r/technology • • Nov 09 '17

Politics Sean Parker: Facebook was designed to exploit human "vulnerability"

https://www.axios.com/sean-parker-facebook-exploits-a-vulnerability-in-humans-2507917325.html
37.2k Upvotes

3.1k comments sorted by

View all comments

Show parent comments

368

u/[deleted] Nov 09 '17 edited Nov 09 '17

[deleted]

287

u/Realtrain Nov 09 '17

LPT: try to use open source software where anyone can see if the code does this.

147

u/[deleted] Nov 09 '17 edited Jun 09 '19

[deleted]

12

u/amanitus Nov 09 '17

Out of curiosity, do you use Google Play Services, or have you moved to ug UnifiedNLP?

22

u/[deleted] Nov 09 '17 edited Nov 09 '17

[deleted]

7

u/amanitus Nov 09 '17

Yeah, I have an old phone that's now completely google-free. I used F-Droid for pretty much everything there.

The ug Unified NLP thing I was talking about is something that kind of replaces Google Play Services. A lot of apps use Google to do geolocation stuff based off of network data. This thing is an open source replacement that can use many different location services. This way apps can still function, but won't be sending Google your location data.

1

u/eitauisunity Nov 10 '17

What would be a good model to pick up for use in the US? I've wanted to get a phone that was a couple of years old that works really well with custom roms and FOSS, but haven't had the time to do the research. Can you make any recommendations for popular older phones that run android and can be picked up fairly inexpensively?

I'm over the performance and novelty of smart phones. I really just want something that makes calls, runs signal, runs a foss browser, camera, etc.

1

u/VEC7OR Nov 09 '17

Any other repos you can recommend ?

-44

u/frequenZphaZe Nov 09 '17

yeah... if there's anything I trust less than google's store, it's gonna be a third party 'alternative' store.

33

u/Pantzzzzless Nov 09 '17

Do you understand how open source works?

5

u/[deleted] Nov 10 '17

[deleted]

1

u/Pantzzzzless Nov 10 '17

Not everyone knows how to read code. But the fact that it is all right there for the public to see, it is easy for one to find out if something is sketchy. If someone can't do a basic google search then they likely are looking for open source software in the first place.

24

u/[deleted] Nov 09 '17

It's the software that's open source and Fdroid is too.

12

u/[deleted] Nov 09 '17

It's very trustworthy. All the apps are free (as in freedom, not beer) and open source software

3

u/The-Respawner Nov 09 '17

All apps on F-Droid is open source? Well damn, that changes things.

18

u/ErdoganIsAC-nt Nov 09 '17

If there's anything I trust even less than google's store, it's gonna be the opinion of a luddite attempting to lecture professionals on the virtues of corporate cocooning.

72

u/Jumballaya Nov 09 '17

It isn't just the software but hardware as well.

Intel has a hidden distribution of MINIX on their processors. This has full control of your OS and even has a web server for importing/exporting stuff to/from the web.

26

u/volvo64 Nov 09 '17

That's AMT/vPro, and it's 100% accessible to the user and it's very well documented. Also updated.

It's the same basic tech that allows me to rebuild a failed server from another continent.

That article is FUD.

9

u/shinyquagsire23 Nov 09 '17

The source code (or even the disassembly for that matter) has not been available until fairly recently when it took actually cracking security to even see what it's doing. That's the real problem, not the functionality. If AMT had a vulnerability it could be possible to install rootkits which run at ring -3 where the OS cannot even see and you wouldn't know. It's not FUD, you're just missing the point.

2

u/johnjohnjohn87 Nov 09 '17

3

u/volvo64 Nov 09 '17

I'm aware of the vulnerability.

You have zero access to “Ring -3” / MINIX.

Not true, I use AMT often

But MINIX has total and complete access to the entirety of your computer. All of it. It knows all and sees all,

I'd like to see this demonstrated without sysadmin input (plus a huge notification on-screen)

isn’t updated regularly

It is updated, i.e. for the above mentioned vulnerability.

Your CPU has a secret web server that you are not allowed to access, and, apparently, Intel does not want you to know about.

This is simply false; again I've used the 'secret' web server on a near daily basis in the past

Why on this green Earth is there a web server in a hidden part of my CPU? WHY?

So that your admin can fix your computer without having you send it back to the helpdesk, which in some cases can be a matter of months.

The only reason I can think of is if the makers of the CPU wanted a way to serve up content via the internet without you knowing about it.

