8 ms·
Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say
- Tarrosion 10y agoQuestion for HN: I'm in the market for a new Android phone. If I want to avoid this sort of thing, are there manufacturers I should steer clear of?
- kbart 10y agoGet a phone that supports CyanogenMod. Sure, baseband still remains a blackbox and possibly backdoored, but at least you can get rid of most spyware/adware that comes preinstalled with Android. While we don't have fully open source OS with open drivers for smartphones, you cannot trust any manufacturer.
- mnw21cam 10y agoOr simply skip that step and get a phone that comes with CyanogenOS installed.
- kbart 10y agoHow do you know then that CyanogenOS itself was not modified to include unwanted software?
- dandelion_lover 10y agoI guess one could believe the commercial companies whose revenue depends on the trust and on the ethics, such as https://tehnoetic.com/mobile-devices https://tehnoetic.com/mobile-devices.
- jlgaddis 10y agoLike this exact article/submission that we're all commenting on, where a commercial company did exactly that?
- dandelion_lover 10y agoNot exactly. I would not say their revenue depended on ethics...
- deleted 10y ago[deleted]
- jwfxpr 10y agoBaseband concerns are legitimate. A good tinfoil hat approach is to use an iPod touch running an end-to-end encrypted messaging/calling app of your choice, connected to a secure hotspot. Cuts out most baseband vulnerabilities (since your data is encrypted before touching any hardware or software connected to a potentially compromised baseband). All other concerns raised elsewhere here still apply, but the baseband threat is mitigated. Worth it...? Check that threat model again.
- kbart 10y ago"A good tinfoil hat approach is to use an iPod touch running an end-to-end encrypted messaging/calling app of your choice, connected to a secure hotspot." Yes, but it's not much of a phone if it's WiFi only. You could use any laptop for such scenario as well.
- jwfxpr 10y agoYou could, though the attack surface on a laptop is arguably much larger than that on an iPod. And considering most security-conscious users are unlikely to use a classical cellular phone call for a sensitive conversation, it's actually pretty comparable to a phone, considering your hotspot can be as dumb as you like. An iPod + a prepaid portable hotspot is a damn sight more usable on the go than a laptop.
- deleted 10y ago[deleted]
- luke-stanley 10y agoMaybe phones that support Cyanogenmod or Replicant? Perhaps device makers that know how to compile source and host the updates themselves are more likely to have more control over the firmware. So we might ask, what the update policy is, do they provide updates?
- dandelion_lover 10y agoThe only good choice may be https://neo900.org https://neo900.org.
- aluhut 10y ago> 990 EUR Before taxes (VAT, etc.) So this is the threshold I'll have to pass to get a chance for true privacy? A throw-away phone without ID bound to it would be my way to go then.
- dandelion_lover 10y agoWe have to start somewhere. I am asking anyone who can to go for it (I have no connection to this company). We can hope that later it will become more affordable.
- aluhut 10y agoI wish you luck. For all of us :)
- ff10 10y ago"Because Adups has not published a list of affected phones, it is not clear how users can determine whether their phones are vulnerable. “People who have some technical skills could,” Mr. Karygiannis, the Kryptowire vice president, said. “But the average consumer? No.”" Seems to be some work ahead if you want to find out which phone doesn't use this service. And we're only talking about this particular service.
- kogepathic 10y ago> I'm in the market for a new Android phone. Find a phone which has a large community around it, and lots of custom ROMs available. An official Cyanogenmod release is a good sign. It's also a sign that your phone will have a longer usable life than whatever the manufacturer promises you now. Custom ROMs have a long history of extending the life of phones. For example the HTC G1 was abandoned by Google at Donut (1.6) but unofficially received up to Gingerbread (2.3). It's a bit of a perverse example, but hopefully enough to make the point. Phones with good community support receive current versions of Android long after both Google and the manufacturer have stopped giving a shit. To the people who say "you can't trust a random stranger on the internet making a custom ROM to be any more secure than the manufacturer ROM" you're right. If someone wanted to make a custom ROM with malware in it, there's a pretty good chance it may not be noticed. If your threat model includes a three letter agency, then don't use Android. Full stop. The iPhone is the ecosystem you want. I recommend to all my friends and family to buy phones with good community support just to receive updates to ROMs like Cyanogen. The first thing I do when they say they're considering "Phone XYZ" is to look on XDA Developers[0] to gauge the level of community around the model. If it looks dead (e.g. look up any tablet based on the NVidia Tegra for what not to buy [1]) then I recommend they keep looking. I've had really good luck with Chinese phones which are also sold in markets like South East Asia and India. There are millions of users of these phones, so the custom ROM community is quite strong. The hardware is also quite cheap, I have a Xiaomi Redmi 2 I bought last year for $125 USD including shipping, and it runs Android 7 thanks to community developers [2]. [0] http://forum.xda-developers.com http://forum.xda-developers.com [1] http://forum.xda-developers.com/mi-pad http://forum.xda-developers.com/mi-pad [2] http://forum.xda-developers.com/redmi-2 http://forum.xda-developers.com/redmi-2
- andy_ppp 10y agoSounds great! Does Android 7 run smoothly and stable-y on this device?
- kogepathic 10y agoNot quite yet. There are still some issues to be worked out. [0] It runs Android 6 (CM13) great, just in my opinion Nougat isn't polished enough for daily use. [0] http://forum.xda-developers.com/redmi-2/development/rom-cyanogenmod-14-0-t3476873 http://forum.xda-developers.com/redmi-2/development/rom-cyan...
- sampo 10y agoIf you are in the US, the same phone has different submodels for each US operator, and some of these submodels (likely from AT&T and Verizon) may have a locked bootloader, preventing you from installing custom ROMs. For example, Samsung Galaxy S5 from T-Mobile (SM-G900T) you can put Cyanogenmod on, but Samsumg Galaxy S5 from AT&T (SM-G900A) you can not.
- drzaiusapelord 10y agoAll of them except phones made/designed/whatever by Google. That leaves you the Nexus and Pixel lines only. There's a fair bit more oversight there and no shady third-party ROM with 'helpful' spying applications shipped by default (and often uninstallable). Nor do carriers get to modify the ROM themselves or install their own apps. Android is pretty much a wasteland outside of the Nexus/Pixel line. Ignoring security and privacy, you just have a lot of shovelware involved along with a lack of commitment to timely, or if any, updates. I would feel confident a Nexus/Pixel is a secure and nonsense free as a phone running CyanogenMod. Of course, that's difficult to prove, but historically we haven't seen anything like this on a Nexus/Pixel device.
- tdkl 10y agoPixel ? The phone which advertises/ships with a data collection assistant ?
- pdimitar 10y agoI will have to disagree. AFAIK, the recent Qualcomm exploits don't affect Samsung's Exynos SoC. I have an Exynos S7 Edge and it ships with a feature to disallow (read: kill) apps trying to work in the background. After I fine-tuned this list, the phone's battery life improved noticeably. Battery life has actually been slowly and steadily improving after each update by Samsung. I imagine this is a sign of Samsung not liking Google's spyware very much and trying their best to limit background activity. None of us has solid proof of course, but judging by observable facts (and by the pretty awful battery life of the Nexus 6P and the Pixels -- compared to the Exynos S7 Edge at least), I'd say mine aren't that crazy.
- ff10 10y agoSlightly off topic: but doesn't backdoor mean that there's a particular party that has control over the backdoored software? Here it sounds like the device is calling home... or is that sufficient to be called backdoor?
- sesqu 10y agoYeah, backdoor usually means that the device accepts credentials from a third party, and not sending them reports. I suppose you could interpret this "backdoor" as third-party access to the data, rather than to the device.
- rectang 10y agoWe can do better. Auditable open source and reproducible builds are security and privacy differentiators. They make shenanigans like these more difficult to pull off and easier to investigate.
- lost_my_pwd 10y agoFunny how this follows right after this: https://www.theguardian.com/world/2016/nov/14/china-threatens-to-cut-sales-of-iphones-and-us-cars-if-naive-trump-pursues-trade-war https://www.theguardian.com/world/2016/nov/14/china-threaten...
- mSparks 10y agoPah, nothing to hide, nothing to fear, what's the big deal eh? I do hope Eric Schmidt and Trent Lott have been using one of these phones/devices.
- raverbashing 10y agoAnd Zuckerberg
- andrewvijay 10y agoHuawei routers used in Indian govt offices were found to be sending data to China. They were banned after the discovery. Wont be surprised if cellular components that are made in China send back data quietly.
- dandelion_lover 10y agoPeople at HN would appreciate the corresponding links...
- andybak 10y agoI can find references to a ban based on 'security concerns' but not one that found actual evidence of snooping. I only had a brief look however. I too would be grateful to the GP for links.
- Cozumel 10y agohttps://intelligence.house.gov/sites/intelligence.house.gov/files/documents/Huawei-ZTE%20Investigative%20Report%20(FINAL).pdf https://intelligence.house.gov/sites/intelligence.house.gov/...
- andrewvijay 10y agoYo thanks fam!
- ralfn 10y agoDon't assume malice. This would be considered completely normal in China, both legally and culturally. You would a have hard time explaining the concept of privacy to them. This is likely not some big conspiracy.
- dmlorenzetti 10y agoThe flip side of that argument is that the fastest way to explain the concept of privacy to a manufacturer that spies on you, is to stop buying their devices. Consumers don't need to assume a conspiracy in order to communicate their preferences.
- LyalinDotCom 10y agoThis is just a Chinese hoax to scare us like that global warming bullshit.... right... am I right...??? .... /cry
- duked 10y agoH guys, I'm one of the researchers with kryptowire if you have any questions
- csoghoian 10y agoThis seems very similar (or perhaps even worse) than the fact pattern in the HTC/Carrier IQ case. https://www.ftc.gov/news-events/blogs/business-blog/2013/02/device-squad-story-behind-ftcs-first-case-against-mobile https://www.ftc.gov/news-events/blogs/business-blog/2013/02/... Did you provide the Federal Trade Commission with an advance copy of your report, or just DHS? If not, why not?
- duked 10y agoWe did work with DHS and notify all the parties ahead of the press release. We also remember carrierIQ ! We have a comparison table here: http://www.kryptowire.com/adups_security_analysis.html http://www.kryptowire.com/adups_security_analysis.html
- csoghoian 10y agoSo you didn't tell the Federal Trade Commission, even though they previously investigated (and punished) HTC for doing something similar?
- tombrossman 10y agoCurious, do security researchers typically liaise with the FTC when vulnerabilities are discovered? This and your parent comment seem to imply a 'yes' but this doesn't seem like an obvious connection (to me at least). I would expect the first point of contact at DHS to flag this for other agencies' attention if they felt it was necessary. Should DHS feel territorial about this and be reluctant to contact outside agencies that's on them, not the researcher. I wonder if many security researchers know to routinely shop their findings to multiple agencies independently. It doesn't seem like this is common knowledge.
- aluhut 10y agoI wish we could have disposable phones in Germany...
- makmanalp 10y agoDoes anyone regularly audit devices and apps with something similar to a web proxy, to see where they talk to during the course of normal usage? This seems like a decent low-hanging fruit (well, relatively speaking). I also remember there used to be application firewalls in windows that kept track of the connections that each application made and if any of them contacted a new server, they'd ask you for permission. I don't think most folks used them because in the end they kept asking a lot of questions that the users didn't necessarily know how to answer, but I wonder if it wasn't such a bad idea after all, and whether the "default" choice could be mined from other users' settings.
- nommm-nommm 10y agoYes, they do. You can use Fiddler or similar as a web proxy for mobile apps. Stuff has been found like this - https://www.troyhunt.com/controlling-vehicle-features-of-nissan/ https://www.troyhunt.com/controlling-vehicle-features-of-nis... and I recall there's been several more but I can't recall the details.
- freddref 10y agoElephant in the room is of course the amount of data that is sent to the u.s. from phones in the rest of the world. Hardly a surprise that China is getting in on the action too.
- finid 10y agoWell before smart phones, computers all over the world have been calling home (to the USA).
- acqq 10y agoExactly. When an address book is sent to every company that makes an app it's business! When the same is sent to China, it's outrage? Ditto with auto-updates. I'd be glad if I could control much more of my data exposure. But business.
- blacksmith_tb 10y agoI am also a little curious about what the manufacturer (or by extension the PRC government) could do with data from a phone in the US? I actually prefer my backdoors to open to Beijing... they aren't likely to share, and they aren't in a position to do anything to me (I would obviously feel differently if I was a Chinese citizen).
- abhianet 10y agoThis can also be read outside the states as follows: For about $50, you can get a smartphone with a high-definition display, fast data service and, according to security contractors, a secret feature: a backdoor that sends all your text messages to the USA every few seconds. Security contractors recently discovered preinstalled software in some Android phones that monitors where users go, whom they talk to and what they write in text messages. The authorities say it is not clear whether this represents secretive data mining for advertising purposes or a government effort to collect intelligence. [EDIT: Fixed formatting]
- thogenhaven 10y agoDidnt we all knew this would happen eventually?
