6 ms·
I think the real question is what mechanism allows them to push a random app to some phones? google play services is actively listening for remote installation
by simpss 5y ago
I think the real question is what mechanism allows them to push a random app to some phones? google play services is actively listening for remote installation requests?
that's essentially a remote-code-execution backdoor to all android phones?
- ahofmann 5y agoYou can install apps from your browser on the PC since years. I think this also works on apple?
- contriban 5y agoNot exactly. On the Android store you can choose exactly which device to install an application on. For Apple as far as I know the most you can do is buy the app on desktop and, if the device is configured that way, it will receive the new app. This means it’s limited to new purchases and by the device’s settings.
- ahofmann 5y agoOk, but my point was that on Android and iOS it is possible to install apps without touching your phone. This qualifies as remote code execution. You need your credentials for doing this, but google and Apple apparently don't need them.
- pizza 5y agoYes, but RCE is typically shorthand for “RCE by someone other than the owner of the device”
- E8L3i 5y agoThere is a handy feature to do so https://android.gadgethacks.com/how-to/remotely-install-apps-onto-your-android-phone-0328936/ https://android.gadgethacks.com/how-to/remotely-install-apps...
- simpss 5y agoThank you, I've even used this functionality some years ago but didn't remember it existed. I've since de-googled my phone and sacrificed some apps that require google services, but this whole thing shows (to me) that it was the right decision.
- deleted 5y ago[deleted]
- 1vuio0pswjnm7 5y agoNo different than, say, "Windows Update". The entire "updates" culture is essentially RCE backdoor (botnet) functionality for "trusted" tech companies. Consent, where it is actually explicitly obtained, never rises to the level of "informed". That's because even if a user "consents", she still cannot see what is in each update.
- formerly_proven 5y agoWU allows hardware manufacturers to silently install literally anything based on hardware ID matching and the only way to prevent that is to disable WU driver updates entirely (via GPC/registry). In my case the maker of my motherboard installed a persistent “self-repairing” (i.e. difficult to uninstall) from yet another third party. Naturally, I will not buy a product from them (MSI) again. Another way to put this is: windows update will install malware w/o user approval in the background.
- the_pwner224 5y agoYou can probably turn that off from the BIOS. It's (unfortunately) pretty common these days, MSI isn't special for doing this. It's a different mechanism from Windows automatically loading drivers and/or the vendor's malware when you plug in a device.
- aorth 5y agoI think the difference is that I chose to install Chrome/Firefox etc, so I don't mind the automatic updates. In this case nobody actually installed this app by choice!
- fragileone 5y agoI thought this was well-known, Android is not private at all until you degoogle. Unlock your bootloader then install a ROM without Google Play Services such as GrapheneOS, CalyxOS or LineageOS. You can consider installing microG also as an open-source minimal implementation of Google Play Services if some of it's functionality is absolutely necessary for you to keep.
- okdjnfweonfe 5y agoThat doesn't fix the issue ISPs mandate certain capabilities of the cellular modem + the simcards (remember java cards? that ran java? they still exist as simcards!) Government RCE is still 100% on the table regardless of whatever software your phone is running
- remuskaos 5y agoDo any of the privacy oriented custom ROMs protect against that? I can't imagine their maintainers seeing code that just installs any app the ISP wants and be okay with it.
- okdjnfweonfe 5y agoThe problem is, its usually cheaper the more things you can shove into the 1 hardware item, so you have your cellular hardware in the same chip as your CPU and GPU. Not much a ROM can do about this unless the chip itself supports disabling direct memory across the two items, + does it correctly, + doesn't allow it to be reversed from the other side, + you would also need the datasheet to find out how to implement this. Generally why privacy roms don't support more than 1 or 2 brands total, I guess. There are also platforms with strict division between the seperate parts of hardware, la pinephone and the librem5
- sohei 5y agoThe factual basis of your assertion is absolutely true, but your attitude is unhelpful and defeatist. There is a chasm between "a state actor throws an 0day at you" and "Google remotely installs an app on your phone". The latter is done at scale. The former is expensive, risky, and used relatively rarely. If you're organizing a protest movement, it's totally reasonable to factor government 0days into your threat model. For more boring people, running GrapheneOS is a great way to reduce the attack surface they expose to the advertising and mass surveillance industrial complex.
- sohei 5y agoA corollary of your question. If Google can lawfully install arbitrary apps on ordinary users' phones, can it also run arbitrary code on the personal devices of government officials investigating it for price fixing in the ad market?
