[HN Gopher] I Tested an HDMI Adapter That Demands Your Location ...
___________________________________________________________________
I Tested an HDMI Adapter That Demands Your Location and Spams You
with Ads
Author : ghostDancer
Score : 170 points
Date : 2023-09-29 17:05 UTC (5 hours ago)
(HTM) web link (www.404media.co)
(TXT) w3m dump (www.404media.co)
| [deleted]
| freitzkriesler2 wrote:
| Burn it with fire and wipe that iPhone twice. Stuff like that
| terrifies me.
| cwoolfe wrote:
| Given that the device is plugged in, trusted, shows up as a
| computer, and requires external power, it has all the connections
| it needs spy on the screen (at minimum) and remote control the
| victim iPhone without permission in the worst case. (it has video
| feed, and can emulate USB keyboard and mouse) Yikes!
| mtreis86 wrote:
| How hackable is it? That could be useful
| jjoonathan wrote:
| Integrating everything into USB has been great at physical
| simplification, but it really opened up the attack surface.
|
| First party malware is the worst.
| kibwen wrote:
| From the photos, this looks like a Lightning cable, not a USB
| cable.
| mutex_man wrote:
| They're referring to the USB protocol, which lightning
| uses.
| maltalex wrote:
| It's odd that 404 Media chose a .co (Colombia) TLD.
| [deleted]
| dotluis wrote:
| Colombia, not Columbia.
| maltalex wrote:
| My bad. Fixed.
| burnte wrote:
| Not really, lots of companies use .co instead of .com because
| there's different availability. It's been a second tier
| alternative to .com for years.
| theandrewbailey wrote:
| Technically, it's still the ccTLD for Colombia, even though
| anyone can register a .co domain, similar to .io (for British
| Indian Ocean Territory).
|
| https://en.wikipedia.org/wiki/.co
| tredre3 wrote:
| Colombia, not Columbia.
| theandrewbailey wrote:
| You're right, fixed.
| input_sh wrote:
| There's a lot of ccTLDs that are considered to be
| "generic": .ai, .as, .fm, .io, .me, .tv, .ws...
|
| For example Google search will treat them the same as .com,
| while others like .de or .fr are gonna be interpreted as if
| your website is targetting a specific market.
| burnte wrote:
| That is true, but no one is disputing that.
| walthamstow wrote:
| Not as odd as Notion dot Somalia
| rnk wrote:
| The saluspa from "bestway" demands your location before allowing
| you to setup wifi remote control of the portable hot tub on the
| android app. I wonder how on android I can spoof the location
| used by an app, or if anyone figured out if you can control it
| without the app.
|
| I set it up away from my house and use a separate wifi network
| but it pissed me off.
| qingcharles wrote:
| I tried to use Fanduel last night to place some bets for my
| friend in prison. It requires your location. You have to
| install some horrible app that installs a Windows Service and
| has no UI. It still won't work.
|
| After a lot of digging around, I discovered you cannot use
| Fanduel if you have a wired device. The app _requires_ you to
| connect to your router by Wifi or it will not work. WTF.
| bippihippi1 wrote:
| I wonder if their terms of service states claims to give them
| permission to distribute malware or if they think they won't
| get caught.
| gruez wrote:
| Maybe it's for compliance reasons? in other words they really
| want to know you're in a jurisdiction that allows gambling,
| and not using a VPN or whatever.
| maldev wrote:
| This could be a overly cautious legal requirement. I know
| heaters(dyson) won't allow you to control heat remotely in some
| locations, so instead of yanking out hot water from the app,
| they decide to ask your location to verify you're home.
| niij wrote:
| Android apps used to need "location" access for bluetooth
| discovery.
| https://www.androidpolice.com/2021/05/19/android-12-apps-won...
| Larrikin wrote:
| The other poster already explained the old permission.
| There's also a new permission specifically for Bluetooth LE
| now as well for newer devices so location shouldn't be
| needed.
| netsharc wrote:
| Because your location can be inferred by finding which
| Bluetooth devices are around you, as that article says...
|
| > See, back in Android 6 Marshmallow, Google changed things
| so that apps needed location permissions to scan for
| Bluetooth devices. At the time, the rationale was that
| Bluetooth was going to be used for things like interior
| navigation or location tracking in a more abstract sense, and
| your location could indirectly be inferred via Bluetooth
| scanning alone if a given hardware identifier was tied to a
| specific location.
| rightbyte wrote:
| I have always assumed that is a way for Google to normalize
| granting the position permission.
|
| You could "pair" apps with devices if Bluetooth position
| spyware was a concern.
| GauntletWizard wrote:
| Before Android required that permission, there were
| marketing companies selling malls the ability to see who
| was around by the ID of their Bluetooth beacon.
| folmar wrote:
| But pairing work well without the app involved, we could
| just give a permission to a specific already-paired
| devices and keep location for apps that actually need to
| scan.
| JohnFen wrote:
| I would have returned it for a refund, personally.
| dylan604 wrote:
| The 4 outlet water timer I bought came with bluetooth remote
| functionality. It needs GPS location data for it to work. Nope.
