Jump to content

(UPDATE: No actual data is sent) OnePlus is apparently sending stuff back to servers owned by Alibaba

D13H4RD

Welp, this is like, I don't know. How many times does the word "OnePlus" and "privacy" get mixed up with "sending data back" in a bad way?

 

A user on the OnePlus forums reported that the VPN firewall app he was using on his OnePlus 3T had blocked traffic related to sending clipboard data back to servers which are owned by Alibaba.

Screenshot_20180104-172656__01.jpg.b78177fd629beecaa7ed5d3d950308bc.jpg

 

Screenshot_20180104-172816__01.thumb.jpg.733b313b3b2ac6c04db3b60ffa3e7151.jpg

Source: https://forums.oneplus.net/threads/is-clipboard-content-sold-to-alibaba.746610/

 

Quote

An intrepid user on the OnePlus forums, v1nc, noticed a suspicious new system app "com.oneplus.clipboard" attempting to access the network after upgrading to a beta release of Oreo with the December 1st security update. Suspiciously, the IP address led to a block owned by Chinese conglomerate Alibaba. Android Police reached out to OnePlus, which confirmed that this was present in the beta.

 

According to OnePlus:

Our OnePlus beta program is designed to test new features with a selection of our community. This particular feature was intended for HydrogenOS, our operating system for the China market. We will be updating our global OxygenOS beta to remove this feature.

 

Leaving aside the fact that harvesting clipboard information strains the definition of "feature," the representative stated that the transmitted data was not saved "on any server." The representative also claimed that "this feature is not uncommon for China users."

The APK in question is not present in the current stable OxygenOS for the OnePlus 3T. It's unclear if this was also in the OnePlus 3 beta build, though no reports of that have been found.

Source: http://www.androidpolice.com/2018/01/11/oneplus-3t-beta-sent-clipboard-data-to-alibaba-controlled-servers/

 

Given that this is yet another privacy blunder for OnePlus in just a few months, I'm starting to become weary of recommending them. But what's your take?

 

UPDATE: Apparently, no actual data is sent but the servers are apparently used to speed up clipboard actions. 

Quote

Android Police reader Nicholas Torkos installed the latest beta (OP_O2_Open_29) on his OnePlus 3, and used mitmproxy to inspect the data being sent. From his findings, the clipboard data itself is not being transmitted, but the app is making connections to a server whenever the contents of the clipboard is updated.

According to this reddit poster, a note in the HydrogenOS beta changelog indicates that the feature was intended for accelerating actions:

Smart clipboard recognition which provide appropriate buttons to help you accelerate your next action. This feature currently support recognition for url, address and TaoBao (e-commerce) content.

Accordingly, Alibaba operates an AWS-like cloud service, which apparently OnePlus used in development of this feature. While this function is not itself nefarious, the inability of OnePlus to clearly explain what was actually going on after multiple requests—let alone explain why this feature requires cloud processing to begin with—is distressing.

Source: 

http://www.androidpolice.com/2018/01/11/oneplus-3t-beta-sent-clipboard-data-to-alibaba-controlled-servers/

The Workhorse (AMD-powered custom desktop)

CPU: AMD Ryzen 7 3700X | GPU: MSI X Trio GeForce RTX 2070S | RAM: XPG Spectrix D60G 32GB DDR4-3200 | Storage: 512GB XPG SX8200P + 2TB 7200RPM Seagate Barracuda Compute | OS: Microsoft Windows 10 Pro

 

The Portable Workstation (Apple MacBook Pro 16" 2021)

SoC: Apple M1 Max (8+2 core CPU w/ 32-core GPU) | RAM: 32GB unified LPDDR5 | Storage: 1TB PCIe Gen4 SSD | OS: macOS Monterey

 

The Communicator (Apple iPhone 13 Pro)

SoC: Apple A15 Bionic | RAM: 6GB LPDDR4X | Storage: 128GB internal w/ NVMe controller | Display: 6.1" 2532x1170 "Super Retina XDR" OLED with VRR at up to 120Hz | OS: iOS 15.1

Link to comment
Share on other sites

Link to post
Share on other sites

that's the price you gotta pay for wanting a high end spec phone with 'affordable' price I guess :shrugs: ... I was never a fan of Oneplus or any Chinese brand phone for that matter anyway. 

Link to comment
Share on other sites

Link to post
Share on other sites

everyone file an alibaba abuse claim :P

"If a Lobster is a fish because it moves by jumping, then a kangaroo is a bird" - Admiral Paulo de Castro Moreira da Silva

"There is nothing more difficult than fixing something that isn't all the way broken yet." - Author Unknown

Spoiler

Intel Core i7-3960X @ 4.6 GHz - Asus P9X79WS/IPMI - 12GB DDR3-1600 quad-channel - EVGA GTX 1080ti SC - Fractal Design Define R5 - 500GB Crucial MX200 - NH-D15 - Logitech G710+ - Mionix Naos 7000 - Sennheiser PC350 w/Topping VX-1

Link to comment
Share on other sites

Link to post
Share on other sites

time to copy paste hardcore porn on a one plus click farm lol

i9 11900k - NH-D15S - ASUS Z-590-F - 64GB 2400Mhz - 1080ti SC - 970evo 1TB - 960evo 250GB - 850evo 250GB - WDblack 1TB - WDblue 3TB - HX850i - 27GN850-B - PB278Q - VX229 - HP P224 - HP P224 - HannsG HT231 - 450D                                                         
Link to comment
Share on other sites

Link to post
Share on other sites

Definitely not regretting my decision to not get a 5T now :D 

Make sure to quote me or tag me when responding to me, or I might not know you replied! Examples:

 

Do this:

Quote

And make sure you do it by hitting the quote button at the bottom left of my post, and not the one inside the editor!

Or this:

@DocSwag

 

Buy whatever product is best for you, not what product is "best" for the market.

 

Interested in computer architecture? Still in middle or high school? P.M. me!

 

I love computer hardware and feel free to ask me anything about that (or phones). I especially like SSDs. But please do not ask me anything about Networking, programming, command line stuff, or any relatively hard software stuff. I know next to nothing about that.

 

Compooters:

Spoiler

Desktop:

Spoiler

CPU: i7 6700k, CPU Cooler: be quiet! Dark Rock Pro 3, Motherboard: MSI Z170a KRAIT GAMING, RAM: G.Skill Ripjaws 4 Series 4x4gb DDR4-2666 MHz, Storage: SanDisk SSD Plus 240gb + OCZ Vertex 180 480 GB + Western Digital Caviar Blue 1 TB 7200 RPM, Video Card: EVGA GTX 970 SSC, Case: Fractal Design Define S, Power Supply: Seasonic Focus+ Gold 650w Yay, Keyboard: Logitech G710+, Mouse: Logitech G502 Proteus Spectrum, Headphones: B&O H9i, Monitor: LG 29um67 (2560x1080 75hz freesync)

Home Server:

Spoiler

CPU: Pentium G4400, CPU Cooler: Stock, Motherboard: MSI h110l Pro Mini AC, RAM: Hyper X Fury DDR4 1x8gb 2133 MHz, Storage: PNY CS1311 120gb SSD + two Segate 4tb HDDs in RAID 1, Video Card: Does Intel Integrated Graphics count?, Case: Fractal Design Node 304, Power Supply: Seasonic 360w 80+ Gold, Keyboard+Mouse+Monitor: Does it matter?

Laptop (I use it for school):

Spoiler

Surface book 2 13" with an i7 8650u, 8gb RAM, 256 GB storage, and a GTX 1050

And if you're curious (or a stalker) I have a Just Black Pixel 2 XL 64gb

 

Link to comment
Share on other sites

Link to post
Share on other sites

Chinese government and corporate data shit aside, I can see a useful side of this, Imagine being able to send something to cloud backup by copying it. 

Grammar and spelling is not indicative of intelligence/knowledge.  Not having the same opinion does not always mean lack of understanding.  

Link to comment
Share on other sites

Link to post
Share on other sites

17 minutes ago, mr moose said:

Chinese government and corporate data shit aside, I can see a useful side of this, Imagine being able to send something to cloud backup by copying it. 

Imagine how many passwords there'd be in the cloud because you're smart and use a password manager...

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, HarryNyquist said:

Imagine how many passwords there'd be in the cloud because you're smart and use a password manager...

Who copies passwords to their clipboard?

Grammar and spelling is not indicative of intelligence/knowledge.  Not having the same opinion does not always mean lack of understanding.  

Link to comment
Share on other sites

Link to post
Share on other sites

8 minutes ago, mr moose said:

Who copies passwords to their clipboard?

Me? I use a password manager and it doesn't always support the website

Link to comment
Share on other sites

Link to post
Share on other sites

14 minutes ago, mr moose said:

Who copies passwords to their clipboard?

Lots of people do it. Especially with those generic password resets with 9 special characters in it. 

 

I assume everything in my clipboard is for my eyes only. So why not copy and paste a password? 

Link to comment
Share on other sites

Link to post
Share on other sites

14 minutes ago, SC2Mitch said:

Me? I use a password manager and it doesn't always support the website

7 minutes ago, corsairian said:

Lots of people do it. Especially with those generic password resets with 9 special characters in it. 

 

I assume everything in my clipboard is for my eyes only. So why not copy and paste a password? 

Then don't use this type of feature,  I was merely saying it would have it's advantages if corporate/government security wasn't an issue.

