Android

FBI, CIA, and NSA: Don't Use Huawei Phones (cnbc.com) 238

The heads of six top U.S. intelligence agencies told the Senate Intelligence Committee on Tuesday they would not advise Americans to use products or services from Chinese smartphone maker Huawei. "The six -- including the heads of the CIA, FBI, NSA and the director of national intelligence -- first expressed their distrust of Apple-rival Huawei and fellow Chinese telecom company ZTE in reference to public servants and state agencies," reports CNBC. From the report: "We're deeply concerned about the risks of allowing any company or entity that is beholden to foreign governments that don't share our values to gain positions of power inside our telecommunications networks," FBI Director Chris Wray testified. "That provides the capacity to exert pressure or control over our telecommunications infrastructure," Wray said. "It provides the capacity to maliciously modify or steal information. And it provides the capacity to conduct undetected espionage."

In a response, Huawei said that it "poses no greater cybersecurity risk than any ICT vendor." A spokesman said in a statement: "Huawei is aware of a range of U.S. government activities seemingly aimed at inhibiting Huawei's business in the U.S. market. Huawei is trusted by governments and customers in 170 countries worldwide and poses no greater cybersecurity risk than any ICT vendor, sharing as we do common global supply chains and production capabilities."

Advertising

Huawei Got People To Write Fake Reviews For An Unreleased Phone (theverge.com) 39

As spotted by 9to5Google, Huawei has apparently posted fake reviews on Best Buy for its new Mate 10 Pro, which is available for pre-order in the U.S. despite not having any deals with U.S. carriers. "The fake reviews, which are exclusively on the Best Buy website, are likely the result of a contest Huawei ran on Facebook," reports The Verge. From the report: On January 31st, the company posted to a Facebook group with over 60,000 members, asking for people to leave comments on the Best Buy pre-sale page in exchange for a chance to beta test a Mate 10 Pro. The original post has been deleted, but 9to5Google obtained a screenshot before it went down. "Tell us how to why (sic) you WANT to own the Mate 10 Pro in the review section of our pre-sale Best Buy retail page," the post states. On the Best Buy site, there are currently 108 reviews for the phone, 103 of which were written on or after January 31st, the day Huawei posted the contest. Many of the comments directly reference not having any actual hands-on experience with the product itself, but give the phone a five star rating. "I can't wait to get my hands on this phone and demonstrate how amazing it is to people," reads one. "This device looks exciting and beautiful and it would be amazing to have a chance to beta test it," another reads. It seems Huawei is betting that loads of high ratings early on will make people trust the product and lead to higher sales. That's all well and good except that these types of reviews are strictly against Best Buy policy, as 9to5Google points out. "Huawei's first priority is always the consumer and we encourage our customers to share their experiences with our devices in their own voice and through authentic conversation," a Huawei representative told The Verge in a statement. "While there are reviews from beta testers with extensive knowledge of the product, they were in no way given monetary benefits for providing their honest opinions of the product. However, we are working to remove posts by beta testers where it isn't disclosed they participated in the review program."
China

US Senators Voice Concern Over Chinese Access To Intellectual Property (reuters.com) 115

Leaders of the U.S. Senate Intelligence Committee said on Tuesday they were concerned about what they described as China's efforts to gain access to sensitive U.S. technologies and intellectual property through Chinese companies with government ties. From a report: Senator Richard Burr, the committee's Republican chairman, cited concerns about the spread of foreign technologies in the United States, which he called "counterintelligence and information security risks that come prepackaged with the goods and services of certain overseas vendors. The focus of my concern today is China, and specifically Chinese telecoms (companies) like Huawei and ZTE that are widely understood to have extraordinary ties to the Chinese government," Burr said. Senator Mark Warner, the committee's Democratic vice chairman, said he had similar concerns. "I'm worried about the close relationship between the Chinese government and Chinese technology firms, particularly in the area of commercialization of our surveillance technology and efforts to shape telecommunications equipment markets," Warner said.
Android

Android Wear Is Getting Killed, and It's All Qualcomm's Fault (arstechnica.com) 174

The death of Android Wear is all Qualcomm's fault, largely due to the fact that the company "has a monopoly on smartwatch chips and doesn't seem interested in making any smartwatch chips," writes Ars Technica's Ron Amadeo. This weekend marks the second birthday of Qualcomm's Snapdragon Wear 2100 SoC, which was announced in February 2016 and is the "least awful smartwatch SoC you can use in an Android Wear device." Since Qualcomm skipped out on an upgrade last year, and it doesn't seem like we'll get a new smartwatch chip any time soon, the entire Android Wear market will continue to suffer. From the report: In a healthy SoC market, this would be fine. Qualcomm would ignore the smartwatch SoC market, make very little money, and all the Android Wear OEMs would buy their SoCs from a chip vendor that was addressing smartwatch demand with a quality chip. The problem is, the SoC market isn't healthy at all. Qualcomm has a monopoly on smartwatch chips and doesn't seem interested in making any smartwatch chips. For companies like Google, LG, Huawei, Motorola, and Asus, it is absolutely crippling. There are literally zero other options in a reasonable price range (although we'd like to give a shoutout to the $1,600 Intel Atom-equipped Tag Heuer Connected Modular 45), so companies either keep shipping two-year-old Qualcomm chips or stop building smartwatches. Android Wear is not a perfect smartwatch operating system, but the primary problem with Android Wear watches is the hardware, like size, design (which is closely related to size), speed, and battery life. All of these are primarily influenced by the SoC, and there hasn't been a new option for OEMs since 2016. There are only so many ways you can wrap a screen, battery, and body around an SoC, so Android smartwatch hardware has totally stagnated. To make matters worse, the Wear 2100 wasn't even a good chip when it was new.
Android

Rejoice: Samsung's Next Flagship Smartphone Looks To Keep the Headphone Jack Alive (theverge.com) 193

Notorious smartphone leaker Evan Blass has leaked a couple press images of the Galaxy S9, giving us the first indication that it will still have a headphone jack. "The full information spill today is actually focused on a new Samsung DeX Pad, which appears to be an evolution of last year's DeX dock for the Galaxy S8," reports The Verge. From the report: Samsung, LG, and a couple of other companies like OnePlus have remained resolute in their inclusion of a headphone jack, but that was far from a certainty for the next Galaxy S iteration. This is a phone that will compete against the iPhone X, Huawei Mate 10 Pro, and more niche rivals like Google's Pixel 2: all of them surviving sans a headphone jack. So Samsung could have dumped the analog audio output, but it seems to have opted against it, and that's worthy of commendation. USB-C earphones are all still either bad or expensive -- or both -- and phones that retain compatibility with 3.5mm connectors remain profoundly useful to consumers that aren't yet convinced by Bluetooth.
Verizon

Verizon Drops Plans To Sell Huawei Phones Due To US Government Pressure (bloomberg.com) 69

Bloomberg reports that Verizon has dropped all plans to sell phones by Chinese manufacturer Huawei due to pressure from the U.S. government. The decision comes after AT&T walked away from a deal earlier this month to sell Huawei smartphones in the U.S. Bloomberg: Huawei devices still work on both companies' networks, but direct sales would've allowed them to reach more consumers than they can through third parties. The government's renewed concern about Chinese spying is creating a potential roadblock in the race between Verizon and AT&T to offer 5G, the next generation of super-fast mobile service. Huawei is pushing to be among the first to offer 5G-capable phone, but the device may be considered off-limits to U.S. carriers who are beginning to offer the next-generation service this year in a few cities. U.S. security agencies and some lawmakers fear that 5G phones made by companies that may have close ties to the Chinese government could pose a security risk.
United States

The US Drops Out of the Top 10 In Innovation Ranking (bloomberg.com) 364

An anonymous reader quotes a report from Bloomberg: The U.S. dropped out of the top 10 in the 2018 Bloomberg Innovation Index for the first time in the six years the gauge has been compiled. South Korea and Sweden retained their No. 1 and No. 2 rankings. The index scores countries using seven criteria, including research and development spending and concentration of high-tech public companies. The U.S. fell to 11th place from ninth mainly because of an eight-spot slump in the post-secondary, or tertiary, education-efficiency category, which includes the share of new science and engineering graduates in the labor force. Value-added manufacturing also declined. Improvement in the productivity score couldn't make up for the lost ground.

