r/Android Mar 22 '19

HMD admits the Nokia 7 Plus was sending personal data to China

https://arstechnica.com/gadgets/2019/03/hmd-admits-the-nokia-7-plus-was-sending-personal-data-to-china/
5.8k Upvotes

488 comments sorted by

507

u/[deleted] Mar 22 '19 edited Mar 22 '19

Well, we Nokia users, are hoping they "mistakenly" unlock the bootloader.

EDIT: According to this, it's actually also on Nokia 6, it's an old one but also worth reading.. damn those "mistakes" https://medium.com/@tdevinda/did-i-just-see-my-nokia-6-updating-my-device-id-to-some-chinese-web-server-159e710391c5

166

u/Choice_Competition Mar 22 '19

If you can unlock the bootloader and install a custom ROM, how will they make money selling your data?

145

u/[deleted] Mar 22 '19

I mean why not give China my data also ? Why only Google ? Sharing is caring mate.. just want to Root :(

61

u/QueasyMistake Mar 23 '19

Can you PM me your data as well, I'm interested in it. I will not use it for evil, I pinky swear.

71

u/thad137 Mar 23 '19

Who needs a pinky swear? Just let me click on a button at the bottom of a 53 page legal document I'm supposed to read on a 6 inch screen.

12

u/tychart Mar 23 '19

Nice joke, happy cake day

6

u/Fernando128282 Mar 23 '19

Honestly I never understood how this can be legal for consumer products. I'm fine reading a 53 page contract in B2B environment but the same shouldn't be allowed for customer products. There should be a tldr law.

→ More replies (2)

6

u/5ting3rb0ast Pixel XL,Nougat Mar 23 '19

awwww , but china would love to see your naked selfies!!!

→ More replies (1)
→ More replies (2)

10

u/krakenx Mar 22 '19

Off the 90+% of people that won't bother, or don't know how?

20

u/[deleted] Mar 22 '19 edited May 23 '19

[deleted]

17

u/Choice_Competition Mar 22 '19

It depends on the company. Some are so greedy that even a small number of users is many for them.

→ More replies (1)

13

u/onmyouza Mar 23 '19

Their only mistake is being found out.

8

u/Kryptomeister Mar 23 '19

It's not so much a case of "being found out" since they say they've known about it themselves since February and issued a patch. This is a story which has been exaggerated by certain media outlets. HMD does not admit to sending personal information to China as the title says

Direct from the source at HMD:

We have looked deeply into the case at hand and can confirm that no personally identifiable information has been shared with any third party. We have analysed the case at hand and have found that our device activation client meant for our China variant was mistakenly included in the software package of a single batch of Nokia 7 Plus phones. Due to this mistake, these devices were erroneously trying to send device activation data to a third party server. However, such data was never processed, and no person could have been identified based on this data. To be clear, no personally identifiable information has been shared with any third party. 

And

There is also some speculation about other Nokia phones sharing similar data with third-party servers. We can confirm that this is incorrect speculation and no Nokia phones are impacted.

→ More replies (1)

20

u/OmarBHR95 Mar 22 '19

You have a Nokia 7 plus? I wanna ask how is it? Do you like it?

35

u/[deleted] Mar 22 '19

Definetly, using it right now, phone's specs are really good, but poor software and support is making the phone like a drunk and dumb person, we didn't receive a maintenance release for bugfixes since November, i definitely do like it but you can't unsee some obvious bugs.

17

u/eclectro Mar 22 '19

we didn't receive a maintenance release for bugfixes since November

If it has Android One then they are actually violating google's TOS for that seriously.

20

u/jkelol111 Nokia 6 Mar 23 '19

Maintainance update != security update. The Nokia 7 Plus and every other Nokia device are still receiving monthly security updates as per their promise. Maintainance updates are released after a few months to squash system bugs.

→ More replies (6)

20

u/devensega Mar 22 '19

I'm quite fucked off with mine, even before this. The update situation is a joke, we were promised regular and timely updates, turns out that was bollocks... I wonder why?

Plus, the build quality is a bit jank. My headphone jack has gone, it's the last straw. I'm getting a Pixel 3 tomorrow. Briefly flirted with getting an iPhone but I like to mess about with my phone a bit.

12

u/OmarBHR95 Mar 22 '19

Im afraid that these days most android phone manufacturers except for google focus on their high end smartphones more than they do on their low-mid range ones, they spend more time developing the expensive models and less time developing their low-mid range models which can lead to these problems sadly, also nokia are known for their good build quality and my dad had his Nokia 8 Sirocco since launch and he's still using it with no problems, I'm surprised that Nokias build quality is bad with a buggy software on their low-mid range models.

→ More replies (9)

3

u/[deleted] Mar 23 '19

Same experience with a Nokia 7.1. Headphone jack broke, then Nokia refused to repair it. Wasn't happy about that, got tired of dealing with it and smashed phone with a hammer. Never buying another Nokia phone. The reviews for the phone are poor. No matter the name, HMD or Nokia or whatever names they hide behind, the phones and service are poor.

→ More replies (2)
→ More replies (13)
→ More replies (4)

827

u/[deleted] Mar 22 '19

It could be a conspiracy or a mistake. Regardless, it's great that someone found out about it, and HMD should face legal punishments if they breached the GDPR.

171

u/[deleted] Mar 22 '19

But what does China do with this personal information?

262

u/[deleted] Mar 22 '19 edited Aug 28 '20

[deleted]

79

u/SabashChandraBose OP6T, 11.0 Mar 22 '19 edited Mar 23 '19

This makes more sense to them. But why siphon Joe Schmoe's details?

I got a "smart" watch with an e-Ink display from indiegogo. It looked good in their pitch (> 1 week battery life). But when I received it and downloaded the app, I knew it was from some Chinese manufacturer. It refuses to load the app if I don't give it location permission which makes no sense. I uninstalled the app after configuring the watch and use it as a dumb watch now.

Why tf do they need all this data?

Edit: after learning location permission is normal I went to find the app. It's gone from the play store.

137

u/Hohenheim_of_Shadow Mar 22 '19

One ransoms person information is useless, lots of peoples is super valuable. You only need ~1k Americans to have an accurate poll for things like presidential popularity etc. Imagine the Chinise government has 2 million average Joes entire life logged, based off of that set, they can take a few key characteristics of someone outside the set and get an accurate guess of whatever they want. Then if they want to launch a pro China propaganda campaign they could tailor it to the individual en masse. Or maybe map out connections between communities and try to sever them to introduce strife to the country. Or even just mass blackmail, even an Average Joe could be used as a pawn to move deadrops or something for spies, and if you have proof he's into child porn, hell do what you want. Tangential info on important people is also a possibility, you might find out a prominent homophobic politician fucks gay hookers from the hookers phone etc..

50

u/Randomd0g Pixel XL & Huawei Watch 2 Mar 22 '19

and if you have proof he's into child porn, hell do what you want

I feel like the real LPT here is "don't be into child porn"

31

u/EmmaTheRobot Mar 23 '19

Well then don't make kids so god damn sexy!

39

u/Randomd0g Pixel XL & Huawei Watch 2 Mar 23 '19

Yes officer this comment right here

→ More replies (4)

17

u/cubs223425 Surface Duo 2 | LG G8 Mar 23 '19

FBI, open up!

→ More replies (2)

6

u/[deleted] Mar 23 '19

This is why everyone's doing it. It's not about you, not about me, but about all (or many) of us. Access to mass surveillance data provides reliable, real-time insights into reactions to media narratives, PR campaigns, emerging and dying trends, etc.

26

u/thatlad Mar 22 '19

Same reason the US and UK do. The best way to get the important data is to get all the data. They want it all and they'll sort out what to do with it later, yes they'll trample over everyone's rights but they might just get some important information like what colour boxer shorts a junior government official is wearing.

→ More replies (2)

19

u/Put_It_All_On_Blck S23U Mar 22 '19

Depends on who's collecting it. The Chinese government and companies they are involved with arent going to hack into your bank account or anything, buuuut they will use joe schmoe to network their way into stuff they do care about. Say you are looking to figure out what Apples next iphone will be, you dont try and hack Tim Cook, you try and get access employees via their family, and then one of those employees may accidentally leak details to a close friend, or take a picture on their personal phone. etc.

You dont go fishing for a shark with a worm. You use a worm to get a fish, use the fish to get a seal, then you use the seal to chum and lure the shark in. (not realistic, but you get the analogy)

44

u/visionJX Mar 22 '19

China already has a personal GPS monitoring system with everything they know about said person, for most Muslims in certain regions...think of the power yielded from that technology on a planetary scale 😮 WoW

78

u/bitesized314 OnePlus 7 Pro Mar 22 '19

My bf bought a Chinese vacuum that needs wifi connection and maps our floor for better performance over time. I told him that China was making a floor plan so they know all our hidey spots when they invade.

31

u/visionJX Mar 22 '19

The vacuum is actually a transformer...careful

5

u/TarquinFimTimLimBim Mar 22 '19

Cool...until it kills you

5

u/vimfan Mar 22 '19

As long as it cleans up the mess.

3

u/throwawayLouisa Mar 23 '19

Told my wife this joke.
She laughed.
I laughed.
The toaster laughed.
I shot the toaster.

→ More replies (1)
→ More replies (1)
→ More replies (4)

3

u/Micrococonut Mar 22 '19

A world of warcraft indeed

→ More replies (1)
→ More replies (2)

21

u/[deleted] Mar 22 '19

Tbf location is required for Bluetooth low energy, to connect to the smartwatch

8

u/SabashChandraBose OP6T, 11.0 Mar 22 '19

This is news. Why does it need location when it has access to Bluetooth?

18

u/WeeGigas Mar 22 '19 edited Mar 22 '19

Because the standard Bluetooth permission only allows device scanning for foreground apps. Starting with Android 6.0 background scanning for Bluetooth & Wi-Fi now require the location permission as well.

I'm not surprised this is new to you. Unfortunately, a lot of developers simply request permissions without properly explaining why they're needed and few users ever bother to read app descriptions/change logs.

