Potentially millions of Android TVs and phones come with malware preinstalled
arstechnica.com
arstechnica.com
Fast forward 2 weeks and he’s complaining the battery only lasts a couple hours.
The Lock Screen was littered with gambling ads, there were all kinds of apps installed, and the phone was basically unusable.
He claimed to have no idea how it happened. I assumed he was just clicking on any/every pop up. Maybe he really downloaded 1 bad app which then self installed the rest of this crap?
Anyway, I went back to the store and bought him an iPhone SE. That was years ago now and haven’t heard a single complaint since.
I think android phones aren’t for the tech illiterate. It’s way too easy to screw them up.
[1] https://play.google.com/store/apps/details?hl=en&id=com.denp...
/s that’s probably the problem with an unsafe OS by default.
Many of these so called "antiviruses" are malware themselves.
Considering how absolutely dreadful iOS has been when it comes to CVEs allowing arbitrary code executions with kernel level privileges, I don't really think anyone gets to talk about iOS being "secure" by default. Secure for your grandfather maybe. There's a reason Zerodium values iOS zero days less than Android ones too [0], which is quite telling of the amount of them they already have in stock. See also Pegasus, which literally had multiple no-interaction RCEs for iPhones through iMessage (because Apple keeps parsing files through horribly vulnerable parsers). [1]
Apple gets to pretend that iOS is secure because they control the app store, which is the only official point of entry, and iOS is closed source.
[0] https://zerodium.com/program.html
[1] https://citizenlab.ca/2021/09/forcedentry-nso-group-imessage...
You could be right, but I don't think it's a given that the latter follows the former. The reason that Zerodium values iOS zero-days less than Androids is more likely because the US and European governments that purchase these exploits from Zerodium value iOS less than Android, which itself could be attributed to there simply being more Android phones used by adversarial countries than iOS.
iirc it was the other way around for some time
Why did you need to download anything besides Uber? You said that was the only thing he needed a smartphone for.
It really doesn't matter to the point of the story though.
I prefer firefox with a few addons because I generally know what I want, but opera and brave have good defaults out of the box from what I hear.
The article also mentions that the problem is not with Android, but with some unknown phone brands.
The Apple App Store does have shady apps (see for example the recent ChatGPT clones) but the problem there is much less severe. Whether it stays that way with alternative app stores proposed in the EU is an interesting prospect, and a separate question though.
Bad actors have exploited vulnerabilities and because of that there has been a bigger emphasis on security, even down to the hardware level.
One could argue that the sandbox model used in iOS and other operating systems is a response to that era of malware. And we’re more secure because of it.
But a lot of people including myself think of them more as consoles or appliances.
And so it makes perfectly logical sense that we want the flexibility and freedom on our Mac but not on our phones.
It's possible malware somehow found its way to the phone, but the more likely scenario is that the phone was infected out of the factory.
The bottom of the barrel Android phones (no name brands, often phones <$200) feature system level adware that downloads and installs more crap as time goes on. It's one of the reasons these phones can be sold for that cheap.
I have to wonder what brand phone you got him. I've never seen this happen on brand phones, it's always the AliExpress/Amazon crap that's full of ads in seconds. Spend the same amount of money you'd spend on an iPhone SE and I highly doubt you'll get the same result.
This is not correct. In fact the permissions paradigm for both systems is basically identical.
I hasn't been like this for at least 5 years (maybe more), your knowledge is out of date.
Android permissions are asked whenever needed, granular and regularly expire automatically.
Worst is I’ve ever used. Absolute dog poop
Seriously - this machine crashes several times a day, FF in W11 takes WAY more resources than needed - and when I am browsing simple websites on a premier gaming laptop it thinks it needs to drop into 'top gaming performance mode'
and TABS! actually crash on this machine.
I go through at least 3 reboots a day just browsing the web.
Windows 11 is absolute dogshit.
And not to mention they are putting news and ads on my fucking start menu?
