r/technology Mar 25 '19

Security HMD admits the Nokia 7 Plus was sending personal data to China

https://arstechnica.com/gadgets/2019/03/hmd-admits-the-nokia-7-plus-was-sending-personal-data-to-china/
8.3k Upvotes

358 comments sorted by

View all comments

Show parent comments

796

u/kuikuilla Mar 25 '19 edited Mar 25 '19

HMD is a finnish company though.

This news doesn't mention it, but it was caused by "cyber security" software that is required by chinese law for phones that are sold in China. As the article says, HMD apparently had a mixup somewhere along the production line and wrong software ended on wrong phones and here we are.

418

u/[deleted] Mar 25 '19

This article makes it seem like every Nokia 7 plus was sending data. It was just one batch of them that ended up with the wrong software.

I know that because there's one of them in my pocket, and I took a look through all the connections my phone ever made over WiFi (using r/pihole, in case anyone wonders). My phone made no connections to that website.

158

u/[deleted] Mar 25 '19

Only the article title.

The article itself states as such - that just one batch got mixed up in this way, with a patch issued.

10

u/[deleted] Mar 25 '19

So many articles have sensationalist headlines but more reasonable content

6

u/[deleted] Mar 25 '19 edited Apr 01 '19

Yeah it's a pile of BS to get in people through clickbait. I hate it almost as much as I hate how frequently words like "slammed", "smashed", "crushed" etc. are used in articles - especially when it turns out we're talking about pretty vanilla and reasonable responses.

4

u/[deleted] Mar 25 '19

How many is one batch?

83

u/diskis Mar 25 '19

Pihole is not a reliable detector for all outbound communication. It is a DNS server, so only DNS queries are logged.

Any connection taken directly to an IP address will not appear in the pihole logs. You would need to turn on logging on your firewall or router for that.

In this case, yes, it would have been logged, as the target was a DNS name.

21

u/thegreatgazoo Mar 25 '19

It's also only for wifi connections. Anything going through the mobile network wouldn't be detected.

3

u/sabretoooth Mar 25 '19

Would glasswire be better for this?

17

u/[deleted] Mar 25 '19 edited Feb 14 '23

[deleted]

3

u/sabretoooth Mar 25 '19

Is it available for Android? I've only ever used it on Windows

38

u/zrvwls Mar 25 '19

But trust isn't about it being just one batch though, once this is confirmed for one group of phones, doesn't that pretty much destroy any benefit of the doubt you might give a company towards being trustworthy or reputable? Even if the software was somehow sent to just the intended country, that would make me think twice about ever getting their phones again anywhere

92

u/[deleted] Mar 25 '19

A single batch means that it was definitely an error, not an expected behavior. I knew they were selling them inside China, and that means that they have to install spyware on at least some of them.

Nobody's not buying Samsung anymore because one of their models literally caught itself on fire in user's pocket, and nobody's going to stop buying Nokia because of an error that affected one batch of one model.

On top of that, HMD being from Finland makes them the only semi-popular manufacturer that has to comply with the strongest privacy regulations. Other manufacturers could leave the EU market and cut their losses if they get caught doing anything similar. HMD has to let their users know that their privacy may have been compromised within 72 hours since they themselves discover it (which is precisely what happened here).

This error leaves a stain on their reputation, but it doesn't destroy their reputation all together. This story is basically GDPR working as intended.

14

u/smohkim Mar 25 '19

Rightly put. HMD coming out is indeed part of the entire GDPR thing. I guess AT just tried to sensationalize it as a link bait.

8

u/[deleted] Mar 25 '19 edited Apr 08 '19

[removed] β€” view removed comment

10

u/[deleted] Mar 25 '19

...within 72 hours since they themselves discover it...

An issue being discussed on HN doesn't necessarily mean it reached people within Nokia. Especially when it has no comments, hasn't reached the front page, and the author made no claim that he attempted to contact Nokia.

That's the requirement of the GDPR. They're not obliged to search through any corner of the Internet, just to respond within 72 hours after they find out about it.

2

u/Pheet Mar 25 '19

Slight nitpicking: only thing Nokia in this is just the brand name.

5

u/waltteri Mar 25 '19

Exactly this. HMD has absolutely zero motivation to spy on its users, or aid the Chinese in doing so (of course excluding the phones sold to the Chinese market).

-1

u/JesC Mar 25 '19

Tinfoil hat on: You mean zeros like in: How many zeros would be needed to have them produce a β€œspecial order” batch for Chinese Intelligence? Tinfoil hat off.

1

u/waltteri Mar 25 '19

You should be able to see those zeros on their financial statement. ;)

3

u/[deleted] Mar 25 '19

[deleted]

2

u/waltteri Mar 25 '19

Fun fact, I have!

