Isn't this because of the kimwolf (and now 6+ other botnets) that are taking advantage of people running residential proxyware unknowingly on the device which permits outbound connections to 127.0.0.1 on tcp/5555 to auth in and exec wgets or drops a loader that grabs the ddos malware APKs and install it?

It seems to require the user to:

1. Enable Developer Mode by going to an obscure settings page and tapping the build number seven times

2. Enable USB ADB debugging in the Developer Options

3. Establish an actual USB ADB session

4. Enable TCP/IP ADB debugging in the Developer Options

5. Unknowingly download a malware app from the official Play Store

6. Blindly click "Yes" on the permission prompt.

In other words: this is all but impossible to impact regular users, and it requires a particularly careless developer to be hit by it. And it only works if the Play Store is useless at preventing malware in the first place - but I thought their excellent app scanning was the entire reasoning behind all-but-banning 3rd-party app stores and sideloading???

It is "for safety" in the same sense that governments banning all encryption is to "protect the children" or to "prevent terrorism": flawed justification invented to distract from the real reason they want it.

[deleted]

I think expert users on HN seriously downplay the ability and willingness of "regular users" to do very stupid things on their devices. If grandma wants that app that gives her a beautiful horse as a lock screen image, she will follow every one of those six steps that the malware HorseLockScreen app developer presents to her. She will tap a button that has a skull and crossbones icon, that says "tapping this will drain your bank account and kill your dog" if she thinks it will let her do whatever she's trying to do on her device. Have you guys never done IT tech support for your elderly parents' computers?

I'm not saying it's right to respond by simply locking everything down, but let's not downplay the blast radius of basically every attack that involves telling the user to do things.

A long time ago, I fixed Windows machines for pocket change. I can confirm some users will make bad decisions no matter what warnings they're given.

I think the impulse for an OS vendor to try to make such mistakes impossible is about as wrong as selling knives dull so people can't hurt themselves. A knife that can't cut its user is useless as a knife.

Eh, this is a tough conversation for engineering-minded folks because the right answer is probably somewhere in the middle of a few different variables.

Too far towards trying to make mistakes impossible (which is easy for corporations to talk themselves into because it also makes them money and moat) and you make devices useless. Too far towards full user control and you get difficulties in support and security issues (which are tractable if you’re an enthusiast, but not so much if you’re a normie on a corporate-maintained device).

Truthseeking here is further complicated by ordinary end users’ dislikes and usability issues not always overlapping.

It requires a nuanced discussion and willingness to compromise to find the right balance. I don't like it myself when, every macOS release, Apple nerfs the system even more and locks down even more, but I also don't like telling my relatives that their system is part of a botnet and that they need to change all their password and call their bank, simply because they saw a popup that told them to download and run TrojanHappyFunGame.

It used to be common knowledge that downloading stuff could be dangerous. That went away when vendors tried to make it safe.

Many software vendors have deliberately blurred the lines between "on your computer" and "on the internet". When you save something in Application A, is it really being saved on your computer, or is it in the cloud? It used to be obvious, but now you kind of don't know until you do some digging in your filesystem. And, now we actually run some apps from the web!

The phrase "the user doesn't have to know if this is on his computer or the cloud" has done a lot of harm to the software ecosystem.

> Have you guys never done IT tech support for your elderly parents' computers?

This kind of comment is frequently made on HN and elsewhere. However, more than a few "elderly parents" are as computer-sophisticated as their grown children. A safe bet it's not rare to be exchanging ideas with an elderly person sophisticated enough to make comments on HN.

AFAIK there's no shortage of careless, uninformed, non-elderly individuals who get scammed into doing stupid things. Age is only one possible factor out of many contributing to scam vulnerability. And let us not forget that youthful, well-trained professional IT workers, developers and software engineers are not immune to scams via misunderstanding elements of the systems or processes they supervise.

"Ageism" is a word as ugly as what it signifies.

If the users' willingness to do stupid things is boundless, then locking down the system further isn't really of any benefit, since users will continue to venture as far as they need to, no matter the number of safety barriers they've passed. The only solution to that problem is a fully locked down device (which I hope we can all agree should not be the only option).

That's why they're going to fully locked down devices.

So, they will use other vectors, like convincing people to transfer money. Set up fake webshop. Run scams through online marketplaces, etc. The solution is not to make everything impossible. The solution is to educate people.

Right, and for the few people who can’t be educated, there’s always the option of making dedicated idiot-proof devices. Some people need to wear helmets and knee pads while walking around, but that doesn’t mean that all of us do. Some people shouldn’t be allowed near sharp objects, etc.

Stop trying to flatten the human experience, Harrison Bergeron style.

Until they will look indistinguishable from regular businesses doing regular marketing, advertising, and "value engineering" bullshit. It's xkcd://810 of the advertising industry, I guess - all the scammers doing the legitimate, sanctioned scamming like one big happy family, instead of unfairly competing.

Well the messaging we’re told is that the google play store exists for safety - such an app would never exist on there.

Of course this isn’t true, the play store, and yes even the apple App Store to a lesser extent, is riddled with malware.

But what this demonstrates is that, clearly, Google doesn’t care too much about security or safety. It’s a pretense, not a goal. If it was a goal, they’d dump money into fixing the play store, but they won’t and they don’t.

So, we should be highly skeptical when they say something is for “safety” and “security”. At this point, it’s a lot like saying something is for “national security”.

On multiple occasions I had trouble getting people to accept a self signed cert to show them something on a local webpage. It seems that elderly nowadays are super vary of any hacking or scams. YMMV.

Excellent, security education is working. The correct response to someone trying to convince you to accept a self-signed certificate is extreme skepticism; don't undermine people's understanding of good security practices.

> It seems that elderly nowadays are super vary of any hacking or scams. YMMV.

I'm sure you meant "wary". How amazing, education really does work. There is such a thing as overabundance of caution. But it's possible further education could encourage users to apply more balanced caution policies.

> let's not downplay the blast radius of basically every attack that involves telling the user to do things.

That radius would be negligible should the things that must remain secret remain offline.

But no, that's a luddite thing to even think about in an all-connected ever-online world where even wiping one's ass is done via of a swarm of dedicated apps.

On the other hand, there has always been a way to extract secrets from a granny via a mere voice call, so no amount of dumbing it down would really help.

This gave me a hearty laugh not only due to the idea, but because that's been my near exact experience with helping my family.

> In other words: this is all but impossible to impact regular users, and it requires a particularly careless developer to be hit by it.

Have you ever worked with someone who barely knows how to use a mobile phone? They will hand their phone over to someone they barely even know to do something they don't understand. They will follow instructions from a stranger over the phone, without understanding what the phone is warning them about.

I have worked with such a person. They did have someone walk them through a dubious process. Thankfully they realized what was going on before the process was complete, but who knows how much damage was done by the initial steps.

There are legitimate security reasons here. Whether there are reasons beyond that is an open question.

Following this logic, shouldn't we just ban smart phones for everyone then? If we need to dumb down all technology to the absolute lowest level, we should probably ban computers or at least require an official government-controlled license to get access to one. Is this a world you want to live in? Me neither.

I suspect this is in bad faith, but assuming not: how does that follow?

“Large numbers of people will uncritically follow sketchy instructions and get hacked” doesn’t in any way lead to “and therefore they cannot be trusted with devices”.

“People keep dying in auto accidents” doesn’t imply “ban cars” on the first order, it implies “seat belts and airbags”.

Yeah well this new thing is like requiring a certified Ford driver to drive the car.

On the contrary, we should simply restrict app development to a handful of megacorps (who are all in bed with the government) so they can make more money and the government can get the data it wants. Problem solved!

Me personaly, I'm so fed up with these advocates of security-through-universal-presumption-of-imbecility!..

> ban computers or at least require an official government-controlled license to get access to one

People seem to be ok with needing a license to operate a motor vehicle and those are far less dangerous.

Cars are far more dangerous and they kill people. It’s the number one cause of death for some demographics in the US.

A lot of people are misconstruing what I have said, which is pointing out that this can impact regular users. It not intended as a justification to restrict on-device ADB, and it certainly isn't meant to justify more extreme measures. That being said, we should not ignore what happens in the real world since the consequences are real.

Can we freaking sell them dumbphones, then, and stop destroying portable computers for everyone else with that excuse?

Which incidentally is often just a pretense for other motives?

If computers have suddenly become so dangerous for normal people, and they want smartphones nonetheless, add to them a dumb-mode encouraged at the initial setup, and requiring some third party assistance to turn it off once enabled..! (and forbid apps to change their behavior if it's not enabled)

Lots of dumb phones are trojaned on a firmware level. Trojans are different, but in general they allow the third-party (malware author) to accept SMS and forward them over internet. This is used to register accounts on a services which requires a phone number.