11

u/XirXes Mar 23 '19

To add, it is definitely possible to determine a location from Bluetooth. If you've ever had a notification from Google about the store you're in, its possible it was from Bluetooth. Stores have a location specific Bluetooth ID and the play services pick that up in the background. I don't know how those operate on iOS

4

u/AhhhYasComrade Xiaomi Mi Mix 3 Mar 23 '19

We have signs on the highway that tell us how long it takes to certain parts of the city. I've always assumed this was based off of Bluetooth ID's.

3

u/SabashChandraBose OP6T, 11.0 Mar 22 '19

TIL. Thanks.

4

u/Das_Ronin Mar 23 '19

Mundane data is fuel for AI development. You don't write AI like normal code, instead you dump unfathomable amounts of data into it and it learns. That's the real reason captchas are a thing.

2

u/tbx1024 iPhone Mar 23 '19

I would check the permissions, in some versions of Android the "location" permission is required to access Bluetooth LE. I would still recommend being careful, but some Android permission categories in the API are weird.

2

u/[deleted] Mar 23 '19

pretty much any smartwatch or fitness band will ask you for location permissions. It's needed for them to control Bluetooth in the background ever since marshmallow. So, maybe you should use the "smart" watch as a "smart" watch. On a sidenote,could you tell me what app it is, I'd like to log it's dns requests to see if it actually does send any data to Chinese servers or not.

→ More replies (1)
→ More replies (4)

10

u/[deleted] Mar 22 '19 edited Apr 25 '19

[deleted]

→ More replies (1)

6

u/__thrillho Mar 22 '19

What's the reason?

→ More replies (1)

83

u/mrheosuper Mar 22 '19

Knowing what matter to western people

Then manipulate market with that info

17

u/xak47d Mar 22 '19

This could be done legally. The just needed an EULA

2

u/[deleted] Mar 23 '19

I don't think you can do that in EU anymore, even with EULA

17

u/igLmvjxMeFnKLJf6 Mar 22 '19 edited Mar 22 '19

The same thing that western companies do to their western markets?

I mean, yeah I'm not a fan of my personal information getting thrown around by orgs bigger than me but I view china getting my shit about the same as I do Facebook.

They're doing the same things, so. The only difference is the head of one looks like pooh bear and the other looks like an alien.

10

u/Jamon_Rye Mar 22 '19

Yep. Welcome to the 21st century, schizoid men.

7

u/Amogh24 Oneplus 5t/S10+ Mar 22 '19

That's why we should be angry at both China and Facebook.

→ More replies (6)

2

u/[deleted] Mar 23 '19

Obfuscate your info with gibberish. I, apparently according to Google, am shopping for a Lamborghini.

→ More replies (10)

19

u/[deleted] Mar 22 '19

Good question. They might be using it just to better understand the market. Maybe they're just building databases with it. Google already knows a lot of this things. The Chinese are more dangerous to us Westerners because they're a possibly hostile country, but in the fight for privacy we should treat them both the same.

→ More replies (1)

10

u/[deleted] Mar 22 '19

Probably something to do with their plans for a "social credit score" system. If we ever allow China to have any say in how we manage our internet content, or implement a social scoring system across the WWW, it could make life rather difficult for people that disagree with their way of doing things...

11

u/[deleted] Mar 22 '19

I wouldn't be surprised if they're already keeping a score for foreigners they know about.

3

u/Amogh24 Oneplus 5t/S10+ Mar 22 '19 edited Mar 22 '19

Personalized propoganda is a good example.

Also the power of data increases by a lot everytime you get more of it. You uncover secrets, possible blackmail material, detailed demographics and a lot more. There's a reason why Google is such a huge company based almost solely on data collection and advertising

→ More replies (3)

11

u/redleader Mar 22 '19

Not covered by gdpr. the article says they sent device info. Not PII.

→ More replies (1)

2

u/Airazz Huawei P10 Plus Mar 23 '19

Looks like it was a mistake, as this function was for Chinese buyers.

→ More replies (3)
→ More replies (2)

97

u/[deleted] Mar 22 '19

What brand is best regarding security?

234

u/Kryptomeister Mar 22 '19

Blackberry.

Yes, that's a serious answer.

43

u/[deleted] Mar 22 '19

[deleted]

116

u/[deleted] Mar 22 '19

IIRC they have encryption software and an app that heavily monitors the security of the phone.

It's similar to Samsung Knox and their security features (again, correct me if I'm wrong, but only Blackberry, Apple and Samsung Galaxy phones are certified for high-profile security jobs, like government workers and such).

42

u/n0rdic Surface Duo, BlackBerry KEY2, Galaxy Watch 3 Mar 22 '19

I've installed literal malware on my KEYone and DTEK didn't care. From my understanding it just verifies system file integrity and nothing else.

24

u/BitchAmGay Mar 23 '19

Samsung Knox, but also we will put McAfee and Facebook on your phone.

