xad , (edited )

I hate Temu, but this (apparently contracted?) Grizzly Reports report isn't really all that trust inspiring, tbh.

Our experts identified a stack of software functions that are completely inappropriate to and dangerous

The stack difference to the Amazon app they list:

  • Package compile
  • Requesting system logs
  • Some code obfuscation
  • Mac address collection
  • Install permission
  • Wake lock

Meh. That's just a sliver worse than your regular, off the shelves proprietary corporate app. I don't see how they can pull off the promise of being a truly dynamic Android app from that report.

I do believe they hover up data, but they aren't otherworldly super hackers. They will probably just ask for the data and the users will hand it over in a second. For most people, it really is that simple.

KillingTimeItself ,

since people are yelling about it.

It's probably not blatantly bypassing security and privacy features, what it is PROBABLY doing is using the user to bypass them by simply manipulating them to do it.

Social engineering is way easier than whatever bullshit you would need to do to bypass sandboxing and dynamically recompile, or whatever people are claiming, and my guess would be that this is what they're doing.

If the suit is claiming they are doing what i said, that's probably legal, and not going anywhere, unless tiktok ban bill 2.0. If the suit is claiming what others are claiming, it's still probably wrong and probably going to be tiktok ban bill 2.0.

Unfortunately these things aren't all that exciting at the end of the day.

Churbleyimyam ,

Not enough just to get someone else to take your cheap plastic shit to landfill after it's cluttered their space then I guess.

FunnyUsername ,
@FunnyUsername@lemmy.world avatar

Can someone explain to me how you can just simply program something to bypass privacy and security features? What is the point of having these features if you can literally just program something to ignore them? Like....??? Temu is obviously bad if this is true, but if it IS true, it shouldn't have been possible to begin with!!

Churbleyimyam ,

Looking forward to someone answering this

Juantonz ,

Im not sure how they specifically bypass the features in other ways but I imagine some of it is from users accepting permissions under the guise of another use. For example, maybe you accept the microphone permission on tik tok to record video. With that permission in theory the app could now use it maliciously. Of course it should all depend on the users choice for that and im not sure beyond the scope of that.

TORfdot0 shared this comment below:

Someone else posted this report in this thread which does a good job of the deceptive practices and API calls the app uses to trick the user into giving permissions up willingly and otherwise collect data it shouldn’t.

nutt_goblin ,
KillingTimeItself ,

one of the most obvious ways is to simply not bypass them, and then do it from within the application itself. That way you can essentially man in the middle the rest of it, though this would require a rather specific set of events and a particularly nested design of an app.

PanArab ,

At what point does this all just become sinophobia?

PythagreousTitties ,

Probably when the software isn't malware.
But in this case it is.

kibiz0r , (edited )

Comments here: “Yeah right, I’ll believe it when they explain how.”

Article: literally has a section explaining how

Edit:

Replies: "Yeah, but that's just a summary. I'll believe it when they explain in full detail."

Article: literally has a link to the detailed explanation

AProfessional , (edited )

The claim is they completely bypass all Android and iOS security is pretty unbelievable.

If so then the real discussion is how these zero day exploits are just sitting around.

EDIT: It seems the focus is on Android but all the information is nonsensical, like AI generated buzzword bingo.

aodhsishaj ,
AProfessional , (edited )

That source looks better indeed.

Ars quotes nonsense like “bypasses the security” and “exploit the user”.

Those terms have meaning and they aren’t applicable here.

At the end though they do say things like

is able to hack your phone from the moment you install the app

Without any credible evidence.

TORFdot0 ,

It states that it’s somehow breaking the permissions sandbox by dynamically recompiling code after the app is opened. Unless there is some undisclosed exploit that it’s using to break the sandbox, it’s outside most people’s understanding of how these platforms work

MoonRaven ,
@MoonRaven@feddit.nl avatar

It only explains how it would pass (automatic) reviews. Not how it would bypass the sandbox. So yeah, you're right, not enough info sadly.

