Hacker Newsnew | past | comments | ask | show | jobs | submit | spicyjpeg's commentslogin

ZKPs (as well as C2PA and similar user attestation systems) are quite literally a DRM scheme for the web, fraught with all the usual control and accessibility issues while still being relatively easy to circumvent by a sufficiently motivated and funded actor. Given the huge number of shady companies that run "phone farms" for purposes ranging from social media spam to Spotify royalty farming, I doubt they would even put a dent on this kind of automated abuse. They would however be very effective at locking every Linux and GrapheneOS user out of the internet.

I like to call this phenomenon "reverse compression", or occasionally "depression". It's even lossy and subject to generational loss.

Hah. "Depression" fits well for a few reasons.

The internet is still full of individuals sharing deep passion for all sorts of things, but only within the walls of invite-only communities you have to go out of your way to find (Discord servers, private forums) and/or make a financial commitment towards (Patreon).

Or at least it was, before LLM "enthusiasts" started leaking into these otherwise hermetic communities and overrunning formerly safe spaces with mass-produced low-effort content nobody wants to see, particularly when anyone else could prompt the exact same thing into existence.


For me the difference today is that most people sharing their passions are now doing for The Algorithm. It's a far cry from the scrappy days of the early web where people just posted stuff because they thought it was cool. I'm not saying their passion is any less, more just that is so much noise. People are now "creators" and are pressured to constantly create.

Don't go on sites with "creators" then. When people say this they're talking about like 5 websites. They're not "the Internet" at all.

Why do you assume a hobby or interest still has a significant presence on the non-algorithmified open web?

For travel-related hobbies, for instance, there is no longer any kind of significant open-web scene where people just share stuff to help others or because it is cool. (Yes, you can set up your own blog, but pretty much none of your peers will ever see it.) The community might be using a variety of apps beyond your "like 5 websites", but all those apps are designed around phones and minimize text content, and so they are just as pathological as "sites with 'creators'".


I'm not sure what exactly a travel-related hobby app might even be for (other than e.g. a map and a calendar, but there are FOSS ones), but isn't this exactly demonstrating the "creator" mentality? You can make your blog as you like it with text, images, videos, etc. Share it with people in your social circle who are interested. Maybe others will find it too some day if you want it to be open. But if you can't send them a link, they're not really your peer, are they? And if they won't click a link, they weren't interested.

Let me give you long-haul bicycle travel as an example: back when there was an active blogging scene, people sharing route tips and bike-build breakdowns could be sure that a decent amount of other people would find it and benefit from it: the blogs got picked up by search engines and were readily findable, and there was still a culture of using the open web.

Today, no one you will see the content that you posted to help other people out. Google began deprioritizing personal blogs a decade ago already, and now a whole generation has come up that doesn't know the open web is a thing. When people look for tips in this hobby, it is overwhelmingly on phone apps like Komoot or PolarSteps, on the general image-based social media like YouTube or Instagram, or (already for an older-skewing crowd that still uses browsers) on the big for-profit website Bikepacking.com that grew by using its SEO-fu to wipe out the non-profit-driven scene.

There is a community around this hobby, one with a lot of IRL interaction, and people do enjoy that feeling of community. But claiming that people "aren't really your peer" if they don't use the old open web that we knew, is just cutting yourself off from that.


Ha, yes I wanted to keep my comment short without trying to cover every base, but figured I might get this comment. Of course such sites still exist, but still a different phenomena when that was the entire internet. There are a lot of interesting people who run YouTube channels that be so cool to see a GeoCities-type site from, for example.

This isn't even the worst payload ever delivered through Windows Update. The prize for that should probably go to chip manufacturer FTDI, which once abused the system to publish a driver that would semi-permanently brick USB serial bridge parts the driver detected as counterfeit [1] by exploiting a command that the genuine parts did not implement correctly (how ironic) [2]. The backlash was large enough that Microsoft ended up pulling the update almost immediately, but that did not stop FTDI from trying again a few years later with another driver update that deliberately corrupted data sent through detected-counterfeit parts.

[1] https://en.wikipedia.org/wiki/FTDI#Driver_controversy

[2] https://github.com/therealdreg/ftdibrick#diving-deep


It’s almost like money gives some people the idea that being a cunt is 100% ok so long as you get your money.

It’s very annoying when people start sentences with “it’s almost like”.

Definitely an overused phrase online. Yet, absolutely appropriate. It’s almost like I’m a native English speaker or something. ;)

This is indeed what is happening behind the scenes. By default Windows Update will automatically download and install support packages for pretty much any device Windows can identify through manufacturer/device IDs, which includes PCIe and USB devices but also monitors. This is most commonly used to deliver drivers but Microsoft allows these packages to silently install any user-facing application as well, presumably due to peripherals such as GPUs or audio chipsets often requiring "control panels" or similar companion apps.