Also trying to get me to use microsoft outlook 365/whatever as my primary login initially...
F that. W11 is hands down the worst microsoft product ever made, that I am aware of.
Honestly, my Windows machine needs no more attention than my Mac OSX machine. Technically, more, but I do a lot more heavy lifting on my Mac (so I need to reboot more often to free up memory and such).
EDIT: Rather ; can anyone help everyone with a write-up for locking MSFT ads out and keeping normal function?
Anyone 'wireshark' this bitch?
I've had this problem out of nowhere one day (computer would not stop crashing randomly) and it turned out to be a defective memory stick. All good after replacing it.
Windows doesn't overcommit and in GPU-accelerated apps these days the driver commits never-used main memory to back GPU memory.
Result is some users will have tabs and apps crash from out of memory even with 16 GiB of main memory if swap is disabled or very small.
Hint, there's likely a problem with your hardware.
That’s wild. Self replicating bloatware. How could this even be legislated against? I can’t figure out how to legally qualify something as “bloatware” vs something the user would want to automatically download/update.
The problem is that nobody will go after the FWUWGFISA brand of phone on Amazon. They disappear next week and reappear as FUFWEIW. Either Amazon needs to get their crap together (I doubt that'll ever happen) or consumers need to make better purchasing decisions than "let's sort by price and pick the first one in the list".
I don't think there's a good way to solve this problem without massively impacting businesses that do deserve the benefit of the doubt. The driving force behind this crap is consumers preferring the slightly cheaper Amazon rates despite all the news about scams. Perhaps some public education campaign about the problems with resellers can help, and maybe some legislation forcing platforms to show the branding of the actual seller instead of their own, but I don't think placing the responsibility directly on the platform is a good solution to this problem.
I personally stopped trusting Oneplus a while ago. They once were the champions of open source Android phones with affordable models and clean ROMs, but they seem to have changed lanes to become your average Chinese smartphone manufacturer a while back, with expensive phones, questionable business practices, lacking update guarantees and support, and so on.
I've never trusted a carrier branded phone, that basically adds a layer of crap and problematic customization that I don't need. Carriers and ISPs are notoriously shit at providing useful services, that's why Apple become popular for refusing customized phones, and their incompetent and malicious layers on top of already mediocre Android implementations are just a recipe for disaster.
I realize these types of phones are much more common over in the USA, but there's a reason they're cheaper than when you buy the phone from a normal store and it's not because your carrier sympathizes with your financial situation and decides you deserve to save some money.
Xiaomi is the worst, selling top spec phones for dirt cheap by subsidizing them with ads, but even they never ruin your battery life by spamming ads all over the place. Plus, you can turn them off during setup, but most people just hit next to get the annoying setup screens to disappear it seems.
The default choices for settings were terrible. Some components aren't even configurable at all - lots of Samsung's apps and default Android stuff can send notifications, sit in background all the time or report location if its enabled.
Even with this permission, you still need to manually verify every app you install. Background installation is reserved for apps part of the system image (i.e. Google Play, Samsung Store, Huawei Whatevertheycallit, etc.).
These apps don't just appear, they need to be confirmed every single time. For a dropper to get installed into the system and successfully install another app, you need to confirm four different security prompts. That also assumes Play Protect doesn't immediately get rid of the dropper; antivirus scanning, even for apps not part of the Play Store, has been built into Android system images for this reason.
I completely believe their story, I've seen these ad ridden crapdroids with my own eyes. But every single time they have come with malware preinstalled by some shady AliExpress/Amazon reseller.
The current status quo actually stifles competition, because the only way to reasonably avoid these products is to limit yourself to an oligopoly of established (and expensive) brands. Between the two extremes of reputable and adware-subsidized devices, no-name manufacturers that just want to compete on price with shitty hardware and limited support/updates have no real shot.
there are plenty of perfectly respectable phones available for less than 200 USD. At least they are in Norway, for instance, Moto, Nokia, Xiaomi. My Moto G30 (>6 inch display, 128 GB storage, 64 MP main camera) from Lenovo was only 120 USD a couple of years ago.
