- cross-posted to:
- [email protected]
- cross-posted to:
- [email protected]
cross-posted from: https://infosec.pub/post/53326082
A malware campaign dubbed ‘Midnight Mimosa’ has been discovered on low-cost Android smartphones that ship with malicious software embedded in their firmware, allowing attackers to silently install apps, perform ad fraud, and turn devices into residential proxies. […]
silently install apps
Sounds like Google.
(/srs) Anyways, these "new"s are as old as “IoT” itself.
my bank…
graphene os: eww no, sooo insecure, couldn’t possibly trust that, fails checkbox compliance!
rando crapware infested phone that hasn’t seen a security update in 3 years: right this way sir…
I hear this complaint and perhaps I used the banking apps very minimally. I’m running GraoheneOS and just use the browser instead for my banking needs and I haven’t had any issues.
It was a slight setback but its not a huge deal for myself at least.
I actually don’t do any banking on my phone at all, as phones can easily be stolen and if that person saw you typing your passcode, then they can unlock it and get past any screen that asks for your fingerprint.
Yes, I do use my fingerprint, but I can’t always use it (e.g. If I have rebooted or if my phone just won’t let me for some reason), so I don’t keep much on my phone and instead do things like banking on a desktop computer with disk-encryption.
How long left until my bank requires me to use their app? I don’t know and I have no idea if it’ll work on custom ROMs.
But Google told them it was/wasn’t secure! Google has to know, right?
/s
“We checked the checkbox that said ‘security’.”
The researchers found preinstalled malware on devices with model names associated with legitimate manufacturers, including the Doogee S200 X and Cubot KINGKONG X, as well as phones impersonating Samsung and Apple products.
In case you were wondering which brands are mentioned here.
oh no i would have trusted the KINGKONG X
no, you should always be team GODZILLA Y, everyone knows KING KONG X sucks
Well, you should not!!!
A little less than half of the apps you can download for an LG TV will also set up residential proxies.
Gamers Nexus mentioned this article in a recent video:
https://spur.us/blog/smart-tv-apps-residential-proxy-sdksSo…kinda like what apple and google are doing too 😁
Not to shill for Apple or Google, but it’s definitely important to draw a distinction between first party telemetry and straight up distributing malware. If we can’t we honest in our framing then there is really no reason to take what we have to say seriously.
While I wasn’t 100% serious, I wasn’t just joking either.
Sure there is a difference. But not a big one. Do you know what each android process actually does? And both can install any shit they want at any time. You can’t even uninstall their store or apps.
To me personally, the difference is slim. And malware is malware, the difference often is just billions of dollars and doing it more or less on the open.
No, because Apple and Google aren’t providing third parties access to the Internet through your devices.
Actually they do. Through their findmy networks.
Makes me feel so much safer with google or Apple 😁 They could though. All the tech for it is there and already installed. And you wouldn’t even know if they did, because you don’t own your own phone.
Not that I wouldn’t worry about an added layer of spy-shit though. The difference between that malware and the big malware it’s installed on is just slim to me. I’m very security- and privacy-driven.
And the carrier too.
say the thing on the lemmy to get the points that don’t matter
As if I would care about that. This is not reddit.
So… android IS google, and Apple is not doing anything remotely close to this.
Android is google? You don’t say? 😉
And Apple is doing the same shit as google. At least they never tried to hide it
At the end of the day, each of us need to make a choice. Go with Apple and land in their walled garden and everything that comes with that. Choose Android with any OEM and bend over to Google AND the OEM. Get a pixel and bend over to Google (or nuke Pixel stock and install GOS, CalyxOS or whatever rocks your boat). Go the dumb phone way and only bend over to the carriers. Too many factors influence this, not just philosophy, taste or choice. Some people genuinely need a phone that will work with banks or cards, others can live without. Others, as is my case, can separate their life into 2 devices, I have a pixel 8 pro that I use exclusively for work on stock pixel, and a GOS pixel 10 Pro XL for my personal life.
This technological life is a fucking mixed bag for sure.
Totally… I also “solved” it best i could. One dedicated totally anonymous phone for android-auto and one for banking-apps (they ALL need their fucking apps even though i use HBCI with most). Main phone is an aging pixel with graphene. The moment it dies (i’m waiting for many years now) i’m going some linux-phone, no matter how lacking it might be.
Apple is a no-go. But yes, at least there’s “only” one that i have to bend over for. But I was there when they tried so hard with “pay less, get more!” and now it’s “get less, pay a lot more you dumb stupid consumer-trash-idiot”. I would be ashamed of myself for using one.
But yes. It sucks. And i was dumb enough to kinda believe google with “android will always remain free and open!”. Yeah sure. Go fuck yourself.










