Slashdot Mirror


Secret Backdoor in Some US Phones Sent Data To China (nytimes.com)

Security contractors have warned that many Android smartphones ship with preinstalled software that has a backdoor that sends all your text messages to China every 72 hours. (Editor's note: the link could be paywalled; here's the press release.) The New York Times reported Tuesday that "the American authorities say it is not clear whether this represents secretive data mining for advertising purposes or a Chinese government effort to collect intelligence." From the report: International customers and users of disposable or prepaid phones are the people most affected by the software. But the scope is unclear. The Chinese company that wrote the software, Shanghai Adups Technology Company, says its code runs on more than 700 million phones, cars and other smart devices. One American phone manufacturer, BLU Products, said that 120,000 of its phones had been affected and that it had updated the software to eliminate the feature. Kryptowire, the security firm that discovered the vulnerability, said the Adups software transmitted the full contents of text messages, contact lists, call logs, location information and other data to a Chinese server. The code comes preinstalled on phones and the surveillance is not disclosed to users, said Tom Karygiannis, a vice president of Kryptowire, which is based in Fairfax, Va. "Even if you wanted to, you wouldn't have known about it," he said.

111 comments

  1. Ads or government collection by Calydor · · Score: 5, Insightful

    Why not both?

    Is there some magical thing that says if something is collecting for advertisement purposes it can't be shared with intelligence agencies?

    --
    -=This sig has nothing to do with my comment. Move along now=-
    1. Re: Ads or government collection by Anonymous Coward · · Score: 1

      Right. We know from the Snowden leaks that US intelligence doesn't miss any opportunity to collect data. Why would China be any different?

    2. Re:Ads or government collection by Anonymous Coward · · Score: 0

      It certainly can be both. Either way, it must be translated to Engrish first.

    3. Re:Ads or government collection by Anonymous Coward · · Score: 0

      You mean Chinglish.
      There's Ireland, there's Scotland, there's the bloody Irish Sea! They're different!

    4. Re:Ads or government collection by Anonymous Coward · · Score: 0

      All your text are belong to us!

    5. Re:Ads or government collection by Darinbob · · Score: 2

      So many web devs adamantly support advertising as the way to make money and keep their jobs. So why not support government spying a a means to make money, they've already sold their souls to the advertisers so one more concession shouldn't be a big deal, right? After all government spying at least is not as intrusive as ads, the government actually makes it a point to not clutter up the web pages or interrupt you in the middle of a video, and takes a neutral stance in the war between Budweiser and Coors.

    6. Re:Ads or government collection by djinn6 · · Score: 1

      On the plus side, they'll probably only share it with Chinese government, which can't screw me over as much as the American one.

    7. Re: Ads or government collection by Anonymous Coward · · Score: 0

      We learned from Snowden's leaks that the US intelligence agencies do the same things that every foreign intelligence agency in the world does. The only surprising thing was the number of morons who were shocked to find out that a foreign intelligence agencies actually conduct espionage operations. Then there was the morons in Europe who didn't realize it was their own governments collecting data on their own citizens and sharing that data with the US. They actually thought making sure their data was stored on servers physically located in Europe would magically make them immune from further intrusions on their privacy.

  2. Oh no what an awful accident by Anonymous Coward · · Score: 4, Funny

    No reason to be alarmed. Clearly this is just a testing and debugging feature introduced by some errant developer that's been accidentally left in the release build firmware. It will be patched and fixed and you can all go back to buying these phones in safety. No way the Chinese government would have deliberately done this.

    1. Re:Oh no what an awful accident by Anonymous Coward · · Score: 1

      With the Chinese government half a world away, I am way more worried about the US Govt. having my text messages than Chairman Mao.

    2. Re:Oh no what an awful accident by I'm+New+Around+Here · · Score: 1

      Don't worry, they didn't mention Grindr messages in the article.

      --
      If you think I voted for Trump because of this post, you're wrong. I voted for Dr. Jill Stein of the Green Party. Again.
    3. Re:Oh no what an awful accident by SScorpio · · Score: 1

      I'm not worried either considering Mao's been dead for forty years. Chairman Meow on the other hand....

