logoalt Hacker News

Motorola phones have started hijacking the Amazon app to insert affiliate codes

338 pointsby Cider9986today at 3:56 AM190 commentsview on HN

Comments

codedokodetoday at 9:22 AM

Think how bad the market got. Today we have preinstalled garbage apps like LinkedIn, garbage apps mandated to be preinstalled by the government, ads, cloud accounts, notifications spam, telemetry. This is not only Chinese smartphones, for example Samsung also plays this game. I assume there are Chinese backdoors, American backdoors and national government backdoors on almost every phone.

And there seems to be no way to buy a "free" smartphone without Google Services and telemetry below $250. Why 250? Because free OS have multiple bugs and issues and it is not rational to pay more than that.

I am considering two options, one, try to clean up and patch the firmware for a cheap smartphone (remove almost everything proprietary including Google Services, Unrusted Execution Environment, except for basic GUI and launcher), or two, port something like Lineage OS to my phone. Also I need to examine the network traffic and scan for potential weak points like SUID binaries. It is scary to think how much time I will have to waste for this.

Also, it is pretty stupid, in my opinion, to make an OS not based on Android, for example, use Qt for GUI, because there will be no apps for it.

show 3 replies
kaysontoday at 5:22 AM

> In further digging, we noticed that the URL the phone opens up is “kira-abboud.com,” a website that references fashion influencer “@kirasfashionfinds.” Notably, this exact URL isn’t listed anywhere on Abboud’s social media, and the affiliate codes don’t match up either. The redirect coming from Motorola phones is using Amazona affiliate code “sramz-kff-008-20” which is completely different from any of the codes we saw from links shared by Abboud’s accounts and linked websites.

Something funny is up; this doesn't seem deliberate.

show 2 replies
rainforesttoday at 7:12 AM

Note that the smart feed "feature" is Taboola-provided adware[0] so it's par for the course. It's beyond comprehension Lenovo would trash the brand by shipping it on flagships.

[0] https://www.reddit.com/r/motorola/comments/1s61usi/edge_60_p...

show 2 replies
Retr0idtoday at 11:17 AM

I recently got a Samsung A07 to run some tests on. It's stunningly cheap at <£100, and will supposedly get 5 years of software/security updates.

After setting it up, I was surprised (but also not surprised) to see ads on the lock screen. The "feature" is called Glance and while it can be disabled in the settings it took me the help of a video tutorial to actually locate the setting.

show 1 reply
xzxztoday at 5:28 AM

I used to choose Motorola devices for a long time but since 2 years when I bought Edge 30 Fusion I started to notice they automatically (without my knowledge) add 3 stupid apps or games about two times a month :/ There is no way to stop it. My kids phones are stuffed with this sh*t.

show 6 replies
sandreastoday at 6:22 AM

Hmm, this thread and the reports of shady practices make me wonder if this will affect the partnership with GrapheneOS[1]. It seems that such things shouldn't really happen on a device where security is a top priority, whether intentional or not.

1: https://news.ycombinator.com/item?id=47214645

show 2 replies
dmos62today at 7:58 AM

I've a Xiaomi phone on which twice appeared obviously debug/hello-world notifications (something like "testtest111") from apps I've never seen or installed. Then another time all Xiaomi phones of close relatives started getting these cheap, spammy ads for Android games in the notifications, this time from some obscure system app: had to look up on reddit that there are settings that disable this specific behavior.

The degree to which I don't own my own device is insane.

show 2 replies
blitzotoday at 5:24 AM

Isn't this cookie stuffing? Same modus operandi using by Geo-something widget back in 2000s with hidden ebay affiliate links that got caught by FBI. Someone should go in jail for this.

fransje26today at 8:06 AM

This bodes well for the up-coming GrapheneOS cooperation..

Nothing screams "secure" better than app hijacking and url injections.

davidelettieritoday at 8:25 AM

With the digital wellbeing app feature it is possible to set a timer of 0 minutes on all auto-installed and auto-reenabling apps to effectively disabling it for good.

