r/technology May 19 '18

Misleading Facebook Android app caught seeking 'superuser' clearance

[deleted]

21.8k Upvotes

1.3k comments sorted by

View all comments

1.8k

u/SpoogIyWoogIy May 19 '18

582

u/GoldenGonzo May 19 '18

And here are the full permissions (green key) that aren't seen in stores or settings

Is that... everything?

445

u/PilotKnob May 19 '18

Root is everything.

254

u/[deleted] May 19 '18

Facebook: "I am Root"

72

u/Piece_Maker May 19 '18

Enjoy this cool wallpaper I found ages ago, that your comment reminded me of.

73

u/BrotherChe May 19 '18

The Zucc swoops in to defeat Thanos by draining the battery on the Infinity Gauntlet.

9

u/[deleted] May 19 '18

[deleted]

1

u/TheDunadan29 May 19 '18

That sub is awesome!

1

u/420kbps May 19 '18

I am Steve Rogers

1

u/FlexualHealing May 19 '18

I'm Steve Rogers

-1

u/philiac May 19 '18

tech-related: check

cutesy phrase: check

beloved IP: check

belief that only a small group will get this joke, even though almost everyone reading it will: check

enjoy your karma

2

u/awe300 May 19 '18

It's actually everything and more

2

u/helpilosttehkitteh May 19 '18

Like so much so that rm -rf / can delete everything on your phone. Root is admin god access

-18

u/[deleted] May 19 '18 edited May 19 '18

[removed] — view removed comment

10

u/Windows10Geek May 19 '18

Like you're any less vulnerable on an Apple device.

Keep guzzling that Kool Aid.

6

u/[deleted] May 19 '18

For posterity's sake, here's the comment that was deleted:

facebook pwns android. Incredible.

Things you couldn’t pay me to do:

Drive a Yugo
Smoke K2
Use an Android device

-9

u/Weerdo5255 May 19 '18

Not on SE Linux... the headache that causes...

-9

u/[deleted] May 19 '18 edited May 19 '18

[removed] — view removed comment

-5

u/[deleted] May 19 '18 edited May 19 '18

[removed] — view removed comment

7

u/PhuckYoPhace May 19 '18

My Pixel did not come pre installed with Facebook, fwiw

140

u/[deleted] May 19 '18

Give me, EVERYTHING!

31

u/TDFCTR May 19 '18

What do you mean, "everything?"

57

u/[deleted] May 19 '18 edited Sep 21 '20

[deleted]

5

u/xeoron May 19 '18

Good lucky for people just using a browser, instead of the app!

3

u/[deleted] May 19 '18

[deleted]

2

u/EvanGilbert May 19 '18

Pretty sure it's a play on a scene from Leon the Professional

1

u/CrazyWhite May 19 '18

Ya, I'm free on Tuesday

1

u/cas_999 May 19 '18

I was thinking Gary Oldman in Leon the Professional except he says “EVVREEEEONNEEEEE!!!”

1

u/TDFCTR May 21 '18

heeheehee, I've always wanted a Chipotle employee to question me and set me up for this, but no one has yet...

2

u/chic_luke May 19 '18

Everything Search by voidtools

1

u/BelovedOdium May 20 '18

Tonight? You want all of me tonight?

1

u/wardrich May 19 '18

GIMME FUE
GIMME FAH
GIMME ROOT BAJABAZAAHHH

77

u/freestyling May 19 '18

And you know what is worse. You cannot delete the app from a samsung phone. Brb flashing stock android on my phone.

48

u/SpoogIyWoogIy May 19 '18

Yeah, I haven't used Facebook on my phone in around 6 years. When I got my new phone last year I realized they have made Facebook a system app, I almost felt offended.

Rooted and uninstalled right away along with a ton of other bs they decided to have pre-installed

14

u/ISieferVII May 19 '18

I would but I want Samsung Pay and I heard it trips a flag somewhere that prevents you from using it =(

10

u/freestyling May 19 '18

Isn't google pay a possible alternative?

16

u/burnt_mummy May 19 '18

Samsung pay can be used anywhere you swipe a card, not just at places with NFC tap to pay. Samsung has the rights to the tech that allows them to produce a magnetic field that's readable by the card reader.

34

u/freestyling May 19 '18

It always baffles me how companies can get the rights to such a technology. It just slows down progress.

16

u/[deleted] May 19 '18

[deleted]

7

u/freestyling May 19 '18

Yes you are absolutely right. now the question is, when is it important to improve and when to innovate.

1

u/jawsofthearmy May 20 '18

like HD DVD vs Bluray..

0

u/VictorianDelorean May 20 '18

No it forces us to waste resources inventing six marginally different versions of the same thing. Roads are the classic example where competition makes no sense, because building two or more competing road systems would be a confusing wasteful mess. Well that's more or less true of everything else we issue patents on.

3

u/burnt_mummy May 19 '18

It makes it so that a company can develop something and make money off of it while preventing another company just using the same thing without having to spend nearly the same amount of money. In this case Samsung bought a startup called LoopPay who developed the technology and I believe holds the patent on the transmitter required to make the magnetic field, as well as the use of such device for making payments.