South Korea remained the global-innovation gold medalist for the fifth consecutive year. China moved up two spots to 19th, buoyed by its high proportion of new science and engineering graduates in the labor force and increasing number of patents by innovators such as Huawei Technologies Co. Japan, one of three Asian nations in the top 10, rose one slot to No. 6. France moved up to ninth from 11th, joining five other European economies in the top tier. Israel rounded out this group and was the only country to beat South Korea in the R&D category. South Africa and Iran moved back into the top 50; the last time both were included was 2014. Turkey was one of the biggest gainers, jumping four spots to 33rd because of improvements in tertiary efficiency, productivity and two other categories. The biggest losers were New Zealand and Ukraine, which each dropped four places. The productivity measure influenced New Zealand's shift, while Ukraine was hurt by a lower tertiary-efficiency ranking.

AT&T

US Lawmakers Urge AT&T To Cut Commercial Ties With Huawei and Oppose China Mobile Citing National Security Concerns (reuters.com) 60

U.S. lawmakers are urging AT&T, the No. 2 wireless carrier, to cut commercial ties to Chinese phone maker Huawei Technologies and oppose plans by telecom operator China Mobile to enter the U.S. market because of national security concerns, two congressional aides told Reuters. From the report: The warning comes after the administration of U.S. President Donald Trump took a harder line on policies initiated by his predecessor Barack Obama on issues ranging from Beijing's role in restraining North Korea to Chinese efforts to acquire U.S. strategic industries. Earlier this month, AT&T was forced to scrap a plan to offer its customers Huawei handsets after some members of Congress lobbied against the idea with federal regulators, sources told Reuters. The U.S. government has also blocked a string of Chinese acquisitions over national security concerns, including Ant Financial's proposed purchase of U.S. money transfer company MoneyGram International.
AT&T

AT&T Pulls Out of Deal To Sell China's Huawei Phones In the US (phonedog.com) 63

According to the Wall Street Journal, AT&T has walked away from a deal to sell China's Huawei smartphones in the U.S. Neither AT&T nor Huawei have commented on the matter, but the news is certainly going to disappoint those of you who were looking forward to picking up Huawei's flagship Mate 10. Prior to this report, Huawei was expected to announce that its flagship Mate 10 will launch on AT&T in 2018. PhoneDog reports: Huawei has a major presence internationally, with recent reports saying that it's the No. 3 smartphone brand in the world behind Apple and Samsung. The company hasn't made much of a dent in the U.S., though, despite the fact that it's been selling its phones unlocked in the U.S. for awhile now. This AT&T deal would've been big for Huawei, helping it to get its phones inside carrier stores and in front of U.S. consumers, the majority of which still buy their phones from their carriers. Now we'll have to wait and see if Huawei can strike a deal with another carrier or if it'll have to continue on in the unlocked market. A Huawei spokesperson only said "Huawei has proven itself by delivering premium devices with integrity globally and in the U.S. market."
Businesses

China's Top Phone Makers Huawei and Xiaomi In Talks With Carriers To Expand To US Market (bloomberg.com) 44

From a report: Huawei and Xiaomi are in talks with U.S. wireless operators about selling flagship smartphones to American consumers as soon as next year, according to people familiar with the matter. The handset makers are negotiating with carriers including AT&T and Verizon, said the people, asking not to be identified because the matter is private. Talks are still fluid and it's possible no agreements will materialize, they said.
Censorship

Apple, Google CEOs Bring Star Power as China Promotes Censorship (bloomberg.com) 38

An anonymous reader shares a Bloomberg report: Apple's Tim Cook and Google's Sundar Pichai made their first appearances at China's World Internet Conference, bringing star power to a gathering the Chinese government uses to promote its strategy of tight controls online. Apple's chief executive officer gave a surprise keynote at the opening ceremony on Sunday, calling for future internet and AI technologies to be infused with privacy, security and humanity. The same day, one of China's most-senior officials called for more aggressive government involvement online to combat terrorism and criminals. Wang Huning, one of seven men on China's top decision-making body, even called for a global response team to go well beyond its borders. It was Cook's second appearance in China in two months, following a meeting with President Xi Jinping in October. The iPhone maker has most of its products manufactured in the country and is trying to regain market share in smartphones against local competitors such as Huawei. "The theme of this conference -- developing a digital economy for openness and shared benefits -- is a vision we at Apple share," Cook said. "We are proud to have worked alongside many of our partners in China to help build a community that will join a common future in cyberspace."
Software