Can't imagine why anyone would buy a no name mobile at the same price.
If I need an inexpensive phone, I usually buy a refurbished or used phone from a good brand, like Sony or Samsung or Google.
Nothing new, this has been going on since the early days of android / ios. Good hygiene: deactivate/uninstall any/all apps you can at first boot, reboot, then install anew all the apps you really use. Takes a few minutes/hours, worth it most of the time. YMMV.
After 9 months of using the tablets, they all would have an ad pop-up on the lock screen. I'm guessing that they came with malware that activated after X months of use.
Anyway, we wiped the tablets and reinstalled our app from scratch. It wasn't too hard because the tablets were single-purpose, but if those tablets were personal tablets with all of my favorite things, it would suck.
Those things are the bane of my existence. I support / develop some tablet / phone business apps. Some customers cheap out up front on tablets and then I have listen to them complain that leopards ate their face (the tablets come with pre-installed garbage, one of them demands you log in to at least 3 different services on every reboot, strangely slow / unpredictable OS response times to simple API calls...).
It's horrible, I own a couple of the customer's tablets to provide better support and +90% of the time the issue is "you cheaped out and bought a crappy tablet".
These folks save sub $10K or even way less than that up front and then these crappy tablets and their crap-ware eats up their productivity endlessly. Sometimes they have compliance issues with their own people because they tried rebooting and it takes FOREVER for the cheap tablet to actually be usable so their employees don't do the thing with the app at all...
I just tell them all they should have bought iPads / we recommend buying an iPad.
At this point I'm quietly lobbying that we stop supporting Android "unofficially" and push anyone new to use iPads. Android support will be there for the sake of saying we support it... but only as an alternative / best effort just because the ecosystem is full of such bad products / eats up our time with "not the application" / "your people didn't do the thing because they hate their tablet / it didn't work" issues.
What brand?
Haven't been following much (since I'm not interested in paying close to $1k for a phone) but from what I gather the Pixels are still excellent devices.
I can't speak to bloatware on their latest versions, because I switched to a Pixel due to the update policy.
I would assert that the iPhone SE is the best smartphone bang for the buck, especially for users in your family with a tendency to shoot themselves in the foot and need your assistance.
The $399 iPhone SE from 2016 got six years of OS updates and just got another security update last month. That's about $57 per supported year.
As an Android user, I think I'm on-board with this sentiment. Anecdotally, most of the people I know with Android phones are in IT; specifically software engineers.
I once had to transfer files that were downloaded on my phone to a work laptop that couldn't access the external internet and no access to external storage. I installed Termux on my Android phone, dropped to the linux terminal, installed http-server and spun up a server on the local network. I was then able to download the files I needed off of my phone.
Quirky scenarios like the one I mentioned where I can "MacGyver" my Android phone is why I really like the platform. And then there's F-Droid so I don't have to deal with those pesky apps from the Google Play store.
I don't get it, why didn't you plug in a USB cable?
I wish Android devices instead worked like iPods, which had a partition that mounted as a plain old USB/Firewire disk when plugged into a computer.
maybe i have been spoiled by the real computer in my pocket experience of custom rom's.
Frankly, the problem is the ubiquity of native apps. You don't need a native app to get the weather. It shouldn't have any permissions. This is the whole premise of the web. The web has its own problems, but it can't ruin a device like poorly-considered native apps can.
So at least on iOS, the impact of native junkware is limited to notification spam and can't run battery life into the ground as badly. It's not much worse than PWAs can do with webworkers and push notification permissions (and if someone has been granting every app push permissions, you can be sure they'll do the same for PWA push permissions).
Apps are a remininent of the personal computer experience of installing software. but for better or worse that ecosystem does not really exist on phones. apps exist in a sandbox environment with a fine grain permission for device access. really they should just transparently install and run and uninstall. It should behave like a web page with a saner execution environment. the main reason the app ecosystem exists the way it does is so the os manufacturer can seek rent on the device.
