Slashdot Mirror


Samsung Phones Are Spontaneously Texting Users' Photos To Random Contacts Without Their Permission (theverge.com)

Some Samsung smartphones are randomly sending pictures from the device to a user's contacts without explicit permission, according to users and media outlets. From a report: Users are complaining about the issue on Reddit and the company's official forums. One user says his phone sent all his photos to his girlfriend. The messages are being sent through Samsung's default texting app Samsung Messages, and the photos are being sent as SMS messages. According to reports, the Messages app does not even show users that files have been sent; many just find out after they get a response from the recipient of the random photos sent to them. Samsung told the news outlet it was aware of the issue and was looking into it.

111 comments

  1. "Samsung is the best ever at everything!" by RickyShade · · Score: 1

    *Looks down at LG V30* "Good boy"

  2. Move fast, break things, shoot each other in the f by Anonymous Coward · · Score: 1, Funny

    How's that agile development coming along?

  3. Nevertheless by Anonymous Coward · · Score: 0

    The Samsung phones remain the most explosive devices in the market. Not surprisingly so, coming as they are from Samsung, a company on fire, if there has ever been one.

    1. Re: Nevertheless by Anonymous Coward · · Score: 0

      That would possibly be sort of funny for like a day, two years ago.

      You are not a funny person. In real life nobody likes you.

    2. Re: Nevertheless by Anonymous Coward · · Score: 0

      You, in fact, must be great at parties.

  4. Wang pics aplenty!! by HarrySquatter · · Score: 2

    A followup question is: How many wang pics were sent out because of this?

    1. Re:Wang pics aplenty!! by oldgraybeard · · Score: 1

      And to who? lol Just goes to show don't take any pictures you would not want your Mom to see.

    2. Re:Wang pics aplenty!! by Calydor · · Score: 1
      --
      -=This sig has nothing to do with my comment. Move along now=-
    3. Re: Wang pics aplenty!! by Anonymous Coward · · Score: 0

      TBF she did "send to all"

    4. Re:Wang pics aplenty!! by fahrbot-bot · · Score: 2

      A followup question is: How many wang pics were sent out because of this?

      Almost as many as chung photos.

      --
      It must have been something you assimilated. . . .
    5. Re:Wang pics aplenty!! by Anonymous Coward · · Score: 0

      Right? I'm gonna go out and buy a Samsung phone right now. Plausible deniability FTW.

    6. Re:Wang pics aplenty!! by Anonymous Coward · · Score: 0

      A followup question is: How many wang pics were sent out because of this?

      this explains a lot...

      SMS App now changed from Samsung's SMS app to to Google's official SMS app instead... because Google has presumeably not yet had a chance to see all me wang pics OR they have already downloaded all of them anyway!

  5. Re:Move fast, break things, shoot each other in th by magarity · · Score: 2

    How's that agile development coming along?

    I assume from this comment you've never gotten an OTA update from your carrier for a Samsung or any other brand. They're months and months between; hardly agile.

  6. spontaneous burst mode by Anonymous Coward · · Score: 0

    i tried taking a photo from a highrise looking out - my iphone when into burst mode for no good reason, taking 100 or so low resolution photos with a few seconds - I cleaned the glass and rebooted the phone but it still did the same thing at that location -- an hour later at home, the photo app worked normally - I'm wondering if someone at that hotel was able to hack into my phone via blutooth?

    1. Re:spontaneous burst mode by mikael · · Score: 1

      It's possible to activate the various other photo modes by sliding a finger across to the right, then picking the option (Auto, Pro, Panorama, Selective focus, Slow motion, Hyperlapse, Food, Virtual shot, Video collage or Live Broadcast) then pressing the back button. Sometimes that gets activated by accident. I've had my phone switch to front-camera mode simply because of this sensitivity.

      --
      Vintage computer adverts: http://www.vintageadbrowser.com/computers-and-software-ads
    2. Re:spontaneous burst mode by Anonymous Coward · · Score: 0

      But it's Android, can't you just fix it? That's why everyone told me to switch to an Android device.

    3. Re:spontaneous burst mode by Anonymous Coward · · Score: 0

      They're talking about iPhones.

    4. Re: spontaneous burst mode by Anonymous Coward · · Score: 0

      I did check all of those types of settings and made sure "photo" was selected from the horizontal slider - my phone is an iphone 6 se (I don't remember how old) -- iphones can go into burst mode purposely if I hold down the shutter button for 10 seconds- in this case, I didn't touch the shutter button at all--I wonder if there was some sort of internal material degradation due to age that the developers didn't plan for and/or the ~600ft height change / pressure change made this happen? (If seen my apple things do stranger things so this didn't alarm me too much)

  7. Samsung == nope by djbckr · · Score: 5, Insightful

    Some years ago, a co-worker of mine showed me his Samsung phone. It was a beauty, and he let me play with it for a bit. The hardware was wonderful. The proprietary Samsung crap-ware that was on it was what made me decide that I would never get a Samsung phone. It's just like the branded crap-ware on Windows machines. I have a Nexus 6P and I think it's wonderful. It's Android the way it was intended. Yes, I know Google spies on me.

    1. Re: Samsung == nope by amxcoder · · Score: 1

      This is one of the big reasons I just moved away from Samsung phones after many years. I've had Samsung since the original Galaxy S, then an S3, then an S5. The STUFF was still running Android 4.4 and never got updates. They also had more and more bloatware with each generation. Finally broke down and bought a new One plus 6 last week. Hardly and bloat at all. Much like my wife's Nexus.