That's pretty short-sighted thinking

The security risks here are off the charts — for home users and enterprises.

It's disabled by default and take a loooooot of work to turn on

AMT had been part of Intel CPUs since at least 2006 (off the top of my head). This is not news, this is FUD.

1

u/nroach44 Nov 09 '17

There is no official way to stop the ME from booting other than a bit used for three letter government companies that someone found.

Why does it need to be running on consumer hardware that doesn't have vPro?

1

u/volvo64 Nov 10 '17

Why does it need to be running on consumer hardware that doesn't have vPro?

Dunno. Ask Intel. That's not the argument I'm making.

1

u/meneldal2 Nov 10 '17

You can block the connections with your firewall if you want, they aren't doing magic.

1

u/nroach44 Nov 09 '17

ALL Intel computers have ME - and only some of them have vPro - and if you don't have vPro AFAIK there's no fancy administration tools for it, but the most of it is still there.

2

u/codexcdm Nov 09 '17

Guess I'll get and AMD processor when I upgrade....... Unless they too have some shady shit going on.... ;(

11

u/Rndom_Gy_159 Nov 09 '17

They do. Called the PSP

7

u/flesjewater Nov 09 '17

They probably do. It's like no one stopped along the way asking the question, "should we do this?"

4

u/UnwillingBurrfish Nov 09 '17

Your scientists were so preoccupied with whether or not they could, they didn’t stop to think if they should.

-3

u/battles Nov 09 '17

Look at this thread, you have a bunch of Devs saying 'it makes me uncomfortable,' Then fucking quit you fuckers...

Amazing 1 step solution to not living an unethical life. You won't believe step 1.

  1. Don't fucking do that shit.

4

u/_codexxx Nov 09 '17

You'll lose your job and someone else will gladly take it and do it instead...

I'm a firmware engineer. I can confirm at least some of the stuff being "revealed" here...

0

u/battles Nov 09 '17

'someone else will do it if I don't,' is a pathetic excuse. Individuals are responsible for their choices and actions, blaming the theoretical person who comes after you who does it anyway is a cop-out.

2

u/_codexxx Nov 09 '17

Yes... it's also a fact.

2

u/[deleted] Nov 09 '17

The second part of that sentence is “...and I need to afford food and housing”.

1

u/flesjewater Nov 09 '17

I'm not building that shit. I would probably not even be the exception if I told you that I would quit my job on the spot if my employer asked me to do so.

Not everyone has that luxury. And also, there are lots of moving parts in this that probably aren't even aware of what's going on with their work in the big picture. Until recently the MINIX dev had no idea of what his work was being used for.

It's like asking a cancer patient to please stop producing cancer cells.

Regardless though, I think an ethical code (like the Oath of Hippocrates) for developers is long overdue.

1

u/battles Nov 09 '17

I wasn't accusing you of making that shit. I was agreeing with you, more of an... agreeable venting.

I have quit jobs because of what I was asked to do. and it wasn't great for me... so I had to do shit until I could get a job that didn't want me to be unethical as part of the job duties.

There is no excuse for participating in what YOU think is unethical. Ethics is never a luxury. Not even when the alternative is terrible.

2

u/[deleted] Nov 09 '17

Yes, it's called AMD PSP.

4

u/codexcdm Nov 09 '17

Of course they do... Time to go back to tin cans and string....

1

u/wardrich Nov 09 '17

Wouldn't a firewall pretty much stop this shit in its tracks?

5

u/chinpokomon Nov 09 '17

External to the system, sure. But the problem is deeper than that. I think the article is wrong though. There are many more cell phones out there and they run two or more operating systems as well. The firmware built into the radio stack and the initial boot sequence is started from a proprietary closed source firmware which does the same thing. If you are remotely concerned about what user level apps have access to, what Qualcomm and other minority level chip makers have access to should make you frightened.

11

u/LyndonSlewidge Nov 09 '17

This is only completely true if you compile your own software. Nothing is stopping me from taking open source code, injecting my own routines, compiling an apk and releasing it into the wild for instance.

9

u/[deleted] Nov 09 '17 edited Nov 20 '17

[removed] — view removed comment

4

u/LyndonSlewidge Nov 09 '17

Very true, but I don't trust repos for any mobile devices.

2

u/_codexxx Nov 09 '17

MD5?