Edit: the timer stays even after updates so the app is not enabled again

thenthenthentoday at 2:14 PM

Isnt Motorola basically a ‘Shanzhai’ (copy cat) brand now? Some dude putting the logo on some OEM parts? I am thinking of that Commodore phone from a while back and others. While completely speculative, it is interesting to see legit brands go Shanzhai or get Shanzhaied and Shanzhai brands go legit (xiaomi, huawei)

p0w3n3dtoday at 6:59 AM

Is Motorola Chinese by any chance? I remember the Motorola company has been split to phones and the rest

show 1 reply
noduermetoday at 7:05 AM

I like the Stylus G better than most phones I've owned, but Motorola really needs to end its partnership with the offensive "Glance" ad platform. There should not be a third party app like that which keeps re-enabling and reinstalling on every update. I don't understand what Motorola would get out of a partnership with a scammy third rate ad market that would be worth pissing off so many of their customers, but maybe they have some high level corruption in the company.

daft_pinktoday at 3:15 PM

Why would Amazon pay out on scam affiliate links? That’s the thing I don’t really understand from the honey scam.

show 1 reply
realusernametoday at 10:04 AM

Notice that this will pass Play Integrity while your clean rom won't.

andyjohnson0today at 7:10 AM

I have a Motorola G70, so this is concerning. But its hard to believe that this is a deliberate action by Motorola. To me it seems more likely that an update was compromised. Still bad though.

heikkilevantotoday at 6:22 AM

The comments here say that all Android phone manufacturers do stuff like this. I have never noticed that kind of things on my Fairphone. But then again, I don't have many apps and certainly not Amazon.

show 1 reply
zx8080today at 10:27 AM

Vertical videos converted to 16:9 are bad for your readers, Mr Senior Editor.

> Ben Schoon is a Senior Editor

Thank you so much for being not able to consume the screencast video in the article.

rbbydotdevtoday at 12:13 PM

That sounds like a violation of affiliate t&c ? Wouldn't that nullify them, and even lead to lawsuits?

ameliustoday at 9:29 AM

Since Uber, Airbnb and Tesla, now every company thinks they can do borderline illegal stuff to make an extra buck.

What is next? Our banks selling our payment histories to the highest bidder?

show 2 replies
risfriendtoday at 5:52 AM

This is really unethical, replacing original app shortcuts breaks trust.

999900000999today at 5:39 AM

To think I was worried about buying a Xiaomi tablet while already using a Motorola.

Gonna flash a rom on the Xiaomi anyway, but all oems are doing this type of stuff.

show 2 replies
dotcomatoday at 5:07 AM

How low can you go?

pjmlptoday at 10:01 AM

Yeah, I miss the days of multiple choices on mobile phone OSes.

wat10000today at 3:36 PM

If we're going to imprison people for things like guessing user IDs, this surely ought to count as criminal unauthorized access to a computer system.

0x59today at 11:02 AM

Its a source of revenue that doesn't harm the user and cannot be disabled by the user. It's the gold standard.

marcusholttoday at 1:42 PM

Your phone is now a vending machine that charges you for the privilege of inserting coins. The product was never the phone.

gskytoday at 4:21 AM

Chinese brands always pull this stuff

show 2 replies
theologantoday at 1:28 PM

Most non-triumphant.

zb3today at 10:34 AM

This is why we need to fight for the right to unlock the bootloader, not only on flagships.

coretxtoday at 5:38 AM

That begs the question! Did they use a Sony rootkit ? XD

metalmantoday at 8:44 AM

It is laborious to go through all the apps on a phone and dissable the default unessesary "open web link" feature on ALL the apps, but apparently it has some effect in reducing the "draft" from all the back doors

gib444today at 4:23 AM

I was possibly thinking of getting a Motorola with G.ràphenéOS when released.

Yeah, not now.

show 1 reply
warrantisalltoday at 5:33 AM

[dead]

dingensundsotoday at 5:30 AM

Calling this "hijacking the Amazon app" is hyperbolic in my opinion. They replaced the shortcut in the app drawer. To me this looks like normal scummy OEM behaviour, like pre-installing spyware, "anti-" malware, adware etc. which sadly pretty much every mobile/computer manufacturer does.

Replacing the OS is one of the first things I do with every laptop, PC and mobile device to get rid of (most) crap that was installed without my consent.

show 1 reply
sourcegrifttoday at 4:28 AM

If an anti-worker company is getting fleeced, nothing wrong with that.

I hope motorola collaborates with Pine and brings linux to phones. In the age of LLM apps are obviously not a problem. (Hopefully windows Phone 7, not 8 also comes back)

show 1 reply