    4. Re:Oh no what an awful accident by ShanghaiBill · · Score: 2

      I'm not worried either considering Mao's been dead for forty years.

      History is repeating itself. Xi Jinping is purging his political opponents, mostly by accusing them of corruption, and promoting a personality cult. It will be interesting to see if he steps down at the end of his term in office, or whether he stays on "for the good of the nation".

    5. Re:Oh no what an awful accident by Anonymuous+Coward · · Score: 1
      That is an idiotic thing to say.

      Even if the data sent from the phone to the Chinese is encrypted, the phone has to have the key, so it's trivial for just anybody to intercept and read your messages. Including the US Govt. or low-key scammers.

    6. Re:Oh no what an awful accident by whoever57 · · Score: 1

      Even if the data sent from the phone to the Chinese is encrypted, the phone has to have the key, so it's trivial for just anybody to intercept and read your messages

      Apparently you never heard of asymmetric encryption. So, no the phone doesn't need to have the key required to decrypt the data.

      --
      The real "Libtards" are the Libertarians!
    7. Re: Oh no what an awful accident by Anonymous Coward · · Score: 0

      Go Android!!!!

    8. Re:Oh no what an awful accident by Anonymuous+Coward · · Score: 1
      Haven't had your coffee yet?

      The story is about your phone sending your personal data to some 3rd party, not about your phone downloading stuff from some 3rd party. Who has to encrypt and who has to decrypt there?

      The only way to "secure" that somehow is to have some unique (and unpredictable) secret token burned into each phone, and derive the encryption key from it. The IMEI or serial number won't cut it.

    9. Re:Oh no what an awful accident by viperidaenz · · Score: 1

      Or have the phone encrypt the data with the servers public key, so only the servers private key can decrypt it?

    10. Re:Oh no what an awful accident by whoever57 · · Score: 0

      You either did not read or did not understand the link I gave to you. Read it and try to see if you can wrap your tiny mind around it.

      --
      The real "Libtards" are the Libertarians!
    11. Re:Oh no what an awful accident by laing · · Score: 1

      Don't worry, the US Government will most definitely also get a copy of any IP traffic sent between US soil and the PRC.

  3. Another Day, Another Android Exploit by TheFakeTimCook · · Score: 2, Funny

    This is like Windows XP. What a cluster!

    1. Re: Another Day, Another Android Exploit by Anonymous Coward · · Score: 5, Insightful

      This has nothing to do with Android... it's not a bug. This is preinstalled malware on Chinese phones.

      Stop drinking the koolaid.

    2. Re: Another Day, Another Android Exploit by Anonymous Coward · · Score: 0

      Fortunately, it's impossible for the Chinese to preinstall their malware on iPhones.

    3. Re: Another Day, Another Android Exploit by Anonymous Coward · · Score: 0

      Stop drinking the koolaid.

      If you look at TheFakeTimCook's posting history, you'll conclude that he's actually serving the koolaid. His posts are nothing but a constant stream of pro-Apple/anti-[everything else] drivel.

      Looks like he pulled the trigger on this one with an anti-android dig without fully thinking it through.

    4. Re:Another Day, Another Android Exploit by Anonymous Coward · · Score: 0

      no surprise. the primary goal of google (or microsoft. apple, too, for that matter) is market penetration and delivering eyeballs (aka 'products') to their own online services, ad networks, and more recently, 'app stores'.

      security, if it happens, is largely by accident, and certainly takes a back seat to the larger picture: profits.

    5. Re:Another Day, Another Android Exploit by magarity · · Score: 1

      It may be tedious but you can uninstall bloatware from your big-brand Windows PC. The *^&%$ preinstalled Android stuff can't because they compile it into the ROM.

    6. Re: Another Day, Another Android Exploit by Anonymous Coward · · Score: 0

      you forgot your /s tag. It has already happened, as evidenced by the iPhone being allowed to succeed in China. The only question is if it's firmware, malware or Apple actively passing data to the Chinese government. My bet is 2/3

    7. Re: Another Day, Another Android Exploit by TheFakeTimCook · · Score: 1

      Stop drinking the koolaid.