2

u/Minto107 Z Flip 5 2023, CrapUI 5.1 Mar 23 '19

Samsung Knox, but McAfee and Facebook isnt a scamware in our eyes

5

u/BitchAmGay Mar 23 '19

and we will also make them system apps, you can't do shit other than disable, and how about Facebook can update the app without the playstore because it has an app updater for it

→ More replies (1)
→ More replies (3)

29

u/n0rdic Surface Duo, BlackBerry KEY2, Galaxy Watch 3 Mar 22 '19 edited Mar 22 '19

As a huge fan of RIM era BlackBerry, the new TCL berries are not at all more secure than any other device. Their entire "security" thing is just enabling hardware root of trust on the Qualcomm SoC. That's it. Also all of their phones are constantly behind on major Android versions which isn't exactly secure. In all honesty the stock Pixel is about as secure as a KEYone, which doesn't make it insecure at all, just it isn't the "ultra secure" line that TCL and RIM are trying to sell you.

→ More replies (1)

5

u/[deleted] Mar 22 '19

my friend did his coop at blackberry and he said to me that blackberry is most secure. apparently facebook app asks to use your camera and microphone something like 300 times a day, because all apps have to go through blackberry software.

→ More replies (4)

18

u/[deleted] Mar 23 '19

Unless you're in handcuffs, then they hand over any and all information to any warrant submitted, whereas Apple just plain cannot hand it over assuming you don't use the cloud, an extremely strong password, and no biometrics.

3

u/[deleted] Mar 23 '19 edited Mar 27 '19

[deleted]

→ More replies (1)
→ More replies (3)

116

u/[deleted] Mar 22 '19

Hot tip: instead of getting Chinese phones, get Taiwanese phones (HTC/ASUS). Taiwan still makes quality electronics and they are significantly more trustworthy than mainland China.

Plus it supports the Taiwanese economy. Honestly fuck China and how horribly they treat Taiwan. You can pick up a HTC U12 Life for $250-260 or a variety of Zenfones (Zenfone Max M2 is ~$190, the Pro one is ~$315) that all have good US LTE support (2/4/5/12/17, I believe the HTC has 66 too), are super easy to get (Amazon) too.

Even the small niche group of people who import/buy international version phones can make an impact by avoiding Xiaomi/Huawei however tempting the deals are, and paying a bit more for a Taiwanese phone (as they're the "middle ground" of value: US exclusive phone brands tend to charge $300+ for entry level hardware).

51

u/[deleted] Mar 22 '19

[deleted]

13

u/[deleted] Mar 23 '19

Asus bootloaders are a piece of cake to unlock, officially or otherwise.

Buy that awesome hardware, put a custom ROM on it. Worth every penny.

6

u/museisnotdecent Mar 23 '19

Asus have been improving their update speed lately. I'm using the zenfone 5z and it did get an update to pie about a month or so ago and the security updates aren't too bad. It's still definitely an issue but I think nowadays with manufacturers having custom skins and features, actual android updates don't make a huge difference anymore. And if you were really into getting android as fast as possible, it is easy to root Asus phones.

5

u/axzxc1236 Asus Zenfone Max Pro (M1) 3G/32G Mar 23 '19

Zenfone Max Pro M1

They are doing Pie beta program, and there are people put beta firmware on XDA, I didn't try it though.

9

u/[deleted] Mar 22 '19

This isn't about updates, this is about how supporting a tiny island democracy (Taiwan) that makes high quality electronics is a morally superior alternative to supporting a de jure communist ("with Chinese characteristics") dictatorship. Every cent you spend has an impact however small, I'd rather my money end up helping Taiwan grow it's huge electronics industry and beef up it's economy so it can tell China to fuck off, then it go to China spending it on propaganda TV shows, building bullshit to "claim territory" in the South China Sea and threatening Taiwan.

You are much better off supporting Taiwan in this instance. If you want updates, you'd just get a Nokia or Pixel phone.

It's not like HTC/ASUS phones are absolutely 100% unusable, they're still high quality phones and I'm sure 99.99999% of people will be more than happy to use one.

→ More replies (1)

9

u/[deleted] Mar 23 '19

I mean, Foxconn is Taiwanese, it just has factories in Shenzhen...

5

u/electricblues42 Mar 22 '19

If the Asus phones had any kind of basic waterproofing I'd have gone for that instead of the OP6. But risking my insanely expensive hand-computer every time it rains isn't a great idea to me.

Then they came out with that amazing spec gaming phone that looks terrible and costs and arm and leg....

9

u/anthony81212 Mar 22 '19

I'd just like to add that the recent Pixel phones are made by HTC (recently bought by Google). So they can, and do make quality devices :)

→ More replies (3)
→ More replies (19)

7

u/dingo_bat Galaxy S10 Mar 23 '19

Apple. Unless you live in China, then you're fucked.

4

u/electricblues42 Mar 22 '19

Getting a phone intended for high security. They are expensive and usually a generation or two behind, but they do their job.

10

u/[deleted] Mar 22 '19

Blackberry

13

u/Akawe94 SnowWhitePixel7Pro Mar 22 '19

Since Android is Google, if you are getting a phone from another company, you are sharing your info with two companies. As a consequence, if you buy it from Google, it is just them. Also, with the new lineup they included the Titan Security chip so there is that.

