back to article Security bods find Android phoning home. Home being China

Security researchers have uncovered a secret backdoor in Android phones that sends almost all personally identifiable information to servers based in China. The firmware is managed by Shanghai Adups Technology, and according to the company, is contained on over 700 million phones worldwide, including phones available in the …

Page:

  1. Anonymous Coward
    Anonymous Coward

    Sniff sniff

    I smell another transgression by the Chinese Government. It would be a breach of civil rights if they had any to begin with...

    1. imanidiot Silver badge

      Re: Sniff sniff

      Jup, it's positively rank in here

      1. Destroy All Monsters Silver badge

        Re: Sniff sniff

        This article needs to be illustrated with Gloriously Smug Chinese Cartoon Girl!

    2. Anonymous Coward
      Anonymous Coward

      Don't be Evil

      [unless your bottom line depends upon it]

    3. Cem Ayin
      Facepalm

      Re: Sniff sniff

      "I smell another transgression by the Chinese Government."

      Sending millions of users' digital family silver to a single well-known server, apparently without certificate pinning? Using plain old DES in the mix? I know one should never underrate the power of human stupidity, but frankly I'd expect Chinese surveillance agencies to make a better job of it. Actually, I think even North-Corea would do a better job these days...

      1. Anonymous Coward
        Anonymous Coward

        Re: Sniff sniff

        >North-Corea

        North Korea.

    4. Antron Argaiv Silver badge
      Thumb Up

      Re: Sniff sniff

      I'm beginning to think that trusting *any* software coming out of China is inadvisable.

      Or, maybe, we should take the advice of President Reagan, and "trust, but verify".

      // no spy icon?

      1. Unicornpiss

        "Trust but verify"

        I always liked the old adage: "Trust in God but lock your car." or for those of us that are atheists, "Trust in your fellow man but lock your car."

      2. fidodogbreath

        Re: Sniff sniff

        I'm beginning to think that trusting *any* software coming out of China is inadvisable.

        It's hard to avoid, since so many computers, phones and other electronics are made there. You have no idea what might be tucked away in UEFI, or the firmware of your hard drive, or your phone's CPU.

        I have a sinking feeling that when World War 3 starts, every Chinese-made computer, router, phone, etc. in the west will shut down.

        1. Lomax
          Mushroom

          Re: Sniff sniff

          Or as I often say; we will know that world war III has begun when our fighter pilots press the "Start(tm)" button in their cockpit and nothing happens.

  2. Herby

    All your base...

    ...belong to us.

    Enough said.

    1. Anonymous Coward
      Anonymous Coward

      Re: All your base...

      No...no not enough said its time to launch off every zig.

      Then we need someone to set us up the bomb.

      Move zig bitches.

      The prophecy was wrong, its not the year 2101 we need to worry about. Its 2016.

  3. Youngone Silver badge

    Questions

    Do I read this in conjunction with the China v Apple story? Are they connected?

    Also, if the spyware in question might be on 700 million phones, why has it only been discovered on one model of BLU phone?

    1. Anonymous Coward
      Anonymous Coward

      Re: Questions

      700 million is the number of phones any of Adups software is installed on, not (necessarily) the number this particular spyware is on.

  4. Sorry that handle is already taken. Silver badge

    So...

    How, or when, do we find out which devices are infected?

    1. Mr Flibble
      Big Brother

      Re: So...

      If you gain root access, I would expect that you'll be able to see the files in one of the /data/app* directories. I'd not like to say for certain, though.

      1. S4qFBxkFFg

        Re: So...

        These things vary by device, also check:

        /system/app/

        /system/priv-app/

        Look for things like "FWUpgrade" and "FWUpgradeProvider".

    2. Anonymous Coward
      Anonymous Coward

      Re: So...

      "How, or when, do we find out which devices are infected?"

      If they run any sort of OS from Google then they are infected!

      1. Sorry that handle is already taken. Silver badge

        Re: So...

        If they run any sort of OS from Google then they are infected!

        Oh.

        Can you help me install Windows on my phone?

      2. Lomax
        Alert

        Re: So...

