Jump to content

Secret backdoor found on hundreds of thousands of Android phones

Nowak

http://arstechnica.com/security/2016/11/chinese-company-installed-secret-backdoor-on-hundreds-of-thousands-of-phones/

384540?max=1600

 

Just in case you thought your smartphone was private, think again!

Quote

Security firm Kryptowire has uncovered a backdoor in the firmware installed on low-cost Android phones, including phones from BLU Products sold online through Amazon and Best Buy. The backdoor software, initially discovered on the BLU R1 HD, sent massive amounts of personal data about the phones and their users’ activities back to servers in China that are owned by a firmware update software provider. The data included phone number, location data, the content of text messages, calls made, and applications installed and used.

But why is this data being collected? Advertising, what else would it be used for?

 

Quote

The company, Shanghai AdUps Technologies, had apparently designed the backdoor to help Chinese phone manufacturers and carriers track the behavior of their customers for advertising purposes. AdUps claims its software runs updates for more than 700 million devices worldwide, including smartphones, tablets, and automobile entertainment systems. It is installed on smartphones from Huawei and ZTE sold in China.

However, even though it was primarily found on Huawei and ZTE devices, it's also been found on BLU Products phones - even though BLU is an American company.

 

Quote

The backdoor was part of the commercial Firmware Over The Air (FOTA) update software installed on BLU Android devices provided as a service to BLU by AdUps.

But of course, they're completely innocent and this isn't being done for the Chinese government.

Quote

A lawyer for the company told The New York Times that the data was not being collected for the Chinese government, stating, “This is a private company that made a mistake.”

 

A listing of everything transmitted by the phones:

Quote

These devices actively transmitted user and device information including the full-body of text messages, contact lists, call history with full telephone numbers, unique device identifiers including the International Mobile Subscriber Identity (IMSI) and the International Mobile Equipment Identity (IMEI). The firmware could target specific users and text messages matching remotely defined keywords. The firmware also collected and transmitted information about the use of applications installed on the monitored device, bypassed the Android permission model, executed remote commands with escalated (system) privileges, and was able to remotely reprogram the devices... The firmware that shipped with the mobile devices and subsequent updates allowed for the remote installation of applications without the users' consent and, in some versions of the software, the transmission of fine-grained device location information.

And how the data is transmitted:

 

Quote

The user data was sent in JavaScript Object Notation (JSON) format to a number of servers, all with the hostname bigdata: bigdata.adups.com, bigdata.adsunflower.com, bigdata.adfuture.cn, and bigdata.advmob.cn. The data collection and transmission capability is spread across different applications and files. Text message data (encrypted with DES, which Kryptowire researchers were able to recover the key for) and call log information were sent back every 72 hours. Other data, including location data and app use, was sent every 24 hours.

So, those cheap Android phones from China still seem good to you? Or is your privacy more important than saving a couple hundred bucks on a phone?

Link to comment
Share on other sites

Link to post
Share on other sites

ICYMI

 

 

- ASUS X99 Deluxe - i7 5820k - Nvidia GTX 1080ti SLi - 4x4GB EVGA SSC 2800mhz DDR4 - Samsung SM951 500 - 2x Samsung 850 EVO 512 -

- EK Supremacy EVO CPU Block - EK FC 1080 GPU Blocks - EK XRES 100 DDC - EK Coolstream XE 360 - EK Coolstream XE 240 -

Link to comment
Share on other sites

Link to post
Share on other sites

RIP

 

Glad I went for a Windows Phone :) 

My rigs:

Spoiler

NEW Ryzinator build:

CPU: AMD - Ryzen 9 3950X 8-Core Processor

Motherboard: Asus - PRIME X370-PRO ATX AM4

RAM: Corsair - Vengeance LPX 32GB (2 x 16GB) DDR4-2666 @ DDR4-3066

Storage: (3x) Samsung - 850 EVO-Series 500GB 2.5", Samsung - 960 EVO 250GB M.2-2280

PSU: Seasonic Prime TX-750

OS: Microsoft - Windows 10 Pro 64-bit

Additional fan: Noctua - NF-A14 PWM 82.5 CFM 140mm Fan

Case: Fractal Design - Define R5 (Black) ATX Mid Tower Case

GPU: ASUS Radeon RX 580 Dual OC 4GB

Display: MSI 27L Optix MAG272QP @ 165Hz

 

OLD Build (SOLD):

CPU: AMD FX-6100 Motherboard: ASRock 960GM/U3S3 FX (VRM overheating, don't buy) RAM: 8GB Kingston ValueRAM GPU: Onboard ATI Radeon 3000 Graphics Case: Corsair Obsidian 500D Storage: Hitachi HDS721010CLA332 1TB, 119GB SAMSUNG MMCRE28G5MXP-0VBH1 (SSD), 465GB Western Digital WDC WD5000AZRX-00L4HB0 (SATA)  PSU: Be quiet! - Straight Power 10 400 Watt Cooling: Cooler Master Hyper 212 EVO OS: Windows 10 Pro x64 