Apple Is Back To Being the World's Top Wearable Maker (techcrunch.com) 48

Apple is once again the biggest selling producer of wearables after its third-generation Apple Watch, released in September, helped it pip China's Xiaomi to the post. TechCrunch reports: The new device, Apple's first that connects to the internet without being tethered to a smartphone, took the U.S. mobile giant to 3.9 million shipments in the recent Q3 2017, according to new data from Canalys. The firm estimates that the gen-three version accounted for just 800,000 shipments, due to supply issues, which bodes well for Apple coming into the lucrative holiday season. That figure was a big jump on 2.8 million shipments one year previous. It also gave Apple 23 percent of the market, putting it fractionally ahead of the 21 percent for Xiaomi, the Chinese firm that was briefly top of the industry for the first time in the previous quarter. Apple's wearable division has enjoyed something of a renaissance this year, grabbing the top spot in Q1 for overall wearables the first time since Q3 2015. CEO Tim Cook said in Apple's most recent earnings report that Watch sales were up by 50 percent for the third consecutive quarter thanks to a focus on health services. As for the others: Fitbit took third in Q3 2017 for 20 percent, while phone makers Huawei (six percent) and Samsung (five percent) were some way behind in rounding out the top five. In proof of considerable fragmentation within the industry, "other brands" accounted for a dominant 25 percent, according to Canalys' figures.
Businesses

Huawei Surpasses Apple As the World's Second Largest Smartphone Brand (theverge.com) 115

According to analysis by consulting firm Counterpoint Research, China's leading smartphone marker, Huawei, surpassed Apple's global smartphone sales for the first time in June and July. The company is only behind Samsung in sales. The Verge reports: Figures haven't been released yet for August, though Counterpoint indicates sales for that month also look strong. However, it's worth noting that with Apple's new iPhone releases just around the corner, the iPhone maker is almost certain to get back on top in September. Researchers at Counterpoint also point out that Huawei has a weak presence in the South Asian, Indian, and North American markets, which "limits Huawei's potential to the near-to-mid-term to take a sustainable second place position behind Samsung." Its strongest market is China, and it's also popular in Europe, Latin America, and the Middle East. Still, Apple doesn't have much to worry about; Counterpoint says the iPhone 7 and 7 Plus remain the world's best-selling smartphones, while Oppo's R11 and A57 claimed the third and fourth spots, respectively, followed by Samsung's Galaxy S8, Xiaomi's Redmi Note 4X, and Samsung's Galaxy S8 Plus. Surprisingly, despite overtaking Apple in global sales, none of Huawei's phones appear on the Top 10 list.
AI

Hackers Can Take Control of Siri and Alexa By Whispering To Them in Frequencies Humans Can't Hear (fastcodesign.com) 116

Chinese researchers have discovered a vulnerability in voice assistants from Apple, Google, Amazon, Microsoft, Samsung, and Huawei. It affects every iPhone and Macbook running Siri, any Galaxy phone, any PC running Windows 10, and even Amazon's Alexa assistant. From a report: Using a technique called the DolphinAttack, a team from Zhejiang University translated typical vocal commands into ultrasonic frequencies that are too high for the human ear to hear, but perfectly decipherable by the microphones and software powering our always-on voice assistants. This relatively simple translation process lets them take control of gadgets with just a few words uttered in frequencies none of us can hear. The researchers didn't just activate basic commands like "Hey Siri" or "Okay Google," though. They could also tell an iPhone to "call 1234567890" or tell an iPad to FaceTime the number. They could force a Macbook or a Nexus 7 to open a malicious website. They could order an Amazon Echo to "open the backdoor." Even an Audi Q3 could have its navigation system redirected to a new location. "Inaudible voice commands question the common design assumption that adversaries may at most try to manipulate a [voice assistant] vocally and can be detected by an alert user," the research team writes in a paper just accepted to the ACM Conference on Computer and Communications Security.
Android

