22 ms·
I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads
- mock-possum 3y agoShitty. I wonder what kind of profit they make per successful scam.
- MBCook 3y agoWell a single un-refunded $50/mo transaction is pretty good, plus whatever they can get from ads and selling data.
- HumblyTossed 3y agoAnd yet, we can't have side loaded apps because somehow that would make the App Store worse. Phooey!
- LeoPanthera 3y agoThis is not the gotcha you think it is. Imagine how awful the apps we would be forced to sideload would be, if companies like the one that made this dongle were allowed to make them.
- TulliusCicero 3y agoAh yes, the many apps poor Android users are forced to sideload. As an Android user myself, so far I'm up to...zero?
- twiceaday 3y agoYou are correct in lampooning the word "force" but don't throw out the baby with the bathwater. The point is still valid. Also, it seems obvious that the danger is in long-term ecosystem implications. "I haven't had to so far" is irrelevant. Android users had/have(?) to side-load Fortnite. Depending on who you are that might feel like being "forced." Is your argument "If you feel like you are forced to use some app you are wrong and should just stop" or is it "If an app gets big enough that a lot of people feel forced to side-load it, then it earned the right not to abide by any platform holder policies."
- WarOnPrivacy 3y ago> You are correct in lampooning the word "force" but don't throw out the baby with the bathwater. The point is still valid. I have yet to see one, client, customer, friend, acquaintance, relative (or rando who happened to know I'm an IT guy) sideload an app without knowing what they were doing & having a good reason to do so. The list of those who sideloaded is small. However, my list of technically hapless folks is much, much larger - and zero of them seem to have sideloaded anything ever. There's a fair chance I'd wind up knowing if they did. Even my often homeless ex who's down with plugging any connector into any port at any time of day (shapes need not match) doesn't seem to have sideloaded. Certainly her devices are always in a Sideloading=Off state when I check (she is not now a developer!). From an IT view, unintended sideloading looks like a low priority concern.
- TheCoelacanth 3y agoThe reason for making Fornite sideloaded is informative. It's not because they wanted to get around any of the supposed user protections of App Stores; it's because the App Store was leaching too much money.
- NotYourLawyer 3y agoPresumably you don’t have any shitty hardware like this cable.
- RajT88 3y agoIf you own a mainstream android device, you're probably not going to ever have to. If you have something a little weirder, the app store often will not let you install an app which doesn't state compatibility. Sideloading the APK more often than not works fine. Also, there's alternative sources like F-Droid which have stuff you can't get in the Google app store - ad-free Youtube apps - that will never be allowed on the Google app store.
- deleted 3y ago[deleted]
- hedora 3y agoDoes Google ban apps that break if location information is denied? The last time I checked, Apple did and Google did not.
- vinay427 3y agoI wouldn’t expect better of Google. An app like Google Photos on iOS should (in my opinion) be banned because it requires access to all locally saved photos, breaking if either no access or selective/additive photo access is used.
- mixmastamyk 3y agoI don't know. This app from the app store is already near 80% of the worst I could imagine. Only formatting the storage might be worse... and then they wouldn't get any more juicy location data.
- pdntspa 3y agoComputers have been that way since forever. It wouldn't be nearly as bad as you make it out to be.
- brookst 3y agoAs long as the attack surface is N, we might as wall make it 2N.
- HumblyTossed 3y agoPure hyperbole.
- scarface_74 3y agoYou notice that as bad as this cord is, it can’t do anything privacy invasive without asking permission?
- rnk 3y agoThe saluspa from "bestway" demands your location before allowing you to setup wifi remote control of the portable hot tub on the android app. I wonder how on android I can spoof the location used by an app, or if anyone figured out if you can control it without the app. I set it up away from my house and use a separate wifi network but it pissed me off.
- niij 3y agoAndroid apps used to need "location" access for bluetooth discovery. https://www.androidpolice.com/2021/05/19/android-12-apps-wont-ask-for-location-permissions-when-all-they-want-is-bluetooth-scanning-which-yes-was-a-thing/ https://www.androidpolice.com/2021/05/19/android-12-apps-won...
