is possible on a PC without a banking app. As Noam Chomsky has said, as in politics, manufacturers and OS vendors such as Google and Microsoft have been deliberately "manufacturing concent" — a widespread belief in the population of users th…

Manufactured consent requires media complicity to achieve acceptance of Hobson's choice Accept or Don't Use EULAs and corporate, technofeudal non-ownership and the "shame" of specialized knowledge, tinkering, and modifying things. Nerds were frowned upon until electronics and software people became billionaires in the 80's, and technical vocations are still frowned upon in socially most of America. PS: While he maybe…

"Manufactured consent requires media complicity to achieve acceptance of Hobson's choice Accept or Don't"

Right, I've never fully understood why the media was (and still is) so complicit. There's a long history of the media, especially the tech media, mags etc. ass-licking the likes of Microsoft, Google et al. It's been horrible sight to watch over the decades. Perhaps it's because of kickbacks, fear of exclusion from events, press releases, or handouts—free software etc., or that many had/have shares in such entities—or the belief that those who run such entities are only one step removed from the gods—hero worshiping.

We users would now be in a damn side better prosition if the media had done its job professionally.

"technical vocations are still frowned upon in socially most of America."

Right again, and America is not the only place, such thought is endemic across the anglosphere.

Re: Samsung embeds IronSource spyware app on phones across WANA

#308

Earlier quoted context omitted.

Changing from SK to CN is a trade from intentional vulnerability to unintentional vulnerability. I’ve yet to see a secure piece of software come out of China in my 30+ years of coding.

Brother you cannot be serious with this racist take

Saying that a culture is poor at security dev, such as Chinese business culture, is not even remotely rasist.

There are many ethnicities in China, people of all genetic backgrounds. It is the culture that is the problem, not the race.

For example, there are many ethnically Chinese people who grew up in the West, working in businesses, in countries where there is a culture of security.

Now, you could label it 'culturalist', and maybe it is, but there are definitely inferior and superior cultures. Especially, there are parts of cultures which are quite comparable this way.

Re: Samsung embeds IronSource spyware app on phones across WANA

#309
post #303

Earlier quoted context omitted.

I used to feel this way until I learned about counter-UAS tech.

That's wishful thinking. Flying drones aren't the only threat, or the main threat, and there isn't such a thing as "counter-UAS tech", only counter-yesterday's-UAS tech. Radio jamming was "counter-UAS tech" until the mass production of fiber-optic-controlled FPV drones starting five months ago, for example. You can still find vendors marketing it as such. 30 milligrams of high explosive is enough to open your daughte…

> 30 milligrams of high explosive is enough to open your daughter's skull, or, more relevantly, your commanding officer's daughter's skull, and there are a thousand ways to deliver it

While we are talking about flying drones, we are not far off from Slaughterbots becoming reality.[0] Why bother with surgical assassinations if you can blanket entire regions with with swarms of autonomous seek-and-destroy explosives?

After all, as last two years have so amply demonstrated: people are fine with genocide.

0: https://www.youtube.com/watch?v=O-2tpwW0kmU

Re: Samsung embeds IronSource spyware app on phones across WANA

#310

Earlier quoted context omitted.

Changing from SK to CN is a trade from intentional vulnerability to unintentional vulnerability. I’ve yet to see a secure piece of software come out of China in my 30+ years of coding.

Brother you cannot be serious with this racist take

is it racist to wonder why I rarely see a chinese restaurant with inspection score above 80? culture differences are a real thing (if you don't have your head buried in the sand that is).
Post reply on HN