      If you look at TheFakeTimCook's posting history, you'll conclude that he's actually serving the koolaid. His posts are nothing but a constant stream of pro-Apple/anti-[everything else] drivel.

      Looks like he pulled the trigger on this one with an anti-android dig without fully thinking it through.

      I am honored that the AC has so little to actually do in his life that he/she can devote the effort to launch an in-depth analysis of my Slashdot Posts.

      Perhaps if this alleged human would favor us with a Login, we could return the favor, and do an in-depth analysis if his/her Posting history, eh?

  4. Checksum by Anonymous Coward · · Score: 0

    If I was a manufacturer, I would have a checksum on my system image and spot check phones coming back from China to verify that it was not tampered with.

    1. Re:Checksum by Anonymous Coward · · Score: 0

      Sorry, but I ran the numbers and found that implementing such a process would cost us between 10 and 25 cents per phone. So I squashed the whole idea and lobbied my bosses for a bonus for saving us two million dollars a year.

      -- Your friendly neighborhood MBA

    2. Re:Checksum by Anonymous Coward · · Score: 0

      And then they'll just offload the malware onto a chip. Or only about a million other places which are inaccessible without a secret "door knock" sequence (no JTAG). You people are so cute with your checksums ..

  5. Always a good sign... by fuzzyfuzzyfungus · · Score: 5, Interesting

    The really disturbing thing isn't that some shit Chinese handsets are full of spyware; but that our own technology industry is so overrun with advertisers, tracking, and 'analytics', that we can't distinguish between espionage and the Chinese just catching up with our business models; because the only real difference is that espionage tends to run at a loss, while advertising is economically self sustaining.

    1. Re:Always a good sign... by Anonymous Coward · · Score: 4, Informative

      This isn't new. Has everyone already forgot about Carrier IQ?

    2. Re:Always a good sign... by alvinrod · · Score: 4, Informative

      If a government can legally compel a company to hand over their advertising information, there's no functional difference between the two. I can think of very little that a government might want to know about a person that an advertising agency would have no interest in collecting.

      I think that Bill Hicks's thoughts on the matter are still quite appropriate.

    3. Re:Always a good sign... by ljw1004 · · Score: 1

      the only real difference is that espionage tends to run at a loss, while advertising is economically self sustaining.

      I'm not sure what calculation that would be. Advertising costs money, is paid for out of revenue, which is paid for by passing the cost to customers. Espionage costs money, is paid for out of government funds, which is paid by passing the cost to tax-payers.

    4. Re: Always a good sign... by Anonymous Coward · · Score: 0

      There is no difference! If I would have a say, any developer involved with sending any of my data anywhere without a written contract with me would be thrown in jail for many years. I would like to encourage everybody to punch employees working with shit like this hard in the face. I'm glad I don't work in SF. My hands would be in constant pain.

    5. Re:Always a good sign... by fuzzyfuzzyfungus · · Score: 1

      Plus, the ad guys are busily competing with one another to enhance their techniques; and since they are (on the whole) turning a profit, they have no incentive to stop.

      The feds have the disadvantage of being more likely to call down the jackboots on you; but unless particularly irrational their desire to spend money on further surveillance is usually outweighed by their desire to fund other projects once they are reasonably confident that the major threats are being watched.

      It has really been terribly depressing watching the breakdown of even the pretense of privacy, and the rise of people talking about the most egregious commercial surveillance like it is inevitable, or even a feature.

  6. willing to bet, or at least think about by w3bd4wg · · Score: 2

    I am willing to bet that this code was originally meant to monitor Chinese users and was either put in by a Chinese agent without the companies knowledge or forded to be put in by the Chinese government. I would be willing to think that someone forgot to take it out, or someone said lets try this, but for the Chinese government to do something so obvious...I do now know.

  7. Android dominance = Intelligence revenue by Anonymous Coward · · Score: 0

    I have to wonder if the economics of cheap android handsets depends on intelligence agencies pushing it financially. It seems like the most wild-west of the phone OS's. Is this even a thing? Like, would it make sense to understand why certain manufacturers can always win on price?

  8. "updated the software to eliminate the feature" by SpankiMonki · · Score: 5, Funny

    Oh, it was just a feature. Whew! What a relief. For a second there, I thought it might be malware.