- netsharc 3y agoBecause your location can be inferred by finding which Bluetooth devices are around you, as that article says... > See, back in Android 6 Marshmallow, Google changed things so that apps needed location permissions to scan for Bluetooth devices. At the time, the rationale was that Bluetooth was going to be used for things like interior navigation or location tracking in a more abstract sense, and your location could indirectly be inferred via Bluetooth scanning alone if a given hardware identifier was tied to a specific location.
- rightbyte 3y agoI have always assumed that is a way for Google to normalize granting the position permission. You could "pair" apps with devices if Bluetooth position spyware was a concern.
- GauntletWizard 3y agoBefore Android required that permission, there were marketing companies selling malls the ability to see who was around by the ID of their Bluetooth beacon.
- jollyllama 3y ago[flagged]
- deleted 3y ago[deleted]
- denton-scratch 3y agoSo from my reading, the shitty behaviour is from the app, not the cable. Have I misread it? What happens if you try to use the cable without downloading the app? I for one would assume that my cable was defective, if it needed an app to work. I realize that HDMI cables are weird, and that like quite a lot of modern interconnect are not a monolithic standard, but come with multiple support levels; I wish that would stop. A standard is a standard, and market partitioning is no part of the job of a standard.
- fckgw 3y agoThe adapter flashes a QR code on your monitor. It's not plug-n-play.
- RetroTechie 3y agoRequiring the use of an app, in order to use some kind of adapter cable? I must be getting old, feel like I've just crawled from under a rock... :-) That would also mean this cable becomes useless the moment URL encoded in the QR disappears? As for the app: even if it's total crap, if only 50% of cable-buyers proceed to install the app, that 50% is still gained as potentially spied-upon subjects. There's a new please-spy-on-me sucker born every day, so to speak.
- MBCook 3y agoDoes it really matter? This isn’t a real product. It’s a scam product to trick people trying to buy a real Apple part and con them into the app’s clutches. The real part doesn’t need anything. Plug and go.
- bitwize 3y agoIt's not really an adapter cable. It's got a little SOC in there that streams your iPhone's display from the app to the HDMI port. Meanwhile, your personal data is being streamed back to China...
- 3y ago
- cwoolfe 3y agoGiven that the device is plugged in, trusted, shows up as a computer, and requires external power, it has all the connections it needs spy on the screen (at minimum) and remote control the victim iPhone without permission in the worst case. (it has video feed, and can emulate USB keyboard and mouse) Yikes!
- mtreis86 3y agoHow hackable is it? That could be useful
- jjoonathan 3y agoIntegrating everything into USB has been great at physical simplification, but it really opened up the attack surface. First party malware is the worst.
- maltalex 3y agoIt's odd that 404 Media chose a .co (Colombia) TLD.
- burnte 3y agoNot really, lots of companies use .co instead of .com because there's different availability. It's been a second tier alternative to .com for years.
- theandrewbailey 3y agoTechnically, it's still the ccTLD for Colombia, even though anyone can register a .co domain, similar to .io (for British Indian Ocean Territory). https://en.wikipedia.org/wiki/.co https://en.wikipedia.org/wiki/.co
- burnte 3y agoThat is true, but no one is disputing that.
- tredre3 3y agoColombia, not Columbia.
- theandrewbailey 3y agoYou're right, fixed.
- input_sh 3y agoThere's a lot of ccTLDs that are considered to be "generic": .ai, .as, .fm, .io, .me, .tv, .ws... For example Google search will treat them the same as .com, while others like .de or .fr are gonna be interpreted as if your website is targetting a specific market.
- deleted 3y ago[deleted]
- 3y ago
- expertentipp 3y agoI have an impression that covid enabled widespread acceptation of QR codes, and now every app is excused to request camera and photo access because "we need to scan a QR code".
- alwayslikethis 3y agoIt would be nice to have a special way to scan a qr code in which the system reads the QR code for the app without the app being able to see raw camera data.
