[HN Gopher] I Tested an HDMI Adapter That Demands Your Location ...
       ___________________________________________________________________
        
       I Tested an HDMI Adapter That Demands Your Location and Spams You
       with Ads
        
       Author : ghostDancer
       Score  : 170 points
       Date   : 2023-09-29 17:05 UTC (5 hours ago)
        
 (HTM) web link (www.404media.co)
 (TXT) w3m dump (www.404media.co)
        
       | [deleted]
        
       | freitzkriesler2 wrote:
       | Burn it with fire and wipe that iPhone twice. Stuff like that
       | terrifies me.
        
       | cwoolfe wrote:
       | Given that the device is plugged in, trusted, shows up as a
       | computer, and requires external power, it has all the connections
       | it needs spy on the screen (at minimum) and remote control the
       | victim iPhone without permission in the worst case. (it has video
       | feed, and can emulate USB keyboard and mouse) Yikes!
        
         | mtreis86 wrote:
         | How hackable is it? That could be useful
        
         | jjoonathan wrote:
         | Integrating everything into USB has been great at physical
         | simplification, but it really opened up the attack surface.
         | 
         | First party malware is the worst.
        
           | kibwen wrote:
           | From the photos, this looks like a Lightning cable, not a USB
           | cable.
        
             | mutex_man wrote:
             | They're referring to the USB protocol, which lightning
             | uses.
        
       | maltalex wrote:
       | It's odd that 404 Media chose a .co (Colombia) TLD.
        
         | [deleted]
        
         | dotluis wrote:
         | Colombia, not Columbia.
        
           | maltalex wrote:
           | My bad. Fixed.
        
         | burnte wrote:
         | Not really, lots of companies use .co instead of .com because
         | there's different availability. It's been a second tier
         | alternative to .com for years.
        
           | theandrewbailey wrote:
           | Technically, it's still the ccTLD for Colombia, even though
           | anyone can register a .co domain, similar to .io (for British
           | Indian Ocean Territory).
           | 
           | https://en.wikipedia.org/wiki/.co
        
             | tredre3 wrote:
             | Colombia, not Columbia.
        
               | theandrewbailey wrote:
               | You're right, fixed.
        
             | input_sh wrote:
             | There's a lot of ccTLDs that are considered to be
             | "generic": .ai, .as, .fm, .io, .me, .tv, .ws...
             | 
             | For example Google search will treat them the same as .com,
             | while others like .de or .fr are gonna be interpreted as if
             | your website is targetting a specific market.
        
             | burnte wrote:
             | That is true, but no one is disputing that.
        
         | walthamstow wrote:
         | Not as odd as Notion dot Somalia
        
       | rnk wrote:
       | The saluspa from "bestway" demands your location before allowing
       | you to setup wifi remote control of the portable hot tub on the
       | android app. I wonder how on android I can spoof the location
       | used by an app, or if anyone figured out if you can control it
       | without the app.
       | 
       | I set it up away from my house and use a separate wifi network
       | but it pissed me off.
        
         | qingcharles wrote:
         | I tried to use Fanduel last night to place some bets for my
         | friend in prison. It requires your location. You have to
         | install some horrible app that installs a Windows Service and
         | has no UI. It still won't work.
         | 
         | After a lot of digging around, I discovered you cannot use
         | Fanduel if you have a wired device. The app _requires_ you to
         | connect to your router by Wifi or it will not work. WTF.
        
           | bippihippi1 wrote:
           | I wonder if their terms of service states claims to give them
           | permission to distribute malware or if they think they won't
           | get caught.
        
           | gruez wrote:
           | Maybe it's for compliance reasons? in other words they really
           | want to know you're in a jurisdiction that allows gambling,
           | and not using a VPN or whatever.
        
         | maldev wrote:
         | This could be a overly cautious legal requirement. I know
         | heaters(dyson) won't allow you to control heat remotely in some
         | locations, so instead of yanking out hot water from the app,
         | they decide to ask your location to verify you're home.
        
         | niij wrote:
         | Android apps used to need "location" access for bluetooth
         | discovery.
         | https://www.androidpolice.com/2021/05/19/android-12-apps-won...
        