        I think this is correct. In fact my guess is that any given Android device is likely to have multiple backdoors and leakers, some government sponsored, some built in by Google from the start, some from chip manufacturers, some from ad/spamware app makers, some from criminal networks - possibly something put there by your spouse and/or your boss as well. Then you have the various wire taps on the mobile network, and on the Internet itself. Remember that Huawei make most of the infrastructure hardware used in UK mobile networks (and most of our home network routers as well), and that Huawei ≈ Chinese govt. Remember that our own government runs (not so secret any more) massive bulk data collection and analysis programmes. I think it's safe to assume that every call you make, every text you send, every HTTP request you make, is seen, logged and analysed by multiple parties, some more benign than others. If you think this sounds overly paranoid then you haven't been paying attention.

        And as any Cavendish grower will tell you: a big part of the problem is monoculture.

        1. anonymous boring coward Silver badge

          Re: So...

          "I think this is correct. In fact my guess is that any given Android device is likely to have multiple backdoors and leakers, some government sponsored, some built in by Google from the start, some from chip manufacturers, some from ad/spamware app makers, some from criminal networks - possibly something put there by your spouse and/or your boss as well. "

          No wonder battery life is so poor on Android phones.

          And now Google makes you turn on GPS to get some basic crap working. Let me just enter my location manually FFS! I DON'T WANT 1984 TO ARRIVE YET!

  5. Mr Flibble
    Pirate

    Those host names currently point to 118.193.254.27.

    1. Destroy All Monsters Silver badge

      ...and that is who?

      1. Anonymous Coward
        Facepalm

        Here you go, girly will help you

        https://www.apnic.net , put the numbers in the box at the top, press return and all will be revealed.

        1. Adam 52 Silver badge

          Re: Here you go, girly will help you

          Is there an easy way to find out how it routes there? Via Fort Meade and Cheltenham perchance?

          1. Anonymous Coward
            Anonymous Coward

            Re: Here you go, girly will help you

            traceroute (cli)

            whatroute on macosx

        2. Anonymous Coward
          Anonymous Coward

          Re: Here you go, girly will help you

          "https://www.apnic.net , put the numbers in the box at the top, press return and all will be revealed."

          Its not advisable to take the piss out of other people if you don't even know the simplest solution yourself.

          Go to the command line (know what that is?) and type "whois 118.193.254.27".

          1. Anonymous Coward
            Anonymous Coward

            Re: Here you go, girly will help you

            Well I do know the 'simplest solution' is as I have many years of experience in IT, both permie and a successful contractress.

            As I do not know the posters technical ability, I chose the simplest non technical solution.

            Run along now.

            1. This post has been deleted by its author

            2. Anonymous Coward
              Anonymous Coward

              Re: Here you go, girly will help you

              "contractress."

              No such word.

              "As I do not know the posters technical ability"

              Given they're posting to this site I suspect they're not novices.

              "Run along now."

              You're going to have to work harder at being patronising.

              1. Anonymous Coward
                Anonymous Coward

                Re: Here you go, girly will help you

                There is a lovely word - 'Prat'.

                While at it - please open the Oxford dictionary on the page containing 'misogyny' and read ...

              2. FIA Silver badge

                Re: Here you go, girly will help you

                "contractress."

                No such word.

                I don't think language works how you seem to think it does. (If it did you could have at least constructed a full sentence).

                "As I do not know the posters technical ability"

                Given they're posting to this site I suspect they're not novices.

                Really? REALLY?? You quite often get posters on here who've clearly not even read the article they're commenting on. All you can be sure of is they can possibly manage to use some technical equipment without electrocution; or dictate to their carer.

                "Run along now."

                You're going to have to work harder at being patronising.

                Oh, I dunno; I laughed out loud at that bit. Condescension to a tee. (I believe someone younger than myself might remark that 'you got served').

                1. Anonymous Coward
                  Anonymous Coward

                  Re: Here you go, girly will help you

                  "I don't think language works how you seem to think it does. (If it did you could have at least constructed a full sentence)."