Around a month ago LG took advantage of this feature by publishing a Windows "driver" for all their TVs and monitors that consisted entirely of payola bloatware, resulting in predictable backlash [1] and the obligatory subsequent HN discussion [2]. None of this has anything to do with the TVs themselves being connected to the internet or not.

[1] https://youtube.com/watch?v=Q9uefFYe6bM

[2] https://news.ycombinator.com/item?id=48956688


> automatically

This is the root problem.

The computer should not do something that the user did not specifically command. It should not guess, "Oh, the user plugged in device X. This means I have the user's consent to download and install software."


Every user wants their computer to do things they didn't specific command. You may draw the line differently from random user Bob, but your claim is simply wrong.

The *vast* majority of users do want their machine to silently do whatever it takes for their device to work.

I don't want to go handwrite XF86Config. I want my machine to go negotiate resolutions and aspect ratios and pick a default. I don't want to have to go find a CD drive or go to the OEM's website to get my printer or scanner working. Many users want their audio device to be able to talk over HDMI when plugging in a monitor with speakers. And so on.


A particularly worrying trend that keeps spreading is the one of restricting significant amounts of (often non-financial) functionality to the apps only, gated behind your phone passing device integrity checks, in what seems to be a poorly thought out attempt at blocking all forms of scraping and automation (AI or not). The worst offender right now is probably Twitter, which alongside the recent Nitter cease-and-desist now appears to require client integrity on all logged out access.

You can just make an account on a phone and give the login info to Nitter (your own instance), it still works.

The FeliCa NFC standard made its way into more than just transit cards in Japan. One notable user is the Amusement IC network, which lets you quickly log into arcade games across multiple manufacturers using a single card. Some implementations (Konami's e-amusement most notably) even go as far as to allow any FeliCa-compatible card or device to be linked to a profile, including transit cards, phones (with no app required!) and certain models of Sony Bluetooth earbuds which use FeliCa for quick pairing.


> Some implementations even go as far as to allow any FeliCa-compatible card or device to be linked to a profile

This is also put in use in many karaoke joints to save a list of your favorite songs/song history.


If C2PA and similar signature systems ever become a meaningful authenticity signal, they will create huge incentives for someone (potentially a state actor) to hack at least one camera in order to sign images of arbitrary provenance with its private keys. This will in turn inevitably lead to the same game of cat-and-mouse we have seen play out with video DRM schemes, where keys are regularly extracted from exploitable devices and used to decrypt as much content as possible before the device gets blacklisted entirely (harming all legitimate owners in the process).


I've done this btw. I went for the Pixel Camera app since they were the ones bragging the hardest about their "security". Writeup + PoC should be dropping some time tomorrow. Despite 90+ days from initial report, it remains unpatched.

Some proof: https://verify.contentauthenticity.org/?source=https://retr0...

I could also paste a privkey + cert chain in here but el goog's lawyers might not like that.



The article does not make it particularly clear, but the malware in question is delivered through official first-party OTA updates on cheap Chinese aftermarket head units that happen to run Android. It cannot self-propagate to any Android-based head unit, nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit. This seems to be a very similar situation to that of cheap generic Android TV streaming boxes, which often come pre-infected from the factory with residential proxies and other malware as well; most of the infrastructure is likely shared.


Why do they gloss right over how this was distributed? Barring details of any other kind of exploit we would have to assume the vendor's update server was compromised? If so why don't they just say so.


Cheap Android phones and tables often have built-in advertisement from manufacturer. One example of such software, it creates a window with Google Ads on top of browser window. The window is shown only when the browser is active to make it look like the ads is a part of the site. The ads appears only couple weeks after activation so that the user thinks it is a result of installation of some app and Youtube reviewers do not notice existence of malware. The adware consults a remote config which defines in what countries it should work. Another adware component automatically downloads and re-installs it if it is deleted.

I found all these details through examining the official firmware image and reverse engineering.

I don't remember if I reported Google Ads id to Google. It is interesting that Google doesn't notice and care about such use of their products.


> we would have to assume the vendor's update server was compromised

You say "compromised". I say "monetised".

:sigh:


To avoid charges of libel.


In America its not libel if it's true


I see nothing at a glance about the author (Dmitry Kalinin) being American, so I can't imagine that is relevant.


there is the problem. We don't know what country is in question. There are some countries where the truth is not a defense against libel. Thus, depending on where the author is from, or for that matter the publisher or other people who might happen to be in the chain, there could be a libel case if the truth was stated.