 

Retro gaming build:

CPU: Intel Pentium 3 Coppermine @ 800MHz Motherboard: Asus P2B i440BX BIOS 1012 FSB: 133 MHz RAM: 1x 128MB Hynix PC133 SDR SDRAM GPU: ATi Radeon 9200 256MB AGP Case: Full Tower case (unbranded) Storage: CompactFlash card to IDE converter (16GB card) Sound Card: Aztech 2320 ISA Cooling: Stock heatsink fan OS: Windows 98 Second Edition

Link to comment
Share on other sites

Link to post
Share on other sites

7 minutes ago, MSWindowsinside said:

RIP

 

Glad I went for a Windows Phone :) 

I don't think you realize the irony of what you just posted...

You're still sending data, just to M$

CPU - Ryzen 7 3700X | RAM - 64 GB DDR4 3200MHz | GPU - Nvidia GTX 1660 ti | MOBO -  MSI B550 Gaming Plus

Link to comment
Share on other sites

Link to post
Share on other sites

15 minutes ago, PocketNerd said:

I don't think you realize the irony of what you just posted...

You're still sending data, just to M$

At least MS uses it for good purposes.

Not some shady un-encrypted chinese servers without your permission

Roses are red

My name is Roy

We caught the alligator that ate the De Luca boy

Link to comment
Share on other sites

Link to post
Share on other sites

10 minutes ago, UberGamerKing said:

At least MS uses it for good purposes.

Not some shady un-encrypted chinese servers without your permission

Define "good purposes"

Cause depending on who you ask, no purpose is a good purpose.

CPU - Ryzen 7 3700X | RAM - 64 GB DDR4 3200MHz | GPU - Nvidia GTX 1660 ti | MOBO -  MSI B550 Gaming Plus

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, PocketNerd said:

Define "good purposes"

Cause depending on who you ask, no purpose is a good purpose.

Pretty much every service you use on your phone, data is being collected. This isn't new.

Intel® Core™ i7-12700 | GIGABYTE B660 AORUS MASTER DDR4 | Gigabyte Radeon™ RX 6650 XT Gaming OC | 32GB Corsair Vengeance® RGB Pro SL DDR4 | Samsung 990 Pro 1TB | WD Green 1.5TB | Windows 11 Pro | NZXT H510 Flow White
Sony MDR-V250 | GNT-500 | Logitech G610 Orion Brown | Logitech G402 | Samsung C27JG5 | ASUS ProArt PA238QR
iPhone 12 Mini (iOS 17.2.1) | iPhone XR (iOS 17.2.1) | iPad Mini (iOS 9.3.5) | KZ AZ09 Pro x KZ ZSN Pro X | Sennheiser HD450bt
Intel® Core™ i7-1265U | Kioxia KBG50ZNV512G | 16GB DDR4 | Windows 11 Enterprise | HP EliteBook 650 G9
Intel® Core™ i5-8520U | WD Blue M.2 250GB | 1TB Seagate FireCuda | 16GB DDR4 | Windows 11 Home | ASUS Vivobook 15 
Intel® Core™ i7-3520M | GT 630M | 16 GB Corsair Vengeance® DDR3 |
Samsung 850 EVO 250GB | macOS Catalina | Lenovo IdeaPad P580

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, Wikiforce said:

You not aware of their involvement with NSA -_- 

I am, but there is nothing wrong with giving small amounts of data to the NSA.

Microsoft doesnt provided your texts or emails to the NSA, the mobile carriers do that.

 

Microsoft provides the following 2 tiny amounts of data to the NSA:

The email address registered to the phone

When the phone is turned on/off

 

The first one, the phone carriers could do themselves, as they have your phone number and email adress

The second, well who cares if the NSA knows when your phone is turned off/on. not like that makes any difference

Roses are red

My name is Roy

We caught the alligator that ate the De Luca boy

Link to comment
Share on other sites

Link to post
Share on other sites

21 minutes ago, UberGamerKing said:

At least MS uses it for good purposes.

Not some shady un-encrypted chinese servers without your permission

"good purposes"

One day I will be able to play Monster Hunter Frontier in French/Italian/English on my PC, it's just a matter of time... 4 5 6 7 8 9 years later: It's finally coming!!!

Phones: iPhone 4S/SE | LG V10 | Lumia 920 | Samsung S24 Ultra

Laptops: Macbook Pro 15" (mid-2012) | Compaq Presario V6000

Other: Steam Deck

<>EVs are bad, they kill the planet and remove freedoms too some/<>

Link to comment
Share on other sites

Link to post
Share on other sites

45 minutes ago, PocketNerd said:

I don't think you realize the irony of what you just posted...