  9. Two responses by Anonymous Coward · · Score: 0

    1) I am not surprised that anyone would put this in any OS/device they had GOD-LEVEL access to. The temptation is too great.
    2) I doubt this is completely true. It is too much work to hide it.

  10. Japanese by Oswald+McWeany · · Score: 5, Funny

    I'm going to send texts saying I'm eating Japanese food on a more regular basis now.

    Hey honey, look at this Japanese sweet and sour chicken I'm eating. I feel like going to the Japanese restaurant for General Tsao's chicken tonight.

    - that oughta piss 'em off.

    --
    "That's the way to do it" - Punch
    1. Re:Japanese by 93+Escort+Wagon · · Score: 0

      General Tsao's Chicken is Chinese.

      --
      #DeleteChrome
    2. Re:Japanese by Anonymous Coward · · Score: 0

      Whoosh

    3. Re:Japanese by Anonymous Coward · · Score: 0

      Fwooosh!

    4. Re:Japanese by clemdoc · · Score: 1

      whoosh

    5. Re:Japanese by Anonymous Coward · · Score: 0

      and woosh

    6. Re:Japanese by PmanAce · · Score: 1

      It's North American actually.

      --
      Tired of my customary (Score:1)
    7. Re:Japanese by Anonymous Coward · · Score: 0

      General Tsao's Chicken is Chinese.

      Actually, it's American. No one in China knows what the hell General Tso's Chicken is.

    8. Re:Japanese by Culture20 · · Score: 3, Funny

      No one in China knows what the hell General Tso's Chicken is.

      It's four pay grades better than Colonel Sanders' chicken, that's what it is!

    9. Re: Japanese by Anonymous Coward · · Score: 0

      You may well piss in your Japanese food (or shit)

    10. Re: Japanese by Anonymous Coward · · Score: 0

      You want ancestral hall or banquet hall chicken. Chung tong gai if I recall correctly... that may be the Cantonese for the Hunan though. And drier preparation without broccoli as it appears in America.

    11. Re:Japanese by Ogive17 · · Score: 1

      Start mentioning the Senkaku islands if you want to make a splash

      --
      "Action without philosophy is a lethal weapon; philosophy without action is worthless."
    12. Re:Japanese by Anonymous Coward · · Score: 0

      Thats enough whooshs for a hurricane!

    13. Re:Japanese by Anonymous Coward · · Score: 0

      please stop posting. surely there must be better things for you to do.

    14. Re:Japanese by GTRacer · · Score: 1

      I think I love you. I really needed a good laugh, and, like the man said, there it is!

      --
      Defending IP by destroying access to it? That makes sense, RIAA/MPAA. Go to the corner until you can play nice!
    15. Re:Japanese by JustAnotherOldGuy · · Score: 1

      mega-uber-whoosh

      --
      Just cruising through this digital world at 33 1/3 rpm...
  11. Is your phone affected? by resfilter · · Score: 5, Informative

    From the press release, the affected phones have the following services installed:

        com.adups.fota.sysoper
        com.adups.fota

    I'd probably check your phone to ensure those don't exist. ... And it sends data to the following domains, if ya wanted to firewall or sniff it or whatever:

        bigdata.adups.com (primary)
        bigdata.adsunflower.com
        bigdata.adfuture.cn
        bigdata.advmob.cn

    1. Re:Is your phone affected? by Anonymous Coward · · Score: 1

      From the press release, the affected phones have the following services installed:

          com.adups.fota.sysoper

          com.adups.fota

      I'd probably check your phone to ensure those don't exist. ... And it sends data to the following domains, if ya wanted to firewall or sniff it or whatever:

          bigdata.adups.com (primary)

          bigdata.adsunflower.com

          bigdata.adfuture.cn

          bigdata.advmob.cn

      How about carpet bombing the servers you just listed? It would most likely bring down the core of the Chinese internet. We can teach the Chinese how to play "Ping" pong with a good concerted dos session I am sure. While were at it we could really throw a monkey wrench into the jerks in the states that wrote the crapware in the first place. Adware on commercial products is one thing but hiding it should be punished with an equal dose of poison. Hell even Microsoft does not try to hide adware in the system installs, only craptastic second rate OEMs like SONY do that kind of nonsense. Lesson here is if you do not know for sure what is installed don't buy the thing, including cars!