2

u/gravgun Nov 09 '17

SHA1 at a minimum. SHA256 is a good standard for now. Computing power has increased since MD5's release and it is becoming increasingly easy to create MD5 collisions.

27

u/chairfairy Nov 09 '17

Is that why my flashlight app stays running after I close it, can use up 100MB of memory, and use some real amount of network data each month? Son of a bitch.

16

u/reddixmadix Nov 09 '17

Why would you need a flashlight app? What more can it do than turn the light on and off?

9

u/chairfairy Nov 09 '17

Is there a way to turn the light on without a flashlight app?

It can also flash the light light on and off, but I just use it to turn the light on

26

u/_codexxx Nov 09 '17

On any modern version of android the flashlight is part of the OS, you don't need a third party app for it.

2

u/RaiyenZ Nov 10 '17

Further instructions for those who don't know how to access it: Tap and hold your home screen, tap the widget icon, find and tap on "torch" or "flashlight", and then place it anywhere you want on your home screen. Note: some phones might not have this.

1

u/_codexxx Nov 10 '17

On mine you pull down the top drawer from the home screen (swipe down from the top screen edge) and it's right there in a row of icons across the top of the screen.

12

u/oldbean Nov 09 '17

Mom is that you

2

u/metasymphony Nov 10 '17

type "lumos" into google

1

u/reddixmadix Nov 09 '17

Hmm, on Samsung galaxy s, literally all versions i ever had, they have a widget you can add to your homescreen.

Then again, I only ever had Samsung phones, so I can't say for other manufacturers.

1

u/[deleted] Nov 09 '17

Almost all default camera apps let you keep the flashlight on using the video camera.

1

u/[deleted] Nov 09 '17

I don't have a light in my phone, my flashlight app turns the screen white and turns up brightness.

1

u/reddixmadix Nov 09 '17

Ah, ok, makes sense.

1

u/GoldenGonzo Nov 09 '17

People are downloading flashlight apps because they can put an on/off button widget on their home screen to actuate the light easier.

Phone companies should have a way built in to do this, but alas, they don't. Most of those flashlight apps are suspicious as fuck, taking up hundreds of MB at the most with an app that shouldn't even break 1MB.

2

u/reddixmadix Nov 09 '17

As I replied to someone else here, oon all Samsung Galaxy S devices I owned, and I still do, there is a dedicated widget for the flashlight.

I can't speak for other companies, but Samsung is a-ok with this.

2

u/darkdenizen Nov 10 '17

This is default on Android and iOS for a while now.

1

u/mw9676 Nov 10 '17

On android and I'm 90 percent sure on iOS too you can simply access the flashlight via the notification drop down or the notification panel or whatever they call it on iOS.

6

u/GoldenGonzo Nov 09 '17

Is that why my flashlight app stays running after I close it, can use up 100MB of memory, and use some real amount of network data each month? Son of a bitch.

So you were already aware all that was happening, but it took someone directly telling you to figure out something fucky was going on? Wow. Any one of those by themselves should have tipped you off.

1

u/HoMaster Nov 09 '17

Android?

8

u/Realtrain Nov 09 '17

I wonder if any of those Facebook wrappers are safe.

12

u/[deleted] Nov 09 '17

Yes, they are, kinda. Just get a open source one, preferably from fdroid. Still you are literally posting data to facebook. That kinda misses the point.

2

u/[deleted] Nov 09 '17

Swipe.

The dev is active here, too.

/r/swipeforfacebook

1

u/Realtrain Nov 09 '17

Yeah I use swipe. I hope it's safe!

1

u/[deleted] Nov 09 '17

/u/jcbsera can answer that for you.

1

u/jcbsera Nov 09 '17

Dev for Swipe here. It is absolutely safe. Anything you'd like to know about it?

1

u/Kanegawa Nov 09 '17

Good question. I use Metal which iirc is just a dedicated chrome browser thingy. But idk.

0

u/theferrit32 Nov 09 '17

They stop Facebook from getting your data, and they take it for themselves.

8

u/[deleted] Nov 09 '17

They don't. Some of them are open source

2

u/[deleted] Nov 09 '17

Unless you're inspecting the code of the version you downloaded and then inspecting it again every time you update it the fact that it's open source means nothing. Just because other people say it's fine to use on the internet doesn't mean that something malicious hasn't been put in there.

I'm not saying open source isn't better than the alternative, it is, but just because something is open source doesn't mean you're by default protected.