This is why I am so thankful the internet and the web were developed in an academic environment rather than a commercial environment. centralized rent seeking was not a design goal of the internet.
I have a somewhat increasingly constrain opinion on HN. May be Steve Jobs's original model was right / better. Only First Party and extremely selected third party Native Apps. And everything else being Web / HTML 5 Apps.
I pretty much forced her to go to iOS and she's been happen ever since. She really resisted me, though, and complained for a few months, but now agrees it's better.
I switched in Jan 2020. I got so sick of having to upgrade phones every 2 years to get updates. I understand that's changed now (Pixel phones gets updates for 3 or 4 years?), but for more than a decade I bought a new phone every 2 years. I've had the same iPhone (11) since 1/20 and I will keep it for as long as it has updates and/or the battery lasts. So far, it feels like the day I got it.
I completely agree with your last sentence. The protected garden Apple creates is a blessing for most tech illiterate users.
It's happens the authors loose interest in maintaining their apps. Malware authors then purchase their developer keys, issue an update (but change nothing else), and you find yourself being woken up at 2AM in the morning by some screeching Casino ad. Or at least that's what my wifes phone did to her, and of course it was immediately my problem.
I don't know if Android has an Update History for apps now, but back then it didn't. You don't know what app it is, because all the normal functional is untouched so it works as before. In my case there were two of them - which was worse because my technique was to uninstall one by one, then re-install if the problem continued. After a week or two of experimenting I found the right combination of apps to uninstall and my nights became peaceful again.
The Play store cleaned them out after a while of course, but it was painful at the time.
[1] https://www.trendmicro.com/en_us/research/23/e/lemon-group-c...
I already block the IoT junk/cameras.
But it's still a goal I aspire to eventually.
That goes for iPhones too. At some point a customer had managed to get their iPhone infected but they absolutely refused to believe me. I was able to log into their router and verify the source of the malware on their WiFi through a packet dump, but they still refused to believe a device made by Apple could get infected with malware.
Often, we'd take the customer's word for it that they scanned all their devices, remove them from the quarantine list, only to get back into quarantine a week later. After a few back and forths they'd switch ISPs and no longer were our problem.
This is also why I take all of those "Cloudflare is blocking me for no reason at all!" posts with a grain of salt. For sure, those behind a CGNAT ISP will become false positives, but the mere idea that something on their network can be causing problems seems to be taken as a personal insult rather than a reason to start hunting down malware. I also have my suspicions a decent amount of people on here could've made the list by running scrapers at home (I certainly have) or installing shady browser extension VPNs (I have!) but those require action from people themselves so that's hard to prove.
Deny and it can't be your fault.
I wonder if it was a misbehaving app or had persistent root.
The customer wasn't particularly interested in finding out either, they blamed us for false reports the moment their XP machine was scanned and found no viruses.
Moreover, Trend Micro refuses to disclose which phones or even just brands were found to be infected with malware. Which raises the suspicion they are deliberately trying to create FUD.
LTT did a video[1] on the same topic showing a few Chinese smart TV boxes with malware. There is no reason to believe the report is illegitimate.
This is completely irrelevant as it doesn't contradict anything I said.
> There is no reason to believe the report is illegitimate.
It seems you didn't read the Ars Technica piece.
This hypothetical makes absolutely zero sense in reality. If LTT can name and shame, so can Trend Micro. It's that simple.
The rates for lawyers at well known legal firms is about ~$300, and assume it takes 5 hours (which is a conservative estimate) for them to review the lawsuit and draft a motion to dismiss. A favorable outcome is not guaranteed, given that countries like the UK consider statements as libel even when the statements are true.
Still, assuming it takes only ~$1500 and the suit is dismissed afterward, they haven't had any additional income to offset the loss, and the $1500 can easily buy IDA licenses for a team member, which would be a far more productive use of the money.