    2. Re:Is your phone affected? by OrigamiMarie · · Score: 1

      Note: checking your running services has gotten harder in Marshmallow. Here's a guide: http://www.howtogeek.com/25830...

    3. Re:Is your phone affected? by Anonymous Coward · · Score: 0

      From the press release, the affected phones have the following services installed:

          com.adups.fota.sysoper

          com.adups.fota

      I'd probably check your phone to ensure those don't exist. ... And it sends data to the following domains, if ya wanted to firewall or sniff it or whatever:

          bigdata.adups.com (primary)

          bigdata.adsunflower.com

          bigdata.adfuture.cn

          bigdata.advmob.cn

      what details do you want for any phone? I have a problem in my cell phone.

      thanks
      www.ummahrelief.org

  12. General Tso's chicken is "chinese" food by Anonymous Coward · · Score: 1

    General Tso's chicken is about as Chinese as KFC. It's loosely based on Hunan cuisine but it originated in America (NYC). A shame really, authentic Chinese food is awesome. If you're ever in NYC hit up Xi'an Famous Foods, the lamb cumin noodles are fantastic. If you have more time, head over to Flushing and dive into almost any of the shops there and learn what real Chinese food is (and a good deal of it is much, much spicer than what your local take out place serves). I moved to NYC from Texas and I'm still learning how much of what I know about cultural cuisine is wrong. And just to complete the circle, for some reason there a lot of taco/tex-mex joints in the city which are run by chinese families. I know most people will find this is shocking, but they ain't Mexican taco's (and yes, I know what most tex-mex places serve aren't true "taco's" either).
     
    Oh, and I'm pretty certain the OP knows that sweet and sour chicken and general tso's chicken aren't Japanese... that was the joke.

    1. Re:General Tso's chicken is "chinese" food by VorpalRodent · · Score: 1

      It's loosely based on Hunan cuisine

      I initially read that as "Human" cuisine...as a picky eater, I can say that the meaning of the sentence as a whole didn't change substantially once I noticed my error.

      --
      Take it to the limit, everybody to the limit, come on, everybody fhqwhgads.
    2. Re:General Tso's chicken is "chinese" food by Anonymous Coward · · Score: 0

      I think that does a great disservice to chickens, as they most likely taste a lot better than humans

    3. Re:General Tso's chicken is "chinese" food by Dutch+Gun · · Score: 1

      Exactly. And in Japan, curry (which is insanely popular, apparently) is considered "western food". Neither assumption is correct. Food is a bit like language that way, in how it gets borrowed and adapted in ways that make purists cry... but no one else cares, and enjoys their food.

      --
      Irony: Agile development has too much intertia to be abandoned now.
    4. Re:General Tso's chicken is "chinese" food by ShanghaiBill · · Score: 1

      General Tso's chicken is about as Chinese as KFC.

      Most Americanized Chinese food is terrible. Even if you go to an authentic family-run Chinese restaurant, they will often have a separate menu for non-Chinese, with extra starch, grease, salt, and sugar, since they assume that is what you want. You have to specifically ask for the "Chinese menu". Just say "Qing gei wo zhongwen caidan". Oh, and the menu will be in Chinese, so you will need to learn to read hanzi.

    5. Re:General Tso's chicken is "chinese" food by Anonymous Coward · · Score: 0

      Authentic Chinese food is god awful.

      Fixed that for you.

    6. Re:General Tso's chicken is "chinese" food by avandesande · · Score: 3, Funny

      India is West of Japan

      --
      love is just extroverted narcissism
    7. Re:General Tso's chicken is "chinese" food by TheSync · · Score: 1

      I ordered the poached whole frog once from the Chinese menu. I went back to sweet & sour chicken real fast!

    8. Re: General Tso's chicken is "chinese" food by LanceMcGrath · · Score: 1

      So is Hawaii, if you travel far enough.