    2. Re:Samsung == nope by whodunit · · Score: 2

      BINGO. Great hardware - SHIT software.

    3. Re:Samsung == nope by Anonymous Coward · · Score: 1

      I couldn't agree more. Had the Nexus 5 for 3 years. Got an LG G5 just as the G6 came out. Forgot how much crap they also install. One year later, after screen burn, gps issues and the vibrate function not working I discovered the android one project. It's like what the Nexus brand used to be. Loving my Nokia 7 plus with no bloat and guaranteed updates for 2+ years. Pixel range is far too overpriced.

    4. Re:Samsung == nope by Anonymous Coward · · Score: 0

      Use this and get the best of both worlds: https://www.lineageos.org/

    5. Re:Samsung == nope by AmiMoJo · · Score: 2

      My brother has one that just got the Oreo update (Galaxy S6 I think) and they actually removed a lot of the crapware. I hear they are going to produce a pure Android version of their latest one too.

      Seems that after so very long Samsung has realized there is demand for bloat-free phones. I'm currently using a Pixel XL but Samsung hardware is quite attractive (good camera, SD card, wireless charging, replaceable battery, waterproof, USB, headphone jack) so if they do make a pure Android version I'll consider it.

      Having said that they better make that Bixby button remappable on the stock Android version.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    6. Re:Samsung == nope by tkotz · · Score: 1

      I ran LineageOS on a Note II for a long time. it was great. I actually recently passed it to a friend of mine and he is still using it.

  8. No, they are not sent as SMS messages by Anonymous Coward · · Score: 0

    An SMS message can carry at most 140 bytes. You don't have pictures worth worrying about which are that small.

    1. Re:No, they are not sent as SMS messages by rickb928 · · Score: 4, Informative

      It's called MMS...

      --
      deleting the extra space after periods so i can stay relevant, yeah.
    2. Re:No, they are not sent as SMS messages by Anonymous Coward · · Score: 0

      But TFS erroneously says SMS.

    3. Re:No, they are not sent as SMS messages by EvilSS · · Score: 1

      But TFS erroneously says SMS.

      Because that's what's important here, an article using the wrong acronym. FFS YDA AC

      --
      I browse on +1 so AC's need not respond, I won't see it.
    4. Re:No, they are not sent as SMS messages by Anonymous Coward · · Score: 0

      But TFS erroneously says SMS.

      Because that's what's important here, an article using the wrong acronym. FFS YDA AC

      Actually, it is quite important. Not sure where this was reported, but in some places MMS is quite expensive. Sending all your pictures through it can bankrupt more than a few.

    5. Re:No, they are not sent as SMS messages by Anonymous Coward · · Score: 0

      Maybe it's converting the images to ASCII art.

    6. Re:No, they are not sent as SMS messages by EvilSS · · Score: 1

      as opposed to sending then through SMS?

      --
      I browse on +1 so AC's need not respond, I won't see it.
    7. Re:No, they are not sent as SMS messages by Anonymous Coward · · Score: 0

      8======D ---

    8. Re:No, they are not sent as SMS messages by Anonymous Coward · · Score: 0

      MMS is not SMS. You can tell by looking at the first letters.

    9. Re:No, they are not sent as SMS messages by Cederic · · Score: 2

      I can send several thousand SMS messages this month and it wont cost me a penny.

      Each MMS message will cost me 50p. Automatically sending all the images from my phone via MMS to even a single recipient would cost me a three digit sum.

      I can imagine for some people you could add a digit with ease.

    10. Re:No, they are not sent as SMS messages by OolimPhon · · Score: 1

      A good reason for not keeping all your pictures on your phone.

      I download all mine to local storage every couple of months or so and then clean out the phone. One, it frees up phone memory and two, if the phone gets lost or stolen, there's less for the finder to use against me.

    11. Re:No, they are not sent as SMS messages by Cederic · · Score: 1

      Indeed. However the phone doesn't differentiate between photographs I've taken and things like the book covers for the multiple ebooks I have on it.

    12. Re:No, they are not sent as SMS messages by Impy+the+Impiuos+Imp · · Score: 0

      (__*__)

      --
      (-1: Post disagrees with my already-settled worldview) is not a valid mod option.
    13. Re:No, they are not sent as SMS messages by EvilSS · · Score: 1

      I can send several thousand SMS messages this month and it wont cost me a penny.

      Each MMS message will cost me 50p. Automatically sending all the images from my phone via MMS to even a single recipient would cost me a three digit sum.

      I can imagine for some people you could add a digit with ease.

      Cool, so how do you send an image via SMS and not MMS?

      --
      I browse on +1 so AC's need not respond, I won't see it.
    14. Re:No, they are not sent as SMS messages by rickb928 · · Score: 1

      My point.

      --
      deleting the extra space after periods so i can stay relevant, yeah.
    15. Re:No, they are not sent as SMS messages by Cederic · · Score: 1

      Base 64 encoding? I haven't tried.

    16. Re:No, they are not sent as SMS messages by EvilSS · · Score: 1

      Did you even read this thread before commenting?

      --
      I browse on +1 so AC's need not respond, I won't see it.
    17. Re:No, they are not sent as SMS messages by Cederic · · Score: 1

      Why yes, yes I did. You were nonsensically comparing SMS and MMS costs, and although it would be a pain in the arse, it's significantly cheaper to use SMS.

    18. Re:No, they are not sent as SMS messages by EvilSS · · Score: 1

      LOL so apparently you didn't read it.

