Millions of mobile phones come pre-infected with malware, say researchers(theregister.com)
theregister.com
Millions of mobile phones come pre-infected with malware, say researchers
https://www.theregister.com/2023/05/11/bh_asia_mobile_phones/
11 comments
At this point, I barely see a difference between "malware" and most commercial operating systems. Certainly anything samsung or microsoft makes are just thin pretenses to steal as much information as possible. I'm not familiar with Googles stuff but I can't belive it's any different.
A but unhinged to compare first party telemetry to actually unrestricted malware, no matter how you square it
You say "first party telemetry" in a way that makes the reader think you believe "Microsoft just wants to make Windows better."
I had a much longer comment, but it eventually detracted from this point: you can't guarantee where that data goes, how it's stored through its life, etc.
I had a much longer comment, but it eventually detracted from this point: you can't guarantee where that data goes, how it's stored through its life, etc.
Unlike malware authors, most big tech companies are bound by legal and ethical frameworks regarding data collection, retention, and usage.
Inappropriate usage of PII can lead to severe consequences in most western countries.
Inappropriate usage of PII can lead to severe consequences in most western countries.
Do you fully trust these companies to comply with those legal and ethical frameworks? I don’t. It’s a common refrain that paying these fines is a worthy cost of doing business.
Legal frameworks that end in settlement costs that amounts to X% of quarterly profit.
We can clearly see where the incentives are aligned.
We can clearly see where the incentives are aligned.
> Inappropriate usage of PII can lead to severe consequences in most western countries.
Facebook still being around shows this is just wishful thinking.
Facebook still being around shows this is just wishful thinking.
American business ethics is nothing to brag about, and their legal framework is basically "by using this service you allow us to do anything we want".
> most big tech companies are ~bound by~ supposed to follow legal and ethical frameworks
Also, be careful, the concept of "ethical frameworks" is used by companies to become their own judges and jury.
Also, be careful, the concept of "ethical frameworks" is used by companies to become their own judges and jury.
Remember Cambridge Analytica? Pepperidge Farm remembers.
> you can't guarantee where that data goes, how it's stored through its life, etc.
Sure, it's definitely a security risk.
However there is a strong line betweeen a first party spyware that collects data to sell, and the malware discussed in this article, that was specifically places there to try to steal your credit card or banking info for criminals.
I'm fine with legal penalties for the manufacturers in both cases though.
Sure, it's definitely a security risk.
However there is a strong line betweeen a first party spyware that collects data to sell, and the malware discussed in this article, that was specifically places there to try to steal your credit card or banking info for criminals.
I'm fine with legal penalties for the manufacturers in both cases though.
The comparison is direct and apt, as a comment on a story about devices delivered with hostile software on them.
From a consumer POV, they are indistinguishable, are they not?
At least third party malware works silently and efficiently. First party hateware puts ads in the start menu.
From a consumer POV, they are indistinguishable, are they not?
At least third party malware works silently and efficiently. First party hateware puts ads in the start menu.
One annoys while the other may drain your bank account. I'd say the distinction is still quite stark.
You entered your bank card data on your phone? OMG!
Nonconsensual apps and telemetry is indistinguishable from malware.
From a privacy perspective, maybe.
From a security perspective they’re totally different. Malware can be used to perform arbitrary code execution compromise my machine, pivot to my work computer compromise my aws keys, spin up $100k/mon infrastructure to run unrelated scams, syphon down my customer database ransomware it / post it on the dark web.
Telemetry is unlikely to do the above. If it does it gets reclassified as malware. The distinction is valid and useful.
Claiming otherwise is either ignorant in the extreme or deliberately deceptive. Which are you?
From a security perspective they’re totally different. Malware can be used to perform arbitrary code execution compromise my machine, pivot to my work computer compromise my aws keys, spin up $100k/mon infrastructure to run unrelated scams, syphon down my customer database ransomware it / post it on the dark web.
Telemetry is unlikely to do the above. If it does it gets reclassified as malware. The distinction is valid and useful.
Claiming otherwise is either ignorant in the extreme or deliberately deceptive. Which are you?
Both are terrible and should be removed. Functionally they're the same.
Malware outright steals your banking information and empties your bank account.
Microsoft, Google or Apple do not do this. Staff for telecoms in developing countries do.
Microsoft, Google or Apple do not do this. Staff for telecoms in developing countries do.
If a bit of software jammed adverts into your search results or put adds into various fields on your machine, I’d call them malware.
Why do you differentiate when it’s pre-installed for you?
Apple, Microsoft and Google absolutely do this.
Why do you differentiate when it’s pre-installed for you?
