I was reading about this yesterday and confirmed that I did not have gov.ma.covid19.exposurenotifications.v3 nor gov.ma.covid19.exposurenotifications installed. I turned off auto-updates in the Play store (Settings -> Network preferences -> Auto update apps -> Don't auto update apps) and went to sleep. This morning I woke up with a cheerful notification that Google can help with COVID notifications and gov.ma.covid19…
Remember when Tim Cook put Bono's album in the iTunes library of everybody? That's when it felt that the smartphones are not our devices. Someone you don't know can and U2 album to your library without you ask for it or being able to do anything about it. You can understand it with an OS update. It's the new shiny thing that comes with bunch of stuff and this new one has this new app. However, getting it without acti…
Massachusetts health notifications app installed without users’ knowledge
331–340 of 407 posts
Re: Massachusetts health notifications app installed without users’ knowledge
#332Earlier quoted context omitted.
It's pure madness that Play Services comes with this sort of backdoor. This is clearly what I would consider a deliberate RCE vulnerability.
Somebody that's affected by this should report it as a remote code execution vulnerability in the PlayStore app.
Re: Massachusetts health notifications app installed without users’ knowledge
#333Earlier quoted context omitted.
This sounds worse to me? Rather than violation of a relatively small privacy (phone number), you instead get timestamp social graph interactions in the physical world. This seems like fat more extreme an invasion than the former.
The whole protocol was designed very cleverly from the start to avoid all the privacy blocks that might inhibit people from using it [1], because the main drawback in this is that it's completely useless unless you have a critical mass of users that actually use it. It is very difficult to explain to people that are not curious about the technology and all they hear is 'tracing = tracking = no privacy'. I imagine thi…
But this is literally true. This is an app pushed to people remotely without their consent or even knowledge. People cannot trust the claim that there is no privacy gotcha involved in this, especially when previous attempts seem to have opened the log of this information to all installed apps:
https://themarkup.org/privacy/2021/04/27/google-promised-its...
You cannot trust them when they say that the app respects your privacy.
Re: Massachusetts health notifications app installed without users’ knowledge
#334Earlier quoted context omitted.
Remember when Tim Cook put Bono's album in the iTunes library of everybody? That's when it felt that the smartphones are not our devices. Someone you don't know can and U2 album to your library without you ask for it or being able to do anything about it. You can understand it with an OS update. It's the new shiny thing that comes with bunch of stuff and this new one has this new app. However, getting it without acti…
Omg are you serious?! I have forever wondered how the heck I somehow managed to get the U2 album on my phone. I used to put a lot of music on my phone and assumed I did it by accident some how even though I didn’t own the U2 album (I used to download a lot of music back then so assumed did by accident). That solves a crazy long lived mystery on my end thank you. I don’t even know how I feel about that now. I don’t li…
If was very creepy to have an album injected in my library. A socially inept blunder that I bet Steve Jobs would have never done.
By the way, I can't believe he has died 10 years ago. It feels so recent.
Re: Massachusetts health notifications app installed without users’ knowledge
#335Earlier quoted context omitted.
>google play services is actively listening for remote installation requests? Uh, yes? That is and always has been core functionality. You can click "install" on the Google Play website on your laptop and the app will magically appear on your phone, if both devices are signed in to Google. I triggered this behavior accidentally a good 10 years ago when I got my first Android phone, and it gave me the shivers - it rea…
That's not the behaviour of what happened here, where an app was downloaded without user initiation or intervention. There was no authorization from the user of the actions that were taken by Google or the app's vendor.
Re: Massachusetts health notifications app installed without users’ knowledge
#336Earlier quoted context omitted.
Why do this at this late date? A year ago it would have been useful. Now, 59% of Massachusetts's population has been fully vaccinated. About 70% have at least one shot. A bit more pushing and they'll hit 80%, which seems to be about where the epidemic dies out for lack of new carriers.
> Why do this at this late date? A year ago it would have been useful. Because it took time to develop, and now they just shipped it? Maybe if the US had had a functional federal government prior to January then a national exposure notification app might have been developed, rather than relying on the states to do their own thing. Or not. But it's too late now. I'm not a USAian so I don't know what the take-up of a f…
Hm. Mandatory XKCD: https://imgs.xkcd.com/comics/tornadoguard.png
Re: Massachusetts health notifications app installed without users’ knowledge
#337I was reading about this yesterday and confirmed that I did not have gov.ma.covid19.exposurenotifications.v3 nor gov.ma.covid19.exposurenotifications installed. I turned off auto-updates in the Play store (Settings -> Network preferences -> Auto update apps -> Don't auto update apps) and went to sleep. This morning I woke up with a cheerful notification that Google can help with COVID notifications and gov.ma.covid19…
It's pure madness that Play Services comes with this sort of backdoor. This is clearly what I would consider a deliberate RCE vulnerability.
Re: Massachusetts health notifications app installed without users’ knowledge
#338Earlier quoted context omitted.
That's not the behaviour of what happened here, where an app was downloaded without user initiation or intervention. There was no authorization from the user of the actions that were taken by Google or the app's vendor.
From a technical standpoint, it is the same. The phone maintains a connection to a Google server and listens for "authorized" installation requests - where "authorized" means "authorized by Google". When you click "install" on the Play Store on your laptop, you're not talking directly to your phone (how would that even work?) - you're talking to Google, who then speaks to your phone on your behalf.
Re: Massachusetts health notifications app installed without users’ knowledge
#339Earlier quoted context omitted.
No different than, say, "Windows Update". The entire "updates" culture is essentially RCE backdoor (botnet) functionality for "trusted" tech companies. Consent, where it is actually explicitly obtained, never rises to the level of "informed". That's because even if a user "consents", she still cannot see what is in each update.
WU allows hardware manufacturers to silently install literally anything based on hardware ID matching and the only way to prevent that is to disable WU driver updates entirely (via GPC/registry). In my case the maker of my motherboard installed a persistent “self-repairing” (i.e. difficult to uninstall) from yet another third party. Naturally, I will not buy a product from them (MSI) again. Another way to put this is…
It's a different mechanism from Windows automatically loading drivers and/or the vendor's malware when you plug in a device.
Re: Massachusetts health notifications app installed without users’ knowledge
#340I emailed massnotifyhelp@mass.gov to ask why the app was on my phone, and I got the following response: Hi [my name], In order for MassNotify to be available to users in their phone’s settings, an update was made by Google that resulted in some users seeing MassNotify appear in their app list in the Google Play Store. Apologies if this caused any confusion. The appearance of MassNotify in the app list does not mean t…