Live data from Hacker News

Motorola cell phones are regularly phoning home

beneaththewaves.net

91–100 of 117 posts

Re: Motorola cell phones are regularly phoning home

#91

Small nit to pick: IMSI + IMEI aren't enough to clone your phone - the SIM card stores a shared secret used for challenge-response authentication with the network, and the device (theoretically) can't read the secret, only send the SIM a challenge and get the response to send to the network.

The article is about a CDMA phone from Verizon.

Re: Motorola cell phones are regularly phoning home

#92
post #77
post #56

Earlier quoted context omitted.

> From a "hacker" perspective, even metadata on the key employees of a corporation is incredibly valuable -- imagine knowing with what firms a company is communicating, giving inside lines of investment-impacting activities like acquisitions. This is enormously valuable stuff. When Boeing and McDonnell Douglas merged, executives from those companies would fly to different, distinct cities for negotiations and then dr…

> IIRC, ExxonMobil did the same when acquiring XTO. Exxon didn't want XTO's share price to skyrocket on rumors of an acquisition as it could've made the deal unprofitable. That doesn't make sense. If shares rose on the merger rumor, Exxon could still offer a low price, since everyone knew XTO's price would collapse if the merge fell through.

During an acquisition the price on the shares of the acquirer goes down while the acquiree goes up. Since most mergers tend to be stock swaps rather than cash they would have to invest more shares than originally intended. If the merger falls through both would lose out as the acquirer would be seen as wasting a lot of money with nothing to show and the acquiree would be see as not so valuable.

Re: Motorola cell phones are regularly phoning home

#93
post #8
post #4

Earlier quoted context omitted.

What if you DO have something to hide? Company secrets can be very, very valuable for someone.

Use encryption all the time, and don't use any Microsoft products. All companies that have valuable secrets should already have this policy in place.

...don't use any Microsoft products...

Should be "don't use proprietary software," no? That would apply to Google as well.

Re: Motorola cell phones are regularly phoning home

#94
post #8

Earlier quoted context omitted.

Use encryption all the time, and don't use any Microsoft products. All companies that have valuable secrets should already have this policy in place.

Any Microsoft product? They shouldn't use any Google product by the same token. Report: Android malware up 614% as smartphone scams go industrial http://www.theregister.co.uk/2013/06/26/android_malware_bloo... From http://gawker.com/5637234/gcreep-google-engineer-stalked-tee... In at least four cases, Barksdale spied on minors' Google accounts without their consent, according to a source close to the incidents. In an…

In light of the second article, I find it ridiculous that people are asserting they have an expectation of privacy in google communications when apparently random creepy engineers have access to that data! I'd at the very least expect strong internal lockouts on customer information, with keys limited to "need to know" people...

Re: Motorola cell phones are regularly phoning home

#95
post #85

My next phone probably won't be a Motorola then. Does anyone know if this is a part of the Android Kernel? If it is it means they've modified the source code and they're obligated to share their changes.

They can make changes in user space and in application space and not share the source since only the kernel is GPL

Re: Motorola cell phones are regularly phoning home

#97
post #81
post #43

Why did it take someone 2 years to spot this????? Doesn't anybody care to watch what's going in/out of their appliances any more? Furthermore, if this report is true: why aren't there more tools out there so that there are more eyes watching this stuff? Or is everyone just too busy being "social" ??

Not a lot of people know how or have the time to setup sniffers for their appliances and then go through the logs. Maybe like 0.001% can do that. How would you sniff your device? WiFi and let your router do the thing? It wouldnt be difficult for your phone to stop suspicious activity when WiFi or VPN is turned on. How do you sniff 3G? Can you sniff GPRS/GSM for any suspicious activity? Now we're talking 0.000000001%.

Ahem, not to sound like a pessimist.

Android 4.x has vpn, so one way to sniff data is to setup openvpn and on your server tcpdump or wireshark everything.

To sniff 3G/GSM I believe one would have to root their phone and sniff it there as most people dont have 3G/GSM hardware. I dont know more about that, perhaps its as "easy" as rooting it and running tcpdump on the device and saving to sd-card from some of its interfaces?

Re: Motorola cell phones are regularly phoning home

#98

Earlier quoted context omitted.

With unencrypted communication, any insecure Wifi network is enough to "leak" your information, it's much worse then "only" Google/NSA/etc having access to it.

Whether you data is encrypted or not is really not relevant when the device's OS cannot be trusted. You can encrypt 'till the cows come home, but if the OS is stealing your data before you have a chance to encrypt it, your encryption is worthless. I just want people to stop thinking that encryption is some magic bullet that will solve all communication trust issues.

It's not completely worthless - it's the difference between the targeted attacker having your data through the backdoor in your devices OS, and that attacker PLUS anyone on the unsecured wifi in the coffee shop having your data. Yes, it's a difference of degree, not kind; but it's still relevant.

Re: Motorola cell phones are regularly phoning home

#99

This seems related to Motorola's MOTOBLUR system: http://en.wikipedia.org/wiki/Motoblur In all fairness, it seems that the implementation uses a middle server (pretty common in big companies where good engineering isn't a requirement) where log in data is sent, is stored in the users' profile and where timelines and other content is parsed before being sent back to the user's device, in a "dumb" format that the BLUR…

The article has been updated to point out that this model does not use to MotoBlur interface. Apparently having (what looked like) a mostly stock Android interface was an important buying consideration.

Re: Motorola cell phones are regularly phoning home

#100
post #79

Earlier quoted context omitted.

Yes, they're taking all of your logins and passwords, including your Google account, and their back end servers are even occasionally logging in with them. "Also interestingly, while testing Picasa and/or Youtube integration, Motorola's methods of authenticating actually tripped Google's suspicious activity alarm. Looking up the source IP in ARIN confirmed the connection was coming from Motorola."

Only when you are using the motoblur versions of those packages. Setting up a Google Account through the initial setup won't send the info to moto, setting up any account in your stock-homescreen for widgets will send your information to moto.

Not true. The article has been updated to clarify that this model does not use the MotoBlur interface. Apparently the code is still there, and still active.
Post reply on HN