Here's my article about that from 2021. It's for the devices sold in Russia, but this issue is worldwide: https://habr.com/ru/articles/575626/

And here's more detailed research of two particular devices: https://notes.valdikss.org.ru/trojan-digma/

"Can we freaking sell them dumbphones"

Nothing is stopping the guy at Walmart or Tmobile from selling them dumbphones, or are you implying they are forced to?

Try letting the blame trickle down from the pyramid's apex instead of blaming the footman.

Here is the first iPhone ad:

https://www.youtube.com/watch?v=6Bvfs4ai5XU

The ad depicts it as a mere phone instead of a potentially hostile Turing machine. There is equivalent messaging in the android ecosystem but its advertising is not so ubiquitous.

You are right, better locking them out of the Play Store, there's too much risk using it.

We could also imagine a 24h delay to get Play Store access with a modal to make them understand the risks.

Those people will be conned in a million other ways.

You haven't been able to connect to an android device on port 5555 for yeeears. Every time you enable adb/IP it generates a new random port, or you need to use the QR/PIN pairing thing. On top of needing to enable developer options, adb/IP, confirm the fingerprint.

Millions of Superboxes and various digital picture frames say different.

https://synthient.com/blog/a-broken-system-fueling-botnets

Kimwolf exploits vulnerable Android Debug Bridge (ADB) services. Many low-cost TV boxes come "pre-infected" with proxy SDKs; Kimwolf then scans these residential proxy networks and exploits the devices within minutes as it propagates.

https://www.cloudflare.com/learning/ddos/glossary/aisuru-kim...

This is like saying that SSH is insecure because some device vendors install SSH, permitting root login with a default password of 'root'.

Yeah let's block port 80, too many people expose unprotected api.

This is what several cellular ISP to (block ports <1024 and 5555) to protect the users on IPv6.

You can unlock it with additional free option.

Well yes, but those won't get Google's new updates either. Open ADB on 5555 was a problem we solved almost a decade ago and these devices are still vulnerable. Even further restricting ADB in the latest version won't do anything to prevent that.

Hadn't thought about that additional attack vector those proxies are enabling. In addition to "internet access from residental connection" privileges, the attacker also gets access to loopback on the device that does the proxying...

But even then, shouldn't this show the same permission prompt for the user that anything else trying to connect to port 5555 would?

Yes, but users are told to allow it if they want to get free coins etc.

You can't fully protect people from the risk of taking bad advice from malicious strangers.

Not the least because most of our industry relies on it to make money. Marketing and advertising themselves are institutionalized forms of "do this thing that's actually harmful to you to get free coins / be safe / get laid".

> Not the least because most of our industry relies on it to make money.

I mean, this seems more like one of the root causes for a lot of bad things in the industry me...

Told by whom though? If it's through proxyware, then there are three parties who mostly don't know each other:

- the app embedding the proxyware SDK for money

- the proxy operators

- the attackers/botnets using the proxy to access ADB.

The botnet has no access to the app, so it can't show any messages.

The app can show messages, but probably has no connection to the botnet. (I hope)

The proxy operators could show a message by abusing the SDK even more, but that would mean they actively colluded with the botnet. Is that likely? Then they could just give the botnet direct access to the app, no need to do the whole proxy thing.

It isn't being done behind-the-back of proxy operators.

It's one more revenue stream to be able to remote control real android phones to pass device attestation checks etc.

It's marketed to users with phrases like "earn money from your phone whilst you sleep".

And it's entirely Cloudflare's and Google's fault. When you say you need to have X to do Y, people are going to find ways to get X.

Ok, that makes more sense. Hooray for stuff getting even worse...

Remote attestation itself being a questionable idea at best, so it's bad things creating a market for even worse workarounds.

No objection there.

Also telling that advertising and locking down devices are driven by the same companies...

From memory, for the kimwolf exploit things, other user already had good points about the device already beeing compromised. But also, the authentification part of ADB was just completly disabled, which is why this worked. Basically it was so-compromised as-is that ADB was just sitting here open, as is you where to put SSH with no authentification at all.

There are so many people in my neighborhood here that are actively members of residential proxy networks that it makes me stabby. They don't seem to care.

That said, I wasn't under the impression kimwolf was that technically sophisticated. Some of the others are, though.