Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

> lenovo android phones contain spyware

views
     
TSericmaxman
post Dec 12 2013, 06:48 PM, updated 12y ago

-
*******
Senior Member
7,951 posts

Joined: Sep 2005
QUOTE
I own a lenovo P780. I just received it the other week. It is my first Android device. Coming from the linux world (god rest your soul my precious N900) I was not ready to add all my usual user accounts and information till I was satisfied the thing was not spunking my data all over the place to god knows who.

So before getting 'into' the device I was installing xprivacy (permissions manager), afwall+ (firewall), catlog (logcat viewer), networklog (network I/O logger) and interceptor-ng (packet snooper).

First I set about removing some of the pre-installed bloat. In lenovo's defence there was not really any bloat as such. Despite removing some garbage I keep noticing in logcat a DNS request for 'fsr.lenovomm.com'. This irked me. What the hell was trying to call Lenovo? I then used networklog to determine what programs were responsible for this. It came quickly apparent that it was ALL of the inbuilt lenovo software. The dialer, contacts manager and battery settings program etc.

I then used interceptor-ng to look at the traffic.

Sonovvab****

Everytime I used a lenovo program, it would spam my information to 4 remote servers. One of them is addressed:

CODE

http://ec2-54-251-138-207.ap-southeast-1.compute.amazonaws.com/


The information is being sent in clear text. It includes my IMEI, model information and a lot of other numbers that could well contain location and other metrics.

The only way to stop it while maintaining the functionality of the phone is to firewall ALL the lenovo programs. Browser, dialer, contacts, notes, messages and lenovo launcher. 'Just replace them' you say? I cannot. The phone is a dual sim device, I know of no other dialer/conacts that supports dual sims properly.

I now feel extremely paranoid. My N900 never pulled shit like this. All the programs came from a Debian repository and were HEAVILY vetted. There was no spyware on it because you could quite simply not get away with it. (except for Nokia cherry, but that is another story). Conversely, every damn program on my p780 wants to know my location and the contents of my sms/phonebook. On a PC I use a firewall to stop bullshit from connecting to me, on android I have to use a firewall to stop bullshit from dialing home at every opportunity.
reddit
mudkipryan94
post Dec 12 2013, 06:50 PM

someone need a sarcasm meter?
********
All Stars
12,000 posts

Joined: Feb 2010
From: Banting, Puchong, KL



walau... i can't accept this news lor.. shakehead.gif
Miracles
post Dec 12 2013, 06:52 PM

★ Detective /K ★
******
Senior Member
1,171 posts

Joined: Dec 2006
GG Lenovo. This is scary sh*t.
arubin
post Dec 12 2013, 06:53 PM

Holy Pastafarian
****
Senior Member
670 posts

Joined: Oct 2007
From: Church of the Flying Spaghetti Monster


root and install custom rom.

problem solved.

tricky bit - lenovo is so shite that no custom roms can be bothered to support it. laugh.gif
TSericmaxman
post Dec 12 2013, 06:54 PM

-
*******
Senior Member
7,951 posts

Joined: Sep 2005
QUOTE(arubin @ Dec 12 2013, 06:53 PM)
root and install custom rom.

problem solved.

tricky bit - lenovo is so shite that no custom roms can be bothered to support it. laugh.gif
*
root and freeze all lenovo apps.

thats why i never bother to get a lenovo/alcatel/*insert china brand*
ichi_24
post Dec 12 2013, 06:57 PM

Casual
***
Junior Member
480 posts

Joined: Nov 2007
From: /K/opitiam



lel ever since i bought the p780 and a706 i used titanium and remove those bloatware

lel everyone should know bloatware do this stuff
SUSHuman10
post Dec 12 2013, 07:00 PM

Look at all my stars!!
*******
Senior Member
6,774 posts

Joined: Nov 2010
» Click to show Spoiler - click again to hide... «

buraqdunia
post Dec 12 2013, 07:02 PM

On my way
****
Junior Member
617 posts

Joined: Jul 2006


my pov is,

1. without emei no. we can't remotely disable our device. Even rendered that device useless.
2. to send emei no... ; in this case ;
» Click to show Spoiler - click again to hide... «
, they can pull of that item been sold after report generate for disabling emei.
3. the only protect end user, all participate in receiving emei no must not disclose to other 3rd parties. and must include in T&R.
4. any telco must not register using that emei to their line. best thing, triangulate that no, and apprehend the theft if report has been made.

Sorry for my bad english.

This post has been edited by buraqdunia: Dec 12 2013, 07:07 PM
SUSCliffrisonJr.
post Dec 12 2013, 07:02 PM

Young and Bangang.
*******
Senior Member
2,422 posts

Joined: Oct 2012
From: In your ♥


tipu

ini semua agenda yahudi

Bump Topic Add ReplyOptions New Topic
 

Change to:
| Lo-Fi Version
0.1913sec    0.40    5 queries    GZIP Disabled
Time is now: 9th December 2025 - 01:52 PM