- akerro 10y ago>Security contractors recently discovered preinstalled software in some Android phones that monitors where users go, whom they talk to and what they write in text messages. The American authorities say it is not clear whether this represents secretive data mining for advertising purposes or a Chinese government effort to collect intelligence. We can tell the same about Facebook, Google, Yahoo, Twitter, Uber, Microsoft, Visa, AmericanExpress...
- static_noise 10y agoSomehow the USA manages that almost every key IT corporation has their headquarters in the states sooner or later.
- akerro 10y agoI think that's because market is more mature and people adopt thing quicker, so it's easier to sell more at the beginning of a business.
- static_noise 10y agoThe big market and financial strength is one important factor but I believe that there are quite a few other forces at work which are not so obvious.
- Programmatic 10y agoDo you have any hypothesis on the potential forces at work?
- static_noise 10y agoSorry, I can't provide you with any good hypothesis. I'm just looking at what is known assuming that if something is of statistical significance without an obvious cause, that there is probably something going on that we don't see. Yet, correlation is no proof auf causation.
- agumonkey 10y agoIf it's only sms then that's not that bad. Are the SoC setup in a way to make crypto practically impossible on these ?
- mikegerwitz 10y agoYou cannot have privacy and security without free/libre software. While such doesn't doesn't guarantee privacy or security, operating systems that make an effort to build the system entirely from source without any proprietary components are much less likely to have a problem like this slip through the cracks of a large, active development community. Unfortunately, currently the only Android operating system to do this is Replicant, which has terrible hardware support and---due to the sorry state of affairs for mobile---lacks many features requiring proprietary drivers. Cyanogenmod stops short, but would still make situations like this much more difficult. Even if you don't subscribe to the principles of software freedom, please consider helping out the Replicant project if you know enough about the operating system. I use a Replicant device (S3) and I'd love to see others working to get version 6 out: http://blog.replicant.us/2016/08/replicant-6-early-work-upstream-work-and-f-droid-issue/ http://blog.replicant.us/2016/08/replicant-6-early-work-upst... We also need reproducible builds of the operating system and its software---again, something that cannot be done without a fully free/libre OS. Despite increased surveillance on such a vulnerable and enticing target, this doesn't get enough emphasis.
- the_duke 10y agoThat's the old open source argument. And while many things could most certainly be discovered by extensive, costly audits, that someone has to pay for... OS code bases are huge. How difficult would it be to hide functionality like this in some obscure code that's camouflaged as something else? How hard would it be to automatically install an app that does this after first boot, disguised as some self updating or analytics feature? Not very, I think. If someone puts an Android fork online, who has the time to go through the changes to discover something like this? Also, such features could even easily be placed on a tiny, dedicated chip inside the phone, completely apart from the OS. If you don't build the hardware yourself, component by component (assuming that the components themselves are trustworthy), and audit every single LOC in the OS, something can always slip by.
- dandelion_lover 10y agoThe source code is not the only condition for security. However it drastically decreases the threshold for the audits. People can even make a crowdfunding campaign and pay to professionals like it was done with TrueCrypt. But even without such a campaign, evil developers would be in a constant danger that someone may discover a backdoor. It is a very unstable situation: just one person is enough to make a lot of noise, and everyone could be this person. And yes, people do read the sources: https://www.fsf.org/blogs/community/who-actually-reads-the-code https://www.fsf.org/blogs/community/who-actually-reads-the-c... It's all about defense in depth: https://en.wikipedia.org/wiki/Defense_in_depth_%28computing%29 https://en.wikipedia.org/wiki/Defense_in_depth_%28computing%...
- softwarelimits 10y agoEasy to avoid: just buy a phone that was built in your country.. oh, wait...
- freddref 10y agoIf we don't really object to sharing our data with a wide range of u.s. companies, why would we care if it is shared with China or anyone else also?
- code_duck 10y agoChinese companies are harder to monitor and learn about. More importantly, they are not bound by and/or are unlikely to follow any data privacy laws.
- jlgaddis 10y agoOn the other hand, American companies don't seem to be bound by the laws that we think they are either. As example, I'll submit PRISM (while admitting that we're still not 100% clear on that) and the retroactive immunity provided to telecom companies.
- kutkloon7 10y agoWhat's the big deal? Google does this on a much bigger scale and of course shares its data with the US government when asked. Why is it suddenly scary when a Chinese company does the same?
- asdfologist 10y agoDespite its many flaws, the US government is still held accountable for its actions by voting citizens.
- tremon 10y agoHow do I, as a non-US but otherwise voting citizen, hold the US government accountable?
- the_duke 10y agoBecause you agreed to it of course, after reading EULA of the OS, provider and your Google account very diligently, deciphering the lawyer speak and considering the implications. cough
- code_duck 10y agoEither Google or an unknown company in another country could do something unwelcome with my data. However the type of thing either entity may do with it differs. For instance, unknown actors controlling malware on your phone might misuse banking or social media credentials to steal my money or post spam. Google is unlikely to do that.
- bitmapbrother 10y agoThat's cute. You make it sound as if Apple doesn't share your data with the US government when asked. Oh, look what do we have here: >In one of the leaked emails sent by Apple Environment, Policy and Social Initiatives Vice President Lisa Jackson to Podesta, the Apple team clearly stated that the current methods of encryption in place allows the firm to essentially send an unlimited amount of personal and sensitive user data to law enforcement. >Jackson further emphasized that Apple already has a 24-hour live team established for the sole purpose of handling law enforcement and government requests. “Thousands of times every month, we give governments information about Apple customers and devices, in response to warrants and other forms of legal process,” Jackson stated. “We have a team that responds to those requests 24 hours a day. Strong encryption does not eliminate Apple’s ability to give law enforcement meta-data or any of a number of other very useful categories of data.” You have to love that 24 hour live team whose sole purpose is to provide customer data to law enforcement and government people.
- finid 10y agoThis is why some users are going real paranoid. So somebody decided that their first and only Android device will not have access to the Internet. Instead, it's sole role is to function as a camera. linuxbsdos.com/2016/11/05/the-samsung-android-tablet-that-will-never-access-the-internet/
- codedokode 10y agoI have a chinese Android phone. Instead of connecting it to the Internet I connected it to my computer over bluetooth and started monitoring the traffic it tried to send. There were attempts to connect to Google servers and chinese manufacturer's servers. The data sent to China was supposed to contain sensitive information like phone number or SIM card identifier. It also has an auto-update (read: backdoor) feature that cannot be disabled. I ended up making a linux-based whitelist firewall to access the Internet but it is pretty inconvinient because I have to manually enable every new host. And I can use it only at home. As a consumer I am very disappointed and feel being deceived by Google. I know about "you are the product" saying but the smartphone is not free. I bought an expensive (two hundred dollars!) device and I had to spend a lot of my time to be able to control its activity. And of course the advertisement never mentioned that a smartphone is going to spy on me. We need a law against this.
- mbgaxyz 10y agoAre there are any consumer protection laws that would help here, for example, to obtain a full refund if it is proven that a manufacturer and retailer sold you a product full of spyware?
- codedokode 10y agoI am not a lawyer. Ususally consumer protection laws protect only from not providing advertised features. There might be something related to privacy laws but I am not sure how they work internationally.
- e40 10y agoAs a consumer I am very disappointed and feel being deceived by Google. Why Google and not the maker of the phone? They're the ones that wrote the backdoor that sent stuff to China. You're not suggesting that Google helped with that, are you?
- codedokode 10y agoGoogle could provide easy ways to control Internet traffic and to gain root access. For example, they could grant access to builtin linux iptables which doesn't cost anything to implement. And Google is easier to influence than noname chinese company. Or they could not to sell Android license to companies not repecting consumer's privacy. Even if I got refunded, what would I buy instead? Free market doesn't work here and all major manufacturers have some form of tracking and preinstalled software built in. It looks like the only way is to buy a backdoored proprietary device and replace a ROM (and then solve all kinds of problems with hardware not working properly or battery getting drained).
- TACIXAT 10y agoI used to analyze mobile malware and the line of what was OK and what wasn't really came down to how big the company was. If it was an unknown firm set up as analytics / advertising, it was fine to block. If it was a mega analytics / advertising it was not malware because it was a massive company.
- MrTrapy 10y agoPor isso uso pombo correio
- Animats 10y agoFrom the article: "A Google official said the company had told Adups to remove the surveillance ability from phones that run services like the Google Play store." Google hates it when a program phones home to someplace other than Google.
- est 10y ago> Ms. Lim said the software was intended to help the Chinese client identify junk text messages and calls. She did not identify the company that requested it and said she did not know how many phones were affected. She said phone companies, not Adups, were responsible for disclosing privacy policies to users. “Adups was just there to provide functionality that the phone distributor asked for,” she said. This whole article is a lot less racist if this paragraph is put on top. You know because every app made by some of the 1.3B people must be a government effort to collect intelligence. The app is bad because it does the function without consent, not because it's made by Chinese.