Live data from Hacker News

Massachusetts health notifications app installed without users’ knowledge

play.google.com

331–340 of 407 posts

Re: Massachusetts health notifications app installed without users’ knowledge

#331
post #326
post #261

I was reading about this yesterday and confirmed that I did not have gov.ma.covid19.exposurenotifications.v3 nor gov.ma.covid19.exposurenotifications installed. I turned off auto-updates in the Play store (Settings -> Network preferences -> Auto update apps -> Don't auto update apps) and went to sleep. This morning I woke up with a cheerful notification that Google can help with COVID notifications and gov.ma.covid19…

Remember when Tim Cook put Bono's album in the iTunes library of everybody? That's when it felt that the smartphones are not our devices. Someone you don't know can and U2 album to your library without you ask for it or being able to do anything about it. You can understand it with an OS update. It's the new shiny thing that comes with bunch of stuff and this new one has this new app. However, getting it without acti…

Omg are you serious?! I have forever wondered how the heck I somehow managed to get the U2 album on my phone. I used to put a lot of music on my phone and assumed I did it by accident some how even though I didn’t own the U2 album (I used to download a lot of music back then so assumed did by accident). That solves a crazy long lived mystery on my end thank you. I don’t even know how I feel about that now. I don’t like that they can push things to my device. What is next photos? If someone can just insert data into a phone how can we in a court of law accept that it wasn’t false? I really hope some follow up on how this happened comes out.

Re: Massachusetts health notifications app installed without users’ knowledge

#332

Earlier quoted context omitted.

It's pure madness that Play Services comes with this sort of backdoor. This is clearly what I would consider a deliberate RCE vulnerability.

Somebody that's affected by this should report it as a remote code execution vulnerability in the PlayStore app.

I'm not affected by this, but that's an interesting idea. I wonder what'll happen if I report this (assuming Google has a place to report vulnerabilities in its products). They'd probably dismiss it as "invalid" because, see, it's not an RCE if it's only exploited by a "trusted party" like Google themselves.

Re: Massachusetts health notifications app installed without users’ knowledge

#333
post #93
post #84

Earlier quoted context omitted.

This sounds worse to me? Rather than violation of a relatively small privacy (phone number), you instead get timestamp social graph interactions in the physical world. This seems like fat more extreme an invasion than the former.

The whole protocol was designed very cleverly from the start to avoid all the privacy blocks that might inhibit people from using it [1], because the main drawback in this is that it's completely useless unless you have a critical mass of users that actually use it. It is very difficult to explain to people that are not curious about the technology and all they hear is 'tracing = tracking = no privacy'. I imagine thi…

>It is very difficult to explain to people that are not curious about the technology and all they hear is 'tracing = tracking = no privacy'.

But this is literally true. This is an app pushed to people remotely without their consent or even knowledge. People cannot trust the claim that there is no privacy gotcha involved in this, especially when previous attempts seem to have opened the log of this information to all installed apps:

https://themarkup.org/privacy/2021/04/27/google-promised-its...

You cannot trust them when they say that the app respects your privacy.

Re: Massachusetts health notifications app installed without users’ knowledge

#334
post #331
post #326

Earlier quoted context omitted.

Remember when Tim Cook put Bono's album in the iTunes library of everybody? That's when it felt that the smartphones are not our devices. Someone you don't know can and U2 album to your library without you ask for it or being able to do anything about it. You can understand it with an OS update. It's the new shiny thing that comes with bunch of stuff and this new one has this new app. However, getting it without acti…

Omg are you serious?! I have forever wondered how the heck I somehow managed to get the U2 album on my phone. I used to put a lot of music on my phone and assumed I did it by accident some how even though I didn’t own the U2 album (I used to download a lot of music back then so assumed did by accident). That solves a crazy long lived mystery on my end thank you. I don’t even know how I feel about that now. I don’t li…

Oh yeah: https://www.cbsnews.com/news/is-apples-free-u2-gift-a-sign-o...

If was very creepy to have an album injected in my library. A socially inept blunder that I bet Steve Jobs would have never done.

By the way, I can't believe he has died 10 years ago. It feels so recent.

Re: Massachusetts health notifications app installed without users’ knowledge

#335
post #310
post #132

Earlier quoted context omitted.

>google play services is actively listening for remote installation requests? Uh, yes? That is and always has been core functionality. You can click "install" on the Google Play website on your laptop and the app will magically appear on your phone, if both devices are signed in to Google. I triggered this behavior accidentally a good 10 years ago when I got my first Android phone, and it gave me the shivers - it rea…

That's not the behaviour of what happened here, where an app was downloaded without user initiation or intervention. There was no authorization from the user of the actions that were taken by Google or the app's vendor.

From a technical standpoint, it is the same. The phone maintains a connection to a Google server and listens for "authorized" installation requests - where "authorized" means "authorized by Google". When you click "install" on the Play Store on your laptop, you're not talking directly to your phone (how would that even work?) - you're talking to Google, who then speaks to your phone on your behalf.

Re: Massachusetts health notifications app installed without users’ knowledge

#336
post #22

Earlier quoted context omitted.

Why do this at this late date? A year ago it would have been useful. Now, 59% of Massachusetts's population has been fully vaccinated. About 70% have at least one shot. A bit more pushing and they'll hit 80%, which seems to be about where the epidemic dies out for lack of new carriers.

> Why do this at this late date? A year ago it would have been useful. Because it took time to develop, and now they just shipped it? Maybe if the US had had a functional federal government prior to January then a national exposure notification app might have been developed, rather than relying on the states to do their own thing. Or not. But it's too late now. I'm not a USAian so I don't know what the take-up of a f…

that I've never had an alert from it despite living in a region with high covid incidence has been reassuring.

Hm. Mandatory XKCD: https://imgs.xkcd.com/comics/tornadoguard.png

Re: Massachusetts health notifications app installed without users’ knowledge

#337
post #261

I was reading about this yesterday and confirmed that I did not have gov.ma.covid19.exposurenotifications.v3 nor gov.ma.covid19.exposurenotifications installed. I turned off auto-updates in the Play store (Settings -> Network preferences -> Auto update apps -> Don't auto update apps) and went to sleep. This morning I woke up with a cheerful notification that Google can help with COVID notifications and gov.ma.covid19…

It's pure madness that Play Services comes with this sort of backdoor. This is clearly what I would consider a deliberate RCE vulnerability.

It doesn't "come with" this backdoor. It is this backdoor. Maintaining a connection with the Google mothership is, approximately, Play Service's entire function.

Re: Massachusetts health notifications app installed without users’ knowledge

#338
post #335
post #310

Earlier quoted context omitted.

That's not the behaviour of what happened here, where an app was downloaded without user initiation or intervention. There was no authorization from the user of the actions that were taken by Google or the app's vendor.

From a technical standpoint, it is the same. The phone maintains a connection to a Google server and listens for "authorized" installation requests - where "authorized" means "authorized by Google". When you click "install" on the Play Store on your laptop, you're not talking directly to your phone (how would that even work?) - you're talking to Google, who then speaks to your phone on your behalf.

it could work with google cloud providing oauth and the phone verifying it's the same account.

Re: Massachusetts health notifications app installed without users’ knowledge

#339

Earlier quoted context omitted.

No different than, say, "Windows Update". The entire "updates" culture is essentially RCE backdoor (botnet) functionality for "trusted" tech companies. Consent, where it is actually explicitly obtained, never rises to the level of "informed". That's because even if a user "consents", she still cannot see what is in each update.

WU allows hardware manufacturers to silently install literally anything based on hardware ID matching and the only way to prevent that is to disable WU driver updates entirely (via GPC/registry). In my case the maker of my motherboard installed a persistent “self-repairing” (i.e. difficult to uninstall) from yet another third party. Naturally, I will not buy a product from them (MSI) again. Another way to put this is…

You can probably turn that off from the BIOS. It's (unfortunately) pretty common these days, MSI isn't special for doing this.

It's a different mechanism from Windows automatically loading drivers and/or the vendor's malware when you plug in a device.

Re: Massachusetts health notifications app installed without users’ knowledge

#340

I emailed massnotifyhelp@mass.gov to ask why the app was on my phone, and I got the following response: Hi [my name], In order for MassNotify to be available to users in their phone’s settings, an update was made by Google that resulted in some users seeing MassNotify appear in their app list in the Google Play Store. Apologies if this caused any confusion. The appearance of MassNotify in the app list does not mean t…

This raises an interesting point. Android subdivides much of its core functionality into various hidden "apps". Everyone's all up in arms about this, but I don't remember a similar outcry when the Covid-19 exposure API was "forcibly" added to the Google Services Framework. This isn't really any different from that, or any other OS update. I naturally agree that Google's remote-root is creepy and weird, but why is this the thing that's put a bee in everyone's bonnet? Is it just that an app in the app list is more visible? Won't this outcry merely encourage them to do things the less-visible way?
Post reply on HN