• dhork@lemmy.world
    link
    fedilink
    English
    arrow-up
    130
    arrow-down
    3
    ·
    5 months ago

    “Temu is designed to make this expansive access undetected, even by sophisticated users,” Griffin’s complaint said. “Once installed, Temu can recompile itself and change properties, including overriding the data privacy settings users believe they have in place.”

    That’s just nuts

    • paraphrand@lemmy.world
      link
      fedilink
      English
      arrow-up
      37
      arrow-down
      5
      ·
      edit-2
      5 months ago

      This is why companies like Apple are at least a tiny bit correct when they go on about app security and limiting code execution. The fact it aligns with their creed of controlling all of the technology they sell makes the whole debate a mess, though. And it does not excuse shitty behavior on their part.

      But damn

      And if they got this past Apple in their platforms. That’s even wilder.

      • chiisana@lemmy.chiisana.net
        link
        fedilink
        English
        arrow-up
        17
        arrow-down
        4
        ·
        5 months ago

        The article linked to the analysis and on a quick glance, it seems to be done entirely against the Android variant of the app. This makes sense because if the alleged actions are true, they’d never have gotten on to the App Store for iOS Apple users… or at least as of a couple months ago. Who knows what kind of vulnerability is exposed by Apple only doing limited cursory checks for 3rd party App Stores.

      • GenitalHurricane@lemmy.world
        link
        fedilink
        English
        arrow-up
        8
        ·
        5 months ago
        1. Dynamic compilation using runtime.exec(). A cryptically named function in the source code calls for “package compile”, using runtime.exec(). This means a new program is created by the app itself.—Compiling is the process of creating a computer executable from a human-readable code. The executable created by this function is not visible to security scans before or during installation of the app, or even with elaborate penetration testing. Therefore, TEMU’s app could have passed all the tests for approval into Google’s Play Store, despite having an open door built in for an unbounded use of exploitative methods. The local compilation even allows the software to make use of other data on the device that itself could have been created dynamically and with information from TEMU’s servers.
        • GenitalHurricane@lemmy.world
          link
          fedilink
          English
          arrow-up
          8
          arrow-down
          1
          ·
          5 months ago

          Ah yes, delete your original incorrect comment instead of continuing the discussion about how wrong and lazy it was to make, nice.

  • Etterra@lemmy.world
    link
    fedilink
    English
    arrow-up
    45
    arrow-down
    3
    ·
    5 months ago

    I can’t believe anyone would buy from Temu. I knew they were Chinese knockoff bullshit the second I saw their first obnoxious ad.

      • exu@feditown.com
        link
        fedilink
        English
        arrow-up
        1
        ·
        5 months ago

        Apparently for some people (my mom) the search or filters work better on Temu. No idea why, I only ever use AliExpress.

    • Oaksey@lemmy.world
      link
      fedilink
      English
      arrow-up
      8
      ·
      5 months ago

      Plenty of items on eBay are just people who buy from China directly and mark up prices. If it is likely made in China and I don’t want it quickly, I’ll buy off aliexpress. That said, alibaba wanted me to upload photo ID which I noped out of. Temu started spamming my email address when I’d never used them. The unsubscribe link went to their website said to adjust your account settings if you didn’t want spam… I never created and account and avoided them completely following that.

    • Fades@lemmy.world
      link
      fedilink
      English
      arrow-up
      7
      ·
      5 months ago

      somethings people don’t care about quality. An example, the one time I checked out Temu way back when it first made its splash I bought some targets for shooting… Hard to fuck that up and got em cheap as fuck with that promo deal they do to hook you. Uninstalled it right after, probably not worth it but I feel like that is a common experience. There are items where you just simply can’t fuck up so the ultra cheapness works out.

      With that said, an obligatory FUCK temu and those like it.

    • trolololol@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      4
      ·
      5 months ago

      I can’t believe people pay full price on cheap stuff. The only reasonable thing to do is pay cheap on cheap stuff. And the delivery times are unbeatable .

      • odelik@lemmy.today
        link
        fedilink
        English
        arrow-up
        3
        ·
        5 months ago

        I can’t believe people buy cheap trash that would be sold on Temu.

        But here we are, people buy cheap ass trash off Temu. If China started picking through the trash we shipped them and sold it back to us on a site like Temu, something tells me people would still buy it.

        • BruceTwarzen@lemm.ee
          link
          fedilink
          English
          arrow-up
          1
          ·
          5 months ago

          People would buy an actual turd on temu if it’s cheap enough. Just read these comments here… But it’s cheap. Congrats, you bought cheap garbage and it got send around the globe by a company that sells your data

    • MigratingtoLemmy@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      arrow-down
      15
      ·
      5 months ago

      With how cheap they are, people will and should buy from TEMU. Aliexpress as a general store never had much of a competition for English speakers outside of Banggood for select electronics. Taoboa is good but it’s harder to use

      • protist@mander.xyz
        link
        fedilink
        English
        arrow-up
        14
        arrow-down
        3
        ·
        5 months ago

        So for you, the lowest price is the only thing that matters? It doesn’t matter whether it’s a shitty product? Or that they’re one of the least efficient shippers due to their tariff avoidance strategy, and in doing so are contributing more per purchase to climate change than even companies like Amazon and Walmart?