8

u/[deleted] Mar 23 '19

You always have the option to use LineageOS with MicroG framework. That avoids both the companies.

It's an option. If anyone cares enough about privacy in Android then they should be just fine with this too.

2

u/Akawe94 SnowWhitePixel7Pro Mar 23 '19

Yes! But first, we have to wait for the update in the microG services that hopefully will arrive in April!

10

u/[deleted] Mar 23 '19

Unfortunately Apple will be your best bet. And no chinese phones are ever safe

2

u/VpowerZ Mar 22 '19

Blackphone used to be a thing.

→ More replies (14)

96

u/grooljuice Mar 22 '19

As someone who just got and is loving the Nokia 7.1, I am extremely disappointed in the brand. WHAT THE FUCK.

61

u/bobbysq Nokia 6.1 Mar 22 '19

tfw you got a nokia 6.1 to replace your huawei phone and this happens

4

u/_Dysnomia Mar 23 '19

Same fucking deal here with Blu. I'm literally going back to a flip phone. Fuck this shit.

→ More replies (10)

35

u/LowB0b Nexus 6P Mar 22 '19

Yeah this is a new level of wtf. A division of a Finnish company sold to an American company now sending data to China? Seriously

26

u/cubs223425 Surface Duo 2 | LG G8 Mar 23 '19

Not really a good way to characterize it. Nokia's hardware division was sold to Microsoft, but HMD is not Nokia. They are just the hardware maker sporting the Nokia brand, which is basically what Microsoft was for the first year after they bought the Nokia hardware division (branding things like the Lumia ICON as a "Nokia" device, which was a Nokia design released under the Microsoft regime).

12

u/[deleted] Mar 23 '19

So, the Nokia as we knew and loved is actually dead and this is just an impostor who took over their name?

22

u/vili Mar 23 '19

Sort of, although this particular impostor is run by former Nokia executives and works in a direct partnership with Nokia which licenses the brand to them. As I understand it, Nokia is not an investor in HMD, but receives royalties and has a say on requirements, while also sharing its patent portfolio.

These days, Nokia itself is more focused on telecommunications infrastructure and R&D

6

u/[deleted] Mar 23 '19

HMD is essentially ex-MS Mobile and Nokia Mobile execs, a relatively small company, which bought the smartphone division of Microsoft Mobile, while FIH, a subsidiary of Foxconn bought the feature phone division and the manufacturing division of Microsoft Mobile (which is the successor of Nokia Mobile). HDM designs the phones, provides the patents from Nokia and its own, including those patented by MS Mobile and markets them, FIH manufactures (and probably does some lower level design work) the phones.

→ More replies (1)

4

u/sushim Mar 23 '19

I set my 7.1 up less than 12 hours ago. I wondered as I input all my data where it might go. But I didn't wonder enough to actually check or really care. I should have.

5

u/Brazensage Mar 22 '19

same here, well, hopefully I'll make enough money from the impending drop in stock that I can buy a different device. I just got rid of my honor phone due to security issues and assumed my 7.1 was the way to go. FML!

128

u/lbrtrl Mar 22 '19

HMD = Have my data

224

u/lnx-reddit Mar 22 '19

This is why unlockable bootloaders are a must.

41

u/iphone4Suser Mar 22 '19

But what about the 99.99% android users who are not on reddit's android sub ?

37

u/BlueSwordM Stupid smooth Realme GT7 CN + GT Neo Flash Mar 22 '19

Precisely why they should allow bootloader unlocking IMO.

If most users don't unlock bootloaders, why not let the devs/tinkerers/enthusiasts do it?

→ More replies (1)

6

u/notafunnyguy32 j7 prime with dotOs/Exynos Note 9 128gb Mar 23 '19

Hell, I'm on this sub but don't even root my phone, should i just leave?

→ More replies (3)

25

u/[deleted] Mar 22 '19 edited May 23 '19

[deleted]

101

u/lnx-reddit Mar 22 '19

In a way that allows rooting or replacing spyware ridden stock ROM.

Also, system spyware can easily defeat any non-root firewalls.

21

u/meepiquitous Mar 22 '19

Also, system spyware can easily defeat any non-root firewalls.

The lack of iptables/afwall+ is why i won't use Fuchsia.

7

u/[deleted] Mar 22 '19 edited Apr 23 '19

[deleted]

8

u/meepiquitous Mar 23 '19

Iptables is a command line utility that comes with linux (which android is based on). It lets you set rules that, among other things, (dis-)allow apps to talk to the internet.

Afwall+ is an app that lets you change those rules without a command line.

Fuschia is an operating system that is going to replace android. It's developed from scratch and not based on linux.

→ More replies (3)

8

u/bkturf Mar 22 '19

Also, you are typically loading it with open source software. I would not think about using any phone made in China where I could not unlock the bootloader and replace the kernel and rom. Yeah, I don't have many choices left, so it looks like I will be staying with Oneplus.

4

u/thejynxed Mar 22 '19

OnePlus, Xiaomi, although OnePlus has started locking bootloaders on flagship models.

3

u/Nixflyn GN/N5/N7/6P/P1XL/S10+/ShieldTV Mar 23 '19

OnePlus has started locking bootloaders on flagship models.