      --
      I browse on +1 so AC's need not respond, I won't see it.
    19. Re:No, they are not sent as SMS messages by tehcyder · · Score: 1

      MMS is not SMS. You can tell by looking at the first letters.

      It's quite close though!

      --
      To have a right to do a thing is not at all the same as to be right in doing it
  9. Would using Rust instead of Java have helped? by Anonymous Coward · · Score: 0, Funny

    Correct me if I'm wrong, but I assume this software is written in Java, like many Android apps are. Would using a modern programming language like Rust instead of an older language like Java have prevented a bug like this from happening (assuming it actually is a bug that is being reported by these users) in the first place?

    1. Re:Would using Rust instead of Java have helped? by Anonymous Coward · · Score: 0

      No.

    2. Re:Would using Rust instead of Java have helped? by Cley+Faye · · Score: 1

      Software doing something quite complicated like crafting a message, sending an attachment etc. is not software being faulty and the execution being corrupt, it's software doing what it was told. The problem likely lies before the software turns from idea into code, so the language is irrelevant. Until we have AI-powered compiler that can analyze human behavior, no language, no matter how modern, should prevent a developper from writting code that do stuff, no matter how silly it is.

    3. Re: Would using Rust instead of Java have helped? by Anonymous Coward · · Score: 0

      Rlrust is a pile of hipster garbage. Worry less about your dev tools and worry more about your developers skills.

    4. Re:Would using Rust instead of Java have helped? by slashcross · · Score: 1

      Correct me if I'm wrong, but I assume this software is written in Java, like many Android apps are. Would using a modern programming language like Rust instead of an older language like Java have prevented a bug like this from happening (assuming it actually is a bug that is being reported by these users) in the first place?

      I assure you, bad code can be written in any language.

      --
      Slashdot your i and slashcross your t.
  10. Re:Move fast, break things, shoot each other in th by rickb928 · · Score: 3, Informative

    It's not the release schedule that's Agile, its' the development process...

    --
    deleting the extra space after periods so i can stay relevant, yeah.
  11. So how do you fuck that up? by Anonymous Coward · · Score: 0

    First, it's clearly not an SMS message. However, I'm trying to think through what mechanism could spontaneously pick a target and send these, and the simplest explanation is malicious code. It's probably disgruntled employee, but I wouldn't rule out competitors. There's a lot of money behind wining market share in the smartphone world.

    1. Re:So how do you fuck that up? by nwf · · Score: 1

      You didn't mention "marketing". Not sure how, but with Samsung, it's probably some dumb marketing feature gone awry.

      --
      I don't know, but it works for me.
  12. It's a feature by Anonymous Coward · · Score: 0

    Seriously, it's not a bug, it's a feature to let users who are socially awkward, get a funny story with people they don't talk to much.
    And if it sends a naked picture of you, well you should've deleted it or never taken it in the first place, you reap what you sow. And by that I mean this is what you get for buying a Samsung phone.

  13. Sharing is caring by mveloso · · Score: 3, Funny

    Samsung is just trying to show that it cares by connecting you with your friends.

    1. Re:Sharing is caring by Anonymous Coward · · Score: 0

      I've programmed my phone to respond with a text "thanks for the nudes!"

  14. Re:Move fast, break things, shoot each other in th by Contract+Gypsy · · Score: 0

    Agile, so Agile, 2 week sprints 14 days of 12 hours work, that brings out the greatest most stable programs. That Scrum guy better run!

    --
    Life is in a state of dynamic equilibrium, it both blows and sucks
  15. Bixby by LynnwoodRooster · · Score: 2

    I blame Bixby, about the worst digital "assistant" I've ever seen. I bet that Bixby is "interpreting" actions or words to do something stupid...

    --
    Browsing at +1 - no ACs, I ignore their posts. So refreshing!
    1. Re:Bixby by nwf · · Score: 1

      I blame Bixby, about the worst digital "assistant" I've ever seen. I bet that Bixby is "interpreting" actions or words to do something stupid...

      That's probably the answer. They added bixby for marketing reasons, since all the cool kids have digital assistants and they needed one as well. It's just that they can't write decent software. Having had a Samsung phone for doing Android development, I know I'll never get another one because their software is just so bad.

      --
      I don't know, but it works for me.
    2. Re: Bixby by Anonymous Coward · · Score: 0

      Yeah, that's my guess too. Samsung's messaging and email apps are pretty good actually. Only thing Bixby button is good for is the magical vol down+ bixby + power trick when my DeX dock gets hung up.

    3. Re:Bixby by LynnwoodRooster · · Score: 1

      I'm not a fan of Samsung software, but I so freaking love the Note... I'm a "write it down/sketch it out" kind of guy, and having an essentially endless notebook with me at all times it so convenient. If someone else came out with a phone with a decent stylus/note-taking/sketching tool, I'd jump in a heartbeat. But until then... At least in the meantime I've disabled the Bixby button!

      --
      Browsing at +1 - no ACs, I ignore their posts. So refreshing!
    4. Re:Bixby by The+Black+Oak · · Score: 1

      Even when it's "Turned Off" - Samsung needs to seriously stop trying to make software, they are really bad at it and keep doing it despite knowing that they are just driving their customers away. They are bordering on insanity with this, same as sprint and verizon - obviously piss poor bottom level software developers yet ;they keep doing it.

  16. Re:Move fast, break things, shoot each other in th by Anonymous Coward · · Score: 0

    Don't take pictures of your cock and you won't have to worry about them being sent to your mom.

    Problem solved.

  17. 1% more likely in Rust (troll?) by raymorris · · Score: 5, Informative

    I imagine this is probably a troll, but just in case:

    The language chosen would have very, very little effect on this. This is a problem with the overall design of the app.

    Rust, like Python, Java, Perl, PHP, VBScript, JavaScript, and most other languages, doesn't lend itself to one very specific type of bug called a buffer overflow. That specific issue is mostly just seen in C. Rust is like most languages in that buffer overflow isn't the bug you have to worry about in Rust (or in Perl, PHP, Python, Java, etc.)

    What's different about Rust is a very clever marketing thing they did. They took the fact that most languages, including Rust, don't have buffer overflows and hyped it to Trumpian proportions. In marketing material that would make PT Barnum blush, they exclaimed "Rust is secure because it doesn't have buffer overflows! Write all your software in Rust and you'll never have another bug!" Understand this is analogous to saying "spiders are venomous, don't use spiders. Tigers have no venom! If you use tigers, you never have to worry about venom at all. Buy some tigers from us today so you can be safe!"

    The problem then is that newbies who don't understand much about programming *think* they're safe because they're using tigers. No need to be careful with tigers because they aren't venomous. Er, I mean no need to be careful when you're using Rust because it doesn't have buffer overflows. That makes it slightly more dangerous, since a lot of people aren't being as careful as they should, thinking Rust is somehow magic.

    I maintain a database of every CVE (security bug) ever reported. Well under 1% of them are buffer overflows, so it's a tiny percentage of problems that Rust protects against.

    1. Re:1% more likely in Rust (troll?) by Anonymous Coward · · Score: 0

      Alligators or crocodiles would probably be a better counter-example.

      Tigers are dangerous, of course, but they're dangerous mostly just because of their size & strength. Temperamentally, a tiger who's born in captivity, raised by humans, and lives a life of pampered indulgence won't end up being fundamentally different from a housecat. They'll chill with you on the couch, curl up with you in bed, gleefully play with boxes, chase laser pointer dots, get high on catnip, and feast on tuna like it's the Food of the Gods.

      In contrast, no amount of loving care & indulgence will EVER make an adult alligator or crocodile safe to share your home with... not even with training, disclaimers, conditions, and qualifiers.

    2. Re:1% more likely in Rust (troll?) by Anonymous Coward · · Score: 0

      The problem then is that newbies who don't understand much about programming

      TFA's issue doesn't even remotely count as a "bug" however. That is unless you consider successfuly crafting an SMS message, accessing and attaching a random picture to it, then accessing a random contact's phone number, and sending the message to that number, on a repeated basis, to be "undefined" behavior.

      This is intentional behavior. Such an app would need not only to query the correct APIs for this data and for sending the message for this to happen, but the permissions as well. Surprise surprise, Samsung's bloatware has every possible permission by default last I checked, including permissions that don't show up in the permissions dialogs. The API accesses aren't random either. Someone had to write the code for it to do this successfully, on a repeated basis.

      If this was some "unfortunate chain of unintended events," the next question would be how is it hiding the fact the message was sent? What API would exist that hides SMS messages that the service subscriber may have to pay for, that doesn't inform them the message was sent out at the very least for billing / legal purposes?

      This smells like some debugging function left in accidentally. At least we had better hope that it is, because I can think of 4-5 different ways, off the top of my head, that this "unintended" functionality could be abused.

    3. Re:1% more likely in Rust (troll?) by serviscope_minor · · Score: 1

      What's different about Rust is a very clever marketing thing they did.

      No.

      They took the fact that most languages, including Rust, don't have buffer overflows

      But most languages can't operate in the same spaces as C and C++.

      That specific issue is mostly just seen in C.

      And C++. And it just so happens that most of the high performance software in the world is written in one of those two languages.

      Particularly web browsers (until Rust).

      Write all your software in Rust and you'll never have another bug!"

      That sounds like an invented claim.

      The problem then is that newbies who don't understand much about programming *think* they're safe because they're using tigers.

      Right so we should neuter everything we use to build the major bits of infrastructure in the world because newbies?

      I maintain a database of every CVE (security bug) ever reported. Well under 1% of them are buffer overflows, so it's a tiny percentage of problems that Rust protects against.

      That's a very disingenuous claim. Firstly you should only compare to large C++ programs, because that's what Rust is competing with. It's vapid to compare to other languages because no one has written a major web browser in anything other than C++ because C is far too hard for the task and nothig else is remotely fast enough.

      Rust's sole purpose is to provide a C-like machine model with memory safety, which includes safety from data races, use-after-free, dangling reference bugs and so on. The goal is to allow people to write in that machine model, i.e. not lose performance, but without all the potentials for foot-shooting in C++.

      Those cliams are rather subtle and it seems a bit hard for many people to understand so they often get simplified.

      --
      SJW n. One who posts facts.
    4. Re:1% more likely in Rust (troll?) by Cederic · · Score: 1

      they're dangerous mostly just because of their size & strength. Temperamentally, a tiger who's born in captivity, raised by humans, and lives a life of pampered indulgence won't end up being fundamentally different from a housecat

      So they'll let you know you've stroked them too much by pinning your arm down with claws?
      They'll lie down in a 'please play with me' way then bite you?
      They'll mock fight with you, using claws to pull your hand towards their mouth while their rear legs kick repeatedly at it?

      My cats are lovely but there's a reason tigers aren't common pets.

    5. Re:1% more likely in Rust (troll?) by Anonymous Coward · · Score: 0

      Hello,

      I'm interesting by this new "Tiger" programming language and I wish to subscribe to your newsletter.

    6. Re: 1% more likely in Rust (troll?) by Anonymous Coward · · Score: 0

      Basically, yes. Think about how different the outcome would be if your cat behaved *exactly* the way (s)he does now, but weighed 400lb instead of 15lb. That's *exactly* why it's dangerous to play with tigers.

      There's a phrase in French or Latin used by lawyers that I can't remember now, but it basically translates to, "a difference in size(scale) that becomes a difference in kind". Kind of like how leaking PII in public court documents wasn't great, but wasn't really a big deal back when reading it required going to the courthouse, filling out a form, presenting an ID, and knowing which specific file to request in the first place... but became a VERY big deal once it became possible to automatically harvest the court records for an entire county, OCR them, and systematically data-mine them on a grand scale.

      Tigers & housecats both do "love swats" and "control bites". The difference is, a housecat can't do much more than give you a scar. A tiger doesn't fully understand its own relative strength or the relative fragility of humans compared to them. That's why very few people who get injured by their own tigers want to see the tiger punished or killed... they KNOW it was all just a tragic misunderstanding by their big kitty.

      Cats have instincts. So do humans... except in humans, we call it "neurosis" when somebody driven by emotion does something harmful & illogical. Think about two housecats who are friends, observe something scary outside through a window, and proceed to attack each other in response for no directly-logical reason. Or the way humans react to fear by relentlessly hunting for scapegoats & punishing them, even if they know with almost 100% logical certainty that those being punished are actually innocent & the REAL guilty party is going free.

    7. Re:1% more likely in Rust (troll?) by bingoUV · · Score: 1

      Wow!

      Write all your software in Rust and you'll never have another bug!"

      That sounds like an invented claim.

      Ok, maybe.

      The problem then is that newbies who don't understand much about programming *think* they're safe because they're using tigers.

      Right so we should neuter everything we use to build the major bits of infrastructure in the world because newbies?

      This is definitely a an invented claim.

      --
      Bingo Dictionary - Pragmatist, n. A myopic idealist.
    8. Re:1% more likely in Rust (troll?) by tehcyder · · Score: 1

      get high on catnip

      I really don't want to be anywhere near a tiger high on catnip.

      A ten pound house cat going mental is one thing, a four hundred pound tiger would be something else.

      --
      To have a right to do a thing is not at all the same as to be right in doing it
  18. The real question is by cdsparrow · · Score: 3, Insightful

    Who gets arrested when it sends out nude selfies from someone under 18? The coders? The CEO of Samsung?

    Lawyers love this kind of stuff, lol

    1. Re:The real question is by ole_timer · · Score: 1

      the person who took them...obviously (self referential humor)

      --
      nothing to see here - move along
    2. Re:The real question is by R3d+M3rcury · · Score: 1

      Hm.

      If the person sending it is under 18, I believe the answer is "both." It's kiddie porn, after all.

      Now, as an adult, if my phone accidentally sent a dick pic to someone under 18, I suppose I would be charged with some sort of sex crime but the person receiving it would be fine.

    3. Re:The real question is by Anonymous Coward · · Score: 0

      You jest, but there have been cases where the teen gets charged under the child pornography laws for making it. There are some states that try to address this, but there are still quite a number of them that still prosecutes under child porn laws.

    4. Re:The real question is by AmiMoJo · · Score: 1

      Sadly it would probably be the victim going to jail, because in many jurisdictions merely taking such photos would be a crime.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    5. Re:The real question is by thegarbz · · Score: 1

      By victim you mean the person who made the child pornography. :-)

      Yeah I get what you're saying, but the law doesn't understand.

  19. Wow by Anonymous Coward · · Score: 0

    So many incredibly dumb things being said in that reddit post (which is what should have been linked, but the fucking verge article):

    https://www.reddit.com/r/GalaxyS9/comments/8u36jz/my_s9_sent_my_entire_photo_gallery_to_my/

    I'm actually amazed at the number of people that have no fucking idea how anything works.

  20. I tried to like Android by Anonymous Coward · · Score: 0

    Last summer, I went home to England for a visit with a brand new Google Pixel. Great handset, but the software was just dodgy. The only redeeming feature of the phone was the camera, which took some stunning photos, especially at Stonehenge, and at home around the Hampshire coast. I returned to America and the dodgy software kept acting odd, even after a full reset. I traded it in for an iPhone 8 and have been happy since. I did notice that quite a few Britons are now moving to the iPhone in lieu of Android, which still has a worldwide share of something like 80-85%. In China, the iPhone is considered less than top-of-the-line Xiaomi handsets. The problem with Android is that unless you buy a Pixel, you're getting a balkanised device that may or may not see updates. I'm not one to root my devices, so I use stock ROMs. Methinks I will be staying with the iPhone unless and until Google make a truly compelling device. The iPhone 8 just works. It's predictable, gets updates for years on end, and is generally far more reliable. YMMV.

  21. sos, part 2 by ole_timer · · Score: 0

    Samsung = android = bloatware

    --
    nothing to see here - move along
  22. Blackmail threat a few days ago by Anonymous Coward · · Score: 0

    A few days ago, I received a blackmail threat from some guy in Estonia threatening to distribute pictures from my smartphone unless around $470 was sent to a Bitcoin address.

    iket Dtils: JWF-837-46497
    Email: XXXXXXXX
    Camera ready,Notification: 27/06/2018 02:57:49
    Status: Waiting for Reply 98xuCaPy9A5f04wEnImPkL3WrF6By69Hu5_Priority: Normal

    Good day,

    If u were more scrutiny while playing with yourself, I wouldn't worry you. I don't think that playing with yourself is extremely awful, but when all colleagues, relatives and friends get video of it- it is certainly for you.