- hedora 3y agoI think this flow sort of supports that. https://9to5mac.com/2020/10/07/limit-third-party-iphone-photos-access/ https://9to5mac.com/2020/10/07/limit-third-party-iphone-phot... If I remember right, there’s a way to get a “take picture” option in the chooser. I’m not sure how the qr code would then be recognized, though I’m not sure why you wouldn’t have them get the qr code via the system camera app.
- MBCook 3y agoThat’s intended for selecting a pre-taken photo without giving an app library access. You’d have to get the user to take the picture then come back to your app. What you really need is a system dialogue that pops up the camera and only returns the QR code to the app, the way the photo picker can see the whole library but only gives the app the one selected photo.
- gkbrk 3y agoPretty sure Android has this. You can make an app without camera permissions, send an intent that opens the built-in camera to take a picture and you are given access to only that picture. It means you cannot record things in the background all the time, and users don't need to make a decision about a sensitive permission.
- freitzkriesler2 3y agoBurn it with fire and wipe that iPhone twice. Stuff like that terrifies me.
- reilly3000 3y agoI say the big 404 and instinctively bounced. I can’t be the only one. I went back to find their 404 page and am quite satisfied with what I found: https://www.404media.co/i-te/ https://www.404media.co/i-te/
- ASalazarMX 3y agoThe cyberdemon really ties the room together.
- gpderetta 3y agoVery nice old school Geocities look.
- shoo 3y agodont forget to click here
- stevenhuang 3y ago(spoiler: clicking it plays https://www.404media.co/assets/audio/error.mp3?v=ae29046532 https://www.404media.co/assets/audio/error.mp3?v=ae29046532 ) ughh i heard this before and feel like it's on the tip of my tongue but.. i can't remember where it's from??
- Joking_Phantom 3y agoMusic from the hit 1993 video game Doom. The first level's theme. In case you weren't joking. It was quite the popular game.
- logbiscuitswave 3y agoI’ve seen a few 404 Media articles on here as of late and I’ve been pleasantly surprised by the high quality of the content.
- 3y ago
- deleted 3y ago[deleted]
- proactivesvcs 3y agoI Visited a Web Site That Demands My Email Address to Spam Me With Newsletters.
- jmrm 3y agoThis kind of shady devices should be banned in Western Countries, not only for trying to get their users' information, but also for being a device that can go directly to the e-Waste bin without a minimal usage
- ale42 3y agoThey should be banned everywhere...
- blibble 3y agohow long until everything on Amazon is doing this?
- swader999 3y agoAll the people involved in this product need a significant public award for their efforts.
- mixmastamyk 3y ago> I decided to connect the cord using an old iPhone that I no longer use and that no longer has anything I care about on it. Uh oh. Hope that means securely wiped and not just "I deleted the notes and photos and put in a drawer."
- nenaoki 3y agoIt's far easier just to securely wipe. Half a dozen taps, not including passphrase input.
- xavdid 3y agoNot related to this story specifically, but I've been very impressed with 404 media's stories thusfar. They haven't been around long, but they've already done a lot of impressive journalism. I'm glad we've finally got a tech media outlet with teeth.
- userbinator 3y agoWould be interesting to reverse-engineer the app and find out how it works, then make an open-source version.
- nikau 3y agoMean while a 6 year old Samsung has usbc and just works.
- brazzy 3y agoSo, a trojan device that makes the user give it basically full control over their phone, allowing a third party to do whatever the hell they want with the user's data and accounts - and what does it actually do? Show targeted ads. Truly the dumbest timeline.
- lordwiz 3y agoWe need to think about the role of government in regulating consumer electronics. Should the government require companies to disclose more information about the security and privacy risks of their products? Should the government ban the sale of products that pose a significant security risk? The lack of transparency on the security details will take a toll on the consumers in the coming future.
- DarkmSparks 3y agoI always wondered how Amazon gets away with listing "Apple lightning cables" (and all the other scam/junkware they list) that are not made or sold by Apple. Its like they abandoned any respect for trademarks and parents and got away with it.
- lloydatkinson 3y agoThe irony that I got two popups on this site.