Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
flakeloaf
Feb 26, 2003

Still better than android clock


truer words

basically nobody talks to us at the office christmas party, which is squarely in "features aren't bugs" territory but still

Adbot
ADBOT LOVES YOU

Mr. Nice!
Oct 13, 2005

c-spam cannot afford



stolen from the china thread, but nokia 7s are phoning home to china.

LordArgh posted:

so the norwegian news broadcaster nrk has discovered that the nokia 7 plus has been sending packets of data to someone in china which includes information such as the phone's geographical location, sim card number and the phone's serial number. after this was revealed today, the finnish data protection agency has started to look into it. the owners of nokia, hmd global, did not want to answer questions about whether the phones are required to do this in order to be sold in china, or about who owns the server the data are being sent to.

i couldn't find an article about it in english, but here's the original report on it that you can run through google translate or something:

https://nrkbeta.no/2019/03/21/norske-telefoner-sendte-personopplysninger-til-kina/

champagne posting
Apr 5, 2006

YOU ARE A BRAIN
IN A BUNKER

"" posted:

Hver gang telefonen ble slått på, skjermen aktivert eller låst opp, gikk hans geografiske posisjon, samt SIM-kortnummer og telefonens serienummer til en server i Kina.

"Every time the phone ('s screen) was turned on or unlocked his geo position, sim-number and phone serial number was sent to a server in china"

IMEI, IMSI, phones numbers and goodies sent to china in plain text.

Cybernetic Vermin
Apr 18, 2005

super-weird at first since they should be running a clean google image outside of the driver layer, but it seens most likely it is a qualcomm driver doing the call "home" https://raw.githubusercontent.com/b...rationTask.java

mystes
May 31, 2006

But don't use Huawei phones because they might be sending your data to China.

Media Bloodbath
Mar 1, 2018

PIVOT TO ETERNAL SUFFERING
:hb:
It's almost as if Android phones are not built with security in mind.

Mr. Nice!
Oct 13, 2005

c-spam cannot afford



mystes posted:

But don't use Huawei phones because they might be sending your data to China.

¿porque no los dos?

univbee
Jun 3, 2004




Mr. Nice! posted:

stolen from the china thread, but nokia 7s are phoning home to china.

technically wouldn't a nokia phone home to finland?

Mr. Nice!
Oct 13, 2005

c-spam cannot afford



univbee posted:

technically wouldn't a nokia phone home to finland?

nokia mobile was owned by microsoft until 2016 when a former nokia exec began producing phones with foxconn and various other chinese manufacturers.

endlessmonotony
Nov 4, 2009

by Fritz the Horse

Mr. Nice! posted:

nokia mobile was owned by microsoft until 2016 when a former nokia exec began producing phones with foxconn and various other chinese manufacturers.

Not exactly.

Nokia's mobile business was sold to Microsoft, yes, but the resulting entity was/is Microsoft Mobile. Nokia never sold their IP, just licensed it.

HMD Global, the new licensee, is based in Finland - and the phones are designed in Finland too, by former Nokia designers. It's just that it's Foxconn manufacturing them.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug
So my company is implementing Stealth to microsegment parts of our DC and network, and I've talked about this previously, but my big concern is lack of info on known weaknesses to Stealth and I'm kinda pissed we are not just doing proper segmenting via VLANs and 802.1x certs.

Anybody know some pertinent questions I should ask as a Red Team guy? My big one up front is "What are you doing to stop pivoting at entry points into the microsegments" and "What happens if someone compromises a common point of interest and MITMs the segment?"

Mr. Nice!
Oct 13, 2005

c-spam cannot afford



endlessmonotony posted:

Not exactly.

Nokia's mobile business was sold to Microsoft, yes, but the resulting entity was/is Microsoft Mobile. Nokia never sold their IP, just licensed it.

HMD Global, the new licensee, is based in Finland - and the phones are designed in Finland too, by former Nokia designers. It's just that it's Foxconn manufacturing them.

thanks

exmachina
Mar 12, 2006

Look Closer
Dammit I was going to buy that phone.

