Live data from Hacker News

Samsung embeds IronSource spyware app on phones across WANA

smex.org

321–330 of 500 posts

Re: Samsung embeds IronSource spyware app on phones across WANA

#321
Not in this field but, if you're willing to sacrifice performance for security (by avoiding closed, western, hardware) how hard would it be to for a group of top hardware and software engineers to make a secure smartphone?

Id gather you could go very far with the following list:

- Proved correct micro kernel

- Encrypted messaging by default

- Encrypted memory

- Encrypted messaging between processes.

- hardware switches for modems, peripherals and battery

Re: Samsung embeds IronSource spyware app on phones across WANA

#322
post #57

Earlier quoted context omitted.

> I suspect a strong link between mass surveillance [...] and the very recent targeting of the senior Iranian nuclear scientist and military officers at their homes in Iran. We all like to imagine this super cool clandestine hacking operation using peoples mobile phones to secretly track people who visit nuclear facilities back to their homes. The much more logical explanation is someone approached a low level employ…

> The much more logical explanation is someone approached a low level employee at the MEAF who turned over a USB stick with the governments org charts and payroll records in exchange for their kids getting a full ride to a prestigious foreign university. If there are spies in foreign countries going around offering life-changing sums of money for USB sticks, which people are accepting is it not also plausible that fo…

Yes, this happens. Industrial espionage is popular.

From what I've seen with bribes, it doesn't even take life-changing amounts of money.

Re: Samsung embeds IronSource spyware app on phones across WANA

#323
post #309
post #303

Earlier quoted context omitted.

That's wishful thinking. Flying drones aren't the only threat, or the main threat, and there isn't such a thing as "counter-UAS tech", only counter-yesterday's-UAS tech. Radio jamming was "counter-UAS tech" until the mass production of fiber-optic-controlled FPV drones starting five months ago, for example. You can still find vendors marketing it as such. 30 milligrams of high explosive is enough to open your daughte…

> 30 milligrams of high explosive is enough to open your daughter's skull, or, more relevantly, your commanding officer's daughter's skull, and there are a thousand ways to deliver it While we are talking about flying drones, we are not far off from Slaughterbots becoming reality.[0] Why bother with surgical assassinations if you can blanket entire regions with with swarms of autonomous seek-and-destroy explosives? A…

Slaughterbots is just the beginning; it's definitely too late to prevent that scenario now.

Why bother? For the same reason to bother with surgical assassinations if you can blanket entire regions with nuclear fireballs. Radioactive wastelands are unprofitable! This is a general problem with genocide: it only gets you land, and since the Green Revolution land is abundant. Protection rackets, on the otehr hand, are highly profitable, but only with some exclusivity; if extortionists multiply, the unique Nash equilibrium is multiple gangs that collectively demand many times the victims' total revenues, resulting in ecological collapse.

More generally, the threat of violence is only effective as a form of coercion when you can credibly withdraw the violence as a reward for compliance. Violence provides no incentive to comply to someone who believes they are just as likely to be a victim whether they comply or not.

But swarms of autonomous seek-and-destroy explosives are plausibly the most effective way to provide that surgical-assassination threat, perhaps combined with poisons, solid penetrators, and/or incendiaries. The Minority Report spiders (not yet technically feasible) or a quadcopter can be enormously more selective than a GBU-57, a Hellfire missile, or even a hand grenade, and can choose to avert their attack at the last millisecond upon the presentation of properly signed do-not-assassinate orders, even if long-distance communication is jammed.

Re: Samsung embeds IronSource spyware app on phones across WANA

#324
post #308

Earlier quoted context omitted.

Brother you cannot be serious with this racist take

Saying that a culture is poor at security dev, such as Chinese business culture, is not even remotely rasist. There are many ethnicities in China, people of all genetic backgrounds. It is the culture that is the problem, not the race. For example, there are many ethnically Chinese people who grew up in the West, working in businesses, in countries where there is a culture of security. Now, you could label it 'cultura…

>>Brother you cannot be serious with this racist take

>There are many ethnicities in China, people of all genetic backgrounds. It is the culture that is the problem, not the race.

This just seems like nitpicking to me. Colloquially most people would classify discrimination based on country of origin, or "culture" (whatever that means) as racism, even if it doesn't meet the technical definition. For instance Trump's travel bans have been called by many as "racist", even though it covers a bunch of countries, and even though the countries are majority muslim, it also excludes major muslim countries like Pakistan and Indonesia.