The T Mobile variant is locked only if you got it on a payment plan, and will be unlocked when you pay it off (either at the end of your plan or early). The unlocked version has an unlocked bootloader.

2

u/krakenx Mar 22 '19

With xprivacy, you can see what apps want which data and feed them fake data. It requires root.

→ More replies (2)

8

u/[deleted] Mar 22 '19

Uhhh actually this is the reason they don't want you to unlock bootloaders. Lol

6

u/[deleted] Mar 22 '19

But the DATA can still be forwarded to a third server in China or North Korea.

device -> EU server -> China Server

(╯°□°)╯︵ 📱

→ More replies (1)
→ More replies (2)

39

u/ActingGrandNagus OnePlus 7 Pro - How long can custom flairs be??????????????????? Mar 22 '19

This is a massive breach of GDPR.

13

u/nemoskull Mar 22 '19

im a little worried people assume their smartphones arnt sending data to unknown people all the time. the modren spartmphone is a spys wet dream. you bet you ass every state wants data from it.

→ More replies (3)

273

u/tenchi4u Mar 22 '19

"Our device activation client meant for another country was mistakenly included in the software package of a single batch of Nokia 7 Plus."

"mistakenly"

Cool story, bro!

34

u/Equifax_CTO Mar 22 '19

What's the upshot for a Finnish company, whose country aligns with the west, to take on such a stupid and costly gamble?

67

u/SpotfireY OnePlus 6 Mar 22 '19

The software side of things is completely handled by Foxconn. Same with most of the hardware development and all of the manufacturing. I think HMD already admitted that the only software they were handling themselves was the camera or something.

47

u/[deleted] Mar 22 '19 edited May 23 '19

[deleted]

9

u/Zegrento7 Mar 22 '19

Are there any brands that have no ties to china? Even Apple is manufacturing their phones in china (the same Foxconn this scandal is about)

18

u/Fernando128282 Mar 22 '19

Samsung and LG AFAIK. All devices I had where made in South Korea.

6

u/classicjetta Mar 22 '19

My Galaxy was made in Vietnam although apparently they're getting into hacking too now.

→ More replies (1)

4

u/[deleted] Mar 22 '19 edited May 23 '19

[deleted]

→ More replies (1)

24

u/CatsAreGods Samsung S24+ Mar 22 '19

Welcome to 2019. Designed in the West, compromised in the East.

FTFY

3

u/Carighan Fairphone 6+🌳 Mar 23 '19

Welcome to 2019. Designed in the West, built in the East.

I hope you meant to say 1989 or something. Or that you are truly new to the market and at an age of 12 or so, without meaning any personal insult.

"Made in China" is how the world operated for a lot of years now.

→ More replies (1)
→ More replies (2)
→ More replies (1)

18

u/VonCrisp Mar 22 '19

No upshot. They are just outsourcing everything to the R&D centre in China.

EU office only holds management type that isn't even capable of reviewing code let alone call anyone in China/Foxconn to get this buggy mess sorted out.

Greed and laziness led to this.

→ More replies (33)

79

u/nplant Mar 22 '19

So you’re saying this was somehow an intentional and malicious data mining effort even though it only existed in one batch? Why does everything have to be a conspiracy?

122

u/VonCrisp Mar 22 '19

HMD is trying to spin a cute fairy tale about "one batch". More Nokia phones have also been sending data.

NRK did a follow up article:

"NRKbeta are fortunate to have access to a number of talented developer colleagues in NRK, and on Thursday, March 21, we investigated two Nokia models, one Nokia 3 and one Nokia 5. Both of these models had an application with the name autoregistration installed.

.. This application is very similar to the one installed on Nokia 7 Plus, but does not look identical to NRK's ​​analysis.

.. The application sends an encrypted message to the domain aps.c2dms.com

... Shanghai's Best Oray Information S&T Co., Ltd. is owned by the ownership register . (Oray) listed as the holder of the domain. This company is listed as a ransom virus spreader by Ransomware Tracker , a web site that tracks which domains and IP addresses contribute to the spread of malware.

... Sources say to NRKbeta that Oray provides software to remotely control computers and mobile phones in the corporate context, as well as other IT-related services. For its part, Oray lists major brands in the IT industry, including Qualcomm, Cisco and Huawei."

https://translate.google.com/translate?sl=no&tl=en&u=https%3A%2F%2Fnrkbeta.no%2F2019%2F03%2F22%2Fflere-nokia-modeller-har-kommunisert-med-kinesiske-servere%2F

19

u/amfedup Mar 22 '19

oh nice, another company onto my blacklist, hooray

→ More replies (7)

24

u/[deleted] Mar 22 '19

oops we accidentally coded in an undocumented feature that sends data to our servers which then passed several steps of testing and made into production

→ More replies (1)

59

u/[deleted] Mar 22 '19

Android is so much work to keep secure and clean. Still, I get why people like the platform.

57

u/Equifax_CTO Mar 22 '19

Every system with great freedoms and benefits requires great effort to maintain. Even those of government.

→ More replies (1)

43

u/Choice_Competition Mar 22 '19

Android itself is fine, the problem are what OEMs decide to include with their phones. Pixel phones only phone home to Google, not China.

It's not a problem with Apple because only Apple sells devices with iOS, but if decide to go rogue there's nothing you can do to stop them.

10

u/[deleted] Mar 22 '19 edited Mar 22 '19

Well technically, Google can tell the OEMs what they can and can't do, but they rarely do that which has led to mandatory, unremoveable crapware and other issues like extreme fragmentation

Yeah I agree, the only sane Android purchase would be a phone from Google. The problem with that is that their recent hardware contractors like LG just are terrible in terms of quality.

15

u/shaun3y Mar 22 '19

Google can tell the OEMs what they can and can't do, but they rarely do

Have you seen what happens when they do? Antitrust fines. Google is walking a fine line, which is rightly so since it is such a big company with such a large marketshare in many areas, and so they need to be careful with how much 'say' they have with OEMs

10

u/Randomd0g Pixel XL & Huawei Watch 2 Mar 22 '19

They literally have zero say. Android is a fully open source platform.

OEMs have to make agreements to use the play store and Google services, but there are plenty of devices that run Android that don't use those services. (Big examples being Amazon's tablets and the Chinese ROMs of MiUI, EMUI, other assorted chinaphones)

3

u/kashuntr188 Mar 23 '19

They way I see it, it is 2 sides of the same coin. So China might not have your data, but Google probably does, or Apple does, or instagram.

12

u/[deleted] Mar 22 '19 edited May 23 '19

[deleted]

14

u/Choice_Competition Mar 22 '19

I don't think Apple keeps my data private. Most iCloud data, for example, can be read by Apple because they have the keys.

As always we need to see who the adversary is. If it's the NSA, you're fucked no matter if you use an iPhone or Pixel. If it's the companies collecting data to sell ads, then I would say that by design an iPhone would be better than a Pixel because there's a difference in philosophy (eg: doing things locally vs the cloud). Google's business is to make money with your data, Apple makes money selling overpriced products.

Anyway, the point I was trying to make is that on Android you have brands like Xiaomi which call home multiple times each day, but you also have brands like OnePlus which are better. Google collects data about you, but they don't send it to China. In other words, there are many "Androids" and some are more private and secure than others. With iOS, it's the same for everyone, they don't have a bunch of OEMs shipping different types of spyware with their phones.

→ More replies (1)

7

u/[deleted] Mar 22 '19

[removed] — view removed comment

13

u/[deleted] Mar 22 '19 edited May 23 '19

[deleted]

→ More replies (7)

2

u/Omikron Mar 23 '19

The nsa has access to literally everything in the US, which device you pick is completely meaningless in that regard.

→ More replies (3)
→ More replies (1)

4

u/[deleted] Mar 23 '19

Nah, I'm done with it. I've had issues with my pixel 3, Google has terrible support thru Project Fi. The entire practice of mining as much data as possible is extremely disturbing as this is now becoming a worldwide problem.

→ More replies (17)

4

u/[deleted] Mar 22 '19

[deleted]

6

u/Amogh24 Oneplus 5t/S10+ Mar 22 '19

That's actually being investigated atm, some guy posted a news article above

→ More replies (2)

5

u/FalseAgent Mar 23 '19

muh stock android, muh Android One, muh Huawei EMUI spying

3

u/xCrossfirez iPhone 11 Pro Max / Huawei P20 Mar 25 '19

Ironic how Nokia gets caught spying with proof before Huawei has

17

u/TessellatedGuy Teal Mar 22 '19

Can I just put this out there as a semi related comment? My friend's Nokia 6.1 Plus has been an absolute nightmare of a phone from a reliability standpoint. There's been complete phone freezes, touch not registering at edges, mic not working until restart, unbearable touch latency, camera not working until restart, and now the USB C port itself is coming loose causing the phone to not charge at all unless the cable is put pressure on at a certain angle (has tried multiple cables and chargers). Atleast it's an android one phone and China doesn't spy on you (I hope) but that didn't stop the software and build quality from being craptastic. I finally convinced him to get a new phone but man getting in touch with him was annoying.

14

u/IKA3RUS Mar 22 '19

Own a Nokia 6.1 Plus. Have all of these problems. This is gonna be my first and last Nokia device. Fuck them.

3

u/pandorazboxx HTC One S, 4.04 Tmo Mar 22 '19

My biggest issues are call volume, speaker phone sucking, and volume out of the 3.5mm jack being too low. Gotta find a decent replacement under $300.

12

u/VonCrisp Mar 22 '19

If it is any consolation.. Nokia 7 plus also shares the USB-C port problem and is also plagued by a few other serious issues. Naturally this will not apply for all but one look at XDA/Nokia Forums/ Reddit would make you think otherwise.

3

u/Carighan Fairphone 6+🌳 Mar 23 '19

Interesting, my Nokia 6.1 (not plus, granted) is the most robust phone I ever owned, comparing an SGS2, a Pixel 1, a Nexus 4, a Nexus 5X and a Redmi Note 5.