You're still sending data, just to M$

In Microsoft case it's a golden huge front door with cash on it ;)

Link to comment
Share on other sites

Link to post
Share on other sites

Lets be real.  Expensive phones are likely transmitting stuff too.  Maybe not to the same servers, but don't be a fool.  They all want your data

Intel 4670K /w TT water 2.0 performer, GTX 1070FE, Gigabyte Z87X-DH3, Corsair HX750, 16GB Mushkin 1333mhz, Fractal R4 Windowed, Varmilo mint TKL, Logitech m310, HP Pavilion 23bw, Logitech 2.1 Speakers

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, TidaLWaveZ said:

ICYMI

 

 

 

1 hour ago, BroliviaWilde said:

This appears to be a repost:
 

 

Didn't notice. Was in a rush to get out the door and I really wanted to get something posted, so... ¯\_(ツ)_/¯

Link to comment
Share on other sites

Link to post
Share on other sites

2 hours ago, BlueChinchillaEatingDorito said:

Pretty much every service you use on your phone, data is being collected. This isn't new.

Right, but we're usually told pretty clearly as to why, and we can opt into or out of it.

In the case of Windows, most people have no choice as they need to use it for Work.

CPU - Ryzen 7 3700X | RAM - 64 GB DDR4 3200MHz | GPU - Nvidia GTX 1660 ti | MOBO -  MSI B550 Gaming Plus

Link to comment
Share on other sites

Link to post
Share on other sites

4 hours ago, PocketNerd said:

Right, but we're usually told pretty clearly as to why, and we can opt into or out of it.

In the case of Windows, most people have no choice as they need to use it for Work.

 

Can opt into or out of it? Well not really. It'll usually be in the EULA and realistically the only way to fully "opt out" is not straight up uninstall the app.

 

Intel® Core™ i7-12700 | GIGABYTE B660 AORUS MASTER DDR4 | Gigabyte Radeon™ RX 6650 XT Gaming OC | 32GB Corsair Vengeance® RGB Pro SL DDR4 | Samsung 990 Pro 1TB | WD Green 1.5TB | Windows 11 Pro | NZXT H510 Flow White
Sony MDR-V250 | GNT-500 | Logitech G610 Orion Brown | Logitech G402 | Samsung C27JG5 | ASUS ProArt PA238QR
iPhone 12 Mini (iOS 17.2.1) | iPhone XR (iOS 17.2.1) | iPad Mini (iOS 9.3.5) | KZ AZ09 Pro x KZ ZSN Pro X | Sennheiser HD450bt
Intel® Core™ i7-1265U | Kioxia KBG50ZNV512G | 16GB DDR4 | Windows 11 Enterprise | HP EliteBook 650 G9
Intel® Core™ i5-8520U | WD Blue M.2 250GB | 1TB Seagate FireCuda | 16GB DDR4 | Windows 11 Home | ASUS Vivobook 15 
Intel® Core™ i7-3520M | GT 630M | 16 GB Corsair Vengeance® DDR3 |
Samsung 850 EVO 250GB | macOS Catalina | Lenovo IdeaPad P580

Link to comment
Share on other sites

Link to post
Share on other sites

11 hours ago, Daring said:

So, those cheap Android phones from China still seem good to you? Or is your privacy more important than saving a couple hundred bucks on a phone?

Even back then, cheap Android phones didn't appeal to me because I was concerned of tanking performance on basic tasks (constant stuttering and frequent lagging) so nope. Ain't gonna buy those Chinese Android phones.

 

 I'm wondering if they've done a similar test with high end Android phones. I'm looking forward for a LG V20.

There is more that meets the eye
I see the soul that is inside

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

If i were to get one of those cheap Chinese phones i would probably install a custom rom anyway . . .  Tgeir android skins are often terrible 

AMD Ryzen R7 1700 (3.8ghz) w/ NH-D14, EVGA RTX 2080 XC (stock), 4*4GB DDR4 3000MT/s RAM, Gigabyte AB350-Gaming-3 MB, CX750M PSU, 1.5TB SDD + 7TB HDD, Phanteks enthoo pro case

Link to comment
Share on other sites

Link to post
Share on other sites

23 hours ago, UberGamerKing said:

At least MS uses it for good purposes.

Not some shady un-encrypted chinese servers without your permission

MS does the same thing, because even if you try to disable it it still sends the data. Without your permission! 9_9

Link to comment
Share on other sites

Link to post
Share on other sites

9 hours ago, Coaxialgamer said:

If i were to get one of those cheap Chinese phones i would probably install a custom rom anyway . . .  Tgeir android skins are often terrible 

As I said in the other thread, that's pretty damn useless, considering the likelihood of hardware backdoors being present.

And that's for all Chinese produced hardware, not just specific brands. I would be surprised if the Oneplus was any different.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×