TrustZone Downgrade Attack Opens Android Devices To Old Vulnerabilities (bleepingcomputer.com) 45

An anonymous reader writes from a report via Bleeping Computer: An attacker can downgrade components of the Android TrustZone technology -- a secure section of smartphone CPUs -- to older versions that feature known vulnerabilities. The attacker can then use previously published exploit code to attack up-to-date Android OS versions. The research team proved their attack in tests on devices running the ARM TrustZone technology, such as Samsung Galaxy S7, Huawei Mate 9, Google Nexus 5, and Google Nexus 6. They replaced updated versions of the Widevine trustlet with an older version that was vulnerable to CVE-2015-6639, a vulnerability in Android's Qualcomm Secure Execution Environment (QSEE) -- Qualcomm's name for its ARM TrustZone version that runs on Qualcomm chips. This vulnerability allows attackers root level access to the TrustZone OS, which indirectly grants the attack control over the entire phone. The research paper is available here, and one of the researcher's authors explains the attack chain in an interview here.
Android

Vulnerabilities Discovered In Mobile Bootloaders of Major Vendors (bleepingcomputer.com) 76

An anonymous reader writes: Android bootloader components from five major chipset vendors are affected by vulnerabilities that break the CoT (Chain of Trust) during the Android OS boot-up sequence, opening devices to attacks. The vulnerabilities were discovered with a new tool called BootStomp, developed by nine computer scientists from the University of California, Santa Barbara. Researchers analyzed five bootloaders from four vendors (NVIDIA, Qualcomm, MediaTek, and Huawei/HiSilicon). Using BootStomp, researchers identified seven security flaws, six new and one previously known (CVE-2014-9798). Of the six new flaws, bootloader vendors already acknowledged five and are working on a fix. "Some of these vulnerabilities would allow an attacker to execute arbitrary code as part of the bootloader (thus compromising the entire chain of trust), or to perform permanent denial-of-service attacks," the research team said (PDF). "Our tool also identified two bootloader vulnerabilities that can be leveraged by an attacker with root privileges on the OS to unlock the device and break the CoT."
AI

Huawei Unveils AI Mobile Chipset Said To Rival A11 Processor In Upcoming iPhones (macrumors.com) 77

On Saturday, Chinese mobile maker Huawei unveiled its first artificial intelligence smartphone chipset, which it hopes will lure customers away from Apple's upcoming range of new iPhones and towards the Asian company's "most powerful handset yet," the Mate 10, which is set to debut next month. Mac Rumors reports: Huawei touted the Kirin 970 AI mobile chipset's built-in "neural processing unit" at the IFA consumer electronics trade show in Berlin, claiming that the technology is "20 times faster" than a traditional processor. The world's third largest smartphone maker claimed that mobile devices powered by the Kirin 970 will be able to "truly know and understand their users," by supporting real-time image recognition, voice interaction, and intelligent photography with ease. According to Nikkei, the Kirin 970 integrates 5.5 billion transistors in a single square centimeter about the size of a thumbnail, which includes an octa-core central processing unit, a 12-core graphics processing unit, a dual-image signal processor, a high-speed 1.2Gbps Cat.18 modem, and AI mobile computing architecture. The Kirin 970 is said to be based on the same 10-nanometer technology as Apple's existing A10X Fusion processor and the A11 processor that will power its new iPhone range, set to debut this month. The Mate 10 is said to be a bezel-less all-screen handset with a 6-inch, 2:1 display and a 2,160 x 1,080 resolution. Like Apple's so-called "iPhone 8," the Mate 10 is also expected to feature some form of facial recognition and improved cameras.
Security

Secret Chips in Replacement Parts Can Completely Hijack Your Phone's Security (arstechnica.com) 62

