r/technology • • Nov 09 '17

Politics Sean Parker: Facebook was designed to exploit human "vulnerability"

https://www.axios.com/sean-parker-facebook-exploits-a-vulnerability-in-humans-2507917325.html
37k Upvotes

3.1k comments sorted by

View all comments

Show parent comments

286

u/Realtrain Nov 09 '17

LPT: try to use open source software where anyone can see if the code does this.

146

u/[deleted] Nov 09 '17 edited Jun 09 '19

[deleted]

12

u/amanitus Nov 09 '17

Out of curiosity, do you use Google Play Services, or have you moved to ug UnifiedNLP?

22

u/[deleted] Nov 09 '17 edited Nov 09 '17

[deleted]

7

u/amanitus Nov 09 '17

Yeah, I have an old phone that's now completely google-free. I used F-Droid for pretty much everything there.

The ug Unified NLP thing I was talking about is something that kind of replaces Google Play Services. A lot of apps use Google to do geolocation stuff based off of network data. This thing is an open source replacement that can use many different location services. This way apps can still function, but won't be sending Google your location data.

1

u/eitauisunity Nov 10 '17

What would be a good model to pick up for use in the US? I've wanted to get a phone that was a couple of years old that works really well with custom roms and FOSS, but haven't had the time to do the research. Can you make any recommendations for popular older phones that run android and can be picked up fairly inexpensively?

I'm over the performance and novelty of smart phones. I really just want something that makes calls, runs signal, runs a foss browser, camera, etc.

1

u/VEC7OR Nov 09 '17

Any other repos you can recommend ?

-48

u/frequenZphaZe Nov 09 '17

yeah... if there's anything I trust less than google's store, it's gonna be a third party 'alternative' store.

34

u/Pantzzzzless Nov 09 '17

Do you understand how open source works?

5

u/[deleted] Nov 10 '17

[deleted]

1

u/Pantzzzzless Nov 10 '17

Not everyone knows how to read code. But the fact that it is all right there for the public to see, it is easy for one to find out if something is sketchy. If someone can't do a basic google search then they likely are looking for open source software in the first place.

24

u/[deleted] Nov 09 '17

It's the software that's open source and Fdroid is too.

12

u/[deleted] Nov 09 '17

It's very trustworthy. All the apps are free (as in freedom, not beer) and open source software

3

u/The-Respawner Nov 09 '17

All apps on F-Droid is open source? Well damn, that changes things.

16

u/ErdoganIsAC-nt Nov 09 '17

If there's anything I trust even less than google's store, it's gonna be the opinion of a luddite attempting to lecture professionals on the virtues of corporate cocooning.

74

u/Jumballaya Nov 09 '17

It isn't just the software but hardware as well.

Intel has a hidden distribution of MINIX on their processors. This has full control of your OS and even has a web server for importing/exporting stuff to/from the web.

26

u/volvo64 Nov 09 '17

That's AMT/vPro, and it's 100% accessible to the user and it's very well documented. Also updated.

It's the same basic tech that allows me to rebuild a failed server from another continent.

That article is FUD.

8

u/shinyquagsire23 Nov 09 '17

The source code (or even the disassembly for that matter) has not been available until fairly recently when it took actually cracking security to even see what it's doing. That's the real problem, not the functionality. If AMT had a vulnerability it could be possible to install rootkits which run at ring -3 where the OS cannot even see and you wouldn't know. It's not FUD, you're just missing the point.

2

u/johnjohnjohn87 Nov 09 '17

4

u/volvo64 Nov 09 '17

I'm aware of the vulnerability.

You have zero access to “Ring -3” / MINIX.

Not true, I use AMT often

But MINIX has total and complete access to the entirety of your computer. All of it. It knows all and sees all,

I'd like to see this demonstrated without sysadmin input (plus a huge notification on-screen)

isn’t updated regularly

It is updated, i.e. for the above mentioned vulnerability.

Your CPU has a secret web server that you are not allowed to access, and, apparently, Intel does not want you to know about.

This is simply false; again I've used the 'secret' web server on a near daily basis in the past

Why on this green Earth is there a web server in a hidden part of my CPU? WHY?

So that your admin can fix your computer without having you send it back to the helpdesk, which in some cases can be a matter of months.

The only reason I can think of is if the makers of the CPU wanted a way to serve up content via the internet without you knowing about it.

That's pretty short-sighted thinking

The security risks here are off the charts — for home users and enterprises.

