+ Reply to Thread
Results 1 to 3 of 3

Thread: Pre-installed Spying Firmwares On Your Device?

  1. Link to Post #1
    France On Sabbatical
    Join Date
    7th March 2011
    Location
    Brittany
    Posts
    16,763
    Thanks
    60,315
    Thanked 95,898 times in 15,481 posts

    Default Pre-installed Spying Firmwares On Your Device?

    Security company finds 700 million Android phones have spying firmware pre-installed

    Mike Wehner BGR Tue, 20 Dec 2016 16:26 UTC





    © Flickr/asgw

    The term "mobile phone security" is something of a joke these days, with the number of exploits, bugs, and breaches that are endlessly assaulting us and putting our personal information at risk. So, when security outfit Kryptowire sounded the alarm on Chinese company Adups for using its preinstalled apps to spy on Android users with Blu smartphones, it wasn't exactly a shock. Now, however, the impact of Adups alleged spying is growing in magnitude, and it's dragging other Android device manufacturers into the quagmire.

    Adups is a company that facilitates over-the-air updates for mobile devices, so its firmware is pre-installed on lots of devices. However, the firmware does much more than it claims, and has the ability to snoop in areas that it shouldn't, and without the user ever knowing. That information can then be collected by Adups for whatever purposes it desires.

    Trustlook, another digital security firm, dug deeper on what devices utilize Adups and could be used by the Chinese company to scrape your private information, and the list is absolutely massive. Trustlook says that over 700 million Android smartphones have Adups firmware installed that puts the user at risk of having text messages, call histories, and device information collected without their knowledge or consent.

    Many of the manufacturers who utilize Adups are smaller companies who only release their devices in Asia or specific smaller markets. However, there are a few notable names on the list, including Lenovo, ZTE, and the aforementioned Blu.

    The Blu R1 HD was the first device found to be relaying this sensitive information back to Adups, and the company took action to halt the app's nefarious habits, but it's now up to the rest of the dozens and dozens of manufacturers on the list to do the same. The best course of action right now seems to be keeping the phone as updated as possible, and installing any security patches that come down the pipeline.
    "La réalité est un rêve que l'on fait atterrir" San Antonio AKA F. Dard

    Troll-hood motto: Never, ever, however, whatsoever, to anyone, a point concede.

  2. The Following 19 Users Say Thank You to Hervé For This Post:

    Bill Ryan (23rd December 2016), Bob (23rd December 2016), Bruno (23rd December 2016), ceetee9 (24th December 2016), Chester (23rd December 2016), Daughter of Time (23rd December 2016), enigma3 (23rd December 2016), Ewan (24th December 2016), Foxie Loxie (23rd December 2016), gaiagirl (24th December 2016), Johnny (23rd December 2016), ljwheat (24th December 2016), Matthew (23rd December 2016), mojo (23rd December 2016), Nasu (23rd December 2016), Pam (24th December 2016), ponda (23rd December 2016), seko (23rd December 2016), Sierra (23rd December 2016)

  3. Link to Post #2
    France On Sabbatical
    Join Date
    7th March 2011
    Location
    Brittany
    Posts
    16,763
    Thanks
    60,315
    Thanked 95,898 times in 15,481 posts

    Default Re: Pre-installed Spying Firmwares On Your Device?

    Although independent, simultaneous inventions can occur planet wide, one may still wonder if the idea wasn't pushed on to the Chinese from some other quarter(s):

    How the NSA’s Firmware Hacking Works and Why It’s So Unsettling

    One of the most shocking parts of the recently discovered spying network Equation Group is its mysterious module designed to reprogram or reflash a computer hard drive’s firmware with malicious code. The Kaspersky researchers who uncovered this said its ability to subvert hard drive firmware—the guts of any computer—“surpasses anything else” they had ever seen.

    The hacking tool, believed to be a product of the NSA, is significant because subverting the firmware gives the attackers God-like control of the system in a way that is stealthy and persistent even through software updates. The module, named “nls_933w.dll”, is the first of its kind found in the wild and is used with both the EquationDrug and GrayFish spy platforms Kaspersky uncovered.

    [...]

    Full article: http://www.wired.com/2015/02/nsa-firmware-hacking/

    -----------------------------------------------------------------------------

    In the case of a firmware hack, the only solution left is trash the hard drive and buy a new one... but how to know that, that new HDD isn't already infected right out of its manufacturing process... directly at the factory? You know, that "Intel Inside" kind of stuff?
    "La réalité est un rêve que l'on fait atterrir" San Antonio AKA F. Dard

    Troll-hood motto: Never, ever, however, whatsoever, to anyone, a point concede.

  4. The Following 13 Users Say Thank You to Hervé For This Post:

    Bill Ryan (23rd December 2016), Daughter of Time (23rd December 2016), enigma3 (23rd December 2016), Ewan (24th December 2016), gaiagirl (24th December 2016), Johnny (23rd December 2016), ljwheat (24th December 2016), Matthew (23rd December 2016), meeradas (24th December 2016), ponda (23rd December 2016), sanma (23rd December 2016), sheme (31st December 2016), Sierra (23rd December 2016)

  5. Link to Post #3
    Canada Avalon Member Ernie Nemeth's Avatar
    Join Date
    25th January 2011
    Location
    Toronto
    Age
    66
    Posts
    5,661
    Thanks
    26,233
    Thanked 36,614 times in 5,382 posts

    Default Re: Pre-installed Spying Firmwares On Your Device?

    On sort of the same topic. Today, waiting in line at the bank, I tried connecting to the free wifi. I don't know what possessed me to do so but I did. I know better. The pop-up TD flyer stopped my data connection entirely, and for a while after my phone would not make or receive calls (until I remembered the fix - restart phone).

    It is insidious, insulting and ultimately a dangerous practice , this innocently creating spy ware that even the most trusted brands employ.

  6. The Following 7 Users Say Thank You to Ernie Nemeth For This Post:

    Bill Ryan (24th December 2016), Ewan (24th December 2016), gaiagirl (24th December 2016), Hervé (23rd December 2016), ljwheat (24th December 2016), ponda (23rd December 2016), sheme (31st December 2016)

+ Reply to Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts