Hacker News new | ask | show | jobs
by codedokode 2 days ago
I do not see problems with fake ad clicks and have no sympathy for ad companies.

Also pre-installed adware is not a surprise, I found adware in the official firmware image of a certain Chinese tablet.

What worries me much more is backdoors from the foreign companies and governments that can be pre-installed at the factory to collect intelligence information. For example, I became aware that a certain maker of a popular mobile OS was collecting the cell tower IDs and WiFi access point identifiers along with GPS coordinates of a device. Obviously they collect this information to be able to guide missiles and drones when GPS signal is jammed (GPS is very low power and easy to jam). This is not acceptable.

How can we prevent this? I think, for every imported device having a CPU and Internet connectivity:

- the user must be able to re-flash firmware with their own code.

- the local government must have access to the full source code and be able to search for vulnerabilities or backdoors, including using AI tools. Found vulnerabilities are considered a reward and may be used against countries not doing inspections. No access - no import permission.

- any telemetry or data collection, or updates must be opt-in only and disabled by default.

- any telemetry or updates must go through a server controlled by the local government, in unencrypted form, to detect attempts to collect intelligence information or install malicious update.

Sadly our government instead only demands that manufacturers pre-install their closed-source software on all imported devices and that's all.

9 comments

> I do not see problems with fake ad clicks and have no sympathy for ad companies.

I am not shedding any tears for the ad companies, but I don't exactly expect or want a consumer device to be doing this in the background without the owner's knowledge.

Sure. And you'll quite literally never be able to get any meaningful reduction in this practice unless you attack it at the level of big, publically known companies; the warnings about these local dinky things I suppose are not harmful and help individuals a bit -- but I'm concerned they give the entirely false impression that the extremely similar stuff coming from the big boys is definitely a-ok.
Reduction in what practice? Are there big companies doing ad fraud?

I want big companies to stop spying on me, which is a completely different issue.

They're not at all "completely different issues."

Both are well within the category of

"If you buy a device to do a thing, then the device does something else that is not readily apparent to the user that user would find objectionable if they had clearer knowledge."

This is immoral and harmful regardless of precise vector/action.

That spying harms me while ad fraud harms random companies is already enough to separate them by a lot, I'd say.

But also the spying is expected by a lot of people. And a lot of people wouldn't object so much to screwing up internet ads.

>What worries me much more is backdoors from the foreign companies and governments that can be pre-installed at the factory to collect intelligence information.

Most Americans are at a greater threat of harm from their own government that a foreign one. What worries me is all the mass surveillance done by big tech which bypasses the 4th Amendment and gives the government Americans data without a warrant.

There's already a front door with the adtech for US alphabet boys. This could likely be collected by others as well. We saw this happened where foreign hackers exploited a backdoor designed for American authorities[1]. This is what experts are referring to when they say there's no backdoor only for me.

This could be compelling to politicians, though, and would certainly be a step in the right direction.

>- any telemetry or data collection, or updates must be opt-in only and disabled by default

This should be how it is for everything foreign made software or not. Would be very hard to get done with the big tech lobby in the US.

[1] https://techcrunch.com/2024/10/07/the-30-year-old-internet-b...

> Obviously they collect this information to be able to guide missiles and drones when GPS signal is jammed

Are there a lot of missiles that travel slowly enough to be able to guide themselves via watching for nearby wifi signals?

> for every imported device having a CPU and Internet connectivity

Why limit this to imported devices?

>> Obviously they collect this information to be able to guide missiles and drones when GPS signal is jammed

> Are there a lot of missiles that travel slowly enough to be able to guide themselves via watching for nearby wifi signals?

Cheap, slow-moving drones are the hot new missiles on the battlefield of today. This often talked-about model files at 115 mph (https://en.wikipedia.org/wiki/HESA_Shahed_136).

In some areas GPS is spoofed and the displayed location is wrong. If, for example, a "smart" car gets a task from its manufacturer to film some secret object, it would fail if it relied only on GPS and did not use cell towers and WiFi points for determining its location. So knowing their location determines whether the mission would fail or succeed. So foreign devices should not be allowed to collect such information.
I think that might have been semi-sarcastic. I mean, there are lots of reasons to do this sort of thing, some are bad, some are not so bad, most are not war.
Fake ad clicks cost the advertiser money, not the ad company.

Ad companies generally try to detect fake clicks, but any fake clicks that get through just earn money for the ad company (at the cost of making the advertisers campaign have a lower ROI)

> Fake ad clicks cost the advertiser money, not the ad company.

It also diminishes the value of the clicks provided by the ad company. It doesn't cost them dollars directly, but makes all their advertising worth less.

Good products do not need much advertising. For example, when buying DRAM, I compare the specification and prices and do not look at the advertisement.
> a certain maker of a popular mobile OS was collecting the cell tower IDs and WiFi access point identifiers along with GPS coordinates of a device. Obviously they collect this information to be able to guide missiles and drones when GPS signal is jammed

Is this sarcasm? GPS can take several minutes to get a location, and works poorly indoors. One of the reasons why Google Maps is so quick and precise is because Google has gathered exactly this data through users and Street View drive-bys.

Could it be used for missiles? Sure. Is it obviously the intention? No.

Yeah this is extremely standard:

Apple: https://support.apple.com/en-us/102515

> If Location Services is on, your device will periodically send the geo-tagged locations of nearby Wi-Fi hotspots and cell towers to Apple to augment Apple's crowd-sourced database of Wi-Fi hotspot and cell tower locations.

Google: https://support.google.com/android/answer/15157297?sjid=1648...

> When Location Accuracy is on, Google periodically collects information about the locations of wireless signals and sensors observed by your device to crowdsource location estimates. This helps everyone find locations better.

Mozilla used to run a very similar service: https://en.wikipedia.org/wiki/Mozilla_Location_Service

Not to mention truly crowd-sourced databases like wigle.net.

They should ask the permission from device owner and local government before collecting the data.
They do ask the device owner - if you review the location services description on android[1] you will see they explicitly say they collect this information from your device. I strongly disagree that they need to get government permission for this - they are simply recording signals that reach the device, akin to making notes about what kinds of cars you see. This is not a thing a government should have control over people doing and not a thing that should be registered with the governement.

[1] https://support.google.com/android/answer/3467281?sjid=66634...

In the article you refer to, I see no mention of asking user's permission. However, I remember, when using an old version of Android, there indeed was a popup nagging me to allow sharing location data with Google every time I enabled GPS. Very annoying, makes you want to never enable GPS in the first place.

Regarding the government, the problem is that many people do not fully understand the mechanism of collecting the data. I remember the case when members of US military disclosed the location of secret objects through fitness tracker app. And they were probably smarter than average smartphone user. Obviously it would be better if enabling GPS required an approval from their commander.

I suppose they don't "ask you" in the same way that gmail never presents the user with a dialog explaining that gmail needs to store their emails in order to provide their email service. Instead they explain how the location service works and you can decide if you want to enable or disable it.

I'll agree that militaries would prefer their soldiers to not to dumb things - but I don't agree that it's 'obviously' best if people needed permission to enable GPS! If that's the case depends a lot on which soldier is enabling the GPS and their relation to me. In general I would say that government control of people recording and distributing their observations is associated with the most authoritarian governments and by claiming we should get government permission you appear to be aligning yourself with an authoritarian approach to data controls.

Should Google ask permission from the device owner, and from the local government before collecting the data? I heard a certain foreign mobile app was banned in US for doing less than that.
> I do not see problems with fake ad clicks and have no sympathy for ad companies.

Yeah, it's like—a cheap streaming stick AND it poisons the advertising well? I'm pretty happy with my Fire TV Stick, but they're really tempting me here.

My pinenote runs the original spyware image - I don't have a problem with Winnie the Pooh reading along with me.
> Yeah, it's like—a cheap streaming stick AND it poisons the advertising well?