Re: Samsung embeds IronSource spyware app on phones across WANA

#325
post #8

The "unremovable" part is inaccurate. While you can't completely remove it because it resides on the system partition, you most probably can still disable it with an adb command: adb shell pm uninstall --user 0 com.package.name This command is very powerful as it works for any app, even those that have "disable" greyed out in the settings. I disabled the Galaxy Store on my S9 this way for example.

How would one go about using adb? Motorola, stock Android. Do I need to root my phone for this to work or what are the requirements, or how do I perform it?

Re: Samsung embeds IronSource spyware app on phones across WANA

#326

Earlier quoted context omitted.

But if the system partition could be smaller, other partitions could be larger.

The system partition is made some fixed size, the same way disk partitioning works on PCs, and never resized, because resizing file systems is still a non-trivial task. It often has some free space too to accommodate future system updates. On my 128 GB Pixel 9 Pro, /data is 109 GB. The rest is /system (although `df -h` doesn't show it explicitly, no idea what's up with that) and various other system-related partition…

Yes, but if the phone shipped with less bloatware on the system partition, then maybe that partition would be made smaller initially.

Meaning the user would have access to more of the phone’s advertised storage.

Re: Samsung embeds IronSource spyware app on phones across WANA

#327

Earlier quoted context omitted.

I agree, but I think three extra conditions would need to be added here. 1. Devices should be allowed to display a different logo at boot time depending on whether the software is manufacturer-approved or not. That way, if somebody sells you an used device with a flashed firmware that steals all your financial data, you have a way to know. 2. Going from approved to unapproved firmware should result in a full device w…

4. Apps with special security needs are allowed to detect whether a device is unlocked and can either disable themselves or go into a mode that shifts ALL related liability onto the user. It's not the bank's fault if the user disabled protections and some spyware logs the online banking password or something like that.

My bank app refuses to work on LineageOS, but I can use the web interface just fine which has the exact same UI and functionality as the app. In both the native app and the web app I have to authorize any transactions using my national ID, which for me is a hardware token (the app for my national ID also refuses to run). Why is it somehow insecure to initiate this flow from a native app on LineageOS while it is not insecure to do the exact same via a browser on LineageOS? If the app can be compromised, so can the browser - the bank cannot trust all its browser based clients anyway.

The web app has been running with this security model for decades on PCs, and it has been fine. The whole narrative about remote attestation being necessary to protect users is an evil lie in my opinion, but it is an effective lie which has convinced even knowledgeable IT professionals that taking away device ownership from users is somehow justified.

Re: Samsung embeds IronSource spyware app on phones across WANA

#328

The only thing that is stopping me from switching to an iPhone is file level access and Syncthing - is that a solved issue? Anyone care to share?

Yes, for ~7 years now the Files app has existed. Sandboxing is still a thing.

Möbius Sync and Synctrain are the options for Syncthing. Both work, neither are official (nor is the currently-maintained Syncthing fork for Android).

Re: Samsung embeds IronSource spyware app on phones across WANA

#329
post #8

The "unremovable" part is inaccurate. While you can't completely remove it because it resides on the system partition, you most probably can still disable it with an adb command: adb shell pm uninstall --user 0 com.package.name This command is very powerful as it works for any app, even those that have "disable" greyed out in the settings. I disabled the Galaxy Store on my S9 this way for example.

How would one go about using adb? Motorola, stock Android. Do I need to root my phone for this to work or what are the requirements, or how do I perform it?

1. Install android SDK / android studio on your computer.

2. Plug phone in to computer using USBC cable.

3. Answer prompt on phone granting permission to computer.

4. Run adb commands.

Re: Samsung embeds IronSource spyware app on phones across WANA

#330

I suspect a strong link between mass surveillance (by corporations for advertising or by states for intelligence purposes) and the very recent targeting of the senior Iranian nuclear scientist and military officers at their homes in Iran. Wherever you are from or whatever side of the conflict you are on, I think we can all agree that it’s never been easier to infer so much about a person from “semi-public” sources su…

“hopefully politicians will soon”

The gop is controlled by donors who are mostly free market liberals. Elon won’t let anyone “censor” (regulate) x. The democrats don’t care about national security historically, and it’s not currently an issue their cosmopolitan TikTok loving base cares anything, at all, about. “Security” is something that most democrats I talk to now associate with deportation or military spending, both of which they ferociously hate. Across parties, policy and discourse are reactive. Security requires a proactive orientation that it seems the public sector may structurally lack.

Post reply on HN