> There are some countries where the truth is not a defense against libel

Germany, for example. Utterly bizarre and baffling that a democracy protects its politicians this way. /s


It's important for people to be able to critize elected officials.


Indeed this is an odd disclosure and I am not familiar with past posts by them.

Moreover, no CVE is associated with this claimed vulnerability. It's not even stated which Android version or automotive head-unit variant version is affected.



Oh, I see I'm getting downvoted by the Russian bots, quelle surprise.


[flagged]


Wikipedia's source policy makes it nearly impossible to refer to anything that is not in the media, and any sensitive article has to use weasel words like this. Are you just noting the issue with the article, or actually doubting that Kaspersky Labs is a de-facto FSB branch since at least 2015?


Up until 2015 all was good with Kaspersky. But then in February of that year they posted a detailed writeup on malware created by the Equation Group, the NSA. [1] Within a month US media outlets, relying on anonymous sources, began posting endless claims that Kaspersky was a part of the Russian government. Over the next years Kaspersky opened a bunch of 'transparency centers' offering full code audits and inspection, relocated their core infrastructure and customer data to Switzerland - subsequently falling under their data regulations, and so on.

And if they were in any way affiliated with the Russian (or any) government, there seems no logical reason they'd publicly share their findings of the NSA malware, let alone the other transparency actions. Their data would be vastly more valuable if kept secret, because it'd open the door to greater exploitation of US cyber activities and being able to covertly secure desired systems. Instead their actions benefited everybody, but obviously embarrassed the NSA and as a result the US.

[1] - https://media.kasperskycontenthub.com/wp-content/uploads/sit...


KL is a credible shop, they basically founded the modern anti-malware industry and pioneered most basic techniques in the 90's and early 2000's, together with some of their then-rivals like Dr. Web. There's a reason they were trusted, and there's a reason they tried to deny their takeover, they have a genuinely earned reputation.

This doesn't mean they aren't a FSB branch, in the same way e.g. NSO Group is a Mossad branch, with one difference that KL sell themselves as defensive and NSO Group doesn't. It was confirmed by KL employees in their socials that the management has been largely taken over by actual FSB officers. Some have left the company out of protest because they felt it's getting raided (отжим in Russia is not like your usual corporate takeover...). It's impossible to link it now as most of these people are living abroad since 2022 or earlier and either removed all their stuff or their socials entirely, some have renounced their citizenship by this point. But as a general rule, assume every important business in Russia is taken over by the government since 2022, either directly or indirectly. In 2026, whitewashing Kaspersky Labs of all companies is weird.

>But then in February of that year they posted a detailed writeup on malware created by the Equation Group, the NSA. [1] Within a month US media outlets, relying on anonymous sources, began posting endless claims that Kaspersky was a part of the Russian government

There was also a war happening, which you aren't saying.

>Over the next years Kaspersky opened a bunch of 'transparency centers' offering full code audits and inspection, relocated their core infrastructure and customer data to Switzerland - subsequently falling under their data regulations

The audits are to check the checkboxes, they mean very little. Plenty of former Russian companies that moved abroad are keeping ties with the developers at home, despite all audits, fronting campaigns, and otherwise pretending they aren't (not all though, others did actually migrate).

>if they were in any way affiliated with the Russian (or any) government

I mean, YK himself is KGB and there are no former ones, as they say. KL is one of the main government cybersec contractors, for starters. In a country where the government controls most of the economy they are producing critical industrial security systems like data diodes and secure gateways with their own OS, you can go to their site and look at all this yourself.

Cybersec industry in general is heavily affiliated with their respective governments, I don't think it's a secret for anyone and denying this is just silly. Some of them are more than others.

>there seems no logical reason they'd publicly share their findings of the NSA malware ... Their data would be vastly more valuable if kept secret, because it'd open the door to greater exploitation of US cyber activities and being able to covertly secure desired systems.

What? This doesn't make any sense, sorry. Security agencies usually publish or leak actions of their adversaries.

>Instead their actions benefited everybody

Did their inaction benefited anyone? RuNet which has been great got basically destroyed and turned into a safe haven for half of world's cybercriminals on their proud watch, and they aren't writing anything on this. They serve as part of their "roof".

Note I'm not saying they aren't doing good things, you're right, it's pretty good when the spooks keep each other and cybercriminals in check, see the article in OP, Apple's hardware backdoors (Operation Triangulation), and many other cases.