- GavinMcG 5y ago"Arbitrary" is doing a lot of sneaky work here. You're implying that the law would somehow allow Google to manipulate investigators. But the law has broad allowances and exceptions in lots of areas, and competing permissions/denials that together weave specific allowances. There's little reason to think that the law couldn't allow app installation in general and also disallow either targeting of individuals or collection/manipulation of certain kinds of data.
- sohei 5y agoAnother question worth asking is "what is the governing law?" It is almost certainly contract law via Google's ToS. Government phones probably have different ToS, but government employee' personal phones have the same ToS we have. If Google is asserting non-contractual rights, I'd like to know what they are. Edit: I edited this comment because it was rude, and that was not my intent.
- GavinMcG 5y ago[Edit: the comment originally said their question wasn't implying anything] Of course you're implying something. If nothing else, you're implying the one might imply the other, and that the implication is worth attention. The governing law that would protect people is a lot of things, and ToS is the least of it. The Wiretap Act applies, for example.
- sohei 5y ago> ToS is the least of it I'm afraid I disagree. Google running code on your phone implies it believes you have consented to that. That consent was not given in the app store, so it must have come from the ToS. Consent is an exception to virtually every protection that exists: Wiretap Act, state wiretapping laws, the CFAA, and state computer trespass laws. Remember, consent is the difference between a home invasion and a dinner party. So it seems that Google would have to cook up a pretty implausible stopping principle to argue that whatever allows them to do this does not also enable the hypothetical I described above.
- tdeck 5y agoMy guess is that it's the Play Store app itself that does this (con.android.vending). That app is responsible for both updating itself regularly and installing/updating other apps. One possible way: There is a daily job run in the Play Store called "daily hygiene" that performs various configured tasks based on device state and device targeting. It would not be difficult to add some code to install this app for MA users, then push it with the next Play Store update. I am very unpleasantly surprised that this app was installed from a policy perspective, however.
- dTal 5y agoThey don't have to add any code or push a Play Store update or wait for a daily cronjob. Listening for remote installation requests is a core feature of Google Play Services. It is not a mystery how this was done.
- deleted 5y ago[deleted]
- hungryforcodes 5y agoSo you keep "claiming", but where is this documented?
- thepangolino 5y agoIsn’t there a feature from the app stores allowing for remote installation of apps?
- dTal 5y ago>google play services is actively listening for remote installation requests? Uh, yes? That is and always has been core functionality. You can click "install" on the Google Play website on your laptop and the app will magically appear on your phone, if both devices are signed in to Google. I triggered this behavior accidentally a good 10 years ago when I got my first Android phone, and it gave me the shivers - it really drove home the point that Google had root on my phone, not me. In fact, this entire behavior is so normalized on phones we now have a special word for the process of downloading an app and installing it manually, the way we do on PCs: "sideloading".
- IncRnd 5y agoThat's not the behaviour of what happened here, where an app was downloaded without user initiation or intervention. There was no authorization from the user of the actions that were taken by Google or the app's vendor.
- dTal 5y agoFrom a technical standpoint, it is the same. The phone maintains a connection to a Google server and listens for "authorized" installation requests - where "authorized" means "authorized by Google". When you click "install" on the Play Store on your laptop, you're not talking directly to your phone (how would that even work?) - you're talking to Google, who then speaks to your phone on your behalf.
- simpss 5y agoit could work with google cloud providing oauth and the phone verifying it's the same account.
- IncRnd 5y ago> From a technical standpoint, it is the same. Yes, of course, but this isn't a technical issue. Look at the webpage that this hn page references. When people say, "an app was installed on my device without my consent or knowledge," the exact method the device used to listen isn't important. The first issue is that Google software allows non-authorized software installations. The second issue is that a government forced the installation of the app. The technical specifics are just implementation details.
- smeej 5y agoRelated question I'm not wrapping my head around: How does the thing know you're a Massachusetts resident? People who have the contact tracing setting disabled are reporting they still got the app, so the obvious answer seems not to apply. Is it just getting installed on any device that enters MA? New England states are pretty small, and there's a lot of crossover, especially with states like Maine and New Hampshire, which wouldn't take this very well. Or, if you have a layover at Boston's Logan airport, do you now end up with its contact tracing app?
- Jailbird 5y agoNot a resident. I just found it installed due to HN. I am in MA at this time.... and have no idea when it was installed. (Of course I uninstalled it immediately)
- neltnerb 5y agoIf they're also hitting phones that were only in the state temporarily it must be using cell tower locations right? I use an always on VPN and it still auto installed (without opting in) but I have my E911 address set here so I'd have guessed that otherwise.