Huawei P30 Pro alleged to be querying China servers
en.ocworkbench.com
en.ocworkbench.com
https://github.com/pe3zx/huawei-block-list/blob/master/analy...
>Our research team studied the video and we have several reasons to doubt its authenticity. We’ve conducted a thorough audit over the last 48 hours based the few details that are in the video and didn’t find anything. We reached out the researcher and instead of replying he removed the video*. We’ll communicate if indeed there is a risk.
https://avleonov.com/tag/exploitwarelabs/
Tl;DR an amateur with no presence outside of facebook did not actually find what state level security experts tried to find for 10 years.
I feel uncomfortable with what seems to me to be a campaign against Huawei at the same time our government is worried about being competitive in 5G tech. I could be wrong through, I didn’t believe that Russia would dare to meddle in our election until there was hard evidence.
The most disturbing aspect of this ignorance is that apparently our own intelligence agencies were among the ignorant.
The intelligence agency assessments themselves, as publicly reported, have consistently said there were Russian efforts to interfere with the election campaign.
Wikipedia has an extensive article citing numerous academic studies on the matter:
https://en.wikipedia.org/wiki/Foreign_electoral_intervention
> the country intervening in most foreign elections is the United States with 81 interventions, followed by Russia (including the former Soviet Union) with 36 interventions from 1946 to 2000
Of course the USA frequently interferes in foreign elections. We spy on other countries too.
It’s normal for a country to spy and interfere in others, but not to like when others spy and interfere with them. Such is international politics.
They way I'm reading this, they were seeing DNS requests to beian.gov.cn which was worrisome. Now they say those are the result of manually visiting baidu.com which makes more sense.
See https://github.com/pe3zx/huawei-block-list/blob/master/analy...
“ICP Beian” stands for the process of obtaining the Business ICP registration number that allows you to host your website on a Mainland Chinese server. [0]
So these communications could be literally anything on the phone and all we know is that it's communicating with a server in mainland China?
[0] https://www.tmogroup.asia/entering-china-ecommerce-icp-beian...
Because it was developed by an American company and runs software written by an American company.
If I don't trust them I might as well throw the device away now.
Is this really not obvious?
that would be called ‘phoning home’ and has the potential for significant information disclosure (IP, location, phone status, likely other information).
Sinkholing all requests the most concerning one Ive found is Google analytics running as root continually trying to dial out every few minutes. It doesn't give up and keeps retrying even after hours of failed requests. This is without any phone/internet usage.
All contemporary smartphones leak a ton via DNS and various background sync processes. Perhaps scrappy developers from emerging markets are more egregious in violating expected norms, but these outcomes are pervasive at the moment across the whole ecosystem.
It is perfectly known that Huawei sells Chinese and Global editions of their phones. It's a pity there's so much vagueness when reporting that you can't even know which edition or firmware were they testing.
I think we'll be doing a service to ourselves by ignoring vague reporting about IT security and decide based on documented and repeatable reports.
https://github.com/pe3zx/huawei-block-list/blob/master/maste...
Looks like a troll.
He even know what's my favorite porn site, I don't believe china will know that better :)