Live data from Hacker News

Samsung embeds IronSource spyware app on phones across WANA

smex.org

381–390 of 500 posts

Re: Samsung embeds IronSource spyware app on phones across WANA

#381

Earlier quoted context omitted.

When a security analysis was done of Chinese parts of the Dutch mobile network, that was pretty much the conclusion: Chinese vendors deliver software and components full of vulnerabilities, but none of them seem to be intentional. Since then there has been a movement to reduce Chinese vendors in general our if security concerns, as well as to improve the security posture of the mobile networks by doing things like "e…

> Chinese vendors deliver software and components full of vulnerabilities, but none of them seem to be intentional. Plausible deniability.

If we're talking about cheap products, then it's more likely due to cost savings rather than malice. But yeah, no one can give you defitive proof of this.

Re: Samsung embeds IronSource spyware app on phones across WANA

#382

Earlier quoted context omitted.

It's in a read only filesystem. You can't modify read only data, but you can choose to ignore it.

Only because it is mounted as one. It is like saying that you can't have your house in pink because it is green.

If you modify a file on the partition the device will fail to boot. Your metaphor is not equivalent because it ignores security.

Re: Samsung embeds IronSource spyware app on phones across WANA

#383
post #251

Earlier quoted context omitted.

The truth is far outside the Overton window. Yes, privacy is a question of civil defense in the drone age. But the existing crop of states will never acknowledge that; their structure and institutions presume precisely the kind of mass databases of PII that create this vulnerability, as well as institutional transparency for public accountability. This makes them structurally vulnerable to insurgencies that expropria…

This has been going on in Russia on massive scale. For bribes officials sells anything including highly sensitive databases. Those were used to uncover various Kremlin-run assassins targeting oppositions. Then Ukrainian special services used those to target high-ranking Russian military officers. Russia tried to crack down on that but it just increased the database price tag.

Do you have sources for that? No problem if they're not in English.

Re: Samsung embeds IronSource spyware app on phones across WANA

#384

Earlier quoted context omitted.

> Were on earth did you get that notion from? Literally cited the source. > My PCs and corporate PCs I've been responsible for were networked including the internet These came later, in the mid 90s. If you have a source for any PC having been "warranted with no conditions about what software was run on them," I'd love to see it. Practically every warranty for PCs voided if you e.g. overclocked the CPU. And almost all…

Deliberate abuse and misuse of a product is not covered under any normal warranty, and overclocking the CPU could fall into that category depending on the specific warranty (some CPUs could not be overclocked for that reason so it was irrelevant). User software is another matter altogether. Users could always install whatever they wanted. It seems you are not old enough to remember that the PC was originally designed…

> warranties took this into account and it was a normal procedure to add RAM, disk drives and video cards etc. without voiding the warranty

Again, very limited warranties that only covered manufacturing defects. Not the warranties integrated products have today. In most cases, a manufacturing-defect warranty is not voided by rooting your device. (It may become more difficult to prove it’s a manufacturing defect, however. The law varies state to state.)

What fundamentally changed is warranties expanded as products became more integrated and the market expanded beyond power users. You cannot provide accidental-damage insurance for a user adjusting their BIOS.

Re: Samsung embeds IronSource spyware app on phones across WANA

#385
post #383

Earlier quoted context omitted.

This has been going on in Russia on massive scale. For bribes officials sells anything including highly sensitive databases. Those were used to uncover various Kremlin-run assassins targeting oppositions. Then Ukrainian special services used those to target high-ranking Russian military officers. Russia tried to crack down on that but it just increased the database price tag.

Do you have sources for that? No problem if they're not in English.

Here is an example of such investigation into russian general: https://youtu.be/alUPgLLIxeM?si=0x1QtJrJf2yfPCZi

Or investigation into some russian topics: https://theins.ru/en/inv

Re: Samsung embeds IronSource spyware app on phones across WANA

#386

Earlier quoted context omitted.

Thanks, my issue so far was with the 2nd step, as if my Linux did not recognize my device. I might have a go on Windows if Linux will not work again.

Knoppix has an old android adb and drivers. Still recognizes Samsung A and chinese androids and is functional. Other dristros surely offer the same support

Not sure what the issue was, I did not debug it. I will try again and see if it works or not, and will debug it further if it does not work. Arch Linux or Void Linux definitely should offer the same or more (or better) support.

Re: Samsung embeds IronSource spyware app on phones across WANA

#387
post #331
post #315

Earlier quoted context omitted.

>After all, as last two years have so amply demonstrated: people are fine with genocide. Last two years? Try last few decades at the very least. People only care about the war in Gaza more because it's controversial. For non-controversial cases people just agree it's bad but shrug their shoulders. https://en.wikipedia.org/wiki/Bosnian_genocide https://en.wikipedia.org/wiki/Rwandan_genocide https://en.wikipedia.org/wi…

What's ridiculous is that it's even seen as controversial by some.

It is will how some people will live in their bubble and not see the controversies

Re: Samsung embeds IronSource spyware app on phones across WANA

#388
post #57

Earlier quoted context omitted.

> I suspect a strong link between mass surveillance [...] and the very recent targeting of the senior Iranian nuclear scientist and military officers at their homes in Iran. We all like to imagine this super cool clandestine hacking operation using peoples mobile phones to secretly track people who visit nuclear facilities back to their homes. The much more logical explanation is someone approached a low level employ…

> The much more logical explanation is someone approached a low level employee at the MEAF who turned over a USB stick with the governments org charts and payroll records in exchange for their kids getting a full ride to a prestigious foreign university. If there are spies in foreign countries going around offering life-changing sums of money for USB sticks, which people are accepting is it not also plausible that fo…

This is the thing that has always concerned me about Cloudflare. The structure of their operation is "we do a MITM on most of the encryption on the internet". Even if that doesn't make you immediately suspicious that it was set up as a spying operation on purpose (compare "encryption added/removed here" Snowden slide), it makes them a massive state espionage target. Do they really have the ability to resist that level of persistent targeting from every country in the world?

Re: Samsung embeds IronSource spyware app on phones across WANA

#389
post #288

Because the link is down: https://web.archive.org/web/20250506145643/https://smex.org/... The article leaves out quite a lot about what AppCloud is, but it's essentially how Samsung monetizes their non-flagship device users and can do things like insert installation advertisements into the notification tray, and silently install apps. Personally, if I found this on my device it'd be the final straw to grit my teeth a…

I can assure you that they do the same thing with flagship phones, especially carrier versions of the phones -- speaking from first hand experience. I have seen notifications from apps I have never heard of multiple times. That's what I have been thinking recently -- given that Samsung is quietly doing these shady things with my phone, and other annoyances like Samsung forcing Galaxy AI on me (try selecting some text…

> Samsung forcing Galaxy AI on me (try selecting some texts in a browser or webview)

I did. No Galaxy AI.

Re: Samsung embeds IronSource spyware app on phones across WANA

#390

I found the app on my Samsung phone but I also found something interesting. Go to Settings->Apps and find the app in the list. Click "Configure in AppCloud" and then click "Personal Data". A form shows up where you can request access to the data or request a deletion of the data. I just requested access to my data, received an email confirmation where I had to click a link. I am curious to see what they will send me…

> Click "Configure in AppCloud"

Not found on this Samsung phone.

Post reply on HN