Apple, Microsoft and Google absolutely do this.
Plenty of apps people call malware do not rob your banking account. They could be tracking your location, using your microphone, and tracking other activities. These are known as info stealers. The problem with the word malware is that it has no clear definition and is evolving along with technology and threats.
Malware has a clear definition, it’s any software that is maliciously targeting the end user.
The issue is some people have been conditioned into believing software that tracks your every move, restricts freedom to your hardware, and can be easily spied on, are fine as long as they come from [insert company of choice], because it “helps improve the experience”, or even worse, because they “have nothing to hide”.
The issue is some people have been conditioned into believing software that tracks your every move, restricts freedom to your hardware, and can be easily spied on, are fine as long as they come from [insert company of choice], because it “helps improve the experience”, or even worse, because they “have nothing to hide”.
[deleted]
> Microsoft, Google or Apple do not do this.
I would make the argument that their long tail effects are worse.
I would make the argument that their long tail effects are worse.
[deleted]
Yet people piss on Apple users
That’s an even stronger example of malware. At least with Android I have the choice to use a custom ROM.
[deleted]
Yea because they somehow think their magical OS doesn't track them
Most companies want your data. Apple also fights for exclusivity of having your data.
Ironic, when I consider iOS and MacOS to be malware too.
I suppose this article, if nothing else, helps illustrate the difference between opportunistic companies that install crapware that tracks us and exfiltrates all the data it can and nefarious parties that do the exact same thing, but don't pay the vendor for the privilege.
"Hey - they shouldn't take your data - that's our job! We paid to do that!"
"Hey - they shouldn't take your data - that's our job! We paid to do that!"
Yesterday I got an ad for an illegal casino on a Xiaomi Poco X4 Pro 5G phone, from the GetApps stock app: https://imgur.com/a/xdh9uUt
No thanks, this was the last drop, I will unlock the bootloader and install a third-party ROM. Not decided yet, either Pixel Experience (a huge postitve factor here is that their ROMs are built using CI, not by humans) or crDroid.
No thanks, this was the last drop, I will unlock the bootloader and install a third-party ROM. Not decided yet, either Pixel Experience (a huge postitve factor here is that their ROMs are built using CI, not by humans) or crDroid.
A better solution would be to return it under warranty as defective (a device whose stock apps are adware - for illegal stuff no less - would definitely count) and buy a replacement from a manufacturer that doesn't engage in such shenanigans.
It would not definitely count as defective, and certainly not in a developing country where warranty laws are weaker and/or not enforced.
In my home country they'd probably laugh you off if you'd try to return an otherwise perfectly working device because a bloatware app showed you an illegal ad.
In my home country they'd probably laugh you off if you'd try to return an otherwise perfectly working device because a bloatware app showed you an illegal ad.
I had one 6+ years ago. It was a capable, cheap, some rebranded Chinese phone sold locally as a "local" phone. Once security came up to me to show me the phone MAC and turns out it was me who is sending my contact data, messages and whatnot to some unknown party.
That time I somehow got to hidden programs with debloater or something? And disabled the app... since then I value well known vendors more.
Not sure if this is exactly my case, but something very similar: https://www.reddit.com/r/privacy/comments/9ak1gt/i_bought_a_...
That time I somehow got to hidden programs with debloater or something? And disabled the app... since then I value well known vendors more.
Not sure if this is exactly my case, but something very similar: https://www.reddit.com/r/privacy/comments/9ak1gt/i_bought_a_...
Windows 10 and 11 should also be counted as malware, if you ask me…
Anything that isn’t open source and phones home, personally.
Some days I thnk we had to invent ransomware to make what platform and OEM apps do seem acceptable or normal.
If you count the US government's backdoors, then every mobile phone comes pre-infected with malware.
[deleted]
One more reason (to the pile of thousands other reasons) why I never ever buy a shitty Android phone
There is a huge fundamental difference between telemetry for the sake of product lock-in, advertising, and profits...vs data harvesting for oppressive regimes that make people disappear, and malicious actors to hack, steal, and blackmail people and organisations.
Just because the action is somewhat similar, the outcome is world's apart.
Just because the action is somewhat similar, the outcome is world's apart.
Trump was elected by vote. Hitler too.
So, the outcome in the west may suddenly change after elections. What will you do then? It will be too late to "uncollect" 30 years' data about you.
It's still a private company collecting for profit,not a government. I'm not saying that's good either, I'm just saying "Microsoft collects advertising data so China can bug phones" is an insane comparison.
While reading comments here I realized what 'Whataboutism' is. It is not 'this is the problem but that is problem as well'. It is: 'look what others are doing' which just shifts focus without addressing the issue.