| Should have known some shit like that would be part of the
| deal, and could have saved a few bucks by getting the version
| without remote.
|
| People need to just stop with this tracking bullshit.
| hedora wrote:
| In fairness, some of those pull precipitation, heat and
| transpiration info from weather reports.
|
| It still shouldn't require it though. At least on iOS,
| requiring it should get them banned from the app store.
|
| I want side loading to exist for iOS, but I also want bans
| like the above to apply at my discretion to anything I pay
| money for.
| dylan604 wrote:
| anyone making a "smart" water timer using today's weather
| forecasting would be something that could be called "The
| Plant Killer". my area can say that there's 80% chance of
| rain, yet not one drop can fall where I am while other
| areas can say they received .25" of rain. sounds like
| watering isn't necessary. oops. dead plants. There's other
| times where no weather is forecast, yet I've received .25"
| of rain. oops. wasted water. also, your "smart" decision to
| not water because of rain means all of the plants on my
| patio didn't get watered while I was on vacation/work
| trip/etc, which is the primary reason I bought the timer in
| the first place.
|
| Your smart is dumb. Just turn the water on at the time I
| said. That's plenty smart for me. If I can update the
| schedule from my couch, great! But...not at the expense of
| all of this tracking bullshit
| blibble wrote:
| how long until everything on Amazon is doing this?
| reilly3000 wrote:
| I say the big 404 and instinctively bounced. I can't be the only
| one. I went back to find their 404 page and am quite satisfied
| with what I found: https://www.404media.co/i-te/
| ASalazarMX wrote:
| The cyberdemon really ties the room together.
| gpderetta wrote:
| Very nice old school Geocities look.
| swader999 wrote:
| All the people involved in this product need a significant public
| award for their efforts.
| xavdid wrote:
| Not related to this story specifically, but I've been very
| impressed with 404 media's stories thusfar. They haven't been
| around long, but they've already done a lot of impressive
| journalism. I'm glad we've finally got a tech media outlet with
| teeth.
| mixmastamyk wrote:
| > I decided to connect the cord using an old iPhone that I no
| longer use and that no longer has anything I care about on it.
|
| Uh oh. Hope that means securely wiped and not just "I deleted the
| notes and photos and put in a drawer."
| proactivesvcs wrote:
| I Visited a Web Site That Demands My Email Address to Spam Me
| With Newsletters.
| HumblyTossed wrote:
| And yet, we can't have side loaded apps because somehow that
| would make the App Store worse. Phooey!
| LeoPanthera wrote:
| This is not the gotcha you think it is. Imagine how awful the
| apps we would be forced to sideload would be, if companies like
| the one that made this dongle were allowed to make them.
| pdntspa wrote:
| Computers have been that way since forever. It wouldn't be
| nearly as bad as you make it out to be.
| mixmastamyk wrote:
| I don't know. This app from the app store is already near 80%
| of the worst I could imagine. Only formatting the storage
| might be worse... and then they wouldn't get any more juicy
| location data.
| TulliusCicero wrote:
| Ah yes, the many apps poor Android users are forced to
| sideload.
|
| As an Android user myself, so far I'm up to...zero?
| twiceaday wrote:
| You are correct in lampooning the word "force" but don't
| throw out the baby with the bathwater. The point is still
| valid. Also, it seems obvious that the danger is in long-
| term ecosystem implications. "I haven't had to so far" is
| irrelevant.
|
| Android users had/have(?) to side-load Fortnite. Depending
| on who you are that might feel like being "forced." Is your
| argument "If you feel like you are forced to use some app
| you are wrong and should just stop" or is it "If an app
| gets big enough that a lot of people feel forced to side-
| load it, then it earned the right not to abide by any
| platform holder policies."
| WarOnPrivacy wrote:
| > You are correct in lampooning the word "force" but
| don't throw out the baby with the bathwater. The point is
| still valid.
|
| I have yet to see one, client, customer, friend,
| acquaintance, relative (or rando who happened to know I'm
| an IT guy) sideload an app without knowing what they were
| doing & having a good reason to do so.
|
| The list of those who sideloaded _is_ small. However, my
| list of technically hapless folks is much, much larger -
| and zero of them seem to have sideloaded anything ever.
| There 's a fair chance I'd wind up knowing if they did.
|
| Even my often homeless ex who's down with plugging any
| connector into any port at any time of day (shapes need
| not match) doesn't seem to have sideloaded. Certainly her
| devices are always in a Sideloading=Off state when I
| check (she is not now a developer!).
|
| From an IT view, unintended sideloading looks like a low
| priority concern.
| [deleted]
| NotYourLawyer wrote:
| Presumably you don't have any shitty hardware like this
| cable.
| RajT88 wrote:
| If you own a mainstream android device, you're probably not
| going to ever have to.
|
| If you have something a little weirder, the app store often
| will not let you install an app which doesn't state
| compatibility. Sideloading the APK more often than not
| works fine.
|
| Also, there's alternative sources like F-Droid which have
| stuff you can't get in the Google app store - ad-free
| Youtube apps - that will never be allowed on the Google app
| store.
| hedora wrote:
| Does Google ban apps that break if location information is
| denied?
|
| The last time I checked, Apple did and Google did not.
| denton-scratch wrote:
| So from my reading, the shitty behaviour is from the app, not the
| cable. Have I misread it?
|
| What happens if you try to use the cable without downloading the
| app? I for one would assume that my cable was defective, if it
| needed an app to work. I realize that HDMI cables are weird, and
| that like quite a lot of modern interconnect are not a monolithic
| standard, but come with multiple support levels; I wish that
| would stop.
|
| A standard is a standard, and market partitioning is no part of
| the job of a standard.
| fckgw wrote:
| The adapter flashes a QR code on your monitor. It's not plug-n-
| play.
| numpad0 wrote:
| I think I've come across this specific screen. In my case,
| this was its equivalent of "No Signal" screen, and the app
| was only needed to update the firmware if needed, not to
| connect. It seemed to exploit AirPlay somehow and therefore
| finicky unlike official dongles.
| RetroTechie wrote:
| _Requiring_ the use of an app, in order to use some kind of
| adapter cable? I must be getting old, feel like I 've just
| crawled from under a rock... :-)
|
| That would also mean this cable becomes useless the moment
| URL encoded in the QR disappears?
|
| As for the app: even if it's total crap, if only 50% of
| cable-buyers proceed to install the app, that 50% is still
| gained as potentially spied-upon subjects. There's a new
| please-spy-on-me sucker born every day, so to speak.
| eastbound wrote:
| The nice thing about such a cable is that it could connect
| to the cloud to display that screen without plugging the
| other end.
| MBCook wrote:
| Does it really matter? This isn't a real product. It's a
| scam product to trick people trying to buy a real Apple
| part and con them into the app's clutches.
|
| The real part doesn't need anything. Plug and go.
| bitwize wrote:
| It's not really an adapter cable. It's got a little SOC in
| there that streams your iPhone's display from the app to
| the HDMI port.
|
| Meanwhile, your personal data is being streamed back to
| China...
| ThatPlayer wrote:
| The official Apple HDMI adapter does the same thing with
| an SoC in there. The difference is native iOS support
| instead of a 3rd party app needed to support it.
| ASalazarMX wrote:
| Part of me is looking forward to the time when a
| government activates a significant part of all the
| spyware/adware/backdoors/etc in the world as part of a
| cyberwar. COVID would be a child's game compared to that,
| but that disaster would at last make people understand
| how bad tech has become at this point.
|
| Double points if the operation is started by another
| state/group that stole those backdoors.
| eastbound wrote:
| The worst part of adult life is realizing you already
| live in a world where this happens. Regularly. And no-one
| bats an eye. And you try to maintain sanity by adding
| hypothesis ("But I mean, with the government giving the
| keys to...") and all of the evil you can think of, also
| exists.
| mock-possum wrote:
| Shitty. I wonder what kind of profit they make per successful
| scam.
| MBCook wrote:
| Well a single un-refunded $50/mo transaction is pretty good,
| plus whatever they can get from ads and selling data.
| jmrm wrote:
| This kind of shady devices should be banned in Western Countries,
| not only for trying to get their users' information, but also for
| being a device that can go directly to the e-Waste bin without a
| minimal usage
| ale42 wrote:
| They should be banned everywhere...
| [deleted]
| expertentipp wrote:
| I have an impression that covid enabled widespread acceptation of
| QR codes, and now every app is excused to request camera and
| photo access because "we need to scan a QR code".
| alwayslikethis wrote:
| It would be nice to have a special way to scan a qr code in
| which the system reads the QR code for the app without the app
| being able to see raw camera data.
| hedora wrote:
| I think this flow sort of supports that.
|
| https://9to5mac.com/2020/10/07/limit-third-party-iphone-
| phot...
|
| If I remember right, there's a way to get a "take picture"
| option in the chooser. I'm not sure how the qr code would
| then be recognized, though I'm not sure why you wouldn't have
| them get the qr code via the system camera app.
| MBCook wrote:
| That's intended for selecting a pre-taken photo without
| giving an app library access. You'd have to get the user to
| take the picture then come back to your app.
|
| What you really need is a system dialogue that pops up the
| camera and only returns the QR code to the app, the way the
| photo picker can see the whole library but only gives the
| app the one selected photo.
| gkbrk wrote:
| Pretty sure Android has this. You can make an app without
| camera permissions, send an intent that opens the built-
| in camera to take a picture and you are given access to
| only that picture. It means you cannot record things in
| the background all the time, and users don't need to make
| a decision about a sensitive permission.
| folmar wrote:
| I don't know for iOS but on Android they are not excused, just
| register intent for your url and let the system camera app/qr
| code scanner pass it.
|
| Effectively you can expect it to work for Android 8+ as the
| previous versions don't necessarily have a QR code scanner.
| jollyllama wrote:
| [flagged]
___________________________________________________________________
(page generated 2023-09-29 23:01 UTC)