Keep in mind that it's your IP and identity associated with those clicks and anything else criminals decide to do with your IP address. That means you're identity is being linked to things you may or not want to be known as being interested/involved in. The ads your TV stick clicks on can cause data brokers to include your name in lists of people who are heavily into drugs, have mental disorders, belong to certain religions or political parties, etc. All of that can come back to haunt you later.

Depending on what other activity your connection is used for as a proxy it can also get you in trouble with the police or with your ISP.

So you're saying it's going to weaken the presumption that an IP can be easily tracked to an individual? Even better!
No, your IP will be easily tracked to you as an individual. You'll just suffer the consequences of whatever your streaming stick does with your IP. If your stick clicks a bunch of ads for fast food your heath insurance bill goes up because their algorithm thinks you're a higher risk. If your streaming stick clicks a bunch of ads for high end luxury goods, online stores start charging you more than they charge your neighbor for the same items because their algorithms think you have money to burn. Your streaming stick clicks a bunch of ads for addiction recovery services, you don't get a call back for the next job you apply to because the HR department paid a data broker to run a background check looking for "red flags".

What you do on the internet has very real impacts on your life offline and it's going to happen more and more over time. AI will make it easier for companies to leverage the massive amounts of data avilable to them about you. Surveillance pricing is spreading. Consumer reputation services are spreading. Law enforcement is buying up data from data brokers. Extremists are using data brokers to decide who to target with violence.

Nobody cares if the data they have isn't 100% accurate. The data broker doesn't care. He gets paid either way. The companies buying your data don't care either. It's all a numbers game to them. They just have to be right enough times to justify the cost of the data.

None of this is based on reality. Can you show any of this ever happened to anyone?
This should get you started at least. Keep in mind that nobody is going to tell you that they charged you extra or didn't give you a job offer because of data collected from a data broker. No one is going to be transparent about how they use your data against you.

None of the data being collected about you ever goes away. It doesn't matter if the data comes from you. or your backdoored streaming stick, the more data they have associated with you, the more opportunists exist for you to be screwed over by it.

It's almost impossible for a person to know when or how their offline life is being influenced because of the dossiers containing their online activity, but it absolutely impacts the prices you pay, the policies businesses will tell you they have, the opportunities you are offered, and even how long companies leave you on hold when you call them on the phone.

https://www.cbsnews.com/news/data-brokers-selling-personal-i...

https://web.archive.org/web/20191130221040/https://www.nytim...

https://link.springer.com/content/pdf/10.1057/s41272-019-002...

https://www.mccarter.com/insights/ftc-surveillance-pricing-s...

https://www.npr.org/sections/health-shots/2018/07/17/6294415...

https://nypost.com/2022/12/20/how-employers-spy-on-your-sear...

https://www.cnbc.com/2014/04/16/data-mining-is-now-used-to-s...

https://www.wired.com/story/minnesota-lawmaker-shootings-peo...

https://www.wired.com/story/opinion-data-brokers-are-a-threa...

https://sites.sanford.duke.edu/techpolicy/wp-content/uploads...

https://epic.org/data-broker-helped-anti-abortion-group-targ...

https://www.foxnews.com/politics/nsa-purchases-americans-int...

https://www.ftc.gov/news-events/news/press-releases/2014/04/...

https://www.washingtonpost.com/technology/2023/02/13/mental-...

https://arstechnica.com/tech-policy/2017/03/senate-votes-to-...

https://www.vice.com/en/article/data-brokers-netflow-data-te...

https://www.eff.org/deeplinks/2023/11/debunking-myth-anonymo...

Talk about the gift that keeps on giving…
Oh this was a failed device that Mozilla offered. I had a couple back in the day. It was called Matchstick. Sick t shirts. Basically an OSS chromecast.
> What worries me much more is backdoors from the foreign companies and governments that can be pre-installed at the factory to collect intelligence information.

The Snowden leaks showed that the US was already doing this. I'm certain that everything purchased is already infected with something. Most likely bugs and bad security.

The problem is that when you need these powers most as a citizen is when your government is least likely to allow it.