Telemetry found in Nokia 7.2 & 6.2

Peter-Parker
Peter-Parker ✭✭
edited March 2020 in Nokia 7.2

Hello!

I would like to hear Nokia or HMD Global official reply to the following posts:

No 1 (English): https://www.reddit.com/r/privacy/comments/fbxg0a/less_than_a_year_after_removing_3rd_party/

No 2 (German): https://www.androidpit.de/forum/801980/kennt-jemand-das-paket-co-sitic-pp

I can confirm that my device has the same app they speak about


Comments

  • i have the same application in my 7.2, and my phone was made in India.

  • Corvo
    Corvo ✭✭

    This is a privacy/security issue. Please provide us some clarity here HMD

  • Akhil
    Akhil ✭✭✭

    I dont have this app in my 7.2

  • @Akhil did you check in Data usage? App is not visible in System apps.

  • singhnsk
    singhnsk Super User

    It isn't exactly telemetry. But yeah it should not have been there in regions in which that carrier does not operate.

    I did a long answer on Reddit about this.

  • Peter-Parker
    Peter-Parker ✭✭
    edited March 2020

    @singhnsk @Burkhard Korak i don't get it

    why does this app speak to Columbia several times per day? why sms access? why is it not displayed in system apps?

  • Jocke.Sve
    Jocke.Sve ✭✭✭
    edited March 2020

    If worried, it's quite simple to disable (or remove) that component entirely.

    (Agreed, it shouldn't be there in first place!)

    How to:

    https://www.xda-developers.com/disable-system-app-bloatware-android/


    Disable:

    adb shell pm disable-user --user 0 co.sitic.pp


    Remove (use with caution!)

    adb shell pm uninstall --user 0 co.sitic.pp


    EDIT/Update:

    As this component and it's .apk (sysdll.apk) are installed in "system/priv-app/" it might be impossible to totally disable it this way.

    IDK if 'sysdll.apk' is used to or by any other app or service...

  • "uninstall" works fine, I did it a week ago, no issues and no telemetry

    don`t forget to reboot the phone

  • Jocke.Sve
    Jocke.Sve ✭✭✭

    TY!

    Witch one did You uninstall, co.sitic.pp or sysdll.apk?

  • @Jocke.Sve I am somewhat extreme when it comes to privacy, so I removed 5 apps:

    co.sitic.pp
    com.hmdglobal.enterprise.api
    com.qualcomm.qti.qms.service.telemetry
    com.qualcomm.qti.qmmi
    com.qualcomm.qti.qdma
    

    The original post (the English one) is mine

    I confirmed my findings with a couple of users on my local forum (also they gave me the German forum link) before posting this.

    I was not able to reach Nokia \ HMD by email or otherwise, so this forum is my last chance to get a comment.

    I really don`t want to jump to conclusions and I would like an official statement.

  • Peter-Parker
    Peter-Parker ✭✭
    edited March 2020

    I have been pointed to a comment here on Reddit

    According to author, this is a killswitch for phones locked to a specific carrier, not a telemetry. So, the issue is killswitch preinstalled on phones in (probably) all regions.

    A Colombian company can still log requests from all devices around the world and get the data of daily active devices in every country by IP. Not good.

    Upd: @singhnsk you did not link your Reddit reply when you replied to me here and I did not see it until today 😃

  • Jocke.Sve
    Jocke.Sve ✭✭✭

    No negative effect after uninstalling co.sitic.cc!

    The question is though: How and why the heck it's there from the beginning??

    Android One should NOT contain anything like this!

  • singhnsk
    singhnsk Super User

    I thought I won't do self promotion here lol. That's a fair privacy risk. Somebody at HMD should clarify about this. I am sure, it is a mistake and not a deliberate attempt at logging the users.

    @Jocke.Sve Is the sitic app different than the sysdll.apk? It is just a visible package name for the sysdll.apk, right?

  • Jocke.Sve
    Jocke.Sve ✭✭✭

    I'm not 100% sure but I assume You are correct.

    After uninstalling I cant see the sysdll package anymore.

  • singhnsk
    singhnsk Super User

    Great great! Thank you for the official reply. Was able to figure this by disassembling the APK already though. Thank you for ensuring that you'll be saying goodbye to it during the A10 update which is happening very soon 😊

  • Hi @HMDLaura ,

    Thanks a lot for your reply and for preparing a fix for this issue.

    There is also a smaller concern about a daily connection to dapi.hmdglobal.net

    I could not find the part in Privacy policy or Legal information in my phone that reflects these connections. Is this diagnostics data? What does it consist of? Does it fall under Privacy policy?

  • Akhil
    Akhil ✭✭✭

    I found the app.. I revoked all permissions of the app and disabled background data.. phone is working fine except that app window pops up 3-4 times a day..

  • chetan18
    chetan18 ✭✭✭

    Thanks for replying. But being Nokia is Most Trusted Brand since many years, we have never expected this. So my request to you please don't do this in future. We love Nokia brand.

  • Peter-Parker
    Peter-Parker ✭✭
    edited March 2020

    Hi everyone!

    I have a new connection logged from my Nokia 6.2, the URL is tls.telemetry.swe.quicinc.com

    I found some forum discussion that links that connection to the app: com.qualcomm.qti.qms.service.connectionsecurity

    So, either this app was sleeping or it had nothing to send for a month after purchase.

    This is not hidden, not exactly 3rd party (since Qualcomm is hardware vendor), but still a telemetry.

    I think Privacy policy should be updated to clearly state that some (diagnostics? non-personal?) data is being sent to HMD and it's partners.

    P.S. could someone please edit the topic title and remove "hidden" and "3rd party" from it, so the title would not be misleading?

  • singhnsk
    singhnsk Super User

    P.S. could someone please edit the topic title and remove "hidden" and "3rd party" from it, so the title would not be misleading?

    Hi @Peter-Parker, I have modified the title as per your suggestion.