As for LTT, they engage in many behaviors that legal wouldn't approve of. If I interrupted my colleague by saying "that's what she said" every two sentences, I would be fired the next day. LTT does it all the time, and there's nary a complaint (of course, I'm not privy to their internal operations).
It's nonsense. I'm really close to getting a "dumb phone" and calling it quits for mobile.
I bought Xiaomi with the hope of it becoming popular enough to get LineageOS support, but a month after I bought my phone they released a slightly different version that actually became a hit so I was stuck with MIUI. The hardware in my phone was about equivalent with phones twice the price at the time and even features an IR blaster, which no other brands seem to do anymore, so it was worth a try.
If you read the T&C and deny the prompts, it's not that bad. You need to go through every Mi app's settings and disable ads, but after that you can use them just fine. They're great phones for the money if you're willing to deal with denying the stupid prompts. I very much knew what I was getting into, I just lost the LineageOS gamble. They come with Google Play so you can just download Google Drive/Photos/Files/Dialer/whatever and use the phone like any other.
I wouldn't recommend them to the average user, though they're often still a better deal than most of their competitors in terms of value per dollar.
Luckily, another custom ROM project picked up my phone and I'm pretty happy with it now. They're great phones for tech savvy people looking to save hundreds of dollars if you've got an hour or two to clean up the crap.
The bootloader unlock is 7 days and has been for every xiaomi phone I've owned.
You can turn off "Sync" which is xiaomi's backup/sync service if you don't want to sync stuff up to the cloud...
Providing your IMEI / phone number aka "personal info" is standard even across Apple with registering AC+ etc.
There's community roms that remove all the chinese bloatware that comes preinstalled (https://xiaomi.eu/community/) plus add a bunch of new features that make it a pretty awesome experience.
Besides, I want to be able to switch TVs without having to worry about the TV's built-in software every single time.
There are also some unofficial ROMs in XDA for other devices, and some dev also offers ROMs for Raspberry Pis in his website.
How is the Nvidia stock image beyond the home screen?
The Nvidia Shield is probably your best bet on the least amount of crap on there that still gets regular updates. You can change the luancher to hide the ads and lock down as much of the phone home with Adguard.
Also when you look at majority of Android TV devices, none of them get any update. The only ones that seem to do are the Chromecast TV and Nvidia Shields. If you're in Murica, you can pickup the new Onn box for $20 but being that cheap it will probably be phoning home more.
End of the day you just want your TV to just work. If you start having to sideload Netflix/Prime/Hulu, you're gonna encounter sooner or later spending hours just to fix it.
My phone and computer don't get high res Amazon prime content either and I'm not going to bother with workarounds if downloading torrents is just as easy.
Agree having Jellyfin/Plex you primary way to consume media makes life a lot easier.
It's also trivial to sideload on it any app you want, just by changing permissions and allowing installations not from the Google store. It's also fairly simple to hide suggestions from bundled apps like Netflix etc from the homescreen - we don't use any streaming services.
Once you do that, there are zero ads on it. As opposed to other models, even flagship TVs from LG.
I actually bought this Sony model specifically due to the reviews that said this was the case. Kudos to Sony for making this. It is a tad more expensive than LG models, but it's worth it.
I've never bought one personally, but have read that Sony Xperia phones also come with a pretty vanilla version of Android. If I were in the market for an Android flagship, they'd be in the running. They're pricier but I don't mind that if it gets me an OS with as little manufacturer meddling as possible.
The easiest method I can think of is to just get one of those Android TV Chromecasts. They're not much more expensive than the Amazon TV boxes and the software actually works and gets updated.
Does OSMC support Netflix, Prime? And do you happen to know how well Kodi<>Jellyfin integration works? A quick search brought up either crickets (Jellyfin) or long-winded discussions such as this one: https://discourse.osmc.tv/t/how-to-all-platforms-can-i-use-n...
