OxygenOS is Allegedly Data-mining Personally Identifiable Information for...

 
 
 
OxygenOS is Allegedly Data-mining Personally Identifiable Information for...

 
xda-developers
Oct 11, 2017 5:40 AM • by Adam Conway
OxygenOS is Allegedly Data-mining Personally Identifiable Information for Analytics

While the OnePlus phones have a good reputation for their price and openness to development, the company itself has made some questionable decisions in the past with regards to how they handle user data. At the time, we discovered that OxygenOS would leak your device's IMEI onto the network while your device checks for an update. Now, OnePlus is accused of collecting even more sensitive, personally identifiable information according to security researcher Christopher Moore.

During a Hack Challenge he was participating in last year, Moore decided to probe the internet traffic from his OnePlus 2. He discovered that his phone was sending HTTPS requests to the domain open.oneplus.net. He decrypted the data using the on-device key and was able to see all of the data being sent back to OnePlus' AWS servers.

He then analyzed what information was being sent to this domain and found that OnePlus was collecting screen on, screen off, device unlock events, abnormal reboots, serial number, IMEI, phone numbers, MAC addresses, mobile network(s) names and IMSI prefixes, and wireless network ESSID and BSSID.

But the data-mining doesn't stop there, as Moore found that OxygenOS was also collecting time stamps of when he opened and closed applications and even which activities were being opened.

Moore did some digging and discovered that the code responsible for this data collection is part of the OnePlus Device Manager and the OnePlus Device Manager Provider, which is contained in the system application OPDeviceManager.apk.

If your device isn't rooted, then you can run the following ADB command to disable this system application on your OnePlus device:

pm uninstall -k --user 0 net.oneplus.odm

A tutorial on how to set up ADB and run this command can be found here. Alternatively, if your device is rooted you can install this Magisk module.

All of this information is, again, sent over HTTPS so it can't be intercepted by anyone else (provided you are on a secure network). Though, one wonders what OnePlus is doing with this kind of information. In a statement, OnePlus offered the following explanation behind the analytics they are collecting:

We securely transmit analytics in two different streams over HTTPS to an Amazon server. The first stream is usage analytics, which we collect in order for us to more precisely fine tune our software according to user behavior. This transmission of usage activity can be turned off by navigating to 'Settings' -> 'Advanced' -> 'Join user experience program'. The second stream is device information, which we collect to provide better after-sales support.

Keep in mind that this data-collection is only occurring on OxygenOS, so if you have a custom AOSP-based ROM installed such as LineageOS then your phone is safe from data-mining. For a more technical breakdown, we recommend you read the original blog post that Mr. Moore made linked below.


Source: Chris's Security and Tech Blog




Android Advices
Oct 10, 2017 8:49 PM • by Karunakar Donthamshetti
ZTE Blade Force with 5.5-inch Screen & 3,000mAh Battery Launched For $130

ZTE will be working on a new device with a foldable concept called as Axon M and is now launched another smartphone from the company which would be available in the BoostMobile prepaid market, which is named as ZTE Blade Force. It is priced at $129.99, which would be giving an extra offer up to 14.92% off, which applies to buy only in online. It is the Mexico Roaming and Voice Roaming capable device. This phone is powered by Android 7.1.1 Nougat operating system with pre-installed applications.

It flaunts 5.5-inch touchscreen display with an HD resolution, which you can experience your photos, videos, and your apps never like before. It is supercharged with a 1.4GHz quad-core processor packed with 2GB of RAM, which delivers flawless multi-tasking experience when you run more apps at the same time. There is a 16GB of internal storage which also further expandable via MicroSD card slot. The dual-SIM phone is carried a 3G/4G LTE, LTE Plus, and HPUE, which you can switch between Sprint's nationwide 3G and 4G LTE networks and the LTE Plus networks where it is available.

The HPUE network would provide the faster speeds with carrier Aggression. The other connectivity options include Bluetooth, Wi-Fi 802.11 b/g/n, Micro-USB port and more. The ZTE Blade Force is equipped with a 3,000mAh capacity battery which is rated to deliver 23.5 hours of talk time and gives good standby time. For photography, this phone offers an 8MP primary camera and has a 5MP front-facing camera for taking pictures which moment you liked. It is the fourth largest handset maker in the United States.




 
 

This email has been sent by Froze ONE (isnanmm0@gmail.com). It is the potion result of 'Tech: Topic watch' from the dashboard 'Personal Dashboard', tab 'Tech > Android'. Unsubscribe

 
 
 

Subscribe to receive free email updates:

0 Response to "OxygenOS is Allegedly Data-mining Personally Identifiable Information for..."

Post a Comment