Live data from Hacker News

There are no secure smartphones

devever.net

61–70 of 124 posts

Re: There are no secure smartphones

#61
post #3

The folks at http://neo900.org/ are well aware of this and that phone is designed accordingly (details at http://neo900.org/faq#privacy ). Hype-driven products like BlackPhone misrepresent their devices as being perfectly secure when this significant attack vector is completely unmitigated. On the Neo900, the modem is connected via USB (bus; there is no physical connector) which means it doesn't have DMA. There is no…

"On the Neo900, the modem is connected via USB (bus; there is no physical connector) which means it doesn't have DMA."

I have been "Mr. Cry About Baseband Ownage From The Rooftops" for years around here, and even I have to admit that a lot of baseband implementation in modern smartphones uses this same USB connected model.

It's not universal, but a lot of USB-connected baseband is out in the world...

Still closed source and owned by the provider. I would love to see an open source baseband with a hard switch to disable it.

Re: There are no secure smartphones

#62

Semi-related: I feel like there should be an open source dumbphone project. Smartphones have a lot of bells and whistles with a large attack area but many people just want to make calls. Sure this wouldn't fix the baseband issue, but it seems the safest way to ensure isolation between personal information and potentially hostile cellular blobs is to never put the information on the device in the first place. A small,…

http://web.media.mit.edu/~mellis/cellphone/index.html

Re: There are no secure smartphones

#63
The article asserts:

    > It would, in my view, be abject insanity not to
    > assume that half a dozen or more nation-states (or
    > their associated contractors) have code execution
    > exploits against popular basebands in stock.
To me this ignores the flip-side of the argument. If US intelligence services really thought the Chinese and Russians could remotely and invisibly hack all/most smartphones then no-one with access to sensitive information would be allowed to do work on one, unless they're very confident that they've managed to secure their devices without leaving a stone unturned.

Soz Hilz[0].

[0] http://media4.s-nbcnews.com/i/newscms/2015_10/913276/150303-...

Re: There are no secure smartphones

#64
post #22
post #4

It's good to draw attention on baseband processors, but there are technical assertions in this post that are probably not accurate (lack of auditing and the notion that you can assess the security of a whole phone system by whether or not there's an IOMMU). The systems security of modern phones is surprisingly complex. Google and Apple both care very deeply about these problems, and both have extremely capable engine…

The team behind Replicant reported that they found a baseband backdoor in Samsung Galaxies[0][1]. I think it's perfectly fine to extrapolate from that that you probably shouldn't trust the baseband, even if Google and Apple are looking into it. Until they have a concrete solution shipped, all the in-the-closet work on the problem is meaningless. 0: https://www.fsf.org/blogs/community/replicant-developers-fin... 1: ht…

This is why I wish Replicant was more successful. They mention a CM issue to fix it, and nobody did. As an owner of several Samsung devices, the fact there is a wholly proprietary processor in my phone with complete control of it makes me not treat it like a computer.

Re: There are no secure smartphones

#65

> For devices with cellular access, the baseband subsystem also utilizes its own similar process of secure booting with signed software and keys verified by the baseband processor. According to the iOS security white paper, the baseband firmware is part of the secure boot chain, and has its own secure boot chain. This allows me to assume it's very hard to inject or replace the the firmware with a malicious code. Whet…

That's just iOS being iOS, on Android the baseband firmware can usually be flashed using fastboot. However, there will presumably still be a bootloader on the baseband processor that checks the authenticity of what you just flashed to it. It's very interesting to just download a baseband firmware (usually called radio.img) from a random Android forum, unpack it and run strings on the code you get. It'll usually be an…

> Testing DDR Read/Write.

> Testing DDR Read/Write: Memory map.

> Testing DDR Read/Write: Data lines.

> Testing DDR Read/Write: Address lines.

> Testing DDR Read/Write: Own-address algorithm.

> Testing DDR Read/Write: Walking-ones algorithm.

> Testing DDR Deep Power Down.

> Testing DDR Deep Power Down: Entering deep power down.

> Testing DDR Deep Power Down: In deep power down.