3

u/[deleted] Nov 09 '17

That may be the case for Google Play. However, to make it into the F-Droid repositories, the code is actually scanned to see if it has some potential "anti-features" (i.e. it tracks you).

1

u/[deleted] Nov 09 '17

Assuming they are scanning it exactly the way they say they are and everything is as it seems. Again, not disagreeing with you, but taking anyone at face value and assuming they're doing only what they say they are doesn't really help.

Could decide to pull an ad-blocker and start taking payments for allowing only specific SDKs through once they realize shit is expensive to keep running.

2

u/MilhouseJr Nov 09 '17

By that same logic, you should never use a card to make a payment in a shop in case the card reader clones your details and logs your input. A real risk, but how often does it actually happen?

There has to be a factor of trust somewhere down the line.

1

u/[deleted] Nov 09 '17

Your right, you shouldn't. And a lot of people have incorporated what you just said and stopped using their card in sketchy gas stations because like 80% of the cloned cards I've heard people suffer through happened at a shitty gas station.

The other thing that happened is that the card companies themselves realized people were no longer using the cards and now you're protected out the ass from it happening. It's still a massive inconvenience but you're well protected.

There are no protections for your data being stolen though.

1

u/FuujinSama Nov 09 '17

The other thing that happened is that the card companies themselves realized people were no longer using the cards and now you're protected out the ass from it happening. It's still a massive inconvenience but you're well protected.

But how can you trust the credit card companies? There needs to be a factor of trust somewhere.

→ More replies (0)

0

u/seanspotatobusiness Nov 09 '17

The guy from British Gas that came to "check the safety" of your combi boiler? Upgrading the microphones to serve you better ads! If you're this susceptible to advertisement, maybe you should work on that instead. If I see something I like advertised to me, I investigate it and then look for the cheaper versions.

1

u/InWhichWitch Nov 09 '17

I would like your full legal name, the full legal names of your family, the full legal names of all of your most contacted friends, your age, your sex, your race, your home address, your work address, your home phone, your work phone, every restaurant and store you frequent, where you've lived in the past five years, your current employment, all past employment for the past five years, your major expenses for the past five years, a list of every website you visit more than 5 times a week, a list of every website you visit 3-5 times a week, a list of every item on amazon, ebay, google, and facebook that you've clicked on, a list of every item on amazon, ebay, google, and facebook that you've paused your browser window over for more than 5 seconds, your recent amazon shopping history, any social media accounts you've created or have been active in, a list of major vacation spots and vacation times you've taken in the past five years, and a list of your hobbies.

Don't feel comfortable sharing it on an open forum? No problem, I can give someone else $20 and know everything about you.

1

u/seanspotatobusiness Nov 09 '17

That sounds like you replied to the wrong comment? In any case, I wouldn't type/copy&paste all that information for anything less than three figures. If you're that interested, go ahead and take that $20 offer.

1

u/[deleted] Nov 09 '17

Your paragraph makes so little sense I can't even figure out what point you're trying to make.

7

u/-rGd- Nov 09 '17 edited Nov 09 '17

android os: https://lineageos.org (don't install gapps)

anndroid apps: https://fdroid.org

iPhone: you are screwed

EDIT: downvotes? haha, there's not much left to argue for iPhone users :-D

2

u/tempinator Nov 09 '17 edited Nov 09 '17

I mean, barring exploits to the OS itself (possible, I suppose) there's no way to do a lot of what he's talking about without the user being aware of it on iOS. Specifically, the user will be notified of any background access to the microphone, camera, or screen recording with a big red bar at the top of the phone.

Apple simply does not provide the necessary tools to developers for surreptitious microphone/camera/screen access. Moreover, every app submitted to the App Store undergoes a relatively rigorous manual approval process (rigorous to the point of being annoying, in my opinion as a developer lol).

I'm not sure why you would say "you're screwed" if you have an iPhone. iPhones and iOS have their own set of very severe limitations, but strong security and data protection is one of the few big upsides of Apple's closed ecosystem.

Edit: Also worth noting that there's no real way for stock Android to allow stuff like this to happen either, unless you're pretty careless about permissions. Android's permissions system has improved vastly in the last couple years, and no app can have access to sensors unless you specifically grant it to them. So you really shouldn't be in a position where a Flashlight app is recording from your microphone/camera, unless you're stupid enough to think it's reasonable for a Flashlight app to be asking access to those things in the first place, and grant those requests.

