Live data from Hacker News

Samsung embeds IronSource spyware app on phones across WANA

smex.org

341–350 of 500 posts

Re: Samsung embeds IronSource spyware app on phones across WANA

#341
post #240

Earlier quoted context omitted.

Words don't just have a literal, technical meaning. If the phone itself doesn't allow a straightforward, user friendly happy-path for removal, it might as well be "unremovable" in a sense that it is indeed unremovable for most users. "adb shell etc" implies that one has a PC with this tool correctly installed, and many people don't even have a PC in the first place. Then comes the case of installing adb, setting it u…

The article claims the app can only be removed with root access, which requires more difficult and technical steps to attain than running an adb command. If uninstalling the app with adb works and doesn't result in the app being promptly reinstalled, then the article has a significant factual error.

Except uninstallining the app does not equal removing it, as you claim. Removing it from list of apps to load is not removal. Not to mention it resets back to installed and you have to rerun the command.

Re: Samsung embeds IronSource spyware app on phones across WANA

#342

Earlier quoted context omitted.

I agree, but I think three extra conditions would need to be added here. 1. Devices should be allowed to display a different logo at boot time depending on whether the software is manufacturer-approved or not. That way, if somebody sells you an used device with a flashed firmware that steals all your financial data, you have a way to know. 2. Going from approved to unapproved firmware should result in a full device w…

4. Apps with special security needs are allowed to detect whether a device is unlocked and can either disable themselves or go into a mode that shifts ALL related liability onto the user. It's not the bank's fault if the user disabled protections and some spyware logs the online banking password or something like that.

Screw that. I want nearly the opposite. I don't really own my device if apps will look at my ownership flag and refuse to run.

We can talk about the consequences of spyware but definitely not a total liability shift. Also preventing root doesn't prevent spyware.

Re: Samsung embeds IronSource spyware app on phones across WANA

#343

Not in this field but, if you're willing to sacrifice performance for security (by avoiding closed, western, hardware) how hard would it be to for a group of top hardware and software engineers to make a secure smartphone? Id gather you could go very far with the following list: - Proved correct micro kernel - Encrypted messaging by default - Encrypted memory - Encrypted messaging between processes. - hardware switch…

I believe a proven correct micro kernel for a production system in smartphone scale is a sufficiently complex engineering task.

[deleted]

Re: Samsung embeds IronSource spyware app on phones across WANA

#344

Earlier quoted context omitted.

If you're a valuable enough target, like these Iranians generals/scientists they just need to find you once and then they can continuously track your movements via satellite. They don't need much precision, just which building to level

"Just which building to level" What's "just" a war crime amongst friends?

When there is no one willing to prosecute it, is it still a crime?

Re: Samsung embeds IronSource spyware app on phones across WANA

#345
post #313

Samsung currently has an unremovable spyware app on North American phones that pastes (records) everything copied to the clipboard by any app. It is the Samsung Keyboard app. It cannot be removed. It doesn't matter if you're using any other keyboard app. Samsung Keyboard pastes (records) everything that gets copied to the clipboard by any app. The Samsung Keyboard app cannot even be disabled from Android. As an aside…

Thanks for mentioning this! I saw it but never put much thoughts into it. Now it seems a huge security risk/active security exploit. Strangely enough, I cannot reproduce this now. I'll see when it happens again, and if I can uninstall keyboard via adb. It's just a pre-installed app, after all.

What do you mean you cannot reproduce it? Enable the setting in your Android to notify you whenever any app pasted from the keyboard.

Unless you have already used adb to disable or remove the app, the issue is guaranteed.

Re: Samsung embeds IronSource spyware app on phones across WANA

#346

Earlier quoted context omitted.

Supermicro IPMI comes to mind. If it was compromised we would have known by now.

Not only is Supermicro headquartered in USA, but it's operations are in Taiwan, which they would very much like you to acknowledge is not the same as mainland China.

*its

Re: Samsung embeds IronSource spyware app on phones across WANA

#347
It's time to start treating such actions, including/especially when done by corporations, as criminal hacking or an act of war, because as many commenters noted, that is what it amounts to. It's frustrating seeing the consequence be an open letter, where if an individual did this, there would international warrants issued against them.

Re: Samsung embeds IronSource spyware app on phones across WANA

#348
post #230

Earlier quoted context omitted.

Even though you seem to have a lot of support on Hacker News, I don't think making root access a fundamental right is preferable. Historically, computers have not granted you access to everything. Most home computers used to have ROM cartridges, which could not be modified, at least not by an average user. Also, when using unrestricted operating systems, such as as MS-DOS, a simple virus could wipe all your hard work…

Why? What is the reason root would be dangerous, if it's not the default? People can be scammed to activate it, but those same people can be scammed to click links and give passwords and personal data. Any action requiring root would need a warning and raise suspicion, or put behind an activation mechanism that's complex enough. Anything else and you lose freedom, and the whole ethos that enabled the advanced IT land…

Having root access implies that you can do all sorts of things: change files, install new software, new kernel modules, etc. Locking this down makes the attack surface for malicious parties much smaller. Many exploits start in user-space and then obtain root access to install rootkits.

Of course you lose freedom, but that is exactly what is needed, because some people just cannot help themselves from exploiting that freedom.

Unless someone figures out a way where we can safely share computing power and connections to real-life services (e.g. banking, having an identity, communication in general), I think there is no real alternative.

Perhaps having separate internets for various purposes would be an option. Ond where we can socialize anonymously, but not trust each other, and one where it's pretty boring, but where you can safely buy goods using your paycheck.

Re: Samsung embeds IronSource spyware app on phones across WANA

#349

Earlier quoted context omitted.

"Just which building to level" What's "just" a war crime amongst friends?

When there is no one willing to prosecute it, is it still a crime?

Yes, though one without consequences. Until the next guy comes along and actually enforced it.

Re: Samsung embeds IronSource spyware app on phones across WANA

#350
Couldn't get rid of some assistant that I would have to have registered with Samsung last phone. When it broke I switched over to a used Nokia. Little bit less convenient but I wish they wouldn't keep pushing that annoying spyware stuff on us... I'm perfectly fine to just use my phone for browsing and staying in touch with ppl... Why the f. Do I need Google Assistant which I also can't cancel...I swear, next phone will be one of those bricks for the elderly...
Post reply on HN