Kaspersky isn't just a credible lab. They were, and remain, the best antivirus provider, by their results on basically any and all test batteries. Similarly their founder (Eugen Kaspersky - I assume who you are referencing with "YK") has never worked for the KGB. He was educated at at a KGB affiliated school and afterwards went to work for the Ministry of Defense. Within a few years the USSR collapsed and he then went, and stayed, within the private sector.

But most importantly - companies (let alone other governments) providing detailed information on how other governments' cyber operations is most certainly not a thing that's done. That report I linked to is not just speaking in evidence free vagaries of the geopolitical 'leak' type you are alluding to. It provided extensive operational details and includes things such as even naming a specific driver as which is implied as being a Windows backdoor with plausible deniability.

They chose to publish it letting the NSA know exactly which methods had been discovered, how they were discovered, and even exact versions they detected and potentially on exactly which machines (if the NSA salts binaries), given that the hash/date info were also provided. All of this is immensely valuable information that could have been both weaponized and 'defensized' for Russian cyber purposes. Providing it helped the NSA more than anybody. Outside of Trumpian 5d chess, there's no rational explanation for this, if one assumes they are in any meaningful way controlled by the Russian government.


FSB? Oh you mean Russian “Federal Security Service” ?


As it says in the first line of the WP article: "Federal Security Service (FSB)"


It's been a while since I thought about Front Side Bus


The article is about a controversy involving allegations. There is plenty of evidence presented that the controversy and the allegations exist. (And if you dig into the links, there is plenty of evidence that the allegations are not without basis.)

> “sources said”

Yes, that's how Wikipedia works. https://en.wikipedia.org/wiki/Wikipedia:Neutral_point_of_vie...


Welcome to Wikipedia


This makes me think whether the whole chain is an intelligence side business — sell cheap electronics for profit and at the same time own them too.


> nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit

Huh, how does that work anyway? And while we're at it, Apple CarPlay as well? Both can run wirelessly via Bluetooth, but BT is nowhere near capable enough to stream full bandwidth video?


Wireless AA and CarPlay use a hotspot your car emits that your phone connects to and transfers the image/inputs/audio that way


Got into a weird situation recently where my cheap android head unit was displaying Car Play from my phone, but (Google Maps) audio from my partner's.

Directions weren't coming from my phone's speaker or the car, but testing audio in the Maps app did (from the car).

Still not sure what combination of connections it had managed to get itself into!


Wireless CarPlay uses Bluetooth to exchange SSID and key info before switching over to WiFi for the duration of the session.


Wow that's cursed, never realized that's how it worked.


Cursed is exactly how I would describe it - because it works great until it doesn’t and it of course gives you zero clue why it won’t connect.


Anecdotally, I just got back from a holiday trip across Europe and crossed four international borders. At every single border crossing, my CarPlay session disconnected, and I had to toggle CarPlay off and back on in my phone settings to reconnect. Very strange, and I still have no idea what caused it.


It's a good idea actually, but it's also really complex to get right.

Early version of Android Auto could transfer over USB 2.0 instead of Bluetooth, which works, but it's not near as high bandwidth.


> Early version of Android Auto could transfer over USB 2.0 instead of Bluetooth, which works, but it's not near as high bandwidth.

This sentence doesn't make much sense - Auto (and CarPlay) still work in wired mode over USB 2.0 if the head unit supports it. They never worked over Bluetooth.

(And they use less than 15Mbps so USB 2.0s 480MBps are more than enough)


They use Bluetooth to configure WiFi. Most people call that Bluetooth, but technically you are correct.


They actually run over WiFi (WiFi direct IIRC) - Bluetooth is mostly just used as a setup handshake and to help the head unit decide which phone in the car should be the one connected.


The way I understand it, the connection is negotiated via BT, but then wifi is used for the fat data pipe to run the display.


I thought the latest Bluetooth protocols were basically designed to hand off to an ad-hoc Wi-Fi connection between the two devices after the initial handshake. (Might be an oversimplification of the real protocol)


They didn't run over BT. BT is used to initiate communication and share the password to a wifi-network. It then uses that Wi-Fi network for most communication, keeping the BT channel strictly for telephony.


It uses Bluetooth to stream audio, but everything else happens through a WiFi connection exposed by the car that the phone automatically pairs with after the Bluetooth handshake.


Not sure about CarPlay, but Android Auto connects via wifi to the head unit for the video feed.


Not sure about carplay, but Android Auto wireless uses wifi for the video stream.


My car requires wired connectivity (USB) for Android Auto.


For a decent amount of the older android / CarPlay usb implementations - you can also buy little WiFi / USB dongles that perfectly enable wireless CarPlay - I’ve used them now on a few vehicles and they have been perfect !


