華為 P30 PRO 傳與中國政府網站連線? - 手機討論

Table of Contents

後續原討論者在 github 的更新:
https://github.com/pe3zx/huawei-block-list

reddit 在 1 小時前發了後續文:
www.reddit.com/r/netsec/comments/bgeevn/analysis_of_false_positive_on_beiangovcn_requests/
縮:http://bit.ly/2KVMcY7

文章報導:
onties.com/thailand/against-the-huawei-p30-pro-without-link-to-china-the-point-is-a-misunderstanding-in-testing/
縮:https://onties.com/?p=370969

看來華為泰國跟就他很快聯繫。


以下是 github 的部份內容

Statement

As a solely maintainer for this project, please accept my deepest apologies for mistakes which cause misunderstadning for Huawei brand and customers. The fact that Huawei P30 Pro initated connections to beian.gov.cn is not true.

I still maintain this project for my own benefits. Please use it at your own risk. Please see more info in next section, on an anaylsis of beian.gov.cn

Explanation for An Existing of beian.gov.cn

Please see my statement above

Due to my responsibility for this hobby research to prevent distributing misleading or misunderstanding information, and suggestions made by other researchers to discover more findings or correct me if I did something wrong. As an intention for this research I told everyone in Thai, we couldn't and shouldn't make a conclusion in this moment until we can see everything clearly.

The requests to beian.gov.cn were happened during testing, originate from baidu.com. Please see this analysis report for more info

Timeline

April 22, 2019: Received a message from Huawei Thailand for supporting. They will try to coordinate with Huawei HQ.
April 23, 2019:
Sent more information about an analysis of www.beian.gov.cn to Huawei Thailand
Updated code and lists to support whitelist domain names and exclude false positive domain names
Updated posts to 2600 Thailand, /r/netsec on the thread and other media
Huawei Thailand ackownledged new update on false positive

Description

Domain names on master.txt are captured DNS requests from Huawei P30 Pro purchased in Thailand. All domains located in China and/or has an IP address within China's ASN. The device hasn't configured with Huawei services, including Huawei ID or any Hi services.

Please note that:

The block list may includes test domain names, baidu.com and qq.com.
By relying on techniques in update.py to verify location domain names. Some domain names such as tencent-cloud.net and hwcdn.net are not flagged. I will find a way to fix this issue later.

--

All Comments

Mia avatarMia2019-04-28
沒買過
Liam avatarLiam2019-05-02
買過的覺得不重要
Irma avatarIrma2019-05-07
我也覺得會在意就不會買華為了
Rachel avatarRachel2019-05-11
高調
Yedda avatarYedda2019-05-16
老實說,如果改為傳回一間號稱99%員工持股的軍方色彩公司,會比較安心嗎?
Bennie avatarBennie2019-05-20
很多人很安心啊 還叫你不要扯政治呢
Ina avatarIna2019-05-24
樓下買來幫試
Skylar Davis avatarSkylar Davis2019-05-29
你是不是還沒搞懂ICP? reddit的回應就寫了那個網址是幹嘛的了不是嗎?
Wallis avatarWallis2019-06-02
一天到晚這種新聞看都煩死了
Emma avatarEmma2019-06-07
我就是怕討論ICP是什麼導致失焦,上篇才不敢深入。顯然要讓一些人理解什麼是ICP有很大的問題
Carolina Franco avatarCarolina Franco2019-06-11
如果你已經知道備案這東西的話 那麼上一篇的內容 和最原始那篇的48樓應該就可以理解了吧?
Selena avatarSelena2019-06-16
現在就是除了百度域名特定網站外,原作者沒看到其他地方出現ICP,所以覺得自己誤判道歉。您一開始錯誤引述,覺得自己一點責任都沒有嗎?
Elma avatarElma2019-06-20
說好如有錯誤就立即更正,結果原文也沒動啊?
Rebecca avatarRebecca2019-06-25
真的這樣就抓到且證明外媒還不狂炒
Lauren avatarLauren2019-06-29
有點智商也是自己蒐集再用私人管道給,誰會直接相連
Iris avatarIris2019-07-03
ICP備啊…對岸互聯網的規定。
Jake avatarJake2019-07-08
我是建議啦 reddit上 甚至這篇最原始的文都有人解釋了 這些東西不標出來 實在是沒有中立可言 不彷貼出來?
Suhail Hany avatarSuhail Hany2019-07-12
http://i.imgur.com/xukZBpJ.jpg
Michael avatarMichael2019-07-17
Reddit上我只找到這篇,感覺派對已經結束了 …
Jack avatarJack2019-07-21
你應該也知道 只看文章甚至標題就以為已經知道所有事的人很多 就像你那篇文會爆一樣 所以如果可以在你的文章本體告訴大家現在事實是什麼 會比較好
Eartha avatarEartha2019-07-26
會在意這種事的人不會買華為啦...
Kelly avatarKelly2019-07-30
pe3zx發布statement約在2小時前,說真的必須推grief3能跟作者同步po文更新消息並且上色,頗有0-day身手但grief3幾乎0時差更新然後指責 Kouta 發布假消息又是見獵心喜又是與惡的距離整個抓小辮子大放厥詞不是沒人看出來,旁觀者清我們也是笑笑而已啦https://i.imgur.com/xuPZ0kB.png
Eartha avatarEartha2019-08-04
Kouta的消息就是有問題啊
Liam avatarLiam2019-08-08
自己散播錯誤資訊(套用現在鄉民愛說的,沒找懂的人查證),還可以牽托別人的責備,也是醉了啦,看的也是笑笑
Irma avatarIrma2019-08-13
我都不好意思說grief3能這樣0時差po文想必是_______
Aaliyah avatarAaliyah2019-08-17
github可以watch訂閱更新。
Annie avatarAnnie2019-08-21
既重視資安卻又力推華為的朋友呢:)
John avatarJohn2019-08-26
這都可以抹嗎,是不是網軍不是隨便google看看過去ptt發言紀錄及知道了?
Mia avatarMia2019-08-30
第一次在這裡討論華為資安吧,看不下去資訊實在錯很大,這作者一開始的論點就很有問題了
Delia avatarDelia2019-09-04
結果下面一堆見獵心喜的推文,實在受不了
Franklin avatarFranklin2019-09-08
我抹你甚麼了?說你重視資安但力推華為說的不對嗎?
Damian avatarDamian2019-09-13
因為我今天工作之餘才有空細細吧github跟討論串讀完啊…很難懂嗎
Xanthe avatarXanthe2019-09-17
還是要修正grief3其實是不推華為的朋友? :)
Poppy avatarPoppy2019-09-22
我確實不推華為啊…文章裡有哪裡在推崇華為嗎?
Connor avatarConnor2019-09-26
就事論事罷了
Elvira avatarElvira2019-09-30
對了,至於Adblock的Log為何不準確?我個人猜測,如果你是在沒越獄或Root的情況下使用,它很可能擋住的只有「前端畫面」有顯示的內容,沒顯示出來的可能就過濾不到,除非你Root過濾全機的所有連線。