3 ms·
China forces the Uighurs and anyone who visits their region (Xinjiang) to install malware on their Android: https://www.extremetech.com/mobile/294389-china-is-i
by mehhh 7y ago
China forces the Uighurs and anyone who visits their region (Xinjiang) to install malware on their Android: https://www.extremetech.com/mobile/294389-china-is-installing-android-malware-on-tourists-phones https://www.extremetech.com/mobile/294389-china-is-installin...
Banning sideloading forced China to use iOS exploits, which are ephemeral and not consistently effective.
Installing apps outside a repository (like on most Linux distros) is a dual edged sword, Apple and Google are poor stewards of their software repositories compared to Debian or OpenSuse.
- Wowfunhappy 7y ago> Banning sideloading forced China to use iOS exploits, which are ephemeral and not consistently effective. But that's just it, China found their own way in! I don't think it's obvious which method is less effective. iPhones were compromised until reboot, and became reinfected as soon as the user next visited the malicious website—which a government can compel people to do frequently. That's still better than Android, but on Android, users knew they were being tracked. iOS users did not. (And of course, because iOS is locked down, it's harder to inspect your phone for signs it's compromised.) If China hadn't found an exploit, do you think they would have given up? I think they would have required iOS users to carry dedicated trackers. Or just surveilled them more heavily. Software restrictions don't impact the powerful, who have access to alternatives. They impact the average user, who has limited reserves of money, knowledge, and time.
- mehhh 7y agoThere is a huge practical difference between being temporarily infected and permanently having malware embedded in your phone. The former is fixable with a software uodate from a company that actively looks to secure your phone, while in the latter case the device is hopelessly compromised. I love sideloading, but if I were a target of interest then iOS is the only reasonable choice.
- lern_too_spel 7y agoThey would just not allow you in if you don't hand over your contacts. Similarly, if I have an Android phone, they won't be able to install the app without my permission. At that point, they can not allow me in.
- jethro_tell 7y agoIt seems like this app is also ephemeral? you just uninstall it after they've ripped all your data. So as usual you should cross borders with an empty phone, no?
- mehhh 7y agoThe app has root, it can easily break out of the APK and ensure reinstallation just like other Android malware does. Factory resetting might work if the system partition is not modified, but that covers only a portion of Android devices.
- lern_too_spel 7y agoThe app does not have root. It just requests a lot of permissions.
- mehhh 7y ago> An app analysis tool shows that this app––MFsocket.apk––gains ROOT access to an Android phone Source: https://chinadigitaltimes.net/2019/07/spyware-used-on-phones-at-xinjiang-border/ https://chinadigitaltimes.net/2019/07/spyware-used-on-phones...
- lern_too_spel 7y agoFengcai is the app your original article talked about, which the police install when you enter Xinjiang. It does not try to get root access. MFsocket is a separate app that has both an iPhone and Android version that police in Beijing use that does attempt to gain root on both platforms. It is unlikely to actually get root on an Android phone that a technologist would use.
- jethro_tell 7y agoWhat steps are we talking about here that a technologist would have taken here?