Live data from Hacker News

Lithuania says throw away Chinese phones due to censorship concerns

reuters.com

331–340 of 427 posts

Re: Lithuania says throw away Chinese phones due to censorship concerns

#331

Earlier quoted context omitted.

> Restrict apps, but can still log in via browser. This isn't paradoxical. You treat the browser as a less trusted security domain than a phone, which usually has a secure boot chain, strong sandboxing, encrypted disk, reliable hardware cryptography etc, and therefore provide a different/better service on the phone. If a phone is missing one of these expected components then you're not the target market for the app,…

I disagree. My main bank allows several high-risk actions to be performed when logged in from a web browser, which are entirely impossible from the mobile banking app. It's completely ridiculous that I can't use my mobile banking app for day to day low risk, low volume transactions if my phone is rooted, yet I can do anything and everything with high values of cash and credit from a Linux machine running any web brow…

> The reality is, the mobile app development is outsourced to incompetent teams for presumably the lowest price who "ensure security" by just saying, "lets chuck a library in that prevents running if the device is detected as being rooted, and call it a day".

I don't understand, why people think so. Banks hire good developers. They don't pay them well (by banks' own standards), but they still pay enough to hire competent programmers.

Unfortunately, working in bank is highly competitive environment, that fosters sycophants and rewards socially adept people, good at obeying orders to letter. Who cares, what the programmers think, they are at the bottom of command chain anyway.

The fraud prevention is often split into it's own department. As for "computer security" department, it is a fang-less security circus, that exists to satisfy PCI DSS. In some banks it outright pretends, that web sites and mobile apps don't exist. All your data will be processed in "secure server enclave", managed by "certified professionals", while sending hashes of credit card numbers to Google Analytics.

Re: Lithuania says throw away Chinese phones due to censorship concerns

#332

Earlier quoted context omitted.

It probably will never be. It just takes one OEM to fuck it up and everyone can use their device ID. That's why hardware backed attestation doesn't work, OnePlus fucked it up and now Magisk can pretend to be that phone and get exempted.

Interesting, I use OnePlus phones, where can I read more about this?

https://www.synopsys.com/blogs/software-security/cve-2020-79...

Re: Lithuania says throw away Chinese phones due to censorship concerns

#333

Earlier quoted context omitted.

Which cell network, in which country? What protocol are those packets going to travel over, what is their destination, and how do they get routed?

The exact same protocol and route as any normal packets - I'd presume that for a phone it's just as for computer network hardware, that OS is not in full control of the IP stack and the firmware can send extra packets that OS won't see (with the same source/routing as configured by the OS after it does it) and process the response packets without propagating them to where the OS might see them.

You would be able to detect those packets then - like if your phone is connected to your home WiFi router.

Re: Lithuania says throw away Chinese phones due to censorship concerns

#334
post #152

From the shared PDF page 23... "It has been established that during the initialisation of the system applications factory-installed on a Xiaomi Mi 10T device, these applications contact a server in Singapore at the address globalapi.ad.xiaomi.com (IP address 47.241.69.153) and download the JSON file MiAdBlacklistConfig, and save this file in the metadata catalogues of the applications. A list of applications for whic…

Is it me or is this an extremely clumsy way of doing censorship? Why not do this at network or server-side level? Why not use some kind of hash (ala Apple'e proposed child pornography hunter)? In this design, everyone would have to have this plain text configuration file ... also other brands (Oppo, Huawei etc.) would have to have it. What if it needs an update? Suppose the hui muslims starts causing trouble ... Or i…

Would people stop calling attention to the fact censorship systems are inherently broken/trivially circumventable?

Last thing we need is to trigger someone into making a better mousetrap.

Re: Lithuania says throw away Chinese phones due to censorship concerns

#335

Earlier quoted context omitted.

> the sophistication of their implementation is bound to increase You're right about this, including with backdoors. Electronics from China must be treated as treacherous computing devices that obey the orders of the Chinese Communist Party. If the West was sensible, we simply wouldn't buy any electronics from them.