TORFdot0 ,

Someone else posted this report in this thread which does a good job of the deceptive practices and API calls the app uses to trick the user into giving permissions up willingly and otherwise collect data it shouldn’t.

fne8w2ah ,

Also fuck their landfillware Chinesium "products".

chiliedogg ,

That's also most of what's on Amazon these days.

InternetUser2012 ,

Amazon is just faster shipped temu garbage

FunnyUsername ,
@FunnyUsername@lemmy.world avatar

Every person I've heard hate on temu shops on amazon, too. It's pretty ironic.

TORFdot0 ,

If it’s $5 and some random assortments of letters for a brand name you might as well just light your money on fire whether you order from temu or amazon or Walmart for that matter

s_s ,

I mean, some things are just fine when they are the cheapest?

GreatAlbatross , (edited )
@GreatAlbatross@feddit.uk avatar

I'm shocked, I say. Shocked!
The idea of an app being used to gather additional datea from a customer!

Muscar ,

"Additional date"

Snapz ,

Have any of you actually ever stopped to process what the tagline, "I'm shopping like a billionaire" means?

I've always interpreted it as,

I'm needlessly buying things that don't make me happy, but making the purchase without any hesitation, knowing that the purchase price could never financially impact me in any real way. When I purchase the thing, I'll probably never use it or actually take it out of the box even. It is just empty, hollow. And somewhere inside, I always know that it's all only possible, because I'm actively exploiting the cheap labor of scores of other people that are made to perpetually suffer in generations of abject poverty to allow for my relative comfort...

🎶*"I'm shopping like a billionaire!"*🎶

FunnyUsername , (edited )
@FunnyUsername@lemmy.world avatar

I am disabled and have limited income I don't have control over increasing or decreasing. I use temu to save a lot of money on essential things that should be cheap but are still overpriced in America. Sponges. Rags. Soaps. Pens. Tools. Home improvement hardware. Plant grow supplies. Gifts for me nieces. The tagline, is just a tagline. Billionaires are not like me and scouring for cheap magic sponges.

Edit: also, temu did not invent drop shipping. Shopping on amazon is literally the same thing.

PythagreousTitties , (edited )

Good to know people that are disabled don't mind using shitty maleware apps, I guess?

What's your point combining using the malware app with you being disabled? Is that supposed to make the app better somehow?

You're not special because you're disabled. Things you use aren't magical amazing. You're still the same as everyone else.

ReveredOxygen ,
@ReveredOxygen@sh.itjust.works avatar

That's... not what they were saying? They were responding to a comment saying it encourages consumerism by saying that they use it for better prices on things they need regardless

PythagreousTitties ,

What does being disabled have to do it?

ReveredOxygen ,
@ReveredOxygen@sh.itjust.works avatar

That's why they're broke

dan ,
@dan@upvote.au avatar

My interpretation of that tagline is that since the prices on Temu are cheap, it means you can shop as if you had a lot of money, without actually spending that much.

RaoulDook ,

I think you cracked the case on that one, that's gotta be what it means.

Appoxo ,
@Appoxo@lemmy.dbzer0.com avatar

Like a worse AliExpress

FlyingSquid ,
@FlyingSquid@lemmy.world avatar

Yesterday, I saw a Temu ad for something and I just wanted to open it to read the info and there were so many popups and "spin the wheel for a prize" and "enter your email here" and so on that I gave up and just looked for the info elsewhere. Never clicking on a Temu link again.

thermal_shock ,

one of the best decisions you'll ever make, next to dns level blocking it on your network.

pantyhosewimp ,

Same, but a year ago.

Also, Temu has tried to take all the shopping search results from Bing/DDG. So those results are trash now.

MehBlah ,

I get their CAPTCHA where I have to slide the puzzle piece over to look at one of their ads. More than half the time I will do this and it will fail saying I didn't do it right. So yeah temu has become a trash site.

Raiderkev ,
dan ,
@dan@upvote.au avatar

That CAPTCHA isn't specific to Temu.

maxinstuff ,
@maxinstuff@lemmy.world avatar

All I want to know is what do these Temu people think my life is like?

https://lemmy.world/pictrs/image/2a70050f-f3a6-49ea-9318-97144bf090fd.jpeg

TheDarksteel94 ,

I mean, you're obviously a sexy military mechanic woman, who goes into battle with fantasy battle armor and goes fishing as a hobby! Duh.

Spacehooks ,

I was wondering what that blue thing was. I thought it was a weird personal tool....

RaoulDook ,

It looks like an archery release, used by compound bow shooters to pull the bow string back and release with a trigger or button

Silentiea ,
@Silentiea@lemmy.blahaj.zone avatar

The bearings combined with the wrenches made me think, like, roboticist. So maybe they make fishing robots that double as sexbots?

beejboytyson ,

Trust me, fish dont need to be robots to be fucked....

towerful ,

Any good RPG has a solid fishing mini game tbh

Stupidmanager ,

Clearly you use adbloker or something cause temu just got excited when you opened up the link.

https://lemmy.world/pictrs/image/f4365e4d-ca7d-495b-ae69-0cb3edf10fb2.gif

djsaskdja ,

Your life looks pretty sick to me!

thermal_shock ,

he's batman

dutchkimble ,

Batwoman

MR_GABARISE ,

No, you don't get it.

These massive Batman pecs need support.

uis ,
@uis@lemm.ee avatar

Batmare

MigratingtoLemmy ,

Bustybats

brlemworld ,

Are you a busty outdoorswoman?

UnaSolaEstrellaLibre ,

Weaponized fishing for covert military operations.

Raiderkev ,

On a skateboard... with tits!

sramder ,
@sramder@lemmy.world avatar

Code Name: Go Fish!

Zink , (edited )

It just thinks you’re a garden variety redneck.

Mr_Wobble ,

Apparently you're big into cranking.

TwitchingCheese ,

How about pass and enforce strong digital privacy protection laws you fucking cowards. When other countries spy on us it's scary and bad, but for US companies? Best we can do is ban porn and demand backdoors to stop E2EE messaging.

maxinstuff ,
@maxinstuff@lemmy.world avatar

Unfortunately they care more about spying on us themselves.

Sabata11792 ,
@Sabata11792@ani.social avatar

That would hurt the advertising, spam, blackmail, malware, and propaganda industries. We can't rip out the economic spine of big tech since they pay the best bribes.

Bertuccio ,

I'm pretty sure Temu is Chinese.

dan ,
@dan@upvote.au avatar

California (and a few other states) are trying. The CCPA and CPRA are a good step in the right direction. If you're a California resident, you can request all the data a business has collected about you, tell them to stop sharing it with business partners, or tell them to completely delete it, similar to the GDPR in Europe.

TwitchingCheese ,

Oh don't worry, they're going to try and kill that too before it hurts them too much, and with the audacity of calling it the "American Privacy Rights Act". https://www.eff.org/deeplinks/2024/06/eff-opposes-american-privacy-rights-act

dan ,
@dan@upvote.au avatar

Ugh. I hate this so much.

Sam_Bass ,

The only thing annoying to me about temu is the cheesy popups for "free" gifts and percent-off wheel spinners.

Blackmist ,

And the product thumbnails that all look like sex toys.

nicgentile ,
explore_broaden ,

Where are you viewing Lemmy posts that you have ads?

gunpachi ,

I think it's the Boost app.

explore_broaden ,

I see; I can’t imagine willingly submitting to ads, but whatever works for them.

smiletolerantly ,

Yeah. Boost itself is great though. Well worth the couple of bucks to get rid of the ads forever.

Xylight ,
@Xylight@lemdro.id avatar

What does Boost have over clients like Voyager?

PythagreousTitties ,

Ads

Xylight ,
@Xylight@lemdro.id avatar

Ads for a platform with political views that despise them. Ironic

Mobiuthuselah ,

I use it too. Tried a few different ones and like boost the best. I finally just paid for the non-ad tier. One time cost of 3.99. I would have been turned off by a subscription.

gunpachi ,

Yeah boost is definitely good, it was my main app until a few months ago. Recently I have been trying Connect, which is another great app.