    I placed malisious soft on a porn web-site which was visited by you. When the victim tap on a play button, device begins recording the screen and all cameras on ur device starts working.

    Moreover, my program makes a remote desktop supplied with key logger function from ur system , so I could get all contacts from your e-mail, messengers and other social networks. I'm writing on this e-mail because It's your working address, so u must check it.

    I suppose that 470 usd is pretty enough for this little misstep. I made a split screen video(records from screen (interesting category ) and camera ooooooh... its funny AF)

    So its your choice, if u want me to delete ur disgrace use my bitcoin wallt ddress: 1PWpbtT6aaUKCNAVC8z6vJhWaFrJhcMXto

    You have one day after opening my message, I put the special tracking pixel in it, so when you will open it I will know.If ya want me to share proofs with ya, reply on this message and I will send my creation to five contacts that I've got from ur contacts.

    P.S. U can try to complain to cops, but I don't think that they can help, the inquisition will last for one year- I'm from Estonia - so I dgf LOL

  23. Great by Anonymous Coward · · Score: 0

    It's not a flaw...it's a feature!

  24. Three Letter Agency by Anonymous Coward · · Score: 0

    A few guesses as to who is really benefiting from this "bug."

  25. By design... by Anonymous Coward · · Score: 0

    ... isn't this how Android is SUPPOSED to work? LOL

  26. Obvious shill by Anonymous Coward · · Score: 0

    Obvious shill is astroturfing

  27. Probably a simple bug, really by Anonymous Coward · · Score: 0

    Probably just a regex error: When searching for a particular contact to send information to, the backdoor app is matching other contacts:
    Alfonsa
    lorennsa
    gonnsalo
    consandra
    lynnsay
    linsay

  28. Not surprised. by Anonymous Coward · · Score: 0

    I've been a long time Android user (I just don't care for iOS). My Moto G4 recently crapped out on me and I bought a Samsung phone. I've never been unhappier with an Android phone. Probably because it's barely Android. Samsung changed all sorts of things. Even with Nova launcher I was only able to turn off so many Samsung apps and replace them. Some built-in Samsung apps couldn't even be disabled. Either way they waste space, work differently than my other Android phones, and seem to be less intuitive.

    I also think all the TouchJizz customizations is why Samsung is always lagging behind on Android updates.

    Ironically the best smartphone experience I had was Windows Phone (and I'm no lover of Microsoft Windows on the desktop). I'd be happy if they would bring Windows Phone back -- it was spiffy and had a nice UI (and give me Gapps on the damn thing!)

    Samsung doesn't seem to impress me on the software front (the HW seems ok).

  29. Makes Me Laugh by dcw3 · · Score: 1

    Considering Samsung's ongoing anti-Apple marketing campaign, this just made me laugh.

    --
    Just another day in Paradise
  30. Roy? Say hi to Siegfried for me by raymorris · · Score: 1

    Siegfried & Roy might have thought that, until 2003.

    1. Re: Roy? Say hi to Siegfried for me by Anonymous Coward · · Score: 0

      Actually, they STILL do. Roy Horn's explanation is that the tiger was startled by someone in the crowd, he stumbled, and his tiger tried to be a good friend and carry him to safety the same way a mother cat carries her kittens/cubs: by the scruff of the neck. The problem is, tigers just fundamentally don't understand that we aren't funny-looking tigers who are just like them.

      My point is, a tiger isn't necessarily "safe" to be around, but an alligator or crocodile will never, EVER be even SLIGHTLY safe to be around.

      I'd argue that a smaller big cat, like a leopard or cougar, is no MORE dangerous (when born in captivity, raised by humans, and generally pampered) than some large dog breeds. A friendly big dog can accidentally knock you over, step on you & break bones. I've gotten bruises by getting happily whacked by a large pitbull's tail. They don't intend to injure you, but it can still happen just because they're so BIG.

      Interesting observation: when somebody has a lion, it's often hard to tell who's the pet -- the lion, or the human. Lions are "pushy" -- literally, they'll push you around using their heads if they want to show you something.

      Cats in general give biologists headaches every time the topic of "domestication" comes up, because they consistently defy our neat, orderly definitions. Cats aren't "domesticated" as much as "signatories to a mutually-beneficial peace treaty", and a random Persian or tabby has WAY more in common with a tiger than a dachshund has in common with a wolf.

  31. MMS cost 30cents each by Anonymous Coward · · Score: 0

    Just wonder how much money the cost can add up to

  32. Plain old malware, not Samsung's fault by Anonymous Coward · · Score: 0

    just another hate-the-biggest-manufacturer post. You'll find the same complaints if you dig around the forums of other manufacturers of Android sets.

  33. Debug / unit t could be part of it. Pocket dialing by raymorris · · Score: 2

    The app is designed to send messages, to contacts, with pictures attached. Obviously that code didn't appear by accident, it was included because that's the purpose of the app. The question is "why is the app doing its thing without being told by the user?" It's as if it's especially prone to "pocket dialing" (or accidental voice dialing?) for some reason.

    > This smells like some debugging function left in accidentally

    Specifically, a test script. Unit testing could easily have behavior similar to what was described.

    > What API would exist that hides SMS messages

    The problem is in the messaging app. Where do you see your text messages other than in your messaging app? There is no hiding happening (no active hiding), rather the "display sent message" function is not being run. Normally the messaging app would do two things - display the message the user types and send the message. The app is not displaying messages that the user isn't typing, so that's normal behavior.

