Study Warns Android Phones from Samsung, Xiaomi and Others Are Spying on Users
hothardware.com
hothardware.com
Because of how embedded mobile phones and cameras are into our lives now, the field for collection of personal data can give a company a huge database of information on anyone based on how they interact with their phones.
Even your phone and Alexa devices are literal microphones that can tap into your personal life at any given time. When this is combined with social media, email, photos and videos, and of course your browser history, anyone can be targeted at any time by these private companies for any reason.
Blackmail will be a likely result. Corporate espionage will also be a constant threat. The future is going to be wild, and we'll likely need to lock our phones up and have private conversations in rooms with no tech at all unless privacy invasion and surveillance is reigned in properly by Gov leadership around the world.
There is, in contrast, probably a fast growing pool of independent hackers and whistleblowers out there to counter these bad behaviors and practices by big corporate interests... The future is both interesting and scary citing all of this.
In fact, I think we are about to enter an era where our personal devices not only don't work exclusively for us but instead work explicitly against us. It will take a while for governments to gather some experience, but I won't be surprised when data gathering becomes mandatory.
Wouldn't it be great for instance, if police could just tap into Alexa's records to clarify a case of rape? Or throttle down your intelligent thermostat because you are wasting so much of our CO2 budget? Or stop your car because it already entered that particular city twice this year?
This is why the government is the only one that should be authorized to hold LIMITED private information. Somehow it's mis-construed to private individuals and companies collecting UNLIMITED personal data on everyone. Strange times.
After the uprising of the 17th of June
The Secretary of the Writers' Union
Had leaflets distributed on the Stalinallee
Stating that the people Had forfeited the confidence of the government
And could only win it back By increased work quotas.
Would it not in that case be simpler for the government
To dissolve the people And elect another?
I doubt China is the best example for what "governments desire". Many people of different kinds go into politics for different reasons, and i personally doubt controlling people is among the top ones. Enriching oneself, having power and reputation, fixing things, etc. seem to be more popular.
My answers to those two questions are Yes and No, respectively. That is the difference.
Politicians as a rule get most, or all, their power by getting themselves in a position where they can control people.
About to? LG smart TVs send filenames on connected storage devices back to LG, Google's phones by default (and until they were caught, even if you explicitly disabled it) send your location to Google for logging, that is then accessed by police with geofence warrants, printers add tracking dots to deanonymize you, Intel and AMD refuse to sell CPUs without their management engines (except to special customers), printers want "authorized" ink, and all of DRM is explicitly anti-user.
We are already firmly in that era, even if you ignore China.
- Locate a phone using discovery data from nearby Bluetooth devices under adversary's control
- Track/access a turned-off phone via a secondary battery-powered GPS module (or similar, like in new iPhones)
- Localize nearby phones via IMSI catchers
The main implausible line of plot devices there are the ability to access any target device at will, just a matter of time/effort. This alludes to organizations having access to zero-day exploits but that's still very unlikely to work against a random phone.
The current state of affairs can be explained without dragging Facebook or other bogeymen into the picture. The inception of A/B testing, business metrics, and even crash analytics on applications deployed to devices that are always on is prime ground to emit tons of metrics regarding anything the application/device does.
Even though I agree that this state of affairs goes against the users' best interests, there's no need to refer to bogeymen to explain why apps phone home.
What I'm worried about is the practice of device reporting done on individual user behaviors unrelated to device operation, which previously required careful measures to not report in software-based monitoring. Rules exist within the US government to protect Personally Identifiable Information, but somehow now not within private companies like FaceBook?
Now that real-time connectivity and information is available, companies have access to data (well beyond what even most governments can collect) that can easily be weaponized against individuals, or even compromised by hackers or less-ethical companies and then also weaponized against individuals or groups in ways no-one has even thought about yet...
"Boogeymen" is perhaps an improper name because they don't even know the devastating impacts that this personal data collection trend will lead to into the future... "Incompetent Egoists" and "Ignorant God Complex" are probably better terms to use in describing the individuals involved in implementing this type of reckless societal behavior monitoring.
Has that changed or can you replace the OS in all phones, now?
Besides the article-mentioned /e/OS, there's also CalyxOS and GrapheneOS. GrapheneOS is seen as the top choice for tightest security, but also comes with the most downsides, being less compatibility with all your favorite apps, slower performance, lack of JIT compilation abilities (because it's unsafe), and, ironically, is completely limited to Google Pixel devices, which happen to have a black box "Titan" security chip that Google promised to open up but never did.
Why they think this unknown chip somehow makes the device more secure, I'll never know.
GrapheneOS also requires a lockable bootloader, because that is another attack vector. Malicious software could alter or downgrade the bootloader and load different software that could then spy on your device or read its contents.
Yet user-friendly Android options routinely tout features like "root access" and "unlocked bootloader" (LineageOS even requires it stay unlocked!)... but in reality these are enormous security holes that should not be there in the first place.
Just like how on the desktop... booting from recovery software or into a "single user mode" practically washes away all security and lets you access all the data. Besides encryption, things like Secure Boot and Mandatory Access Control should be used a lot more often to protect our data, but today unfortunately it is mostly relegated to mobile devices.