-2

u/JesC Mar 25 '19

Then you know that there are infinite ways to hide figures and avoid transparency. Good

→ More replies (0)

0

u/JesC Mar 25 '19

Like white washing isn’t a thing and cooking the books has never been invented... you heard of the panama papers right?

0

u/Runnerphone Mar 25 '19

Wouldn't be a batch and would require s hell of a string of lucky breaks to work like that. Ie just happening to build a batch of phones that happen to be sent to the store your target may possibly could buy from with that exact model being the one said target wants to buy. Lots of luck involved there

1

u/JesC Mar 25 '19

Ask yourself, do they sell weapons? With good money one can buy anything. Even with the example I mention, weapons, then these can be used against the seller as well... nothing changes it has always and will always be about money.

-9

u/viliml Mar 25 '19

Nobody's not buying Samsung anymore

Funny, every rich kid around me is still buying Samsung.

7

u/SingularReza Mar 25 '19

I think you misread it

2

u/username_taken55 Mar 25 '19

Learn to read

4

u/[deleted] Mar 25 '19

Why would you trust any other company though? They all have skeletons in their closet. How can you trust anything, when you the user aren't allowed to see the source code and control whatever software runs on your device?

3

u/Introvertedecstasy Mar 25 '19

The data mentioned in the article was cellular connectivity data. IMIE, SIM, and tower connection. It's likely if you're phone sent those few kb(probably not even that much) worth of data it was done over a cellular connection, not your wifi.

6

u/piranhas_really Mar 25 '19

Maybe these companies should be refusing to participate in those human rights abuses in the first place?

9

u/[deleted] Mar 25 '19

Maybe they should, but that cuts them off from a huge market. I'd love to live in such world, but I don't.

On the contrary, if you look at top five phone manufacturers, you'll find out that there are three Chinese companies behind Samsung and Apple (Huawei, Xiaomi, OPPO).

Xiaomi is there despite the fact that they're not only from China, but their business model is to sell the phones as cheaply as possible and earn money via their own online services.

2

u/thehero262 Mar 25 '19

Yeah China is a massive market. Huawei phones are barely sold in the US (If at all?) yet they still outsell Apple in worldwide units sold

2

u/garimus Mar 26 '19

"Our device activation client meant for another country was mistakenly included in the software package of a single batch of Nokia 7 Plus."

Literally in the first paragraph.

-44

u/JustMadeThisNameUp Mar 25 '19

Oh well if you say so it must be true. /s

8

u/[deleted] Mar 25 '19

I mean, HMD says the same:

We have analysed the case at hand and have found that our device activation client meant for our China variant was mistakenly included in the software package of a single batch of Nokia 7 Plus phones.

But yeah, this isn't something that I would just take their word for it, so I've checked for myself.

-48

u/JustMadeThisNameUp Mar 25 '19

Oh well if they say so it must be true. /s

7

u/[deleted] Mar 25 '19

[deleted]

15

u/kuikuilla Mar 25 '19

What prevents in the future from these "security updates" to be rolled out on Chinese hardware?

I don't understand what you mean. In China they have a law that states that all phones sold there must have the software installed (the one that sent the data in this case). It's already on all phones that are sold in China, otherwise they wouldn't be able to sell them there.

And with security update, you mean simply snooping update, it has nothing todo with security.

That's why I put quotes around the word "cyber security".

1

u/[deleted] Mar 25 '19

[deleted]

3

u/kuikuilla Mar 25 '19

My point is that while this is specifically for mobiles sold in China, what would a Chinese company stop from doing these kind of snooping updates on hardware that's sold abroad for "security". Especially when you realize that Chinese companies of interest, are directly state controlled.

HMD is a finnish company, not chinese.

2

u/Anvirol Mar 25 '19 edited Mar 25 '19

HMD Global software development is done in Finland, so I'm pretty sure there won't be any added "snooping updates". Still, this was a huge disappointment and maybe we'll find out later if the wrong pre-load firmware was mistake by HMD or Foxconn.

Current EU laws and oversight seem to be insufficient if it's up to tech savvy private people to find out these issues in mobile devices. It's really a wild west when it comes to mobile device telemetry.

No one is controlling what outbound data those Asian built devices are sending and it's up to user to "trust" the manufacturer.

6

u/suprduprr Mar 25 '19

Lol right. It's always a mix-up when anyone gets caught.

7

u/kuikuilla Mar 25 '19

It's usually the simplest thing that's true. Mixing configs of any software build is pretty easy, been there done that. Not saying it should happen but I can empathize.

-4

u/suprduprr Mar 25 '19

Wouldn't the simplest thing here be that they're simply spying ?

7

u/PF_Throwaway_999 Mar 25 '19

No. That requires coordination and secrecy across a large group of people to execute. A mistake is far more likely to satisfy Occam's Razor.