Connect has improved a lot since I first tried it, also doesn't have any ads. But all things considered - Boost is bit more polished than connect.

Rekorse ,

What's wrong with voyager? Its already ad-free.

Seems so strange to choose to inject adds over top of lemmy by choice.

Jestzer ,

And it has come a long way too. In fact, I just donated since it’s struck me how solid of an experience it’s been.

olympicyes ,

I’m using Voyager and it’s great. I don’t even use the app, I prefer the PWA.

explore_broaden ,

I also use Voyager and agree, plus it’s actually open source.

foremanguy92_ ,

First, you use Lemmy, that's great. But pls use a client without ads....

nicgentile ,

Been using Boost since it was a Reddit client. By default, it is my go to.

Veddit ,

100% this. Boost is great

foremanguy92_ ,

Maybe but you've done the transition to Lemmy try to use a libre client

nicgentile ,

I'm all for Libre but in this case @rmayayo is my leader.

foremanguy92_ ,

Who is he?

nicgentile ,

He is the dev who made Boost.

foremanguy92_ ,

Why does he done it with ads?

nicgentile ,

Support his development. I will pay to remove the ads at some point when I am not being lazy. Many people like him because he listens, makes changes, has tremendous support and so on. Not to say that others don't but that is just how we roll.

foremanguy92_ ,

I'm okay with him earning money to live, but put ads is absolutely not something to do. Donate to him, etc. But you shouldn't use an app with ads

nicgentile ,

Been this way for many years. Ads don't bother me. And if its continuous help, then we roll with it. But someday I may do the thing.

foremanguy92_ ,

It's not purely the ads that bother me, it's the company behind it, to integer ads you have to use google, meta scripts. Big problem for privacy

DerisionConsulting ,

by "client" do you mean "just use a browser"?

BigFatNips ,

Or, you know, the 98% of clients that don't have ads. I, for one, recommend Voyager.

foremanguy92_ ,

Maybe but not only, for phone I recommend an app that's much more optimized for using on mobile

mrvictory1 ,

Lemmy website is fine on mobile imo. Not perfect but usable and optimized.

foremanguy92_ ,

For sure! Personally I prefer using the app

dan ,
@dan@upvote.au avatar

You can pay just a few dollars to remove the ads from Boost.

foremanguy92_ ,

Bro why using Lemmy if it's for using proprietary client? Voyager, Jerboa, you have others choice...

dan ,
@dan@upvote.au avatar

Ask the 100,000 people that downloaded Boost, not me.

Andromxda ,
@Andromxda@lemmy.dbzer0.com avatar

Probably people who have been using Boost for Reddit before and now want the same experience but for Lemmy

foremanguy92_ ,

But with this change from reddit to Lemmy the should have done the same thing for their client

Andromxda ,
@Andromxda@lemmy.dbzer0.com avatar

That's what you get for using a proprietary Lemmy app. Switch to Thunder, it doesn't have ads, it's open source and in my opinion has the best UI out of all Lemmy apps. Also support the development and join their community: !thunder_app

Appoxo ,
@Appoxo@lemmy.dbzer0.com avatar

From the screenshots alone the interface looks similar to sync

djsaskdja ,

Do you think it’s better than Voyager? That’s what I’ve been using. Pretty satisfied with it.

MigratingtoLemmy ,

Jerboa here but same

Andromxda ,
@Andromxda@lemmy.dbzer0.com avatar

I tried using Jerboa and found it to be incredibly buggy and poorly designed. Not sure what's going on there, considering that it's the official mobile app made by the Lemmy devs

MigratingtoLemmy ,

Has worked mostly fine for me, YMMV

Veddit ,
nicgentile ,

Lol

  • All
  • Subscribed
  • Moderated
  • Favorites
  • [email protected]
  • kbinchat
  • All magazines