The privacy trade-offs of cheap Android smartphones
fastcompany.com
fastcompany.com
If the user tried to delete adware, the backdoor would reinstall it. The backdoor would not activate if the phone is in China.
I downloaded ROM from the link at the manufacturer's website to make sure it is really built-in into the ROM and the tablet was not infected by virus. Either manufacturer or those who made the ROM pre-installed backdoor to earn money from clicking on the ads.
Also on a Russian forum about smartphones I saw similar reports about other cheap models.
UPD: I googled around and it seems that the backdoor (named Cosiloon) has been found and described by antivirus vendors:
- https://news.drweb.com/show/?i=10345&lng=en
- https://www.androidauthority.com/cosiloon-malware-android-de...
- https://blog.avast.com/android-devices-ship-with-pre-install...
When I found it, there was no information about it anywhere.
For those unfamiliar with this: Triada, and it's relatives infect zygote, the java bootstrap system on Android. From there on rooting on it's own can't help, because the process binary is changed, so unless you can replace it with an uninfected one, it's gone. If there are ROMs out there without the infection, flashing helps.
I work for a company that, in between other things, develops and sells Android devices (TVs, tablets, phones, watches, etc.)
We buy a design from a Chinese developer, customize it, add apps and other "value-add" bulls*it, and then import the manufactured products and sell them.
The problem is, we recently found malware in the OS images which were provided by the manufacturer/developer, and traces back to Mediatek themselves, but we were not made aware of it. On request, the developer removed the malware and we sent an OTA to all devices of most models that removes the malware.
The point I'm making is that in many cases, the backdoors and spyware aren't even provided by the company that sells the phones, they are usually secretly put in much closer to the actual manufacturer/developer of the device and/or SoC.
I blame the manufacturer for two reasons. First, because they're the highest level in the chain that's likely to have any knowledge of this stuff.
Second, because they're the one selling it to consumers, and they have a responsibility to their customers to perform due diligence regarding the software they're including with the device.
If batteries start exploding, the device manufacturer can't just throw up their hands and blame their suppliers. The same is true of software. Yes, that probably means accepting huge binary blobs from the ODM or SoC manufacturer puts the company selling it at risk. They can choose to accept that risk, or they can demand better. They have a whole lot more influence on the process than us consumers do.
(There are precious few options for consumers. I'm holding out hope for the Librem 5 and PinePhone here.)
Famously, Nokia (HMD Global), also had apps that could perform such functions, developed by Evenwell Digitech Inc. I wrote about it here -- https://news.ycombinator.com/item?id=17329825, though it didn't gain much traction for a while.
In the end, Nokia (HMD Global) appologised, and said that the apps were mistakenly included in global phone versions (they're supposed to be China-only), but they are being investigated by the Finnish DPO. -- https://uk.reuters.com/article/uk-finland-telecoms/finland-t...
For some cheap phones even without the backdoor the some system components are unstable leading to a subpar experience.
Are they trustworthy?
The centralised (corporatocracy) version of "trust" that is prevalent today one of the biggest obstructions to freedom IMHO.
But it felt that the community is far away from having plausible sources and builds.
I can understand that ultimately this begins with kernel sources that are already just a ZIP archive on some website.
Most are, yes, and the community is pretty good at pointing out the ones that aren't.
But the real question is are they any less trustworthy than Google itself and the phone manufacturers? From what I've observed, they are more trustworthy that that crowd.
Most ROMs are based off of either AOSP or lineage. The list of unofficially supported devices is huge. Since, most devices share the same SOC's they're usually just forked off of each other with gradual tweaks. The Sony open device project is semi supported by sony but doesn't share any code with the stock images.
So, that really just leaves the bootloader. How much attack surface does the boot rom actually provide? I feel like most vendors would probably just assume a backdoored system or boot partition. Your boot rom would have to accommodate for all kinds of potential Android versions. It sounds like a lot of effort for a corner case so not really worth the effort.
Also, don't get me started on the terrible security hygeine of the actual ROM distribution practices.
RedWolf [0] and OrangeFox [1] are both forked from TWRP and provide more features than upstream. Cyanogen and Lineage recovery are based on AOSP, again, with more features than upstream.
Some chipsets (like MediaTek) support "uploading" data from device storage to PC using a proprietary Windows utility and USB cable.
...Presumably that's not the very-obsolete Apple Desktop Bus, but what ADB is this?
Imagine if a real-estate agent kept breaking into houses he sold (through extra doors only he has the key to), and when people complained, he'd point to some fine print on page 23 of a contract you didn't even sign - it was just posted on the door, after you bought the house, stating that entering the house constitutes agreement.
There'd be a million laws against it in a heartbeat.