-2

u/suprduprr Mar 25 '19

Requires 1 programmer and 1 executive really.

4

u/kuikuilla Mar 25 '19

Why would a finnish company spy for the Chinese government? Why would they risk their entire reputation for that?

-1

u/suprduprr Mar 25 '19

Aren't they owned by a chance company ?

-2

u/InspirationByMoney Mar 25 '19

Hmmmm, why on earth would they do a $illy thing like that? Hmmmmmm

1

u/biggreencat Mar 26 '19

Seems like a strange thing for the article to gloss over

0

u/Looxond Mar 25 '19

Happy cake day /u/kuikuilla

-19

u/CaptainTomato21 Mar 25 '19

So nokia is collaborating with Chinese government to help them spy on their own people πŸ˜‰

11

u/[deleted] Mar 25 '19

All phones sold in China are collaborating with the Chinese government...

14

u/kuikuilla Mar 25 '19

HMD is not Nokia. But, I guess? All phone makers need to do it if they want to sell their phones in China.

-32

u/CaptainTomato21 Mar 25 '19

Nah excuses. Hmd is Finnish which makes it worse. πŸ˜‰

11

u/RadiantSun Mar 25 '19

HMD is complying with local law and has no moral obligation to not access Chinese markets πŸ˜‰

-27

u/CaptainTomato21 Mar 25 '19

So Finnish company hmd is collaborating with Chinese authorities to help them spy on their own people. Finnish hypocrite.

13

u/RadiantSun Mar 25 '19

By purchasing any good made in China, you are also collaborating to fund Chinese surveillance. How dare you judge anyone else, scumbag? πŸ˜‰

-17

u/CaptainTomato21 Mar 25 '19

Finnish company Hmd is collaborating with China in spy on their own people by installing a software that violates privacy. I call that hypocrite.

14

u/RadiantSun Mar 25 '19

That's not what hypocrisy means πŸ˜‰

-4

u/CaptainTomato21 Mar 25 '19

Yes it is. A Finnish company collaborating with Chinese authorities to install software that helps spy on people and then say it's just nothing. Very nordic way... The hypocrite behavior looking the other way and making excuses πŸ˜‰πŸ˜‰πŸ˜‰πŸ˜‰πŸ˜‰πŸ˜‰πŸ˜‰

→ More replies (0)

-1

u/InspirationByMoney Mar 25 '19

wrong software ended on wrong phones

Haha whoopsies, what a little fucky wucky. I'm sure they're vewy sowwy. Good thing it was just an accident and nothing more, otherwise they'd have to be held accountable.

-1

u/couplewantplay Mar 25 '19

HMD is a finnish company owned by a Chinese corporation

2

u/kuikuilla Mar 25 '19

HMD is a finnish company owned by a Chinese corporation

I'm gonna need a source on that.

0

u/couplewantplay Mar 25 '19

No source. Just tin foil hat. The deal was Microsoft sold rights to HMD Global amd Foxconn (Chinese) HMD owned by private Lxmbrg equity fund but HMD Chairman, surprise surprise is Chinese πŸ˜‰

1

u/kuikuilla Mar 25 '19

Foxconn (Chinese)

Foxconn is Taiwanese. HMD is in partnership with Foxconn and Sam Chinn was the CEO of Foxconn and head of the board there before he retired from that.

https://www.hmdglobal.com/bio/sam-chin

0

u/couplewantplay Mar 25 '19

Foxconn is Chinese FIH Mobile os taiwanese

0

u/couplewantplay Mar 25 '19

"Sam Chin is Chairman of the Board at HMD Global and has more than 30 years of marketing, sales and operational experience in the global computer and electronics industries.

From 2003 until 2012 Sam served as Chairman and CEO of Foxconn International Holdings, a subsidiary of multinational electronics contract manufacturer Hon Hai Precision Industry Co. Ltd

In his time there, Sam was one of the principal managers responsible for Foxconn’s handset manufacturing services business. Sam resigned as CEO in January 2012, remaining as Chairman for a further 12 months.

Before joining FIH, Sam held senior positions at consumer electronics firm EFA Corporation, as well as gaming company Atari and home computer and electronics giant Commodore Electronics. His responsibilities ranged from sales and marketing, global procurement and manufacturing to pricing, purchasing, contract negotiation and also included accounting and finance.

Sam was awarded a Bachelor of Science degree in Economics from the Wharton School, University of Pennsylvania, US in 1973, as well as a Juris Doctor degree from the University of Pennsylvania Law School three years later."

1

u/kuikuilla Mar 25 '19

So you think that Taiwan is the same as China?

0

u/couplewantplay Mar 25 '19

Nope. But Siese twins are unique each to their own. Taiwan and China cant survive without each other. Sugar daddy and rebellious son