        • MigratingtoLemmy@lemmy.world
          link
          fedilink
          English
          arrow-up
          3
          arrow-down
          7
          ·
          edit-2
          5 months ago

          I’m happy because it’s competition for Aliexpress.

          Arguments against carbon emissions and carbon footprints against corporations isn’t very helpful unless you can do something about it. This is somehow a very unpopular opinion here, for some reason people don’t like being told that they don’t have much power. Boycotting it by yourself won’t work either, because even if the west gives up on it, the East will not. Carbon emissions will remain unless strict regulations are maintained, and we know who buys politicians these days. If I can do nothing about the climate, then yes I’d rather pay less. And I’m not explicitly anti-China like some people here because America is just as hypocritical.

          Yes there are really bad products and their QC is horrible. I’ll say the same for Aliexpress, Taobao, Amazon, Walmart and Bestbuy. Unfortunately for everyone here, we’re going to have to choose between shit options, so yes I’d rather pay less if it’s shit I’m going to get anyway. Besides, I’m smart enough to not make bigger purchases on these sites because I know of their QC situation.

          • Rekorse@lemmy.dbzer0.com
            link
            fedilink
            English
            arrow-up
            4
            arrow-down
            1
            ·
            5 months ago

            Boycotting is a collective action, it spreads like a virus, so you are wrong on its effectiveness.

            You sound like someone who wants hand waive away the real costs of their actions by saying there’s nothing you can do to change things.

            I hope the people who read your post aren’t demotivated to effect change because of it.

            • MigratingtoLemmy@lemmy.world
              link
              fedilink
              English
              arrow-up
              2
              ·
              edit-2
              5 months ago

              What I do not understand is why people are biased against certain companies in such a discussion. If your arguments are correct, then Amazon is a horrendous beast that should have been killed by now with “viral boycotting”. And here we are. Is anyone demotivated by knowing that people still buy from Amazon and make them billions? Why all the hate against TEMU specifically, when they’re trying to undercut Amazon and other stores? Let’s not pretend that Amazon and Best Buy and Walmart are a collective bunch of saints and can mean no harm. Where is the action in this case?

              Let me speak the bitter truth for you: the majority of the population here is American, with an inherent anti-chinese mentality when it comes to capitalistic ventures/operations. That is the reason for the hate. Alibaba faced the same issues, and in case someone wants to bring up Huawei for their actions, remember that AT&T runs an NSA spy-mission in Manhattan. Where is the outcry in this case?

              I might have veered off-topic, but bad QC and cheap deals aren’t inherently a Chinese thing. Hence, I do not follow the propaganda against Chinese shops who are beating American companies at their own game.

              Edit: since I’ve been called guilty of waiving away untoward actions, please enlighten me on how the general American population has stayed “responsible” and managed to put any dent in other non-Chinese companies that have their ethics in the dumpster and actively harm the environment and people (I’m looking at you Nestle, Spotify and OpenAI)

              • eatthecake@lemmy.world
                link
                fedilink
                English
                arrow-up
                1
                ·
                5 months ago

                I’m anticonsumption in general and temu just seems like the epitome of paying for disposable garbage.

                In general i don’t understand why people are buying any nonessential items at all. Everyone is apparently too poor but random crap still sells. I splurged and bought a cheap tablet to use as an ereader this year but only because i can’t justify the expense of buying books and my local library is awful.

  • Bluefruit@lemmy.world
    link
    fedilink
    English
    arrow-up
    43
    arrow-down
    4
    ·
    5 months ago

    Shocked i tell you. I am shocked.

    No way an app would collect data it doesnt need. Preposterous.

    Next thing you’ll tell me is that tiktok is doing the same thing!

        • TWeaK@lemm.ee
          link
          fedilink
          English
          arrow-up
          10
          arrow-down
          2
          ·
          5 months ago

          Erm, WhatsApp would suggest otherwise.

          WhatsApp was the vector for zero click access to a target’s phone from Israel’s weapons grade hacking Pegasus toolkit. They would send a video call, typically in the middle of the night, and with no input from the used they’d get full access. My personal belief is that they used functionality WhatsApp itself uses to access user data.

          There was also an encrypted phone called ANOM, which had this trick calculator app with a hidden encrypted messager. “Made for criminals, by criminals”. Except, when the guy started his business he got investment from the FBI and Australian Federal Police to pay for the servers and some of the phones themselves. Basically every time it sent an encrypted message it sent a separate encrypted message to the ANOM servers. It’s entirely possible (perhaps even likely) that WhatsApp would do this also.

          As for Google, they’re truly insidious. Lots of banks now require you to connect to Google captcha servers - they don’t give you the pictures, it’s just the back end, basically the tracking parts. Then there’s the controversy about them collecting location data when users have said no. They absolutely do collect data they shouldn’t.

