Live data from Hacker News

Motorola cell phones are regularly phoning home

beneaththewaves.net

71–80 of 117 posts

Re: Motorola cell phones are regularly phoning home

#71
post #11

Earlier quoted context omitted.

> Fortunately, I already removed most of those apps when I first got the phone (it was loaded with enough bloatware), Lucky you. I can't remove, for example, my NFL application (which came installed by default), without rooting the phone. I do enough Linux stuff everyday that I really don't want to bother with it on my phone. Honestly, this kind of stuff makes me want to get as far away from engineering as possible.…

> I can't remove, for example, my NFL application (which came installed by default) Settings - Apps - All - NFL Mobile - Disable

I don't have a Disable option. I looked this up online when I got the phone, and at that time, you literally could not disable it. I have a fairly old version of Android, because Verizon decided to stop pushing out updates for my device a long time ago.

Re: Motorola cell phones are regularly phoning home

#72

This seems related to Motorola's MOTOBLUR system: http://en.wikipedia.org/wiki/Motoblur In all fairness, it seems that the implementation uses a middle server (pretty common in big companies where good engineering isn't a requirement) where log in data is sent, is stored in the users' profile and where timelines and other content is parsed before being sent back to the user's device, in a "dumb" format that the BLUR…

A post now on HN from a forum argument of Jan 2012 has a employee stating that ALL motorola phones use Motoblur, except those hat are not Motoblur use a automatically created login for you instead... So it is still a bad thing...

EDIT: submission I am refering to: https://news.ycombinator.com/item?id=5975598

Re: Motorola cell phones are regularly phoning home

#73
post #39
post #38

Isn't that the whole point of the Blur service...it logs into all these social services and combines them to produce a unified presentation? How else could it work?

Now I'm wondering in winphone does this... Wp7 has a built in social network aggregator too.

That aggregator uses OAuth everywhere.

Re: Motorola cell phones are regularly phoning home

#74

Earlier quoted context omitted.

It's not stolen if you still have it.

Try telling that to Hollywood.

And I thing "the mainstream" is comfortable enough with the concept of "Identity Theft".

Yeah, perhaps "stolen" isn't 100% technically correct, but then neither is "shared" in this case…

Re: Motorola cell phones are regularly phoning home

#75
Small nit to pick: IMSI + IMEI aren't enough to clone your phone - the SIM card stores a shared secret used for challenge-response authentication with the network, and the device (theoretically) can't read the secret, only send the SIM a challenge and get the response to send to the network.

Re: Motorola cell phones are regularly phoning home

#76
post #8
post #4

Earlier quoted context omitted.

What if you DO have something to hide? Company secrets can be very, very valuable for someone.

Use encryption all the time, and don't use any Microsoft products. All companies that have valuable secrets should already have this policy in place.

This. We have a firewall in our company to stop things escaping as much as letting them in. There are so many things built into windows that phone home its scary. Even a VLK 7 with internal KMS has a good bash at trying to get out of the network. The problem is that it is virtually impossible to stop it without affecting users as everything goes over HTTP and pokes holes in windows' application level firewall.

Our shift to Java EE recently has resulted in us switching a few users to Ubuntu 12.04. Removing a couple of packages makes it 100% network silent plus we can host a mirror in house of packages.

Windows is going to end up inside virtualbox on a private virtual lan on the workstation if this works out.

I dread to think what nefarious code phones have in them if these are the problems we have with a desktop OS.

Re: Motorola cell phones are regularly phoning home

#77
post #56

Earlier quoted context omitted.

This is where modern intelligence is going. We know that one of the most common targets of Chinese intelligence gathering now is industrial espionage -- stealing trade secrets. I hardly think China is alone in this, and if the NSA or anyone else can get a heads-up that advantages US firms against Chinese, Canadian, or EU firms, you can bet your ass that is going to be communicated to the necessary people. From a "hac…

> From a "hacker" perspective, even metadata on the key employees of a corporation is incredibly valuable -- imagine knowing with what firms a company is communicating, giving inside lines of investment-impacting activities like acquisitions. This is enormously valuable stuff. When Boeing and McDonnell Douglas merged, executives from those companies would fly to different, distinct cities for negotiations and then dr…

> IIRC, ExxonMobil did the same when acquiring XTO. Exxon didn't want XTO's share price to skyrocket on rumors of an acquisition as it could've made the deal unprofitable.

That doesn't make sense. If shares rose on the merger rumor, Exxon could still offer a low price, since everyone knew XTO's price would collapse if the merge fell through.

Re: Motorola cell phones are regularly phoning home

#78
post #38

Isn't that the whole point of the Blur service...it logs into all these social services and combines them to produce a unified presentation? How else could it work?

By using these services' APIs instead of holding onto your credentials?

Yodlee, the worldwide banking network, happily stores millions of people's BANK ACCOUNT passwords, with no interest in using a secure Auth API, and nearly no one cares.

Why should Blur care about keeping your FB credentials private?

Re: Motorola cell phones are regularly phoning home

#79
post #10

Wait, am I understanding correctly that your Facebook password (for example) is being shared with Motorola?

Yes, they're taking all of your logins and passwords, including your Google account, and their back end servers are even occasionally logging in with them. "Also interestingly, while testing Picasa and/or Youtube integration, Motorola's methods of authenticating actually tripped Google's suspicious activity alarm. Looking up the source IP in ARIN confirmed the connection was coming from Motorola."

Only when you are using the motoblur versions of those packages. Setting up a Google Account through the initial setup won't send the info to moto, setting up any account in your stock-homescreen for widgets will send your information to moto.

Re: Motorola cell phones are regularly phoning home

#80

Earlier quoted context omitted.

Given Motorola are now owned by the same Google that participates in the PRISM programme (et al), I'm really not sure the encryption matters so much.

With unencrypted communication, any insecure Wifi network is enough to "leak" your information, it's much worse then "only" Google/NSA/etc having access to it.

Sure, I was just commenting on the potential ability of the NSA in particular to grab it.
Post reply on HN