An additional theft, which is your attention, can also be priced according to "the market", and indeed, if an ad obscures another sites ad then there is, in fact, another (large) set of people the manufacturer is stealing from. Moreover, that last class of people have some powerful advocates in the way of the networks, to wit, Google. But this theft is less straight-forward, I think.
I would argue that the most important theft, which is your right to be secure in your computer mediated dealings, is hardest to argue. But that's there, too.
It's entirely possible that this theory has already been tested, and lost, in US courts.
This scene from Office Space comes to mind.[1]
Maybe that's the worst that does happen, but, when an individual hacks someone, they do jail time.
This kind of shit shouldn't fly.
Can I ask how you did this? Did you have to physically remove the ROM from the board and read it with some sort of chip reader? Or is there an interface to read the ROM into a dump without any damage to the board
Another option if you are able to unlock the bootloader is, using a custom recovery, to create a tarball of each partition and unpack and start decompiling.
Also I checked signatures on applications to exclude unmodified third party apps like Youtube and check only those with unknown signatures. This is where I found that the manufacturer signed their system applications using publicly available Android test key (which means device is vulnerable because anyone can make an app signed with that test key and gain high privileges on device).
Also, some chipsets (like MediaTek) allow downloading storage contents to PC using proprietary Windows application.
Not so sure about this. The Chinese money is too great.
My only complaints is lack of NFC on this device, and that A3 is worse performance/weight wise.
The CPU of the A3 should be roughly equivalent to the A2 CPU. The camera is probably a lot better.
The lack of NFC is unfortunate.
It's not a $17 smartphone as mentioned in the article, but I consider it a "cheap Android smartphone" (and an amazing value).
I think it will get Android 10 later this year.
I tried building LOS from source recently for my OnePlus 7 Pro, which is mainlined into LOS. Installing build prerequisites was easy for me because I use an OS with a package manager and a large catalog of packages. Then, it started downloading the LOS git repos. After a few hours all 58 GB of the free space on my disk was used. I cancelled it and will just stick with the provided LOS builds. Time is worth something too.
All the privacy aware people should actually do is to check the list of officially supported phones on the LineageOS site before buying, then spend 15 minutes to read the installation instruction and follow it.
Plus you get updates.
As far as companies go... Will Microsoft sell you a copy of one of their old unsupported OSs? Of course not.
It's a LineageOS fork which bundles MicroG and several apps to make a more usable out-of-the-box OS.
They have also re-added frequent builds for many of the phones that Lineage had dropped - including the OnePlus X which I have.
Infosec Handbook did a rundown when they first came about: https://infosec-handbook.eu/blog/e-foundation-first-look/
Then they did it again, more recently: https://infosec-handbook.eu/blog/e-foundation-second-look/
There's also this site: https://ewwlo.xyz/evil.html
I think this is a step in the right direction.
As for old builds being removed, this is completely asinine. and their rationale really doesn't hold any water. You can likely find an archived version for your device, or continue building from source, 14.1 still gets Android Security Bulletin patches, for the time being.
0. https://github.com/LineageOS/charter/blob/master/device-supp...
- Something useful that can be turned to commercial or other advantage.
- Advantage; benefit
Suppose you want privacy: You need to buy your way through to get it
Suppose you want something for free: You need to sell your privacy for it
Although your point is right; maybe "luxury" is a better term.
I assume same thing could happen on iOS if one could find a way to make the adware to survive system updates.
This is pretty straightforward on modern hardware.
If any Google engineers are reading this: maybe something to consider for Android 11?
"Google bans reselling. Do you really own your phone?"
It costs around $180 and is quite popular in Europe.
I ask because I've seen some users complaining about ads.
If you have the misfortune to buy through a reseller (gearbest, dx, unofficial stores, amazon, etc) out of several phones I've purchased from resellers, they have all come with malware on them.
This may partially be why Xiaomi is enforcing up to 180 day minimums before they allow a bootloader unlock (to prevent flashing/sideloading system malware apps) by shitty resellers for $ before they ship. It does piss me off once I get the device that I have to go sign up on their forum and beg for a "possible approval" for a bootloader unlock.
I do not trust this phone a single bit, luckily I only use it as an emergency phone for outdoors using a separate Google account and a separate SIM-card.
[edit] sell them rooted
[original] Root it. Unless it's something like Triada[^1], in which case, it's f'd.
Around ~2001, everyone at high school knew how to reinstall windows and find cracks for games. Maybe it's time to be at least that "tech savvy" again with smartphones.