          • TeddE@lemmy.world
            link
            fedilink
            English
            arrow-up
            6
            arrow-down
            1
            ·
            5 months ago

            I’ll accept that maybe I’m giving Google a pass because of misplaced nostalgia, and while I personally have never used or liked Meta Facebook, I’ll concede that for a while it provided a service some people valued.

            It’s still my opinion that Google and Facebook have a large percentage of engineers that personally try to make them a genuinely good service, at least moreso than compared to TikTok and Temu. But I’m willing to concede it’s not as much a practical difference as I would like.

          • TeddE@lemmy.world
            link
            fedilink
            English
            arrow-up
            17
            arrow-down
            3
            ·
            5 months ago

            Emphasis on by comparison, as in “molten hot metal is cooler than the surface of the sun, by comparison”.

            TikTok and Temu actively have code in them that would be considered a virus in other contexts. They exploit your system to gain more access than they should, violating the point of sandboxed access.

            By comparison Meta and Google merely take advantage of user ignorance and apathy by making opting out frustrating - but still technically doable.

            Both practices are terrible, but that’s not the same as saying they’re equally bad.

  • panicnow@lemmy.world
    link
    fedilink
    English
    arrow-up
    36
    arrow-down
    5
    ·
    5 months ago

    I generally think arstechnica.com does a decent job of being a non-garbage news site. I pay a couple bucks a month for the ad-free RSS feed. This story feels terrible to me. I don’t doubt a law suit has been filed, but I would expect some investigation by the reporter of the extra-ordinary claims of privilege escape the application is claimed to be capable of.

    • explore_broaden@midwest.social
      link
      fedilink
      English
      arrow-up
      5
      arrow-down
      1
      ·
      5 months ago

      Given that the headline says that it is a claim in a lawsuit, and the lawsuit is by a state attorney general and not some random nobody, I feel like they are being fairly reasonable.

      • Raploc@feddit.nl
        link
        fedilink
        English
        arrow-up
        1
        ·
        5 months ago

        Yes because AG’s from repub states never ever file frivolous lawsuits that suit their own agenda.

  • TwitchingCheese@lemmy.world
    link
    fedilink
    English
    arrow-up
    27
    arrow-down
    2
    ·
    5 months ago

    How about pass and enforce strong digital privacy protection laws you fucking cowards. When other countries spy on us it’s scary and bad, but for US companies? Best we can do is ban porn and demand backdoors to stop E2EE messaging.

  • Sam_Bass@lemmy.world
    link
    fedilink
    English
    arrow-up
    7
    ·
    5 months ago

    The only thing annoying to me about temu is the cheesy popups for “free” gifts and percent-off wheel spinners.

  • Timecircleline@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    3
    ·
    5 months ago

    But if you install the app you get a free Bluetooth speaker!!

    /Joking. Am I the only one who gets that ad constantly whenever I’m using a device that isn’t running ad blocks?

  • cybermass@lemmy.ca
    link
    fedilink
    English
    arrow-up
    7
    arrow-down
    4
    ·
    5 months ago

    I am not even remotely surprised.

    Every day I hear a story about Chinese software being spyware.

  • Snapz@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    5 months ago

    Have any of you actually ever stopped to process what the tagline, “I’m shopping like a billionaire” means?

    I’ve always interpreted it as,

    I’m needlessly buying things that don’t make me happy, but making the purchase without any hesitation, knowing that the purchase price could never financially impact me in any real way. When I purchase the thing, I’ll probably never use it or actually take it out of the box even. It is just empty, hollow. And somewhere inside, I always know that it’s all only possible, because I’m actively exploiting the cheap labor of scores of other people that are made to perpetually suffer in generations of abject poverty to allow for my relative comfort…

    🎶*“I’m shopping like a billionaire!”*🎶

    • Captain Poofter@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      edit-2
      5 months ago

      I am disabled and have limited income I don’t have control over increasing or decreasing. I use temu to save a lot of money on essential things that should be cheap but are still overpriced in America. Sponges. Rags. Soaps. Pens. Tools. Home improvement hardware. Plant grow supplies. Gifts for me nieces. The tagline, is just a tagline. Billionaires are not like me and scouring for cheap magic sponges.

      Edit: also, temu did not invent drop shipping. Shopping on amazon is literally the same thing.

      • PythagreousTitties@lemm.ee
        link
        fedilink
        English
        arrow-up
        0
        arrow-down
        4
        ·
        edit-2
        5 months ago

        Good to know people that are disabled don’t mind using shitty maleware apps, I guess?

        What’s your point combining using the malware app with you being disabled? Is that supposed to make the app better somehow?

        You’re not special because you’re disabled. Things you use aren’t magical amazing. You’re still the same as everyone else.

  • kibiz0r@midwest.social
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    5 months ago

    Comments here: “Yeah right, I’ll believe it when they explain how.”

    Article: literally has a section explaining how

    Edit:

    Replies: “Yeah, but that’s just a summary. I’ll believe it when they explain in full detail.”

    Article: literally has a link to the detailed explanation