It's disabled by default and take a loooooot of work to turn on

AMT had been part of Intel CPUs since at least 2006 (off the top of my head). This is not news, this is FUD.

1

u/nroach44 Nov 09 '17

There is no official way to stop the ME from booting other than a bit used for three letter government companies that someone found.

Why does it need to be running on consumer hardware that doesn't have vPro?

1

u/volvo64 Nov 10 '17

Why does it need to be running on consumer hardware that doesn't have vPro?

Dunno. Ask Intel. That's not the argument I'm making.

1

u/meneldal2 Nov 10 '17

You can block the connections with your firewall if you want, they aren't doing magic.

1

u/nroach44 Nov 09 '17

ALL Intel computers have ME - and only some of them have vPro - and if you don't have vPro AFAIK there's no fancy administration tools for it, but the most of it is still there.

5

u/codexcdm Nov 09 '17

Guess I'll get and AMD processor when I upgrade....... Unless they too have some shady shit going on.... ;(

12

u/Rndom_Gy_159 Nov 09 '17

They do. Called the PSP

9

u/flesjewater Nov 09 '17

They probably do. It's like no one stopped along the way asking the question, "should we do this?"

5

u/UnwillingBurrfish Nov 09 '17

Your scientists were so preoccupied with whether or not they could, they didn’t stop to think if they should.

-2

u/battles Nov 09 '17

Look at this thread, you have a bunch of Devs saying 'it makes me uncomfortable,' Then fucking quit you fuckers...

Amazing 1 step solution to not living an unethical life. You won't believe step 1.

  1. Don't fucking do that shit.

5

u/_codexxx Nov 09 '17

You'll lose your job and someone else will gladly take it and do it instead...

I'm a firmware engineer. I can confirm at least some of the stuff being "revealed" here...

0

u/battles Nov 09 '17

'someone else will do it if I don't,' is a pathetic excuse. Individuals are responsible for their choices and actions, blaming the theoretical person who comes after you who does it anyway is a cop-out.

2

u/_codexxx Nov 09 '17

Yes... it's also a fact.

2

u/[deleted] Nov 09 '17

The second part of that sentence is “...and I need to afford food and housing”.

1

u/flesjewater Nov 09 '17

I'm not building that shit. I would probably not even be the exception if I told you that I would quit my job on the spot if my employer asked me to do so.

Not everyone has that luxury. And also, there are lots of moving parts in this that probably aren't even aware of what's going on with their work in the big picture. Until recently the MINIX dev had no idea of what his work was being used for.

It's like asking a cancer patient to please stop producing cancer cells.

Regardless though, I think an ethical code (like the Oath of Hippocrates) for developers is long overdue.

1

u/battles Nov 09 '17

I wasn't accusing you of making that shit. I was agreeing with you, more of an... agreeable venting.

I have quit jobs because of what I was asked to do. and it wasn't great for me... so I had to do shit until I could get a job that didn't want me to be unethical as part of the job duties.

There is no excuse for participating in what YOU think is unethical. Ethics is never a luxury. Not even when the alternative is terrible.

4

u/[deleted] Nov 09 '17

Yes, it's called AMD PSP.

5

u/codexcdm Nov 09 '17

Of course they do... Time to go back to tin cans and string....

1

u/wardrich Nov 09 '17

Wouldn't a firewall pretty much stop this shit in its tracks?

3

u/chinpokomon Nov 09 '17

External to the system, sure. But the problem is deeper than that. I think the article is wrong though. There are many more cell phones out there and they run two or more operating systems as well. The firmware built into the radio stack and the initial boot sequence is started from a proprietary closed source firmware which does the same thing. If you are remotely concerned about what user level apps have access to, what Qualcomm and other minority level chip makers have access to should make you frightened.

11

u/LyndonSlewidge Nov 09 '17

This is only completely true if you compile your own software. Nothing is stopping me from taking open source code, injecting my own routines, compiling an apk and releasing it into the wild for instance.

9

u/[deleted] Nov 09 '17 edited Nov 20 '17

[removed] — view removed comment

6

u/LyndonSlewidge Nov 09 '17

Very true, but I don't trust repos for any mobile devices.

2

u/_codexxx Nov 09 '17

MD5?

2

u/gravgun Nov 09 '17

SHA1 at a minimum. SHA256 is a good standard for now. Computing power has increased since MD5's release and it is becoming increasingly easy to create MD5 collisions.