Do Netflix & Prime work on Roku? I also can't find any information about running Tailscale on Roku, beyond putting it on a different network and routing all traffic through a RaspberryPi or something.
Tailscale does not run on Roku, unless you find a way to jailbreak it and side load a custom ROM, which I'm unaware of any. You would have to route all your stuff through a separate network device like a pi. But a Roku will connect to your local network, so you should be able to access anything that way.
I run Plex and Jellyfin on my home server and can connect either by local IP or through my reverse proxy domain.
(In fact, there are also inofficial LOS builds for Raspberry Pi, too: https://konstakang.com/devices/rpi4/ )
This seems to match my requirement of "hackable" quite well, though Nvidia Jetsons are obviously not "fully open" or anything and a quick search yields various threads of people struggling a bit to get LineageOS runnning. But it does seem possible! (Not sure whether Netflix or Prime would run, though.)
It was perfect timing since I am trying to find some simple solution to my old Roku I use to bypass my "smart" TV. But Roku is probably just as invasive privacy-wise.
But to answer your question, no, there's no easy way for even moderately technical people to find out what's in their system image, except when we get a report such as this one.
Technically the drive itself could have malicious firmware (and this is another reason open source device firmware is important; it allows researchers to poke around). But if the storage was removable then you could also replace the drive entirely and copy the original drive's contents to it. Then if the original drive was giving a clean copy if you attempt to dump its contents, the clean copy is what ends up on the new drive.
A cheap Android phone or a cheap Android phone from a questionable brand/source? The root of the blame here isn't with the fact that it's Android, but more likely what was purchased for him. Probably a big batch of user error too as this was his first non flip phone.
What is the author thinking? E.g. Samsung TVs comes with malware preinstalled from factory.
I don't know about the phones, but it has been nagging me to approve some "Bixby" and "Samsung Pay" spyware.
I am never buying a Samsung device again ...
Samsung, Google, and Microsoft are spyware companies.
Just because a large sum of people are "okay" with it, doesn't mean it isn't spyware.
The big difference being that Android is an Open Source project, so you can build an Android phone with all of the OEM spyware removed. The same cannot be said for, say, iOS. You just have to be happy with it, backdoors and all.
If you're convinced that Apple would bend the knee in China but not the US, you should take another look at FIVE-EYES and PRISM. Transparency is the only sane security model in a post-Snowden world. Insinuating otherwise without presenting accountable proof is what we call security theater.
When Apple publicly holds double standards for multiple countries, what makes you so certain they're not doing the same where you live?
Do you have any examples of spyware drivers that inherently prevent you from booting AOSP on compatible hardware?
The flip side is that the cheap/unbranded stuff is almost always not locked down and easily rootable, so you can clean them out.
If we use the "does not act in the interests of the user" to define "malware", then many laptops also come with malware preinstalled. The last few that I set up, I did not even attempt to boot what was on the drive. It just got wiped and I started from a clean install.
People in the market for an Android phone should steer toward known brands like Samsung, Asus, or OnePlus, which generally have much more reliable quality assurance controls on their inventory.
I agree with the other comment here that this feels like a FUD attempt by the big brands due to the smaller competitors eroding their hegemony.
One of my HTC phones (which was a flagship at the time) came with touchpad baked in as a system app, which was later discovered to be malware.
Now if there was a service that did it for me I would consider paying for it. Sort of like a real life Curse Purge Plus [1].
Sorry but this sounds like Google or FB, I expected way worse unless Google and FB services are considered as malware as well
Every single "smart device" is controlled by the manufacturer, who can install anything anytime on it.
The cheapest smart devices have a low sticker price only because they are meant to make money in other ways.
Alas, the pricier ones are also meant to make money in other ways. The more reputable manufacturers mainly want to avoid seeing their names dragged through the mud on the news. Otherwise, they are about as naughty as the disreputable manufacturers.
Your choices are (a) malware or (b) spyware and adware.
That seems excessively cynical and faux omniscient.