Dan Goodin, writing for ArsTechnica: People with cracked touch screens or similar smartphone maladies have a new headache to consider: the possibility the replacement parts installed by repair shops contain secret hardware that completely hijacks the security of the device. The concern arises from research that shows how replacement screens -- one put into a Huawei Nexus 6P and the other into an LG G Pad 7.0 -- can be used to surreptitiously log keyboard input and patterns, install malicious apps, and take pictures and e-mail them to the attacker. The booby-trapped screens also exploited operating system vulnerabilities that bypassed key security protections built into the phones. The malicious parts cost less than $10 and could easily be mass-produced. Most chilling of all, to most people, the booby-trapped parts could be indistinguishable from legitimate ones, a trait that could leave many service technicians unaware of the maliciousness. There would be no sign of tampering unless someone with a background in hardware disassembled the repaired phone and inspected it. The research, in a paper presented this week (PDF) at the 2017 Usenix Workshop on Offensive Technologies, highlights an often overlooked disparity in smartphone security. The software drivers included in both the iOS and Android operating systems are closely guarded by the device manufacturers, and therefore exist within a "trust boundary."
Android

BLU Claims Innocence, Gets Phones Reinstated On Amazon (slashgear.com) 43

Earlier this week, Amazon suspended budget phone maker BLU from selling its phones on the site, citing a "potential security issue." A few days have passed and BLU has made its defense. SlashGear reports: AdUps, the Chinese company that provides affordable firmware update software to countless budget Android phones, is not spyware and not even Kryptowire, the security firm that broke the news last year, called it that, insists BLU. To be fair, Kryptowire really didn't. In its 2016 report, it simply described AdUps' OTA software as "FIRMWARE THAT TRANSMITTED PERSONALLY IDENTIFIABLE INFORMATION (PII) WITHOUT USER CONSENT OR DISCLOSURE." Curiously, that is more or less how the FTC defines spyware (PDF). In its 2017 follow-up, it did drop the second part of that phrase and simply reported on "mobile devices for Personally Identifiable Information (PII) collection and transmission to third parties." While BLU, and a few other OEMs, was caught unaware by the first report, it's insisting on its innocence in this second instance. Its defense stems from the argument that it is doing nothing that violates its Privacy Policy and, therefore, doesn't constitute any wrongdoing. Yes, that privacy policy that barely anyone reads, which can't legally be blamed on manufacturers anyway.

In other words, when you agreed to use BLU's devices, you basically agreed that such PII could possibly be transmitted to a third party outside the US. In this particular case, that does apply to the situation with AdUps. Interestingly, the policy's copyright dates back to 2016, when the AdUps issue first came up. The Internet Archives doesn't seem to have any version of that page before April this year. And so we come to BLU's second arguments: everybody's doing it. The data that AdUps collects is the same or even just a fraction of what other OEMs are collecting. Google is hardly the bastion of privacy and other OEMs are also collecting such data and sending it to servers in China, as is the case with Huawei and ZTE. Finally, BLU says that Kryptowire's new report really only identifies the Cubot X16S, from a Chinese OEM, as the only smartphone really spying on its users.
UPDATE: BLU has confirmed that its devices "are now back up for sale on Amazon."
China

Chinese Giant Huawei Gets Serious About PC Business, Announces Plans For Global Expansion (reuters.com) 53

Speaking of new laptops, Chinese conglomerate Huawei plans a global expansion into computers, it said on Tuesday, posing a fresh challenge to established PC players in a market that has suffered two years of falling sales volumes and pressure on margins. From a report: At a news conference in Berlin, the Shenzhen-based company introduced its first line-up of three personal computer models, including a 15.6-inch screen notebook, a 2-in-1 tablet and notebook hybrid and an ultra slim, metallic 13-inch notebook. Initially, Huawei plans to target the premium-priced consumer market, competing with Lenovo, HP and Dell, which together sell more than 50 percent of all PCs. To a lesser extent, it will also go up against Apple's high-end, but shrinking, Mac computer business. Huawei's Matebook X is a fanless notebook with splash-proof screen and combined fingerprint sign-on and power button, priced between 1,399 and 1,699 euros ($1,570-$1,900). Its Matebook E 2-in-1 hybrid will run from 999 to 1,299 euros while the Matebook D with 15.6-inch display is priced at 799 to 999 euros, it said. Huawei said it aims to offer the new PCs in 12 countries in Europe, North America, Asia, and the Middle East in early June.

Slashdot Top Deals