Or manufacturer any product from there...why does the world continue to be stupid on China and pump up their economy by having the majority of their goods manufactured there? Its going to continue to bite us and everyone in the butt.

> why does the world continue to be stupid on China and pump up their economy by having the majority of their goods manufactured there?

Because big companies make lots of profits from it, I imagine.

> Its going to continue to bite us and everyone in the butt.

Yes, unless we change our ways.

Re: Lithuania says throw away Chinese phones due to censorship concerns

#336
post #152

From the shared PDF page 23... "It has been established that during the initialisation of the system applications factory-installed on a Xiaomi Mi 10T device, these applications contact a server in Singapore at the address globalapi.ad.xiaomi.com (IP address 47.241.69.153) and download the JSON file MiAdBlacklistConfig, and save this file in the metadata catalogues of the applications. A list of applications for whic…

This is pretty clearly a low-effort filter for advertisements deemed political. > 204 "人民报", “People’s daily newspaper” People's Daily is an official Communist Party newspaper... Why on earth would they blocklist that if this is a politically-motivated censorship program (as the paper/many here are implying)?

Talk about sticking your head in the sand. Pretty clearly that's not what it is at all.

Re: Lithuania says throw away Chinese phones due to censorship concerns

#337
post #308

Earlier quoted context omitted.

You are more powerful than you may realize. Work on supporting open source hardware and software options. 1. If you are a developer, consider buying a Pinephone [1] and contributing to the codebase. 2. If not a developer, you can submit bug reports and test fixes. Same for Purism Librem phone as well [2]. 3. If you are neither, or have no time to spare but do have money, you can always purchase one for kicks or donat…

Biggest missing piece in all these "free" phones is giant (bigger than Linux kernel) baseband firmware blob. Until we have something like Osmocom but for LTE, LTE-A, 5G, etc, all this is pointless.

> something like Osmocom but for LTE, LTE-A, 5G, etc

We already do. SrsRAN[1] UE and OpenAirInterface.

[1] https://www.srslte.com/

Re: Lithuania says throw away Chinese phones due to censorship concerns

#338

Are there any good non-Chinese smartphone besides Samsung? Preferably someone who delivers a stock android?

Consider the Gigaset GS4 or one of their older devices. The GS4 is not currently rooted afaik but some of their older devices (GS290?) are supported by (edit)e.foundation [1] and etc. As an additional benefit, they are made in Germany (though the origin of the parts is probably not exclusively German I guess.)

[1] https://doc.e.foundation/devices

Re: Lithuania says throw away Chinese phones due to censorship concerns

#339

Earlier quoted context omitted.

The exact same protocol and route as any normal packets - I'd presume that for a phone it's just as for computer network hardware, that OS is not in full control of the IP stack and the firmware can send extra packets that OS won't see (with the same source/routing as configured by the OS after it does it) and process the response packets without propagating them to where the OS might see them.

You would be able to detect those packets then - like if your phone is connected to your home WiFi router.

Well no, if the baseband firmware sends that then only the cell operator would see them, there's no user-controlled software or hardware between the chip and the mobile operator (like the router in the wifi scenario) unless you run your own 4G cell and record packets there. Just as for your laptop, if your ethernet firmware would be malicious in this way then it would apply only to the ethernet adapter and not any other network adapters like wifi.

Re: Lithuania says throw away Chinese phones due to censorship concerns

#340
post #152

From the shared PDF page 23... "It has been established that during the initialisation of the system applications factory-installed on a Xiaomi Mi 10T device, these applications contact a server in Singapore at the address globalapi.ad.xiaomi.com (IP address 47.241.69.153) and download the JSON file MiAdBlacklistConfig, and save this file in the metadata catalogues of the applications. A list of applications for whic…

Is it me or is this an extremely clumsy way of doing censorship? Why not do this at network or server-side level? Why not use some kind of hash (ala Apple'e proposed child pornography hunter)? In this design, everyone would have to have this plain text configuration file ... also other brands (Oppo, Huawei etc.) would have to have it. What if it needs an update? Suppose the hui muslims starts causing trouble ... Or i…

[deleted]
Post reply on HN