Live data from Hacker News

Lithuania says throw away Chinese phones due to censorship concerns

reuters.com

371–380 of 427 posts

Re: Lithuania says throw away Chinese phones due to censorship concerns

#371
post #314

Earlier quoted context omitted.

I think you will have a hard time proving beyond speculation that Apple or Microsoft has backdoors to their OS. Would be curious to see any sources though. I actually think that is the difference here, Chinese phones and possibly other devices have backdoors, but Apple/Microsoft likely do not.

I think the parent is being more expansive in what they call a "backdoor", and I tend to agree. Does Apple have the ability to remove an app or some bit of content off your phone (ostensibly to remove malware)? I believe they do? That feels like a backdoor to me. And I assume Google (and/or the phone's manufacturer) has the same ability on Android. No idea about Microsoft on Windows.

Backdoor implies something hidden and not advertised. Apple/Google/Microsoft and others are pretty clear about fully being in control of your device. They can push updates (both at the OS and app level), add new trusted root certificates, collect usage data, show ads, remotely track/lock/disable your device and lots more. Apple is even going to start scanning your phone for certain kinds of illegal content.

Re: Lithuania says throw away Chinese phones due to censorship concerns

#372

Earlier quoted context omitted.

> Restrict apps, but can still log in via browser. This isn't paradoxical. You treat the browser as a less trusted security domain than a phone, which usually has a secure boot chain, strong sandboxing, encrypted disk, reliable hardware cryptography etc, and therefore provide a different/better service on the phone. If a phone is missing one of these expected components then you're not the target market for the app,…

What can a phone OS do to an app that a modern browser can't do to a webpage, as it relates to being a frontend to your bank account?

If the bank is planning to use the app to replace their hardware 2FA tokens (that they used to mandate for web transactions here), then the app must be considered more secure than the browser (probably because the secrets can be placed somewhere not trivially readable).

Re: Lithuania says throw away Chinese phones due to censorship concerns

#373
post #366
post #316

Earlier quoted context omitted.

> I think you will have a hard time proving beyond speculation that Apple or Microsoft has backdoors to their OS. This statement is absurd -- they don't need to keep a backdoor around because they control the front door. You do realize that controlling how/whether/when core system software updates are pushed to a device is equivalent to having a backdoor, don't you? The operating system on my phone can be 100% backdo…

"Basically all consumer phones (save for a few cobbled together exceptions) implicitly accept arbitrary software updates from their upstream vendor." Actually ... all phones of all kinds explicitly accept arbitrary updates from the carrier in the form of java code that they can upload, and run, on your SIM card. Your SIM card is a full fledged computer with CPU, RAM and storage and your carrier can upload and run arb…

Yes, this is absolutely also true.

However, there are some phones (including several iPhone generations) where the entire baseband/sim subsystem is isolated from the primary application processor and operating system, and essentially appears as something like a dumb USB modem that the OS can control / use / ignore as it pleases. In theory, this would make it difficult for a carrier to issue a baseband update that (for example) hoovers up photos from internal storage.

This is the same reason you should prefer a cable modem that's physically separate from your router/wifi/etc. Your cable modem gets firmware updates via DOCSIS from your ISP, and if you have one of those combo boxes, you're essentially letting your ISP onto your internal network.

Re: Lithuania says throw away Chinese phones due to censorship concerns

#374
post #204

Earlier quoted context omitted.

What can you send from your phone that will get you arrested by the FBI, vs what can get you arrested by Chinese forces? Is this a valid comparison?

ECHELON! More seriously no platform is trustworthy unless it’s airgapped these days.

Or 100% (hardware, firmware, software) Open Source.

Re: Lithuania says throw away Chinese phones due to censorship concerns

#376

Earlier quoted context omitted.

Free tibet", long live Taiwan independence", or "democracy movement". i sent this to a friend who owns a xiaomi phone and asked him to resent this back to me via sms. the message appeared just fine. note: i am from india so this might not be enabled on the phones here for now

It may appear fine but your friend may be logged.

so what is the chinese government going to do to an indian who sent the text to someone ? force xiaomi to do something sinister to them?

Re: Lithuania says throw away Chinese phones due to censorship concerns

#377

Earlier quoted context omitted.

> Word of warning for those who trust Google as a defender of digital privacy and human rights. Surely that is literally nobody? At this stage I would be seriously concerned for anyone who identifies with this description.

Considering Google has forfeited a lot of money over many years for resisting Chinese censorship I would say they're more trustworthy on this issue than Apple or Microsoft which have both publicly caved. The remnants of the "Don't be evil" culture is what allowed Dragonfly to be resisted. No such culture exists at Apple or Microsoft.

Yes maybe Google resists the Chinese, but what about Russia?

https://www.wired.com/story/russia-apple-google-voting-app-n...

Re: Lithuania says throw away Chinese phones due to censorship concerns

#378
post #297
post #259

Earlier quoted context omitted.

Your post reminds me of the time people in China rioted because students were not allowed to cheat on their exams. There really is something cultural going on there.

That has because the exams were national university entrance exams and the new stronger anti-cheating measures were only being applied in one city. The parents in that city felt that widespread cheating was normal everywhere else essentially turning admissions into a lottery with a big disadvantage to anyone who did not cheat.

That has to be the most lame excuse I've ever heard, at least it's funny!

Re: Lithuania says throw away Chinese phones due to censorship concerns

#379
post #43

Earlier quoted context omitted.

I have installed an AOSP-based rom on my Xiaomi 9T and banking apps (well, at least one) seems to be working fine.

Did you have any problems with AOSP? I want to replace the stock spyware on me mom's 9T, but the experience seems to be mixed, judging by a couple of forum discussions.

Minor inconveniences mostly, but that's probably because I keep flashing different ROMs to try stuff out.

My only "issue" is that because of my escapedes with flashing I now have only Widevine L3 support, so no full-HD videos on Netflix. But this should be easily fixed by flashing xiaomi.eu ROM and then going back to AOSP.

This is my daily driver: https://forum.xda-developers.com/t/rom-11-0-official-davinci...

Re: Lithuania says throw away Chinese phones due to censorship concerns

#380

I'm really not sure how serious I should take the threat of Chinese made electronics - almost all electronics are made China, not just Xaiomi and Hauwei. My iphone is made in China by Chinese contract manufacturer (Foxconn) - does that mean all iphones could be compromised with Chinese malware? It could be possible, but how can you tell? Is it possible to observe network packets going form my phone to a Chinese or Ch…

Presumably Apple ensures there is nothing nefarious in the hardware, but it seems an unlikely avenue for compromise. Most of the "phone" is Apple-provided software. In theory sure, you could have a chip snooping on the bus. But it would have to have a lot of OS-level knowledge and then how would it exfiltrate the data without OS-level access to the IP stack? Like the Bloomberg/Supermicro story, I am extremely skeptic…

Apple itself nefarious. Leeching data to FBI and cops. Google is absolutely horrendous when comes to invading privacy. Amazon literally listens to people using home devices. Good luck using any tech without compromising your and your family's privacy.
Post reply on HN