Report: Chinese phone comes preloaded with spyware
finance.yahoo.com
finance.yahoo.com
- GPS: the wifi and celltower db queries that optimize the service are transferred into a foreign country.
- use Siri: uploads your whole address book to US servers before use
- use iCloud tabs: every URL you visit it uploaded to Apple's US servers
- turn on the only cloud backup solution available on the device, and all your data, including every SMS, every call and all your most private notes and photos are also transferred into the foreign country of the US, with a chance of it being analyzed by certain agencies.
In other words, this might qualify as getting spied on as well.
Whereas if you buy an Android phone in Europe, you know for certain that your data and behavior are being examined by Google, and are available to US agencies.
- wifi and celltower db query servers are indeed hosted outside EU
- Siri indeed uploads your whole address book - it even tells you about that beforehand!
- iCloud tabs must upload every URL to a central server, it would not work otherwise
- the mud puddle test* proves that iCloud backup is extractable from Apple servers by third parties.
*http://www.magnir.com/2012/08/how-secure-is-your-cloud-take-...
I think the unresolved issue is if a normal warrant/subpoena can force a US company to hand over data from a EU subsidiary for a EU end user.
Given the pains the NSA took (no matter how tortured the logic got), to keep trying to claim they weren't spying on Americans [except when they talked to non-Americans, or talked to someone when outside the US, or when an otherwise American communication got routed outside the US, or they accidentally included American data in a sweep "targeted" at non-American data, etc.]... I think we have plenty of evidence that the opposite is true.
Assuming the data is available in the US (so no other country can get in the way), it's easier to demand non-US data than it is to demand US data. Don't forget: part of the detestable legal rationalizations behind this surveillance is that non-US people have no Fourth Amendment rights - eliminating many classes of potential or actual legal barriers.
How's that different from using an Android phone?
Or for that matter any brand of phone + the prevalent mobile surveillance of messages, locations, etc?
BUT...
Given the way smartphones everywhere are made - China and elsewhere - it's impossible for even technical users to know that their phones aren't spying on them. While most of the software running on your smartphone's application processor is now open-source (if you're in the Android majority), the software running on the baseband processor is 100% closed source and secret. We don't know anything about the horrible agreements that have been made between shady government agencies and the baseband manufacturers like Qualcom.
A significant fraction of it is based on a closed source fork of AOSP. The rest (both the Google Mobile Services layer, and the manufacturers customizations) are all closed source and have never been open.
You're skipping over an important practical distinction: The precise software running on the application processor may not be open source, but it is closely related to usable software that is. Given that, it's possible to learn quite a bit by comparing the behavior of the closed-source fork and the open-source base.
Is that as good as "open source all the way down"? Of course not. But it is a hell of a lot better than the "opaque binary blobs all the way down" offered by most of the alternatives.
I fail to see how. It's not like a partial binary blob is better than a full on binary blob. The opaque part might do anything too...
The Carrier IQ software was installed on some Android phones, some iPhones and some Blackberry devices: http://www.computerworld.com/s/article/print/9222319/AT_T_Sp...
Where was Carrier IQ found first? Why?
The link doesn't say. And if anything it was not because there was an open-source part of the phone OS.
For one, on active, sold, phones, the device code is compiled anyway.
I do not dispute that having a related system that is open-source can aid in reverse engineering.
However the source of commercial Android phones is not open source, and does not have the benefits that open source would imply.
If you start to get as paranoid as the entire forum is at the moment accusing blindly Apple, Google, Qualcomm etc. Why nobody asks for a simple piece of evidence for anything ? This could really be a cheap manipulation ...
Edit: grammar
A Chinese manufacturer has even more incentive to steal information and sell it given the razor thin margins on making these phones.
http://forum.xda-developers.com/showthread.php?p=53391745
http://forum.xda-developers.com/showthread.php?t=2395007
Fortunately the solution is pretty simple, as these generic MTK devices are all easy to root and reflash with new firmware.
On the software side of things the closest you can get is a phone running OsmocomBB. That only runs on some dumphones and is not useful from a user perspective, it is only for research. For smartphone software, the closest you can get is a phone running Replicant. That still has all the embedded proprietary software; baseband OS, bootloader, wifi/bluetooth/camera firmware etc.
On the hardware side of things, we have no ASICs with libre designs. I think there have been some cases with libre designs but none manufactured in large quantities. There are myriad patents covering various hardware processes, instruction sets, CPU stuff etc. See bunnie's talk about layers of openness and the Novena laptop for more on this.
RMS uses other people's phones, he doesn't have one himself, mainly due to the network side of things though.
For the truly paranoid (with or without reason), I guess that they would have to go the RMS route -- or find a payphone that isn't within sight of a security camera.