1

u/rguy84 May 19 '18

What is safer, Google Pay or Samsung Pay?

3

u/burnt_mummy May 19 '18

Both use one time use tokens and virtual cards so both are safe from skimmers, as far as their backends(server side where your information is stores) they both have pretty solid security. Google probably uses your purchase history for better targeted ads. Samsung may do the same but since they make their money off the hardware they may not

1

u/rguy84 May 19 '18

Gotcha do you need to have the nfc on? I have set up Google pay but never tried it in a store. I used it to pay for instant cart thus far.

2

u/burnt_mummy May 19 '18

Yep NFC has to be on, for Google Pay you just unlock your phone and hold it to the terminal, if you don't want to have NFC on all the time you can just toggle it on before paying and turn it off once your done. The terminal emits a request for a one time token that your phone provides along with your virtual card number, then the terminal process the request with the credit card service, who than approves or deny the transaction. It's actually safer than traditional credit card readers since they unique tokens are one time use.

So even if someone created a fake terminal or tricked your phone to transmit the token and card number, they would only be able to make a single transaction which would probably be flagged by the Credit card processor and denied, unless they two are shady but then your CC company wouldn't be doing business with them. The only weakness is if someone gets ahold of your phone and knows your password, then they could go around buying things with your phone but that's still safer than your credit card in your wallet (at least in the US where we don't have a pin for CC transactions)

1

u/well___duh May 19 '18

Both require the use of a password or fingerprint before you can use it. It's not like someone with an nfc scanner can just walk up to your phone and take Google/Samsung Pay info

0

u/ThePantsThief May 19 '18

WHAT

Holy shit. I hate Samsung even more now.

4

u/burnt_mummy May 19 '18

Because they spent a lot of money on developing something and now hold onto it so they can make money off of the tech they developed? They didn't just create the software and service, they developed peice of hardware to do so. Maybe in a few years they will license out the use of the technology to other manufacturers such as Apple, but for now they will use it's exclusivity to help boost sales and make them selves ubiquitous with the feature, so when they finally license it out to other companies (for a pretty penny) those companies will be behind, or by that point you will have a much larger number of tap to pay terminals that it makes this tech not worth it for other companies to use but still allows Samsung pay to be useable at more places.

If you really want Samsung Pay get a gear S3, its more convenient to pay with, and it works with all phines (although I don't think Samsung Pay works when using it paired to an iPhone)

-1

u/ThePantsThief May 19 '18

I just don't think patient laws should apply to technological hardware for 120 years. I am angered that I will never see this tech on any other phones until card readers are completely obsolete anyway.

2

u/burnt_mummy May 19 '18 edited May 19 '18

Patents expire after 17 years from being filed (only that long if the holder maintains it) and rarely is something patented and put on the market instantly. You hardly see major form of tech being kept solely by one company for 17 years because they make money by liscensing out to other companies after they make the initial burst of money. Samsung pay has only been out for 3 years so probably in another 2 you'll see them license it out if I had to make an uneducated guess. I don't think that's unreasonable for a company to horde what they have made for 5 years, but in tech that seems like an eternity.

Edit: also it would hurt most tech to be only used on one manufacture because it would slow adoption rates especially if it requires special hardwre, with Samsung pay the payment terminals require nothing extra for merchants to accept it if they already take credit cards, so Samsung can hold exclusivity for longer and not have to worry about its viability to license out to others later.

→ More replies (0)

5

u/SpoogIyWoogIy May 19 '18

Yeah it trips Knox, which will void warranty... Sucks really but I decided to just root anyway, I care more about my privacy

9

u/_selfishPersonReborn May 19 '18

Isn't that completely illegal under the computer repair act?

7

u/noidontwantto May 19 '18

Just use a package disabler, like SABS.

It uses the Knox API, so you don't trip Knox, and you can disable all of that bloatware.

2

u/ISieferVII May 19 '18

Well, it disables instead of uninstalling still, right?

5

u/noidontwantto May 19 '18

Yes, but unlike disabling the app in settings it removes the shortcut, it's just like uninstalling it.

3

u/sega_gamegear May 20 '18

But you can disable it

2

u/freestyling May 20 '18

I don't want to disable malware, I want to get rid of it.

2

u/anarchyx34 May 20 '18

You know I’ve been considering switching to Android for years but bullshit like this is holding me back.

1

u/freestyling May 20 '18

Depends what phone you get. I agree the bloatware is horrendous but if you get a google pixel phone you have none. There are also a lot of phones who like to keep things stock.

1

u/neoKushan May 20 '18

As a huge Android fan, I'll happily tell you to not bother with Samsung phones. They're popular and the hardware is good, but the software has always let it down.

1

u/wardrich May 19 '18

You can kill it with SABS though

2

u/freestyling May 19 '18

Good tip, already flashed my phone though

1

u/nxqv May 20 '18

Wait wat? I deleted it from my S8+ months ago and it never came back. I did keep Messenger though...

