Categories: NewsTech

With Google Services backdoor disabled, the Huawei Mate 30 loses its appeal

Huawei Mate 30 series is launching in Malaysia tomorrow. Although it won’t be shipped with Google Mobile Services out of the box, there was a 3rd party workaround that lets you install Google apps and Play Store easily. Unfortunately, this quick backdoor workaround has been disabled.

Previously, all you’ll have to do is to visit https://www.lzplay.net/#/ and install an APK to enable Google Mobile Services, however, this website is no longer accessible. Even if you still have the APK file, it won’t work anymore and it will show a connection error.

So if you’re planning to pick up a Huawei Mate 30 and Mate 30 Pro, getting it to work like a typical Android smartphone won’t be as easy as expected previously. You could sideload apps but there’s no guarantee that it will work as it lacks the Google framework. On top of that, getting apps outside the Play Store does have its own risk and this can be an issue for non-tech savvy consumers.

Backdoor raises security concerns

Android security researcher, John Wu, has raised some concerns with the LZPlay workaround. He explained that sideloading Google Mobile Services (GMS) for Chinese devices is quite common but this is usually normal for devices that are using Google licensed system image.

He added that system apps and user-installed apps are treated differently on Android. Some GMS packages must be installed as system apps because it requires permissions to function properly. Users can upgrade the system apps via Play Store or manual sideloads provided that the update is signed with the same key as the original version in the system. He mentions that signature verification is important as it prevents attackers from distributing malicious updates.

Most OEMs will include GMS “stubs” in the system which enables you to activate Google apps and service but they need to be signed by Google for it to be compatible with the actual GMS APKs. When he heard that a random APK can install GMS on the Mate 30 Pro, he was quite surprised. He speculated that this could either mean that Google is quietly giving stubs to Huawei or Huawei is blatantly stealing Google’s stub binaries.

Long story short, he concluded that Huawei is well aware of this “LZPlay” app and they explicitly allowed its existence. He alleged that Huawei’s OS has a backdoor to allow such apps from getting additional privileges. From a security standpoint, he said such backdoor should never exist and it is susceptible to malicious tampering. You can read John Wu’s full article here.

When Android Central reached out to Huawei on its involvement with LZPlay, they issued the following statement:

Huawei’s latest Mate 30 series is not pre-installed with GMS, and Huawei has had no involvement with www.lzplay.net

To make matters worse, Alex Dobie from Android Central has discovered that his Mate 30 Pro unit has recently failed the SafetyNet test. Previously, it had passed and early reviewers were able to use their Mate 30 Pro for Google Play.

SafetyNet is a component under Google Play services that assess the health and safety of your Android device. This helps Google to ensure that the device is secure and not rooted.

Google Pay has stopped working on the Mate 30 Pro starting today as it has failed the CTS profile check. You can check out the video below:

With the current situation, Huawei has hit yet another brick wall and hopeful buyers will be limited to apps that are listed on Huawei’s AppGallery. Without an easy and official way of getting Google apps and services, it will be tough to recommend the device for now. Are you still considering the Mate 30 Pro? Let us know in the comments below.

[ SOURCE, 2, 3 ]

Related reading

Recent Posts

Porsche Taycan and Macan EV prices surge in Malaysia: Up to RM410k higher

Porsche has recently updated the price of its EV lineup in Malaysia, and the changes…

7 hours ago

TNG eWallet now lets you search SSM company records and download official documents

If you need to verify a Malaysian business or obtain more background information, you can…

10 hours ago

Bye-bye physical discs: PlayStation goes digital-only from 2028

For close to two decades, buying a new PlayStation game meant picking up a Blu-ray…

11 hours ago

Flexi Parking is back online: Look out for minor teething issues

The Flexi Parking system is operational again after being crippled for the past few days…

11 hours ago

Hotlink 5G Travel SIM offers 7-day “unlimited” internet in 4 countries for RM25

Hotlink has enhanced its Travel SIM offering which lets you stay connected in 4 countries…

12 hours ago

Semak Kasih offers a legit starting point to check for unclaimed takaful and life insurance

The Malaysian Takaful Association (MTA) and Life Insurance Association of Malaysia (LIAM) have recently launched…

1 day ago

This website uses cookies.