I was unaware of these side-loaded malicious apps until now. This is information consumers need to have.
It's very reminiscent of Sony putting rootkits on CD's. Unwanted, dangerous software is being loaded onto your computer by people you paid money to. The companies involved, including MS, should face serious blowback over this, as Sony did.
It's about time some company was prosecuted under CFAA for this kind of abuse. This should easily fit the legal definition of "intentional unauthorized computer access."
But we all know, the law is enforced aginst regular people, not corporations. Are corporations ever prosecuted for invoking something on a user's computer without their authorization?
This isn't even the worst payload ever delivered through Windows Update. The prize for that should probably go to chip manufacturer FTDI, which once abused the system to publish a driver that would semi-permanently brick USB serial bridge parts the driver detected as counterfeit [1] by exploiting a command that the genuine parts did not implement correctly (how ironic) [2]. The backlash was large enough that Microsoft ended up pulling the update almost immediately, but that did not stop FTDI from trying again a few years later with another driver update that deliberately corrupted data sent through detected-counterfeit parts.
> I was unaware of these side-loaded malicious apps until now. This is information consumers need to have.
I really want to ask, earnestly, how do we communicate these things earlier?
I don't think there's a shortage of HN users that one about this type of bullshit going on. I'm not going to tell you "I told you so", and I'll even attack those that do. But when people who are concerned with these types of issues talk out they get dismissed as being conspiracy theorists or simply too sensitive.
I'll admit that sometimes it can be hard to differentiate, but well respected experts in the tech field have discussed such issues for decades. So I really do want to understand, how do we reach you earlier? Before we get to this point. How do we not just come across as uppity tech nerds screaming "I use arch btw" in furry programmer socks?
I really do think we as a community need to figure out how to reach the public better. We're well past what was considered terrifying in 1984. We aren't a society where big brother could be listening to you at any time, we are living in a society where uncle Mark is watching you all the time. Where uncle Pichai knows who all your friends are. Where uncle Nadella knows when you're awake. They know whose been bad and good but they don't even have the decency to deliver gifts under the Christmas tree. Are we only fighting back because their actions have become so obvious? Or are we fighting is the principle enough?
You're talking as if most people care... They don't.
My father can't read any emails I send to him because his inbox is drowning in ads. A coworker ask me to fix her phone where apps crashed all the time. It was full with hundrds of apps I never saw before. The generation born 2010+ doesn't even know what privacy is. "Files" and local storage are alien concepts. This is the state of the world today.
So, communicate earlier to... ? people that already know and never connected their devices in the first place? Or maybe people that are "concerned" but unwilling to take the usability hit that true privacy implies? Like this guy that still has his Windows connected to the internet and then act shocked when he finds out just what exactly those 50+ background services do?
They only care for their devices to be usable, not privacy.
What my coworker wants is a phone that has all the apps in the world preinstalled. What my father wants is a phone that automatically sorts emails and messages.
well, i say it's high time to ridicule the people who try to ridicule others by labeling them as a conspiracy theorist. i'm a proud conspiracy researcher, and when someone throws this thought terminating cliche on me, then i nonchalantly ask stuff like:
wait! did you mean that as an insult or as a compliment?
It's very reminiscent of Sony putting rootkits on CD's. Unwanted, dangerous software is being loaded onto your computer by people you paid money to. The companies involved, including MS, should face serious blowback over this, as Sony did.