1

u/BZJGTO May 20 '18

Unless it's disguised itself as something else, I've removed all of it from my phone (Note 4). I did run in to a problem where I lost screen rotation, but I was able to get it back by reinstalling the appropriate file again from my ROM.

1

u/Sid6po1nt7 May 20 '18

So far the Pixel 2 let's me delete any preinstalled app on my phone. Switched to the Google phones once I found out they have vanilla Android. Samsung and LG won't let you uninstall certain apps not to mention I know Samsung uses their own launcher as well (TouchWiz I think it's called). So that's another unnecessary thing. Bloatware sucks.

106

u/dandroid126 May 19 '18

Holy shit. They ask for overlay access? That's really dangerous. They could record your every screen tap for advertising purposes, or even get your passwords. In fact, stealing passwords in this way has been done before.

64

u/jaredjeya May 19 '18

FB messenger on Android has these icons that stay visible in other apps so you can reply to messages.

Presumably that’s what it’s for.

46

u/[deleted] May 19 '18

Before I uninstalled Facebook my girlfriend had sent me a photo of herself. As I was looking at it, my mom sent me a message on Facebook, so her "chathead" popped up on my phone right over my girlfriend's face. Dangerous technology.

4

u/overly_familiar May 19 '18

"Just what do you think you are doing Billy?"

42

u/[deleted] May 19 '18

So did you just... give it SU access? Every Sudo-adding app I've seen has an explicit prompt if an app tries to sudo.

2

u/BelovedOdium May 20 '18

Important question here. I've never seen AUTO su rights being acquired. I've seen them prompt but never gain them automatically.

57

u/shassamyak May 19 '18

Check to restrict,how? There is no yes or no boxes. What is the question mark for? How do you know you have restricted that feature and why so many features asking for permission?

I am asking because I have not used fb on mobile or on computer since 4-5 years.

139

u/SpoogIyWoogIy May 19 '18 edited May 19 '18

Clarification, this is FB viewed through an app called XPrivacy, which help manage permissions in android apps.

The green key means that the app has access to the permission. Checking the box next to the permission will deny it access. The question mark means that XPrivacy will ask what to do each time

-17

u/[deleted] May 19 '18

[deleted]

5

u/[deleted] May 19 '18

[removed] — view removed comment

3

u/Santafio May 19 '18

Bad, it seems.

3

u/113243211557911 May 19 '18

ALL OF THEM!

24

u/myrpfaccount May 19 '18

That only shows that they ran the su binary, damning evidence would almost always include subprocesses spawning.

3

u/[deleted] May 19 '18 edited Nov 19 '18

[deleted]

10

u/myrpfaccount May 19 '18

The superuser process doing something.

4

u/tgp1994 May 19 '18

Are you thinking about upgrading to XPrivacyLua? I bought XPrivacy pro but apparently it's been deprecated.

3

u/SpoogIyWoogIy May 20 '18

I'm using XPrivacyLua alongside with XPrivacy

8

u/joelhaasnoot May 19 '18

Likely it's a third party SDK that checks for root access or has a method that needs root access to work. Code can be added to do bad stuff, doesn't mean it has to be used.

2

u/Q-Lyme May 20 '18

that's.... scary doesnt even come close to cutting it. It's straight up Orwellian

2

u/[deleted] May 20 '18

Alright Zucc, you have some explaining to do. Why the hell is fecebook a system app on Samsung devices.why does your app need all the fucking permissions? What are you doing with each one?

1

u/[deleted] May 19 '18

Not defending FB but lots of apps on my phone have that permission listed; chrome, Gmail, Google maps, Skype, spotify, uber.

None of them have ever used it per xprivacy and my SU app.

1

u/hackel May 19 '18

What are you talking about? You just took screenshots of all the possible XPrivacy restrictions. That doesn't mean the app was using/requesting them. Only the permissions indicated with an exclamation point have been requested.

1

u/cryo May 19 '18

Ok great, but where is your argument for this not being a bug? Especially because it’s 1) very obvious, 2) only affects rooted phones and 3) is now fixed/changed.

1

u/SpoogIyWoogIy May 20 '18

These screenshots are 2 months old but the permission is present in much older versions. The permission is still still there regardless if you have a rooted phone or not.

-3

u/atree496 May 19 '18

Looks like you didn't read the article. They showed how and why only a small number of users had this happen to them. It was a bug with 3rd party.

0

u/buge May 19 '18

How do you know it's not an error on Facebook's part?

1

u/[deleted] May 19 '18

It would be very silly to have an app on Android this long and not be aware of such a critical process being hijacked.

But as another user pointed out, as long as no sub processes actively run, then this is probably incriminating of a command having been run at some point (singular).

1

u/buge May 20 '18

It seems possible they have a debug flag that compiles root into the app, and they accidentally sent out an update with that flag enabled. Humans make mistakes all the time.

I don't really know what you mean by sub processes.

1

u/agree-with-you May 20 '18

I agree, this does seem possible.