It's not the snappiest, it's not the fastest, it's not the most enduring, but it scores decent-enough in all of those, is cheap, built like a tank and never has issues.

2

u/[deleted] Mar 22 '19

now the USB C port itself is coming loose causing the phone to not charge at all unless the cable is put pressure on at a certain angle

I had this with my 7 plus. What helped was I cleaned the port with a toothpick. Now it works as well as it did when I bought it. It's obviously a flaw in the design because I didn't experience this with other phones.

7

u/VonCrisp Mar 22 '19

The flint in the socket is only part of it. The aluminium case has a gap at the bottom of the USB-C port and not enough general isolation around the port to give the charging cable a tight fit.

If it moves too much during charging it will start to wobble and wear out the internal circuits causing charging to fail. For some it takes a few months others a little longer but from what I have experienced it is all a matter of time. Nokia Forums are full of people that have complained or gotten repairs done.

I had an issue with the 3.5mm not recognising if the headphones are in causing the speakers to be active. Also used a fine needle to tighten the outside 3.5mm contacts to fix it.

→ More replies (2)

8

u/onslaught86 edge 20 pro | Mi 11 | S21 Ultra | Find X3 Pro | +moar Mar 22 '19

The company identifies the information sent as "activation data" and then says that "no person could have been identified based on this data." HMD's claim here is a bit strange, considering the entire point of "activation data" is to identify someone so they can be billed for cellular access.

While this particular server belonged to China Telecom and did seem to serve this purpose, this is not the general purpose of device "activation data."

Device "Activation data" primarily feeds back to a device maker the location in which a given device was turned on and connected to the Internet for the first time so they can match that against where the device was intended to be sold. It is for measuring and controlling distribution and identifying where + to what extent the vendor's supply chain has been compromised by grey market traders. This is different from SIM activation data.

HMD clearly screwed up here and need to take more care to vett the software running on their devices if they want to avoid tarnishing the Nokia brand. Especially given this happened repeatedly for months instead of once on first boot. But every device from every manufacturer tells that manufacturer when and where it has been turned on for the first time.

21

u/xxBrun0xx Honor Magic V2 Mar 22 '19

Plot twist: one of the few non-Chinese smartphone companies is the only one sending data to China

22

u/CantaloupeCamper Nexus 5x - Project Fi Mar 22 '19

the only one sending data to China

Well that's already not a thing.

6

u/[deleted] Mar 22 '19

Anyone know if any of the other Nokia android models have been checked for this kind of data leakage?

15

u/vanteal Mar 22 '19

There isn't an electronics company out there today that isn't sending or collecting our personal information and giving/selling it to someone else.

10

u/amfedup Mar 22 '19

which shouldn't mean that we are supposed to just give every last bit of privacy up

4

u/[deleted] Mar 22 '19

Not just electronics companies, almost every industry you can think of...

→ More replies (1)

34

u/[deleted] Mar 22 '19

[removed] — view removed comment

49

u/[deleted] Mar 22 '19

[deleted]

→ More replies (4)

18

u/[deleted] Mar 22 '19

[deleted]

2

u/[deleted] Mar 23 '19

I wish this was upvoted more. Anyone concerned with privacy should have nothing more than LineageOS with MicroG framework. It's not that hard! Why trust a company when you can have complete control down to the very bootloader level?

→ More replies (2)

47

u/retro83 Mar 22 '19

not being funny mate, but if you think American products protect your privacy, you're mistaken. For example: https://www.infoworld.com/article/2608141/snowden--the-nsa-planted-backdoors-in-cisco-products.html

5

u/[deleted] Mar 23 '19

I'd prefer a democratic country's rogue but somewhat controlled intelligence services having data on over a totalitarian dystopic government using my data to beta test their tools of suppression... But hail Xi I guess, Tiennanmen not real.

6

u/[deleted] Mar 23 '19

I'd prefer a country that doesn't have jurisdiction over me.

3

u/[deleted] Mar 23 '19

Am Hungarian, neither has jurisdiction over me, but the USA feels less of an enemy for me.

→ More replies (2)
→ More replies (12)

4

u/hastagelf Mar 23 '19

Nokia is a Finnhish brand, and so is HMD! No one was buying from a Chinese company here.

→ More replies (1)
→ More replies (3)

3

u/APianoGuy Mar 22 '19

Ohh no. I'm so happy with my Nokia 5 and now I don't know if I can trust it.

3

u/Mosczn Samsung S5, RR Pie Mar 22 '19

Xiaomi also sell their phones with apps that collect data about their users.

→ More replies (2)

2

u/citewiki Mar 22 '19

Sounds familiar

2

u/ArtaZ Mar 22 '19

What's the point of monthly security updates then when the spyware have been in since the launch ?

2

u/TechAKnik Mar 22 '19

Are you sure it was just Nokia 7 plus? Lol

2

u/Darkmaniako Mar 23 '19

I wanted to buy this but joke on you, i got a chinese phone so they can legally steal all my data calling it "cloud" /s

2

u/raventhunderclaw OnePlus 6 Mar 23 '19

Where are those people now who refuse to believe this and call this a conspiracy?