    9. Re: General Tso's chicken is "chinese" food by Anonymous Coward · · Score: 0

      Hawaii is actually east of Japan. Even a moron will not fly westward from Japan to Hawaii.

    10. Re:General Tso's chicken is "chinese" food by UberVegeta · · Score: 1

      in Japan, curry (which is insanely popular, apparently) is considered "western food". Neither assumption is correct.

      Japanese curry is an import from the UK, not from India, which gives it its Western credentials.

      Said curry is gaining popularity in the UK. For the uninitiated, in both places it's commonly sold under the name "katsu curry" which is a direct corruption of the English word "cuts" (katsu curry is served as sliced chicken with breadcrumbs in a mild curry sauce with white rice). This isn't an exhaustive definition, the curry can be sold with things other than sliced breaded chicken.

      There are two slightly odd/amusing things about this. The first is that in England, "katsu" is treated as an exotic foreign word. It really isn't (see above), it's just that Japanese has no phoneme for "cu-" as in "cut", nor "ts", thus it's impossible to say "cuts" in Japanese. The temptation to use "ku-" doesn't work because in Japanese, that's pronounced more like a short "coo-" as in "cooking." The second odd thing stems from the first: having no idea what "katsu" is supposed to mean, it gets interpreted as being the overall flavour. Hence, various food shops that know nothing about Japanese cuisine such as Greggs (a mass-market bakery) are selling nonsensical products such as "katsu bakes," which appears to be some sort of pastry containing chicken and curry powder but otherwise bearing no relation to katsu curry nor indeed the curries created in Britain, upon which katsu curry is based.

      Disclaimer: I am a Japanophile who has worked in Japan, and I'm from Birmingham which considers itself the curry capital of the UK.

      --
      I knew I needed to stop reading Slashdot and finish my PhD when I started to miss articles by Bennett Haselton.
    11. Re: General Tso's chicken is "chinese" food by Anonymous Coward · · Score: 0

      Whoosh, yes that's the joke. If one flew PAST India to get to Hawaii- one could get there. After awhile.

    12. Re: General Tso's chicken is "chinese" food by avandesande · · Score: 1

      Actually I wasn't trying to be funny. Without knowing a thing about Chinese culture I would guess that China has very different perspective on what is Asia, 'the far east', 'the west' etc.... those are 'western' constructs.

      --
      love is just extroverted narcissism
    13. Re:General Tso's chicken is "chinese" food by Dutch+Gun · · Score: 1

      Japanese curry is an import from the UK, not from India, which gives it its Western credentials.

      That's like calling spaghetti an American dish because it was introduced to someone by an American. Anyhow, my point is that it doesn't really matter what we think, as Japanese will continue to consider curry "western", even though it's not, and Americans will continue to think fortune cookies are Chinese, which they aren't. Meh.

      Disclaimer: I'm not a Japanophile. I've just watched a lot of anime.

      --
      Irony: Agile development has too much intertia to be abandoned now.
    14. Re:General Tso's chicken is "chinese" food by painandgreed · · Score: 1

      India is West of Japan

      By Western, they do mean European. That's because the Japanese got curry from advisors from the British navy (who got it from India). Curry is a good way to prevent scurvy which the Japanese had a big issue with on their first naval trip to Hawaii and the Americas and spent month in port just recovering. So, they adopted British naval cuisine which was curry. Apparently, they still serve curry in the Japanese navy every Friday. They have done their own thing with it by adding flour to the sauce to make it thicker, cooking it with beef (which they also got from the 'Westerners'), and serving on rice along with a side salad and glass of milk.

    15. Re:General Tso's chicken is "chinese" food by Rakarra · · Score: 1

      Japanese curry is an import from the UK, not from India, which gives it its Western credentials.

      I see a lot of "Vermont Curry." Until going through Japanese curry options, I had no idea that Vermont was such a curry hotspot and originator!

  13. In Soviet America, Chinese chairman spies you! by fubarrr · · Score: 2

    In Soviet America, Chinese chairman spies you!

    1. Re:In Soviet America, Chinese chairman spies you! by Anonymous Coward · · Score: 0

      "all your phone are belong to the Chairman.". Here we are worrying about a few million phones when billions of other internet ready devices are made inside the red dragons belly.

  14. They can have them... by Anonymous Coward · · Score: 0

    ...nothing but junk anyway. Who uses SMS these days? I hope they purchase the media downloads my operator keeps offering because I'm sure as shit not doing it.

  15. Thanks Google by 110010001000 · · Score: 1, Insightful

    This is on Google. They need to get a grip on Android.

    1. Re:Thanks Google by iggymanz · · Score: 1

      wrong, on the phone manufacturer who installed evil software. the OS is irrelevant, can be done with any OS

  16. The Chinese are Honest by Anonymous Coward · · Score: 0

    Right now there is no reason to believe there was anything untoward going on. This is probably just debug code that got left in or something. Does anyone have any actual proof that this was intentional?

  17. Subnet blocked for SSH abuse by satch89450 · · Score: 1

    I checked the owning subnet, and found that I had already blocked the entire allocation for SSH abuse. Seems there are multiple bad actors in that part of the world.

  18. Backdoors by paskie · · Score: 1

    Meanwhile, Public Backdoor in Many Chinese Phones Sent Data To US.

    --
    It's not the fall that kills you. It's the sudden stop at the end. -Douglas Adams
  19. Re: "updated the software to eliminate the feature by fustakrakich · · Score: 1

    Like everything else, it's totally dependent on your point of view.

    --
    “He’s not deformed, he’s just drunk!”
  20. I sound like the racist guy at work by Anonymous Coward · · Score: 0

    Almost every meeting, I'm warning people about hackers from Russia, China, or phishers from Nigeria.

  21. Google is collecting exactly the same information by Anonymous Coward · · Score: 0

    but they get it out of the phone and your online habits in more subtle ways. If you balk at this article, and then continue to use Android and various Google services, then you clearly have no idea what you're doing.

  22. Which subnet? by bigbang137 · · Score: 1

    What is the subnet? What do you use to block it? Does my phone necessarily need to be rooted for me to block? Thanks.

    1. Re:Which subnet? by Anonymous Coward · · Score: 0

      If you don't leave Mom's basement, you can just use wifi and do all your blocking on the router.

    2. Re:Which subnet? by satch89450 · · Score: 1

      I just checked, and they have moved their name into a different subnet. Snowshoes in action.

  23. security theater by Anonymous Coward · · Score: 0

    What does Kryptowire do?

    "Kryptowire provides mobile application software assurance tools, anti-piracy tools, marketplace security analytics, and mobile brand protection."

    I translate it as "Kryptowire provides useless software applications for code that can not be secured, garbage, aggregation of personally identifiable data from its victims or its clients". No idea what "mobile brand protection" can mean in this context.

    According to Bloomberg, "Kryptowire caters to military, law enforcement, and intelligence agencies." That i think translates to "guaranteed to be untrustworthy, lying AND incompetent if the money is right". But hey, they can figure out that an android service does something, on a phone. Good for them.

  24. It's called "root". (Adminstrator for Windows user by raymorris · · Score: 2

    It's called root. You enable root, then choose from any of the many apps which mount the "rom" read-write and you check off which pre-installed apps you want to remove.

  25. There! by Tablizer · · Score: 1

    It's not "theoretical" anymore, Mr. Comey

  26. Re:I want to be the racist guy at work and parties by Anonymous Coward · · Score: 0

    Russia is not a race. China is not a race. Nigeria is not a race.

  27. Android wins! by Ol+Olsoc · · Score: 1, Funny

    Android collects and sends text messages to state actors much better than that fucking overpriced hipster shit that Apple sells. Tak that - Apple Fanbois!

    --
    The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
  28. The smug bitch : It's just food... by Anonymous Coward · · Score: 0

    It's a post about food, and the two shits you gave was probably more than all the other readers combined (unless they actually ate the chicken).

    1. Re:The smug bitch : It's just food... by Anonymous Coward · · Score: 0

      It was a post about a joke calling Chinese food Japanese, not about how culturally significant you are. You and your elitist friends are the only ones who care about whether or not it's "authentic" Chinese. The rest of us know good and well it's not but eat it because it tastes good.