                  You can't just make up a word and expect it to suddenly appear in the OED or for others not to pick you up on it.

                  "Really? REALLY??"

                  Yes really. You think someone who normally is googling Towie is suddenly going to reply to an article on an exploit in android phones?

                  "Oh, I dunno; I laughed out loud at that bit. Condescension to a tee. (I believe someone younger than myself might remark that 'you got served')."

                  If you think thats clever condescension then clearly you've never been on usenet. It would rate a 2/10 at best. The only thing that got served was "her" (I doubt its a she anyway) smart ass on a plate.

                  1. Anonymous Coward
                    Anonymous Coward

                    Re: Here you go, girly will help you

                    Curious, "I doubt its a she anyway" as to why you would think that? Do you know the poster?

                  2. Sweep

                    Re: Here you go, girly will help you

                    I have very almost no knowledge of IT and I've just replied to an article on an exploit in android phones (I wasn't googling TOWIE though).

                    And what's "googling"? You can't just make up words you know.

                    1. Anonymous Coward
                      Anonymous Coward

                      Re: Here you go, girly will help you

                      "And what's "googling"? You can't just make up words you know."

                      https://en.wikipedia.org/wiki/Google_(verb)

            3. Rosie Davies

              Re: Here you go, girly will help you

              REAL* sysadmins do not use the command line. Real sysadmins sense the route taken from the spin of the photons flowing throughthe fibre.

              Rosie

              *Robotically Enhanced Advanced Lifeforms for those at the back of the class. Yes Smithers, I'm talking to you.

          2. Brewster's Angle Grinder Silver badge
            Trollface

            Re: Here you go, girly will help you

            >Go to the command line (know what that is?) and type whois 118.193.254.27

            It says: 'whois' is not recognized as an internal or external command, operable program or batch file.

            What do I do now?

            1. Anonymous Coward
              Anonymous Coward

              Re: Here you go, girly will help you

              "What do I do now?"

              Install a proper OS.

            2. VinceH
              Coat

              Re: Here you go, girly will help you

              "It says: 'whois' is not recognized as an internal or external command, operable program or batch file.

              What do I do now?"

              > GO NORTH

      2. David Shaw

        I prefer http://www.infosniper.net, gives you a decent handful of detailed look-ups per day, and a nice map

      3. Anonymous Coward
        Anonymous Coward

        Well done. You got the answer without any exposure or risk to yourself.

        1. Anonymous Coward
          Anonymous Coward

          What 'real OS' are you talking about?

          Linux:

          -bash: whois: command not found

          1. Anonymous Coward
            Anonymous Coward

            >Linux:

            >

            >-bash: whois: command not found

            I suggest you check your $PATH for /usr/bin or /sbin because whois is part of the standard unix/linux networking command set and has been for decades.

            1. Alister

              @boltar

              I suggest you check your $PATH for /usr/bin or /sbin because whois is part of the standard unix/linux networking command set and has been for decades.

              I suggest you check your information, it hasn't been included in the standard install for many distributions for years.

              1. Anonymous Coward
                Anonymous Coward

                "I suggest you check your information, it hasn't been included in the standard install for many distributions for years."

                Bollocks.

            2. Brewster's Angle Grinder Silver badge

              "suggest you check your $PATH for /usr/bin or /sbin because whois is part of the standard unix/linux networking command set and has been for decades."

              The program 'whois' is currently not installed. You can install it by typing:

              sudo apt-get install whois

              1. Anonymous Coward
                Anonymous Coward

                "The program 'whois' is currently not installed. You can install it by typing:"

                What fucked up distro do you use? Does it not have ping or traceroute or ssh installed either?

                1. Alister

                  What fucked up distro do you use? Does it not have ping or traceroute or ssh installed either?

                  From my own experience, none of the following have the full set of network tools installed by default:

                  Redhat, Centos, Ubuntu, Debian (and its offshoots, like Mint).

                  They do have ping, and ssh, but not traceroute, whois, dig etc.

  6. Dr Paul Taylor
    Flame

    This is why

    I don't have a "smart"phone.

Page:

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like