           | Larrikin wrote:
           | The other poster already explained the old permission.
           | There's also a new permission specifically for Bluetooth LE
           | now as well for newer devices so location shouldn't be
           | needed.
        
           | netsharc wrote:
           | Because your location can be inferred by finding which
           | Bluetooth devices are around you, as that article says...
           | 
           | > See, back in Android 6 Marshmallow, Google changed things
           | so that apps needed location permissions to scan for
           | Bluetooth devices. At the time, the rationale was that
           | Bluetooth was going to be used for things like interior
           | navigation or location tracking in a more abstract sense, and
           | your location could indirectly be inferred via Bluetooth
           | scanning alone if a given hardware identifier was tied to a
           | specific location.
        
             | rightbyte wrote:
             | I have always assumed that is a way for Google to normalize
             | granting the position permission.
             | 
             | You could "pair" apps with devices if Bluetooth position
             | spyware was a concern.
        
               | GauntletWizard wrote:
               | Before Android required that permission, there were
               | marketing companies selling malls the ability to see who
               | was around by the ID of their Bluetooth beacon.
        
               | folmar wrote:
               | But pairing work well without the app involved, we could
               | just give a permission to a specific already-paired
               | devices and keep location for apps that actually need to
               | scan.
        
         | JohnFen wrote:
         | I would have returned it for a refund, personally.
        
         | dylan604 wrote:
         | The 4 outlet water timer I bought came with bluetooth remote
         | functionality. It needs GPS location data for it to work. Nope.
         | Should have known some shit like that would be part of the
         | deal, and could have saved a few bucks by getting the version
         | without remote.
         | 
         | People need to just stop with this tracking bullshit.
        
           | hedora wrote:
           | In fairness, some of those pull precipitation, heat and
           | transpiration info from weather reports.
           | 
           | It still shouldn't require it though. At least on iOS,
           | requiring it should get them banned from the app store.
           | 
           | I want side loading to exist for iOS, but I also want bans
           | like the above to apply at my discretion to anything I pay
           | money for.
        
             | dylan604 wrote:
             | anyone making a "smart" water timer using today's weather
             | forecasting would be something that could be called "The
             | Plant Killer". my area can say that there's 80% chance of
             | rain, yet not one drop can fall where I am while other
             | areas can say they received .25" of rain. sounds like
             | watering isn't necessary. oops. dead plants. There's other
             | times where no weather is forecast, yet I've received .25"
             | of rain. oops. wasted water. also, your "smart" decision to
             | not water because of rain means all of the plants on my
             | patio didn't get watered while I was on vacation/work
             | trip/etc, which is the primary reason I bought the timer in
             | the first place.
             | 
             | Your smart is dumb. Just turn the water on at the time I
             | said. That's plenty smart for me. If I can update the
             | schedule from my couch, great! But...not at the expense of
             | all of this tracking bullshit
        
       | blibble wrote:
       | how long until everything on Amazon is doing this?
        
       | reilly3000 wrote:
       | I say the big 404 and instinctively bounced. I can't be the only
       | one. I went back to find their 404 page and am quite satisfied
       | with what I found: https://www.404media.co/i-te/
        
         | ASalazarMX wrote:
         | The cyberdemon really ties the room together.
        
           | gpderetta wrote:
           | Very nice old school Geocities look.
        
       | swader999 wrote:
       | All the people involved in this product need a significant public
       | award for their efforts.
        
       | xavdid wrote:
       | Not related to this story specifically, but I've been very
       | impressed with 404 media's stories thusfar. They haven't been
       | around long, but they've already done a lot of impressive
       | journalism. I'm glad we've finally got a tech media outlet with
       | teeth.
        
       | mixmastamyk wrote:
       | > I decided to connect the cord using an old iPhone that I no
       | longer use and that no longer has anything I care about on it.
       | 
       | Uh oh. Hope that means securely wiped and not just "I deleted the
       | notes and photos and put in a drawer."
        
       | proactivesvcs wrote:
       | I Visited a Web Site That Demands My Email Address to Spam Me
       | With Newsletters.
        
       | HumblyTossed wrote:
       | And yet, we can't have side loaded apps because somehow that
       | would make the App Store worse. Phooey!
        
         | LeoPanthera wrote:
         | This is not the gotcha you think it is. Imagine how awful the
         | apps we would be forced to sideload would be, if companies like
         | the one that made this dongle were allowed to make them.
        
           | pdntspa wrote:
           | Computers have been that way since forever. It wouldn't be
           | nearly as bad as you make it out to be.
        
           | mixmastamyk wrote:
           | I don't know. This app from the app store is already near 80%
           | of the worst I could imagine. Only formatting the storage
           | might be worse... and then they wouldn't get any more juicy
           | location data.
        
           | TulliusCicero wrote:
           | Ah yes, the many apps poor Android users are forced to
           | sideload.
           | 
           | As an Android user myself, so far I'm up to...zero?
        
             | twiceaday wrote:
             | You are correct in lampooning the word "force" but don't
             | throw out the baby with the bathwater. The point is still
             | valid. Also, it seems obvious that the danger is in long-
             | term ecosystem implications. "I haven't had to so far" is
             | irrelevant.
             | 
             | Android users had/have(?) to side-load Fortnite. Depending
             | on who you are that might feel like being "forced." Is your
             | argument "If you feel like you are forced to use some app
             | you are wrong and should just stop" or is it "If an app
             | gets big enough that a lot of people feel forced to side-
             | load it, then it earned the right not to abide by any
             | platform holder policies."
        
               | WarOnPrivacy wrote:
               | > You are correct in lampooning the word "force" but
               | don't throw out the baby with the bathwater. The point is
               | still valid.
               | 
               | I have yet to see one, client, customer, friend,
               | acquaintance, relative (or rando who happened to know I'm
               | an IT guy) sideload an app without knowing what they were
               | doing & having a good reason to do so.
               | 
               | The list of those who sideloaded _is_ small. However, my
               | list of technically hapless folks is much, much larger -
               | and zero of them seem to have sideloaded anything ever.
               | There 's a fair chance I'd wind up knowing if they did.
               | 
               | Even my often homeless ex who's down with plugging any
               | connector into any port at any time of day (shapes need
               | not match) doesn't seem to have sideloaded. Certainly her
               | devices are always in a Sideloading=Off state when I
               | check (she is not now a developer!).
               | 
               | From an IT view, unintended sideloading looks like a low
               | priority concern.
        
             | [deleted]
        
             | NotYourLawyer wrote:
             | Presumably you don't have any shitty hardware like this
             | cable.
        
             | RajT88 wrote:
             | If you own a mainstream android device, you're probably not
             | going to ever have to.
             | 
             | If you have something a little weirder, the app store often
             | will not let you install an app which doesn't state
             | compatibility. Sideloading the APK more often than not
             | works fine.
             | 
             | Also, there's alternative sources like F-Droid which have
             | stuff you can't get in the Google app store - ad-free
             | Youtube apps - that will never be allowed on the Google app
             | store.
        
             | hedora wrote:
             | Does Google ban apps that break if location information is
             | denied?
             | 
             | The last time I checked, Apple did and Google did not.
        
       | denton-scratch wrote:
       | So from my reading, the shitty behaviour is from the app, not the
       | cable. Have I misread it?
       | 
       | What happens if you try to use the cable without downloading the
       | app? I for one would assume that my cable was defective, if it
       | needed an app to work. I realize that HDMI cables are weird, and
       | that like quite a lot of modern interconnect are not a monolithic
       | standard, but come with multiple support levels; I wish that
       | would stop.
       | 
       | A standard is a standard, and market partitioning is no part of
       | the job of a standard.
        
         | fckgw wrote:
         | The adapter flashes a QR code on your monitor. It's not plug-n-
         | play.
        
           | numpad0 wrote:
           | I think I've come across this specific screen. In my case,
           | this was its equivalent of "No Signal" screen, and the app
           | was only needed to update the firmware if needed, not to
           | connect. It seemed to exploit AirPlay somehow and therefore
           | finicky unlike official dongles.
        
           | RetroTechie wrote:
           | _Requiring_ the use of an app, in order to use some kind of
           | adapter cable? I must be getting old, feel like I 've just
           | crawled from under a rock... :-)
           | 
           | That would also mean this cable becomes useless the moment
           | URL encoded in the QR disappears?
           | 
           | As for the app: even if it's total crap, if only 50% of
           | cable-buyers proceed to install the app, that 50% is still
           | gained as potentially spied-upon subjects. There's a new
           | please-spy-on-me sucker born every day, so to speak.
        
             | eastbound wrote:
             | The nice thing about such a cable is that it could connect
             | to the cloud to display that screen without plugging the
             | other end.
        
             | MBCook wrote:
             | Does it really matter? This isn't a real product. It's a
             | scam product to trick people trying to buy a real Apple
             | part and con them into the app's clutches.
             | 
             | The real part doesn't need anything. Plug and go.
        
             | bitwize wrote:
             | It's not really an adapter cable. It's got a little SOC in
             | there that streams your iPhone's display from the app to
             | the HDMI port.
             | 
             | Meanwhile, your personal data is being streamed back to
             | China...
        
               | ThatPlayer wrote:
               | The official Apple HDMI adapter does the same thing with
               | an SoC in there. The difference is native iOS support
               | instead of a 3rd party app needed to support it.
        
               | ASalazarMX wrote:
               | Part of me is looking forward to the time when a
               | government activates a significant part of all the
               | spyware/adware/backdoors/etc in the world as part of a
               | cyberwar. COVID would be a child's game compared to that,
               | but that disaster would at last make people understand
               | how bad tech has become at this point.
               | 
               | Double points if the operation is started by another
               | state/group that stole those backdoors.
        
               | eastbound wrote:
               | The worst part of adult life is realizing you already
               | live in a world where this happens. Regularly. And no-one
               | bats an eye. And you try to maintain sanity by adding
               | hypothesis ("But I mean, with the government giving the
               | keys to...") and all of the evil you can think of, also
               | exists.
        
       | mock-possum wrote:
       | Shitty. I wonder what kind of profit they make per successful
       | scam.
        
         | MBCook wrote:
         | Well a single un-refunded $50/mo transaction is pretty good,
         | plus whatever they can get from ads and selling data.
        
       | jmrm wrote:
       | This kind of shady devices should be banned in Western Countries,
       | not only for trying to get their users' information, but also for
       | being a device that can go directly to the e-Waste bin without a
       | minimal usage
        
         | ale42 wrote:
         | They should be banned everywhere...
        
       | [deleted]
        
       | expertentipp wrote:
       | I have an impression that covid enabled widespread acceptation of
       | QR codes, and now every app is excused to request camera and
       | photo access because "we need to scan a QR code".
        
         | alwayslikethis wrote:
         | It would be nice to have a special way to scan a qr code in
         | which the system reads the QR code for the app without the app
         | being able to see raw camera data.
        
           | hedora wrote:
           | I think this flow sort of supports that.
           | 
           | https://9to5mac.com/2020/10/07/limit-third-party-iphone-
           | phot...
           | 
           | If I remember right, there's a way to get a "take picture"
           | option in the chooser. I'm not sure how the qr code would
           | then be recognized, though I'm not sure why you wouldn't have
           | them get the qr code via the system camera app.
        
             | MBCook wrote:
             | That's intended for selecting a pre-taken photo without
             | giving an app library access. You'd have to get the user to
             | take the picture then come back to your app.
             | 
             | What you really need is a system dialogue that pops up the
             | camera and only returns the QR code to the app, the way the
             | photo picker can see the whole library but only gives the
             | app the one selected photo.
        
               | gkbrk wrote:
               | Pretty sure Android has this. You can make an app without
               | camera permissions, send an intent that opens the built-
               | in camera to take a picture and you are given access to
               | only that picture. It means you cannot record things in
               | the background all the time, and users don't need to make
               | a decision about a sensitive permission.
        
         | folmar wrote:
         | I don't know for iOS but on Android they are not excused, just
         | register intent for your url and let the system camera app/qr
         | code scanner pass it.
         | 
         | Effectively you can expect it to work for Android 8+ as the
         | previous versions don't necessarily have a QR code scanner.
        
       | jollyllama wrote:
       | [flagged]
        
       ___________________________________________________________________
       (page generated 2023-09-29 23:01 UTC)