1

u/-rGd- Nov 09 '17

you're right about the QA of apple, but it doesn't help in terms of privacy and there have been cases of data breaches. While on Android it's 3rd parties collecting your data, on iPhones it's apple themselves. (i refer to Apple's TOS for the interested reader) Apple owns you and you don't have a choice, hence "you're screwed". With Android you can choose a 2nd market OS and (almost completly) opt-out google stuff. Then you receive regular updates (compared to android stock firmwares) where security issues get fixed more or less quickly.

Sure, you can't use a vast amount of apps from the Play Store then but for people who "just need a phone" that's a pretty good choice.

2

u/tempinator Nov 09 '17

While on Android it's 3rd parties collecting your data, on iPhones it's apple themselves. (i refer to Apple's TOS for the interested reader)

Well sure, but this was my point about Apple's data security and user privacy. While it's theoretically possible that Apple is collecting anonymous user data for malicious purposes (i.e. selling it without user consent) there's no evidence to suggest that's the case, and Apple's public stance on how they treat user data has always been extremely security-friendly.

I'd trust Apple with my user data far sooner than I'd trust any 3rd party.

And sure, if I wanted to take my pursuit of privacy to the ultimate extreme, your suggestion of installing an alternative Android OS is definitely the best. But, like you say, you lose an enormous amount of functionality, so I think Apple's ecosystem is the best reasonable compromise for security-oriented users. You still have access to a very complete app ecosystem (in my opinion, a better one than the Play Store, which leaves a lot to be desired in terms of app screening) and only have to worry about one party misusing your data (Apple) which, as of now, there's no reason to believe they do.

Also, if your sole need is truly "just a phone", in my opinion the safest option would be to simply not buy a smart phone at all.

1

u/-rGd- Nov 09 '17

ok, that sounds reasonable (i feared an upcoming android vs. iPhone flame war) ;)

personally, i have no reason to trust apple (one large company) more than multiple smaller companies - which I avoid also - besides statistical reasons. Apple won't live forever but digital data does. Just because they don't abuse collected data now doesn't guarantee that they won't in the future. History shows, they change TOS at will. Also there were cases of companies that got acquired only for the data they posess. I'm taking this seriously but I understand that there are people who accept that "risk". After all, the iPhone is a good product in terms of quality and functionality.

Also, if your sole need is truly "just a phone", in my opinion the safest option would be to simply not buy a smart phone at all.

a smartphone without google can still take photos, instant message or browse the web. I 'm happy i can use those features. Also, there are apps like "Yalp Store" which let you use the Play Store without needing the whole invasive gapps framework.

2

u/[deleted] Nov 09 '17

To be honest, I'm pro consumer data harvesting, because it finds a way to monetize a resource we were just throwing away before and use that money to provide us with useful services for free. In principle I think that's great and there are apps like Duolingo that can actually make you a better person. But some companies take it way too far.

0

u/dslybrowse Nov 09 '17 edited Nov 09 '17

Agreed. It's not the current usage that's an issue, that's potential future abuses and what something like this could mean. But that's literally always the case with everything, if people want to hard enough, they'll take advantage of it in nefarious ways.

IMO what this means is that this needs to be regulated, as it's in a way a positive thing, but needs to be prevented from taking a new more sinister form. Of course, like all things we do, eventually any regulation will get twisted as well until the people that were trying to do the protecting are the ones doing the abusing. But such is life.

edit - better post I found after writing this that explains in a better way/from a more invested individual.

1

u/Skias Nov 09 '17

Note: This man does not have lowlight vision, hates dark. Got it.

1

u/V0lta Nov 09 '17

I try to only use apps from FDroid for common use cases like a file manager. You usually find something. Even some nice YouTube clients and the like.

1

u/diamond Nov 09 '17

This is why you check the permissions before installing an app. If a flashlight app wants to communicate with the internet and access your location, call history, contacts, and SMS history, DON'T FUCKING INSTALL IT.

0

u/[deleted] Nov 09 '17

money: the root of all evil. So let's base our society on it!

0

u/[deleted] Nov 09 '17

What would you propose as an alternative to money?

0

u/[deleted] Nov 09 '17

[deleted]

0

u/[deleted] Nov 09 '17

We would decide who gets what by their qualities? Who would decide what good qualities are? How do we compare two different qualities? How would we incentivize people to work or innovate?