4 ms·
The article takes it into a boring direction, and they didn't mention Samsung who is most active in this field. Vendors bypass appstores with their proprietary
by voidz 10y ago
The article takes it into a boring direction, and they didn't mention Samsung who is most active in this field. Vendors bypass appstores with their proprietary apps. Once upon a time I had a Samsung phone, and when I configured its email app, I saw Samsung's own servers, and not my phone, logging in to my email server. Which means they stole my password. That's when I tossed out Samsung devices once and for all.
But anyway, here's the courtesy tl;dr of the article:
Can it be done? Absolutely. Will it be done? Most likely. Have many people suggested that it's already happening to them? For sure, all over the place.
Is it allowed by Google, Facebook and the like? Most definitely not. So is it happening? Probably not, it's just a coincidence that you talk about something specific, and then suddenly find all kinds of ads about it.
Here's a dictionary definition of 'coincidence' followed by an explanation from a professor about how our minds have evolved to correlate stuff all over the place and see patterns in them, even though they're just coincidences.
- digi_owl 10y ago> Once upon a time I had a Samsung phone, and when I configured its email app, I saw Samsung's own servers, and not my phone, logging in to my email server. Which means they stole my password. Would love to see some traffic logs regarding this.
- dave2000 10y agoPlus a copy of all the EULAs you consented to with Samsung when you used their phone and software.
- reitanqild 10y agoHowever relevant this possibly is a court case it is less relevant when you are about to pick between a nexus, an iPhone and a Samsung S-series. Also while IANAL, note that in a number of jurisdictions EULAs like the ones you seem to think about might not be valid. Norwegians consumer authorities recently mocked them and I applaud them for it.
- dave2000 10y agoWith a Nexus you're trusting Google with a lot more info than Samsung could hope to obtain. So if this isn't about legality then I'm not sure what it is. Presumably Samsung aren't storing your email credentials so they can launch a spam campaign, and you've not provided anything like enough information to deduce that they're doing anything other than, perhaps, keeping the email moving. I never read EULAs and I can imagine they're not valid everywhere, but they're useful as a measure of the intent of the company producing them. I imagine Samsung, for example, reserves the right to use any information you provide to ensure a certain quality of service. I'm sure Google have run their EULAs - valid or not - past similar lawyers.
- reitanqild 10y agoGoogle has shown that they fire sysadmins who put their nose into customer data even though tje sysadmin in question had good intentions. AFAIK they also have a fairly strong security record. I'm not saying Samsung doesn't but I don't know.
- cubano 10y agoIt's also an absolutely wonderful blame for people so inclined to inform on others.
- walrus01 10y agoYou set it up with your own IMAP(TLS) and smtpd for email, and in your server logs the logins were coming from Samsung IPs, not the wifi or cellular network your phone was connected to? Where were these Samsung IPs in terms of physical location and netblock? If they're doing MITM on their customers' traffic I'm really curious where it's going through.
- voidz 10y agoCorrect. The logins came from Samsung IPs. I wrote up a fat warning on xda but am unable to find it. Sadly it was too long ago for me to find it back.