Interesting how there is possibly a new category of residential proxy malware “automotive proxy malware”


This is just another mobile device. It even has a SIM card.


It cannot self-propagate to any Android-based head unit

Remember that not that long ago viruses spread through floppy disks.

Today, people share USB sticks full of music from one car to another all the time. They also bring their music from their home car to a rental car and back.


I’ve never met anyone irl who used USB sticks full of music. I know the capability is there in most cars, just never seen it. It seems like Bluetooth capability and Spotify/Apple Music landed in mainstream cars too soon after “play MP3s from USB” was added, for that to catch on.


I did it for a few years, back when I had a new car with the capability but not a phone with a good mobile data plan.

It had the benefit of an information center with physical buttons too, so I could navigate around my library without touch screen madness or voice commands constantly failing to understand band and song names.


> I’ve never met anyone irl who used USB sticks full of music.

I've been doing it for years, since it's so much more convenient than the alternatives: plug the stick into my car and I have my whole music library there and it Just Works.


We haven't met yet.

We use an USB key full of audio books: Harry Potter saga and The Quest of Ewilan among others. The whole family is hooked.

The car UI is much more reliable (no phone to unlock by the copilot, no Bluetooth disconnect). The phone battery is spared for navigation purposes.


I have 256GB of FLAC in my car, and it's great.


My hand is raised. I like having 8GB of music on an old (USB2 is fine) flash drive in my car as a fallback. On longer trips I'll hookup the Android Auto, but if I don't need maps and it's a quick ride, shuffle & repeat all enabled on the USB source.

Sure beats the radio, which plays 2 songs and then 5 min of commercials/sweepers, and has the gall to run ads on the HD text transmission on FM designed for song information.


Most people just bring their phone between cars for music.


My phone is much clunkier to use for this than a USB stick. Plus my phone can't store my whole music library (because there's too much other stuff already on it), whereas a single USB stick does it easily with plenty of room to spare.


Phones can access the whole internet. A USB stick can't stream Spotify or connect to the cloud.


Which doesn't matter to me since the music I'm talking about is music I already have on the USB stick (because it's music I've collected over years and years of buying CDs, mostly before ways of streaming music over the Internet even existed), and I mostly want to listen to that. If I want something else, I can just use XM radio.


You'll be surprised, but some places where a car can go have no phone connectivity.


> It cannot self-propagate to any Android-based head unit

Article does not say that.


Headline really quite clearly implies it, though. I think the correction is apt.

Bottom line is that lots of HN commenters here, as is our wont, will see this as a platform bug with a hated rival and not a bad third party integration that introduced vulnerabilities.

Like, if it was a Linux-based edge system from some fly-by-night contractor, would you be OK with a headline like "Malware infects Debian based refrigerators"? What'd Debian do?


It’s no different than how the old Ford Sync or something else could have been compromised.

The two big things here in my mind are:

1. Android Automotive has gotten very popular since it provides so much and writing your own OS is very very hard and expensive as so many car makers found out

2. Aftermarket head units often use it (see #1) so it’s likely far easier to get out there than if you had to compromise Ford/VW/Volvo/whoever


This is not Android Auto though, which is an entirely different product suite designed to connect a OEM infotainment system to an Android device owned by the vehicle operator. That protocol is proprietary, Google-owned and managed, not part of AOSP, and not available to the integrator of the software in question.

The actually vulnerable system is a custom vehicle head unit that merely happens to be running a software stack based on AOSP. It's not even "Android" in a product marketing sense.

Again, it's like blaming Debian because some loon stuffed it in a wifi NAS or whatever and put a backdoor into their UI. It's insane.


Do you mean Android Automotive?


So? spicyjpeg is pointing out what is true, not just regurgitating TFA.


The 6502 and its variants are still ubiquitous as well, powering millions of toys based on Sunplus/GeneralPlus microcontrollers [1] [2] [3] as well as the vast majority of bootleg game consoles that use variants of "Famiclone" hardware (or occasionally general-purpose 6502 MCUs [4]) to this day. It's fascinating how the toy industry went for the 6502 over the 8051 and PIC12 clones more common in other cheap electronics; I suspect it had to do both with the architecture's better performance (important for tasks such as audio decoding) and with the historical availability of experienced 6502 assembly developers as the game industry moved away from 8-bit platforms.

[1] https://spritesmods.com/?art=tamasingularity&page=2

[2] https://archive.org/details/furby-source

[3] https://dmitry.gr/?r=05.Projects&proj=37.%20Pixter#_TOC_a6fe...

[4] https://github.com/davidgiven/tony-sdk


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: