Live data from Hacker News

Motorola cell phones are regularly phoning home

beneaththewaves.net

51–60 of 117 posts

Re: Motorola cell phones are regularly phoning home

#51

This seems related to Motorola's MOTOBLUR system: http://en.wikipedia.org/wiki/Motoblur In all fairness, it seems that the implementation uses a middle server (pretty common in big companies where good engineering isn't a requirement) where log in data is sent, is stored in the users' profile and where timelines and other content is parsed before being sent back to the user's device, in a "dumb" format that the BLUR…

Ah, thank you. This post was really confusing, having never really used a motorola phone. The post never actually specified how those passwords were being used, just what service they came from and what was being sent. For most of those apps there shouldn't be any (non-exploit) way to get your credentials out to then send them in the clear.

Re: Motorola cell phones are regularly phoning home

#52
post #38

Isn't that the whole point of the Blur service...it logs into all these social services and combines them to produce a unified presentation? How else could it work?

By using these services' APIs instead of holding onto your credentials?

I think the implication is that the aggregation is done server-side, so it needs your credentials there (not that that is a good idea or that sending credentials in the clear is not complete and utter incompetence).

Edit: upon closer reading, credentials were sent over a secure connection, but aggregated content was sent in the clear.

Re: Motorola cell phones are regularly phoning home

#53
post #11
post #7

[deleted]

> Fortunately, I already removed most of those apps when I first got the phone (it was loaded with enough bloatware), Lucky you. I can't remove, for example, my NFL application (which came installed by default), without rooting the phone. I do enough Linux stuff everyday that I really don't want to bother with it on my phone. Honestly, this kind of stuff makes me want to get as far away from engineering as possible.…

Motorola is doing scummy stuff but it's probably better for one's metal health not to sanctify a particular individual. Let's not forget the "nuclear war" waged over rounded corners.

Re: Motorola cell phones are regularly phoning home

#54
[from the article]

    *" I was using my personal phone at work to do some testing related to Microsoft Exchange ActiveSync. In order to monitor the traffic, I had configured my phone to proxy all HTTP and HTTPS traffic through Burp Suite Professional - an intercepting proxy that we use for penetration testing - so that I could easily view the contents of the ActiveSync communication.

    Looking through the proxy history, I saw frequent HTTP connections to ws-cloud112-blur.svcmot.com mixed in with the expected ActiveSync connections."*
Whoever said that this has nothing to do with ActiveSync; You are being disingenuous.

Re: Motorola cell phones are regularly phoning home

#56
post #4

Earlier quoted context omitted.

What if you DO have something to hide? Company secrets can be very, very valuable for someone.

This is where modern intelligence is going. We know that one of the most common targets of Chinese intelligence gathering now is industrial espionage -- stealing trade secrets. I hardly think China is alone in this, and if the NSA or anyone else can get a heads-up that advantages US firms against Chinese, Canadian, or EU firms, you can bet your ass that is going to be communicated to the necessary people. From a "hac…

> From a "hacker" perspective, even metadata on the key employees of a corporation is incredibly valuable -- imagine knowing with what firms a company is communicating, giving inside lines of investment-impacting activities like acquisitions. This is enormously valuable stuff.

When Boeing and McDonnell Douglas merged, executives from those companies would fly to different, distinct cities for negotiations and then drive several hours to the actual meeting location. In that case, just knowing that execs from those two firms were flying to the same city repeatedly would be more than enough to start merger rumors.

IIRC, ExxonMobil did the same when acquiring XTO. Exxon didn't want XTO's share price to skyrocket on rumors of an acquisition as it could've made the deal unprofitable.

Re: Motorola cell phones are regularly phoning home

#57
post #11

Earlier quoted context omitted.

> Fortunately, I already removed most of those apps when I first got the phone (it was loaded with enough bloatware), Lucky you. I can't remove, for example, my NFL application (which came installed by default), without rooting the phone. I do enough Linux stuff everyday that I really don't want to bother with it on my phone. Honestly, this kind of stuff makes me want to get as far away from engineering as possible.…

Motorola is doing scummy stuff but it's probably better for one's metal health not to sanctify a particular individual. Let's not forget the "nuclear war" waged over rounded corners.

Oh, I'm not sanctifying him. I don't even use Apple products, because I don't want to be in the walled garden and I want to be able to hack my stuff.

Re: Motorola cell phones are regularly phoning home

#58
post #8

Earlier quoted context omitted.

Use encryption all the time, and don't use any Microsoft products. All companies that have valuable secrets should already have this policy in place.

An Android phone made by Motorola is reported to be leaking data, and your response is 'don't use any Microsoft products'? How is that relevant?

I was responding to a comment about company secrets. I guarantee you a lot more information is being exfiltrated from large US companies via Windows than via Android, and since most businesses are built around Windows, it's a lot harder for them to do anything about it.

Re: Motorola cell phones are regularly phoning home

#59
post #38

Isn't that the whole point of the Blur service...it logs into all these social services and combines them to produce a unified presentation? How else could it work?

Via the APIs each social service provides. They'd need only an oAuth token provided via your authentication, NOT full credentials. Worst case scenario, store the credentials on the device and authentication against each provider. There's no reason to ever send those credentials to a third party like Motorola.

Re: Motorola cell phones are regularly phoning home

#60
post #40
post #35

Earlier quoted context omitted.

Did you even read the article? It has nothing to do with EAS or Microsoft; it's Motorola software siphoning pretty much all the user's credentials off to Motorola servers.

Yes, I did read the article in its entirety. Did you? The author mentions ActiveSync more than once. *" What I am going to do as a result of this discovery As of 23 June 2013, I've removed my ActiveSync configuration from the phone, because I can't guarantee that proprietary corporate information isn't being funneled through Motorola's servers. I know that some information (like the name of our ActiveSync server, our…

The article is about stealing credentials. If you have an Exchange setup, or Gmail, or Yahoo mail, or IMAP, it's the same.
Post reply on HN