What is considered a 'safe' mid-range phone, preferably with Android one.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

exmachina posted:

Dammit I was going to buy that phone.

What is considered a 'safe' mid-range phone, preferably with Android one.

Just buy a nexus phone, they'll actually get security updates on a regular cadence.

Cybernetic Vermin
Apr 18, 2005

exmachina posted:

Dammit I was going to buy that phone.

What is considered a 'safe' mid-range phone, preferably with Android one.

still that one i'd say, while it is a fuckup it seems an innocuous one (wrong qualcomm driver package loaded, this apparently being a "register with network" step that is required in china), and i would not really have more faith in some other manufacturer

Kassad
Nov 12, 2005

It's about time.

Volmarias posted:

Just buy a nexus phone, they'll actually get security updates on a regular cadence.

The new Nokias will get them too for a while (that's why I bought one, a 7.1).

Kassad fucked around with this message at 16:47 on Mar 21, 2019

neutral milf hotel
Oct 9, 2001

by Fluffdaddy
lol Facebook

https://krebsonsecurity.com/2019/03/facebook-stored-hundreds-of-millions-of-user-passwords-in-plain-text-for-years/

Hundreds of millions of Facebook users had their account passwords stored in plain text and searchable by thousands of Facebook employees — in some cases going back to 2012, KrebsOnSecurity has learned. Facebook says an ongoing investigation has so far found no indication that employees have abused access to this data.

geonetix
Mar 6, 2011


I have a feeling that investigation should be done by a third party instead

endlessmonotony
Nov 4, 2009

by Fritz the Horse

exmachina posted:

Dammit I was going to buy that phone.

What is considered a 'safe' mid-range phone, preferably with Android one.

This doesn't change me recommending 6.1, given it was only the 7 and not "all models".

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

Volmarias posted:

Just buy a nexus phone, they'll actually get security updates on a regular cadence.

the nexus series is discontinued, google only makes pixels now

ironically the nokia phones are actually part of the "android one" branding, which is a promise by the manufacturer to ship a stock OS image and to provide the device with google's monthly security patches for like 2-3 years

Kassad
Nov 12, 2005

It's about time.

endlessmonotony posted:

This doesn't change me recommending 6.1, given it was only the 7 and not "all models".

The 7 Plus, the regular Nokia 7 is a different model.

Schadenboner
Aug 15, 2011

by Shine

geonetix posted:

I have a feeling that investigation should be done by a third party instead

I mean, not if you want the investigation to reach the conclusion Facebook wants it to reach?

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Lutha Mahtin posted:

the nexus series is discontinued, google only makes pixels now

ironically the nokia phones are actually part of the "android one" branding, which is a promise by the manufacturer to ship a stock OS image and to provide the device with google's monthly security patches for like 2-3 years

Pixel, sorry.

WRT Android One, I've seen too many "We Promise To Actually Update This Phone For Years Guys We Really Really Mean It This Time" groups show up to not get jaded about this.

goddamnedtwisto
Dec 31, 2004

If you ask me about the mole people in the London Underground, I WILL be forced to kill you
Fun Shoe

Volmarias posted:

Pixel, sorry.

WRT Android One, I've seen too many "We Promise To Actually Update This Phone For Years Guys We Really Really Mean It This Time" groups show up to not get jaded about this.

did google carry on patching the nexus phones once they started doing the pixels or was it the normal "ooh shiny new thing, let's ignore the old thing" process they always do?

Wiggly Wayne DDS
Sep 11, 2010



Lutha Mahtin posted:

the nexus series is discontinued, google only makes pixels now

ironically the nokia phones are actually part of the "android one" branding, which is a promise by the manufacturer to ship a stock OS image and to provide the device with google's monthly security patches for like 2-3 years
not only discontinued but they've stopped security updates by now

did you not hear the rush of people moving from the 5x after no security updates were pushed after december

e: make that january, but they officially stopped support after november: https://support.google.com/nexus/answer/4457705

Wiggly Wayne DDS fucked around with this message at 18:34 on Mar 21, 2019

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
The 5x only just stopped getting security updates at the end of 2018, after launching in 2015. It's not iPhone levels of support but it's the best you'll get for Android, for now.