    Programmers would write separate unit tests to test those two different parts of the program - the local UI would have tests, and sending messages over the network would have separate unit tests. Running the unit test for the internal process for sending an attachment would be expected to have this behavior - and would not be expected to run anything in the UI. So it would send messages, not display them.

    It's ALSO possible that this is nefarious code. That's possible. Pocket dialing while it the screen is supposed to be locked is also possible.

  34. The Android owner's refrain by Anonymous Coward · · Score: 0

    But other than that, it works extremely well!

  35. Whew by Opportunist · · Score: 1

    Now I have an excuse for sending that pic to the hot chick in accounting. 'twasn't me, it was the phone! Drop that harassment suit already, dammit!

    Besides, that's not a bathing suit. It's a tan line.

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  36. Re:Move fast, break things, shoot each other in th by Anonymous Coward · · Score: 0

    She has already seen it. Not only that, it was inside her! Even Trump's cock was inside his mom. I know this is shocking news.

  37. Re:Move fast, break things, shoot each other in th by Anonymous Coward · · Score: 1

    It's amazed me that it's called "Agile" when it's the MOST rigid and inflexible process from the developer point of view. The schedule is not allowed to slip by even a single day, ever.

    Imagine getting your hair cut. Everything is going well, great haircut, then at the last minute, when she's doing the edges and finishing touches free hand with those electric clippers, you yell "QUICK!!! HURRY UP!!!!1!!!!"

    That's like the last day of a sprint. Rush through those last critical details so you can make the sprint demo. Because if you don't, you might as well have not come to work for the last two weeks.

  38. Re:Move fast, break things, shoot each other in th by Impy+the+Impiuos+Imp · · Score: 1

    The sprint is suppose to let shit slide to the next sprint. That's the whole point of regular mini-releases.

    That doesn't help with hard endpoint feature demands by customers, but that's longer-term whole project planning.

    --
    (-1: Post disagrees with my already-settled worldview) is not a valid mod option.
  39. Re:Move fast, break things, shoot each other in th by Anonymous Coward · · Score: 0

    The only Agile features used in most Agile projects are two week deliverables and a status meeting every morning.

  40. This is a scenario few of us imagined by hey! · · Score: 1

    at the dawn of the consumer digital age: a world in which combines unprecedented convenience with unprecedented complexity and unpredictability.

    For every prior generation convenience, simplicity and predictability were effectively synonymous.

    --
    Post may contain irony: discontinue use if experiencing mood swings, nausea or elevated blood pressure.
  41. Re:Move fast, break things, shoot each other in th by magarity · · Score: 1

    It's not the release schedule that's Agile, its' the development process...

    Deployment to production is the last step of an Agile sprint. Otherwise you're doing Agile halfassed.

  42. Don't pretend it's safer than most other languages by raymorris · · Score: 1

    > Right so we should neuter everything we use to build the major bits of infrastructure in the world because newbies?

    What we should do is not pretend it's any safer than Python, JavaScript, Perl, etc. Most languages don't have the problems that Rust fanbois gloat about. As I said, 99% of all security issues are unrelated to anything Rust does any better, so to pretend that Rust will solve your security problems, or even a significant percentage of security problems, is dishonest.

  43. how do you text a photo? by Anonymous Coward · · Score: 0

    is this ascii art or something? how do you text a photo?

  44. Next-Gen Personal Assistant by Headw1nd · · Score: 1

    As a Samsung owner I am super excited about this feature. This will save me the time and money required to get blackout drunk and do this myself.

  45. Systemic issue of toxic cesspool by Champaklal · · Score: 1

    Samsung has become a toxic cesspool in technical division- Korean counterparts try to steal good projects from engineers abroad and try to sell it as their own. They track with hawk's eye on who is doing what. As soon as they see if there's anything special going on, they swoop and try to snatch it.

    Another set of issue is dominance- Learning department and security depart dominate over engineers. Engineers' belongings are checked when they are leaving, and not when they enter the building. If anything is found, engineers are humiliated and blamed as if they were "stealing" anything. Learning department imposes yearly coding tests, and people are given dedicated time for weeks to compete through that.

    All these issues together drove away the cream of the engineers, resulting in the politicking ones staying in, and the quality of software going downhill.

  46. Re:Move fast, break things, shoot each other in th by rickb928 · · Score: 1

    Of course, slipping to another sprint is actually not deploying, so the last step is sometimes just a sprint away...

    Though around here we see sprints complete, release to production, but of course the 'release' is actually part of the intended release. Parsing the meaning of 'release' is a sport on my team. I'm too optimistic, and usually lose the bet.

    --
    deleting the extra space after periods so i can stay relevant, yeah.
  47. Re:Don't pretend it's safer than most other langua by serviscope_minor · · Score: 1

    You're arguing three silly points. The first is more or less "someone on a forum said something I don't like therefore Rust is crap". Secondly, you're ignoring that the main aim of Rust is the same space as C and C++. And thirdly, you're arguing that all CVEs are equal.

    The thing is, most infrastructure is built in C and C++. If there's a CVE in Chrome, it affects 58% of internet users. If there's a CVE in OpenSSL, it affects an *awful* lot of services. Remember heartbleed?

    What we should do is not pretend it's any safer than Python, JavaScript, Perl, etc.

    Firstly it's irrelevant because no one would write a major web browser in any of those. Remember what Rust if for, and remember how many people a CVE in a web browser affects?

    As I said, 99% of all security issues are unrelated to anything Rust does any better

    Yes you keep saying it but it doesn't make your point any more accurate. None of those supposed other languages you keep harping on about compete with C++. It doesn't matter how safe a Haskell based browser would be it it takes 10 minutes to render a web page.

    so to pretend that Rust will solve your security problems

    Stop denying that a lot of infrastructure is in C and C++ and that those languagea are not safe.

    or even a significant percentage of security problems, is dishonest.

    Eh I mean how important was heartbleed anyway? I mean that hardly affected anyone, nulike that CVE against that obscure wordpress plugin that affected positively 10s of sites...

    --
    SJW n. One who posts facts.
  48. Point being Rust is only for building a browser? by raymorris · · Score: 1

    You keep talking about web browsers, pointing out that most of them have some C++ code. Is the point you're trying to make "if you're writing a new web browser, consider Rust for the C-ish parts?"

    If that's what you're saying, fine, I won't disagree with that.
    If someone is building a new web browser, of course they'll use XUL or similar where appropriate, and it makes sense to consider Rust for other parts. (I didn't say use Rust, but considering it as one option is fine.)

    > The first is more or less "someone on a forum said something I don't like therefore Rust is crap".

    Not quite. Most of the comments and questions about Rust, here on Slashdot and many other places, either state or assume that using Rust will magically make your software much safer than other languages. That's false. To tell people they are safe (and therefore need not be very careful) when they aren't is not only a lie, is intentionally putting people in danger.

    You mentioned Heartbleed. Heartbleed was an input validation error - as in the input wasn't validated at all. If you use invalidated network input for cryptography you have a major bug. That's in no way language specific. Heartbleed written in Rust is still Heartbleed.
    In Rust the function would be called std::ptr::copy_nonoverlapping instead of memcpy - it does the same thing, dump random memory back to the attacker. (Slice clone was not available at the time).

    > And thirdly, you're arguing that all CVEs are equal.

    I didn't say that. I said I study vulnerabilities for a living, full time, and for the last several darn few of them have anything to do with anything Rust would help with. Have a look at the OWASP Top 10 - the most significant types of vulnerabilities that happen nowadays. See how many of the ten are addressed by Rust. Spoiler alert - the number is zero. Rust helps with none of the classes of vulnerabilities that cause the most problems.

    Had Rust come out, with a stable, fully usable version, in 1985 it might have been useful in the age of buffer overflows. As it is, Rust promises that in 2020 it solve a few of the things that were a problem in 1990.

  49. Re:Point being Rust is only for building a browser by serviscope_minor · · Score: 1

    Is the point you're trying to make "if you're writing a new web browser, consider Rust for the C-ish parts?"

    That's literally what Rust was created for.

    If someone is building a new web browser, of course they'll use XUL

    You what? Firefox abandoned XUL.

    and it makes sense to consider Rust for other parts.

    Tha that is precisely what Mozilla is doing right now. They're slowly replacing C++ bit with Rust bits.

    Not quite. Most of the comments and questions about Rust, here on Slashdot and many other places, either state or assume that using Rust will magically make your software much safer than other languages.

    I think you're wildly exaggerating there.

    You mentioned Heartbleed. Heartbleed was an input validation error - as in the input wasn't validated at all.

    It was a buffer overflow overflow error triggered by lack of input validation. But if it had been in a memory safe language it would have been a simple DOS attack, not the single biggest security issue of the year.

    That's in no way language specific.

    Yes it is. How the fuck would heartbleed have allowd you to extract someone else's keys in Python, Java, Haskell, Rust..., well anything other than C or C++? It says here in the CVE that it's a buffer over-read (TIL there was a different term for read vs write in this context):

    https://cve.mitre.org/cgi-bin/...

    That would not happen in not C or not C++, because other language you know, check bounds and do other things.

    Which brings us on to the other topic. Why do people write major bits of infrastructure like SSL libraries and web browsers in unsafe languages like C and C++?

    In Rust the function would be called std::ptr::copy_nonoverlapping instead of memcpy - it does the same thing, dump random memory back to the attacker.

    Well done! You picked an unsafe function. You can get the same effect in, say, python or Java by using a C module and scribbling all over memory too. Kinf od the point is to stick to safe code. And it's auditable.

    The fact you can manage unsafe things in just about any language no matter how hard you try does not mean that C is very unsafe by default and that C++ has quite a number of cases where it's eay to foul up. It's much harder.

    Make no mistake: if you manage to do something memory unsafe in Rust you have either subverted it (by explicitly doing unsafe things) or have found a genuine bug.

    I didn't say that.

    I didn't say you said that, I said you are arguing that. And you are because you kept repeating the point about the number of CVEs only while not taking into account their performance.

    I said I study vulnerabilities for a living, full time, and for the last several darn few of them have anything to do with anything Rust would help with.

    You seem to think that anything other than C or C++ would not have prevented heartbleed either. I don't know how you can study these things full time not know that. Other languages crash or throw exceptions when overstepping the end of an array. C and C++ don't.

    Have a look at the OWASP Top 10 - the most significant types of vulnerabilities that happen nowadays.

    That's great and still doesn't invalidate anything I said. Sure you're more likely to make your web application insecure with an injection bug. But if you get a CVE in Chrome, half of everyone on the intire internet is vulnerable in one go.

    You seem to be intentionally ignoring the distinction between infrastructure and applications. Rust is and always has been aimed at the same space as C++ (and C[*]). The claim that Rust magically makes your code safe against things inrelated to C++ specifically seems to have been invented by you.

    It's possibly you've simply misunderstood people: when people talk about rust being "safe" it's almost always in the context of memry safety and in c

    --
    SJW n. One who posts facts.