[^1]: https://forums.malwarebytes.com/topic/200072-trojantriada
edit: I have obtained the source code of the U-boot bootloader used on those devices, however, the algorithm for the key verification is stored on the Trusted Execution Environment, which means it cannot be extracted (the TEE is a SecureEnclave-like device, with no possible direct access to it's memory or storage, besides de-capping it and reading the bits with an electron microscope) -- more info here: https://source.android.com/security/trusty
EDIT I don't think Doogee N10 falls into low end, at least not by specs. Compare it with Moto C, which is indeed low end.
SC9863A and many other SOCs are flashable with Spreadtrum's ResearchDownload Tool. However, Spreadtrum actually does verify the whole boot process, meaning that booting a modified binary is impossible. If you change the boot partition, it will infinitely reboot with a black screen and vibration. If you leave the boot as-is, but change system, it will get to the splash screen and then reboot. etc.
It genuinely does cryptographicaly verify the signature and hash of every partition. Which is great for security, in theory, unless the OS has preloaded spyware, but the secureboot process prevents you from removing it.
re-edit: Doogee N10 costs 85$. I don't think you can go much lower-end, without basically giving the manufacturer a huge profit margin (i.e. a phone that costs $60, but has 512 MB RAM, has a bigger profit margin than a phone that costs 85$ but has 3 GB RAM.)
Been there, and I didn't even realised the cause. I'm sorry if my previous comment seemed light hearted, I didn't want it to be so.
A device that you buy with your own money cannot "hand-wave" the contract (TOS, EULA, Policies, etc), and say it's OK that you don't own your device or your data.
It's somewhat surprising that the other low-end SoCs are locked by default... I wonder if the key is the same for all of them, and just hasn't been leaked yet.
The key is most certainly not the same, because I doubt they would go through the trouble of doing actual secure boot verification, and storing the data in the TEE, and just have the same key. Additionally, the U-boot code I obtained lies to the user about commands not being found, if the command doesn't contain a valid unlock key.
In the UK, removing carrier lock is legal, and nearly all mobile corners stores can do it.
You were actually intended to be able to install an operating system and programs of your liking on PCs.
Malware is more sophisticated today.
A lot of "tech savvy" people download random ROMs off XDA developers and then enter their bank details into apps.
Also rooting is breaking the security model of the device which is also a dumb thing to do.
More often than not, that's security against the user, not for.
But if you were handed either a Samsung note or a Windows laptop that belonged to someone else. Where you wanted to quickly sign into your bank account.
What would you feel more comfortable to use?
Arguments of user freedom also includes malware freedom. And for the average user who just wants to consume, that's a decent tradeoff.
Getting the best of both security and user-freedom has already been done, but manufacturers prefer to lie that the choice is exclusive - that we can have security or freedom, but not both. And as the article clearly shows, they delivered neither.
One of these use cases is a lot more important than the other.
As always I suggest NoRoot Firewall for everything-Android. But yes it's called a trade-off, like accepting a "free" security software from your ISP which technically invalidates all your encryption efforts.
For those unaware, a new thing phones do is quietly kill apps in order to extend battery, and the extent to which this is done can vary by device and/or software.
Unless it has changed recently on iOS you are very restricted what you can run in the background. I want the freedom to run anything and I have that on Android.
> UPDATE: On some phones with EMUI 9+ (Android P+) Huawei introduced a new task killer app called PowerGenie which kills everything not whitelisted by Huawei and does not give users any configuration options. See below how to uninstall it.
Previous discussion on HN [1]
It's battery saving.
You can create exceptions for apps.
Take it or leave it, that's my comment.
Blame would be misplaced - even the most zealous licensing wouldn't have made a bit of difference in the end. Linux itself was a free rederived fork of Unix. If Google had to rederive their own fork of Linux they could have easily done so with only a little more early expense and reputation damage. At the cost of another proprietary fork gaining influence and control over free software or even open source.
Things will get so much worse, it's frightening!
I mean you could say the same thing about everything. This affects poor people, and those are "disproportionately black and Hispanic". It's like the writer is trying to trigger someone.
As a result one way to fight for justice for the economically disadvantaged is to make use of the racial correlation.
The fact that an issue disproportional impacts the poor and as a result disproportionally impacts people of particular races can also contribute to race-specific second order effects. For example, evidence strongly suggests that some race are treated particularly harshly by the judicial system in the US, leading to increased rates of convictions and harsher sentences-- so having backdoored phones is quite possibly a double whammy, causing additional harm that another population with the same devices wouldn't experience.
Ideally we'd also protect the economically disadvantaged from things like this without needing to reference a particular subset of victims, but when someone advocates for the welfare of others they do it in the world we actually live in, not the world that we would ideally have.
The cheap smartphones are sold mostly in the Asian and African markets where the mass can afford that, and data privacy means nothing to those users.
So, Your data, my data, all are up there somewhere, no matter how cheap or expensive devices we use. Why do we still live in the illusion of data privacy? Is there any?