Grammar and spelling is not indicative of intelligence/knowledge.  Not having the same opinion does not always mean lack of understanding.  

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, mr moose said:

Then don't use this type of feature,  I was merely saying it would have it's advantages if corporate/government security wasn't an issue.

I don't own a 1+? I already said I own a Pixel XL and I really don't care Google know my passwords to some........ sites. 

Link to comment
Share on other sites

Link to post
Share on other sites

17 minutes ago, SC2Mitch said:

I don't own a 1+? I already said I own a Pixel XL and I really don't care Google know my passwords to some........ sites. 

I'm not sure what we are discussing now.  I was merely pondering the benefit of being able to send stuff to a personal cloud account by simply copying it.

Grammar and spelling is not indicative of intelligence/knowledge.  Not having the same opinion does not always mean lack of understanding.  

Link to comment
Share on other sites

Link to post
Share on other sites

"install date" 2008....? what?

 

I mean if this is the first time this has occurred is it not possible that this user has some shit on their phone? Or is this easily replicated throughout all OP devices?

Link to comment
Share on other sites

Link to post
Share on other sites

People need to do more research before  you post things claiming OnePlus is selling user data. For one, people have already tried to download the exact same .apk and replicate the issue to no avail. I have a OnePlus phone and the app has not sent or received any data. NUMEROUS users have not been able to replicate this.

 

If I were to visit "getfreestuff.zyx" and downloaded 8gb of additional ram, only to find out the website had injected malicious code into my pc which took a screenshot of my screen every 15 seconds, I'm not going to blame Microsoft and say they are taking pictures of my screen. (Even if I don't know where the source of the issue originates from)

 

It's also worth noting that yes, China does have shady practices. China claims "

Quote

Our OnePlus beta program is designed to test new features with a selection of our community. This particular feature was intended for HydrogenOS, our operating system for the China market. We will be updating our global OxygenOS beta to remove this feature.

" -official statement from OP

 

So you do have to take everything with a grain of salt, but it only targeted a handful of users that should have been aimed at the chinese market only it seems.

Link to comment
Share on other sites

Link to post
Share on other sites

Oneplus can have all the data they want from me, so happy about my 5t! :)

GPU: MSI GTX 770 gaming || CPU: Intel 4670k @ 4.4Ghz || RAM: 4x4GB 1600mhz Corsair vengeance pro || MOBO: MSI Z87-GD65 Gaming || CPU cooler: Corsair H105 || PSU: Corsair RM650 || SSD: Samsung 840 EVO 120GB, Crucial M4 128GB || Case: Fractal Design Arc Midi R2 || Monitor: ASUS PA238Q

Link to comment
Share on other sites

Link to post
Share on other sites

OnePlus is still a hardware/software champion that is able to keep moderate prices in this "1000€+ ultra premium phone" age of ours. 

 

The experience is still great despite this privacy setback, nonetheless, so they're still a definitive recommend.

Link to comment
Share on other sites

Link to post
Share on other sites

Not surprising honestly, One Plus already has a track record of shady business. It would surprise me if they weren't already selling your personal data for money in other ways too. 

Link to comment
Share on other sites

Link to post
Share on other sites

all the more reason i distant myself from OnePlus, its so alluring but i guess that's the price to pay for a cheap one

Link to comment
Share on other sites

Link to post
Share on other sites

4 hours ago, Goku-sama said:

OnePlus is still a hardware/software champion that is able to keep moderate prices in this "1000€+ ultra premium phone" age of ours. 

 

The experience is still great despite this privacy setback, nonetheless, so they're still a definitive recommend.

Except this is a significant blunder. 

 

This "feature" is supposed to be for HydrogenOS but how did it make its way into an OxygenOS build? 

The Workhorse (AMD-powered custom desktop)

CPU: AMD Ryzen 7 3700X | GPU: MSI X Trio GeForce RTX 2070S | RAM: XPG Spectrix D60G 32GB DDR4-3200 | Storage: 512GB XPG SX8200P + 2TB 7200RPM Seagate Barracuda Compute | OS: Microsoft Windows 10 Pro

 

The Portable Workstation (Apple MacBook Pro 16" 2021)

SoC: Apple M1 Max (8+2 core CPU w/ 32-core GPU) | RAM: 32GB unified LPDDR5 | Storage: 1TB PCIe Gen4 SSD | OS: macOS Monterey

 

The Communicator (Apple iPhone 13 Pro)

SoC: Apple A15 Bionic | RAM: 6GB LPDDR4X | Storage: 128GB internal w/ NVMe controller | Display: 6.1" 2532x1170 "Super Retina XDR" OLED with VRR at up to 120Hz | OS: iOS 15.1

Link to comment
Share on other sites

Link to post
Share on other sites

Yup. Never buying a OnePlus device.

