Live data from Hacker News

Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

mobile.nytimes.com

61–70 of 170 posts

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#61

Question for HN: I'm in the market for a new Android phone. If I want to avoid this sort of thing, are there manufacturers I should steer clear of?

If you are in the US, the same phone has different submodels for each US operator, and some of these submodels (likely from AT&T and Verizon) may have a locked bootloader, preventing you from installing custom ROMs.

For example, Samsung Galaxy S5 from T-Mobile (SM-G900T) you can put Cyanogenmod on, but Samsumg Galaxy S5 from AT&T (SM-G900A) you can not.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#62
post #50

Earlier quoted context omitted.

Consent. The big difference is consent.

Do not use the Internet. Do not use phones. Do not use bank accounts. Do not travel by plane. Do not enter public spaces. Do not show your face. Otherwise you accept our Terms of Service. Thank you for trusting us. (Is it just me or is it actually very hard to figure out whom I've given consent to do something with something that is mine?)

>(Is it just me or is it actually very hard to figure out whom I've given consent to do something with something that is mine?)

Reading and understanding EULAs for every tool you use is a full time job that requires a law degree.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#63
post #48

Earlier quoted context omitted.

> I'm in the market for a new Android phone. Find a phone which has a large community around it, and lots of custom ROMs available. An official Cyanogenmod release is a good sign. It's also a sign that your phone will have a longer usable life than whatever the manufacturer promises you now. Custom ROMs have a long history of extending the life of phones. For example the HTC G1 was abandoned by Google at Donut (1.6)…

I spent a day battling with getting a custom ROM on my Redmi 3 and gave up. In case anyone reads this: Xioami make amazing phones for the price. This $120 USD phone outperforms my S3. But getting a custom ROM on a Xioami is getting increasingly difficult - you have to ask for permission, jump through hoops to unlock the phone and sometimes it just does not work. Xioami is the Apple of China - great UI but increasingl…

This does not blanket apply to all Xiaomi devices. There are official builds of CM available for the Mi3, Mi4, Redmi Note 3, and a fully open source unofficial build for the Mi4C and Mi4S.

Unlocking their bootloader can be done officially through a request, or unofficially. Changing the recovery by replacing a single file in the EDL and retaining bootloader lock is also possible.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#64
post #26

H guys, I'm one of the researchers with kryptowire if you have any questions

From the article: "Kryptowire took its findings to the United States government. It plans to make its report public as early as Tuesday." Can you share the report yet?

Not sure about our policy for sharing the report but we have a slightly more technical version on our blog: http://www.kryptowire.com/adups_security_analysis.html

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#65
post #28
post #26

H guys, I'm one of the researchers with kryptowire if you have any questions

How can someone detect if their phone has this backdoor installed?

The thing is these are system apps so not easy to analyze unless you're root. What you can do is use observe your device traffic and see if any of these domains are pinged:

    bigdata.adups.com (primary)
    bigdata.adsunflower.com
    bigdata.adfuture.cn
    bigdata.advmob.cn
Then check the content of the POST request (usually to url/mobileupload.do )

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#66
post #26

H guys, I'm one of the researchers with kryptowire if you have any questions

This seems very similar (or perhaps even worse) than the fact pattern in the HTC/Carrier IQ case. https://www.ftc.gov/news-events/blogs/business-blog/2013/02/... Did you provide the Federal Trade Commission with an advance copy of your report, or just DHS? If not, why not?

We did work with DHS and notify all the parties ahead of the press release. We also remember carrierIQ ! We have a comparison table here: http://www.kryptowire.com/adups_security_analysis.html

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#67
post #9

Slightly off topic: but doesn't backdoor mean that there's a particular party that has control over the backdoored software? Here it sounds like the device is calling home... or is that sufficient to be called backdoor?

Yeah, backdoor usually means that the device accepts credentials from a third party, and not sending them reports.

I suppose you could interpret this "backdoor" as third-party access to the data, rather than to the device.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#68

Does anyone regularly audit devices and apps with something similar to a web proxy, to see where they talk to during the course of normal usage? This seems like a decent low-hanging fruit (well, relatively speaking). I also remember there used to be application firewalls in windows that kept track of the connections that each application made and if any of them contacted a new server, they'd ask you for permission. I…

Yes, they do. You can use Fiddler or similar as a web proxy for mobile apps. Stuff has been found like this - https://www.troyhunt.com/controlling-vehicle-features-of-nis... and I recall there's been several more but I can't recall the details.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#69
post #56

Huawei routers used in Indian govt offices were found to be sending data to China. They were banned after the discovery. Wont be surprised if cellular components that are made in China send back data quietly.

Don't assume malice. This would be considered completely normal in China, both legally and culturally. You would a have hard time explaining the concept of privacy to them. This is likely not some big conspiracy.

The flip side of that argument is that the fastest way to explain the concept of privacy to a manufacturer that spies on you, is to stop buying their devices. Consumers don't need to assume a conspiracy in order to communicate their preferences.

Re: Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say

#70
post #56

Huawei routers used in Indian govt offices were found to be sending data to China. They were banned after the discovery. Wont be surprised if cellular components that are made in China send back data quietly.

Don't assume malice. This would be considered completely normal in China, both legally and culturally. You would a have hard time explaining the concept of privacy to them. This is likely not some big conspiracy.

Except they know they are exporting thus have to tailor their product to local law. The idea that all these Chinese leaks are just accidental oversights is fairly naive, especially in the light of China's industrial espionage efforts.
Post reply on HN