> Testing DDR Deep Power Down: Exiting deep power down.

> Testing DDR Deep Power Down: Read/write pass.

> Testing DDR Self Refresh.

> Testing DDR Self Refresh: Write pass.

> Testing DDR Self Refresh: Read pass.

> Testing DDR Self Refresh: Entering self refresh.

> Testing DDR Self Refresh: In self refresh.

> Testing DDR Self Refresh: Exiting self refresh.

Yes Galaxy s4 modem, please provide unlimited access to all government agencies of all my phones content and communications.

> Samsung Root CA cert1%0#

Fantastic, you also inject your own root certificate. Thanks.

Re: There are no secure smartphones

#66
post #59

Earlier quoted context omitted.

There just aren't the resources, hardware and information wise, you need. RF engineers don't seem to share the drive for free and open source technology that has been the common theme with software. As a result, we just recently got cheap, widely accessible SDRs, and even they only came about through more or less an accident. And their performance renders them pretty much useless for even just GSM. Now serious SDRs l…

The SIM in 3G isn't really much like a DRM thingy, apart from containing a key; it's more like a securid keyfob. The only interesting thing it does (apart from storing constants like its serial number and variables like your phone book and text messages) is to generate authentication responses (to prove to the network that you have it) and derive session keys (so your phone can encrypt and authenticate what it sends…

"The only interesting thing it does (apart from storing constants like its serial number and variables like your phone book and text messages) is to generate authentication responses"

The most interesting thing your SIM card does is run arbitrary programs that can be uploaded to them, without your knowledge, by the carrier:

https://www.defcon.org/images/defcon-21/dc-21-presentations/...

The SIM card is a full computer, with its own CPU and memory, that lives inside your phone and that you have no control over.

Re: There are no secure smartphones

#67

Or you can just use WIFI and turn the baseband off like I do. The cell companies are all crooks anyways (in the US), and I don't want to do business with them.

Indeed, if you have a second cell modem or smartphone, the modem can connect to the cellular network and provide an IP over Wifi, and the smartphone can use wifi to connect to it. Thus the smartphone is protected by its OS's firewall and any compromises stay on the cell modem, the same way they do with home internet connections.

Re: There are no secure smartphones

#68

This is just a special case of the fact that there's no secure anything. In 2016 that's just the price you pay for using computers. You just have to live with it. Mitigate it the best you can, rely on the ol' "mossad or not mossad" strategy now and then, hope for the best, etc. If you have a strong need for increased security, well, god help you (spoilers: you will receive no help), you're going to pump a lot of effo…

Just get an FSF laptop for security. You can even trust the hard drive if you use software encryption of all your data. I'm not sure what remains insecure on that class of hardware?

Re: There are no secure smartphones

#69

Would really love to see this upvoted more. This basic truth should be common knowledge for privacy-minded or security-minded technologists/developers. There are lots of reasons GSM won't/is hard to make work. What are the options? As more and more carriers in the USA provide wifi-dongles that are connected to 3G, maybe it's better to just do that, and move off making calls directly from your phone completely? For ex…

"There are lots of reasons GSM won't/is hard to make work. What are the options? As more and more carriers in the USA provide wifi-dongles that are connected to 3G, maybe it's better to just do that, and move off making calls directly from your phone completely?"

This is an obvious approach, and the one that I originally pursued when I became worried about baseband exploits, security and privacy. I was looking into using a "samsung galaxy player" (basically, a galaxy S4 with no mobile phone chip in it) and using USB modems to use the cellular network when it suited me.

The problem is, for a variety of weird reasons, a LOT of the realtime voice processing is also built into the baseband, along with the radio functions that we're all talking about here.

So a lot of voice quality and noise cancellation and other things that you would really miss are built into the baseband and difficult to replicate on the main, more general purpose, CPU.

Re: There are no secure smartphones

#70

Or you can just use WIFI and turn the baseband off like I do. The cell companies are all crooks anyways (in the US), and I don't want to do business with them.

Problem is, when you use VoIP over WiFi, you loose echo-cancellation, because the echo cancel hardware resides in the baseband and is not used in WiFi calls.
Post reply on HN