CPU: Ryzen 9 5900 Cooler: EVGA CLC280 Motherboard: Gigabyte B550i Pro AX RAM: Kingston Hyper X 32GB 3200mhz

Storage: WD 750 SE 500GB, WD 730 SE 1TB GPU: EVGA RTX 3070 Ti PSU: Corsair SF750 Case: Streacom DA2

Monitor: LG 27GL83B Mouse: Razer Basilisk V2 Keyboard: G.Skill KM780 Cherry MX Red Speakers: Mackie CR5BT

 

MiniPC - Sold for $100 Profit

Spoiler

CPU: Intel i3 4160 Cooler: Integrated Motherboard: Integrated

RAM: G.Skill RipJaws 16GB DDR3 Storage: Transcend MSA370 128GB GPU: Intel 4400 Graphics

PSU: Integrated Case: Shuttle XPC Slim

Monitor: LG 29WK500 Mouse: G.Skill MX780 Keyboard: G.Skill KM780 Cherry MX Red

 

Budget Rig 1 - Sold For $750 Profit

Spoiler

CPU: Intel i5 7600k Cooler: CryOrig H7 Motherboard: MSI Z270 M5

RAM: Crucial LPX 16GB DDR4 Storage: Intel S3510 800GB GPU: Nvidia GTX 980

PSU: Corsair CX650M Case: EVGA DG73

Monitor: LG 29WK500 Mouse: G.Skill MX780 Keyboard: G.Skill KM780 Cherry MX Red

 

OG Gaming Rig - Gone

Spoiler

 

CPU: Intel i5 4690k Cooler: Corsair H100i V2 Motherboard: MSI Z97i AC ITX

RAM: Crucial Ballistix 16GB DDR3 Storage: Kingston Fury 240GB GPU: Asus Strix GTX 970

PSU: Thermaltake TR2 Case: Phanteks Enthoo Evolv ITX

Monitor: Dell P2214H x2 Mouse: Logitech MX Master Keyboard: G.Skill KM780 Cherry MX Red

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

7 hours ago, NinJake said:

People need to do more research before  you post things claiming OnePlus is selling user data. For one, people have already tried to download the exact same .apk and replicate the issue to no avail. I have a OnePlus phone and the app has not sent or received any data. NUMEROUS users have not been able to replicate this.

 

If I were to visit "getfreestuff.zyx" and downloaded 8gb of additional ram, only to find out the website had injected malicious code into my pc which took a screenshot of my screen every 15 seconds, I'm not going to blame Microsoft and say they are taking pictures of my screen. (Even if I don't know where the source of the issue originates from)

 

It's also worth noting that yes, China does have shady practices. China claims "

" -official statement from OP

 

So you do have to take everything with a grain of salt, but it only targeted a handful of users that should have been aimed at the chinese market only it seems.

This isn't "downloadmoreram.kek" though. This was in a build of OxygenOS based on Android Oreo. 

 

It's supposed to be on HydrogenOS, but some guy screwed up and it found its way into this specific build of OxygenOS. 

 

Like this is not the first time OnePlus was caught sending data back to China or Chinese companies without your permission or knowledge. Like, if you want to send data back, fine, but let me know beforehand and give me the option to opt out. This one may be accidental, but OnePlus needs to be more diligent. 

The Workhorse (AMD-powered custom desktop)

CPU: AMD Ryzen 7 3700X | GPU: MSI X Trio GeForce RTX 2070S | RAM: XPG Spectrix D60G 32GB DDR4-3200 | Storage: 512GB XPG SX8200P + 2TB 7200RPM Seagate Barracuda Compute | OS: Microsoft Windows 10 Pro

 

The Portable Workstation (Apple MacBook Pro 16" 2021)

SoC: Apple M1 Max (8+2 core CPU w/ 32-core GPU) | RAM: 32GB unified LPDDR5 | Storage: 1TB PCIe Gen4 SSD | OS: macOS Monterey

 

The Communicator (Apple iPhone 13 Pro)

SoC: Apple A15 Bionic | RAM: 6GB LPDDR4X | Storage: 128GB internal w/ NVMe controller | Display: 6.1" 2532x1170 "Super Retina XDR" OLED with VRR at up to 120Hz | OS: iOS 15.1

Link to comment
Share on other sites

Link to post
Share on other sites

giphy.gif.1327320e859c545ee1a18c8e6182296a.gif

 

And it's nice that you're using the garbage tier Nep as a profile pic again.

Come Bloody Angel

Break off your chains

And look what I've found in the dirt.

 

Pale battered body

Seems she was struggling

Something is wrong with this world.

 

Fierce Bloody Angel

The blood is on your hands

Why did you come to this world?

 

Everybody turns to dust.

 

Everybody turns to dust.

 

The blood is on your hands.

 

The blood is on your hands!

 

Pyo.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×