      Do you mock people from other countries for bastardization of American foods to meet their local palates? Do you give shit to the Indians for McDonald's having a "Mexican McAloo Tikki" burger? That's as far from American/Mexican as you can get.

      You smug douche.

  29. This is NOT a big deal by Anonymous Coward · · Score: 0

    "WizBang Game App Wants Access to Read and Send SMS - Allow - Deny"

    99.9% of people click Allow without even reading the popup.

  30. Re:Google is collecting exactly the same informati by GTRacer · · Score: 1

    Or, like me, you willingly accepted the bargain. I don't mind *Google* having my info, as it lowers friction across their services and makes my searches/maps better. I don't like the idea they can and do hand it over to the TLA's, but I'm not stupid enough to believe we really have any choice there anyways,

    What I do not agree to is foreign governments or actors having that info. I install precious few apps, mainly because 90% of them are garbage, and otherwise to limit my exposure. That, and XPrivacy + hosts blocking lets me sleep at night.

    --
    Defending IP by destroying access to it? That makes sense, RIAA/MPAA. Go to the corner until you can play nice!
  31. Android is just Linux by Anonymous Coward · · Score: 0

    You can cross compile tcpdump and capture all network traffic to flash for analysis. I did this for weeks when I first got Android to make sure all "evil bits" of which there are many had been successfully exorcised from *MY* phone.

    Obviously anything that comes is preinstalled could hook the kernel and lie but I'm not yet paranoid enough to care about such possibilities. What's next compromised compilers? I seem to recall Microsoft already got caught doing that.

  32. Facebook does that by Anonymous Coward · · Score: 0

    Facebook does something similar in that it would upload a person's contact list, along side with its photos to its servers. If a person on Facebook does not have pictures of themselves posted, and a friend with the Facebook/Whatsapp App on the phone, with a picture of the person in the contact list, it would get uploaded to FB servers and they would have an image.
    FB asks people to identify faces whenever they try to authenticate a person when logging in from non-typical machines. This lets them to validate the photos.

    Things became significantly worse ever since it acquired Whatsapp, where access to users phones became even more invasive.

  33. tacos by Anonymous Coward · · Score: 0

    Tex-Mex tacos are still tacos. The history of Texas and the Southwestern U.S. is such that the definition of "taco" doesn't end at the U.S./Mexico border. The Spanish government may have retreated, but the people remained.

    Tacos continued to evolve North of the border... but then who thinks they haven't continued evolving South of the border too?

    IMHO, the best place to grab a "true" Mexican Taco is in a Mexican restaurant out by the auto garages and cheap homes around a Texan or Arizona border town. Better quality ingredients, cleaner water and higher standards for sanitation. You'll need to speak Spanish of course...

    1. Re:tacos by Anonymous Coward · · Score: 0

      when I lived in Portales, NM, the best place to live and eat was 'across the tracks'. There the friendly, helpful polite persons of Hispanic descent would always offer food to people who looked hungry, the rent was cheaper, and your neighbors always were ready with a helping hand... In the 'not' across the tracks section of town, those folks were afraid their property values would drop so looked at everyone as a potential crook, unless you were a preacher.

      maybe things have changed in the intervening decades?

      But the food across the tracks was better, tastier, and cheaper.

  34. Blackmail by Anonymous Coward · · Score: 0

    The Chinese now have enough information to blackmail a lot of people. Think, what do they know about Anthony Wiener now?

  35. ZTE and Huawei by Anonymous Coward · · Score: 0

    Zooty and Hooey phones ship with pre-broken firmware from China. Now we are seeing apps take advantage of it.

  36. Whats the difference anyway by bearvarine · · Score: 1

    Nowadays "advertising information" is the new biometrics. Or, if you will, meta-biometrics. Its already been reported that it takes only 3 pieces of user preference data to uniquely identify most people. Get used to it. Resistance is Futile. If it isn't already, your every move on the internet is being tracked, indexed, cross-referenced and added to your "dossier". End of story.

  37. Windows 10 by Anonymous Coward · · Score: 0

    And, ALL Windows 10 machines send data back to the U.S. every second.

    Why is it only bad if China does it? That's a little bit of a double standard, don't ya think?