Cybernetic Vermin
Apr 18, 2005

Volmarias posted:

Pixel, sorry.

WRT Android One, I've seen too many "We Promise To Actually Update This Phone For Years Guys We Really Really Mean It This Time" groups show up to not get jaded about this.

it is 100% googles fault if an android one phone ends up not getting updated though, as it is a standardized image that does just pull the monthly updates from google

as noted the issue here is that the image is comingled with a soc support/driver package, and the qualcomm package used on a run of the 7 was incorrectly setup for china

Cybernetic Vermin
Apr 18, 2005

like, not defending the fuckup, because it is a huge fuckup, but don't go buying samsungs or even overpaying hugely for a pixel now

Shame Boy
Mar 2, 2010

i got a pixel 3 and it's very needs suiting and the camera is fantastic :shrug:

Cybernetic Vermin
Apr 18, 2005

they are so loving expensive mostly. nokia has a good combo in being pretty cheap, getting updates, and mostly not being terrible

pseudorandom name
May 6, 2007

buy an iPhone

Celexi
Nov 25, 2006

Slava Ukraini!

neutral milf hotel posted:

lol Facebook

https://krebsonsecurity.com/2019/03/facebook-stored-hundreds-of-millions-of-user-passwords-in-plain-text-for-years/

Hundreds of millions of Facebook users had their account passwords stored in plain text and searchable by thousands of Facebook employees — in some cases going back to 2012, KrebsOnSecurity has learned. Facebook says an ongoing investigation has so far found no indication that employees have abused access to this data.

lmao

Cybernetic Vermin
Apr 18, 2005


if you're spending that kind of money: yeah.

Janitor Prime
Jan 22, 2004

PC LOAD LETTER

What da fuck does that mean

Fun Shoe

Cybernetic Vermin posted:

they are so loving expensive mostly. nokia has a good combo in being pretty cheap, getting updates, and mostly not being terrible

https://www.mirror.co.uk/tech/nokia-smartphones-been-secretly-sending-14167303

Cybernetic Vermin
Apr 18, 2005


:justpost: i guess v:shobon:v

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

Volmarias posted:

WRT Android One, I've seen too many "We Promise To Actually Update This Phone For Years Guys We Really Really Mean It This Time" groups show up to not get jaded about this.

the current iteration of Android One (it's one of those names Google has used for multiple unrelated projects over the years) is supposedly some kind of actual contract that the device manufacturer has to sign in order to use the branding. it hasn't been around very long though so i am interested to see if any manufacturers try and weasel out of it

DrPossum
May 15, 2004

i am not a surgeon

neutral milf hotel posted:

lol Facebook

https://krebsonsecurity.com/2019/03/facebook-stored-hundreds-of-millions-of-user-passwords-in-plain-text-for-years/

Hundreds of millions of Facebook users had their account passwords stored in plain text and searchable by thousands of Facebook employees — in some cases going back to 2012, KrebsOnSecurity has learned. Facebook says an ongoing investigation has so far found no indication that employees have abused access to this data.

:thunk:

Sniep
Mar 28, 2004

All I needed was that fatty blunt...



King of Breakfast
how senior do you have to be at facebook to just get unlimited graph api access as part of your job, like, anything you want at all

fisting by many
Dec 25, 2009



Sniep posted:

how senior do you have to be at facebook to just get unlimited graph api access as part of your job, like, anything you want at all

about 18 months ago they were basically giving that to anyone who had an app, i'm sure cambridge analytica isn't the only company that's done close to mirror facebook's database

Adbot
ADBOT LOVES YOU

DrPossum
May 15, 2004

i am not a surgeon

xpost from cpam cyberpunk dystopia thread

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply