Live data from Hacker News

Vulnerabilities in chips in 37% of smartphones

blog.checkpoint.com

21–30 of 63 posts

Re: Vulnerabilities in chips in 37% of smartphones

#21
post #14

Somehow firmware updates should be enforced by consumers. It doesn’t help, that there are so many different smartphone vendors, and the most of them are pursuiting only for sales. New chips are coming constantly, and old ones get forgotten, left unpatched. Is the future of the smartphone market of secure phones only in the hands of big ones (Apple et al)?

That would be the free market way. Apple has a track record of patching even low level issues for a very long time after sale. If that is something you care about, then you buy the product that supports that.

Perhaps we should also block malware infected devices from using the internet as well to stop there negative external effect on the rest of us.

Re: Vulnerabilities in chips in 37% of smartphones

#22
My approach with phones is to install apps only from very mainstream well known publishers (for Android, I limit apps mainly to those from Google). Other than the stock Google apps for web browser, email, maps, and phone/contacts/calendar I don't find I need many apps.

All computing devices have vulnerabilites. If you feel you need to use them regardless, you can avoid a lot of exploits by not installing random apps from publishers you've never heard of.

Re: Vulnerabilities in chips in 37% of smartphones

#23
post #3

There are so many attack vectors now on phones ranging from the SIM Card (which has an OS as well) to all the baseband chips to the actual OS and the different app privileges (like the old SMS listening port). What's interesting to me about the Taiwanese tech industry is their nimbleness and how MediaTek pivoted from a primarily DVD chip maker to dumb phone chip provider running on Pluto OS to now a smartphone chipma…

Do esims mitigate or eliminate an attack vector?

Re: Vulnerabilities in chips in 37% of smartphones

#24
post #7

The time for open source chips is now. Efabless.com

Er, why do we think open source chips enhance security, when vendors spend $100mns trying to secure their devices?

The biggest problem we have right now is that someone finds a vulnerability in a chip which is at the same time in widespread use and no longer supported by the manufacturer. If everything is open source, anyone can patch the vulnerability even if the OEM won't, and then someone does.

Re: Vulnerabilities in chips in 37% of smartphones

#25
post #14

Somehow firmware updates should be enforced by consumers. It doesn’t help, that there are so many different smartphone vendors, and the most of them are pursuiting only for sales. New chips are coming constantly, and old ones get forgotten, left unpatched. Is the future of the smartphone market of secure phones only in the hands of big ones (Apple et al)?

That would be the free market way. Apple has a track record of patching even low level issues for a very long time after sale. If that is something you care about, then you buy the product that supports that. Perhaps we should also block malware infected devices from using the internet as well to stop there negative external effect on the rest of us.

I care about phone security but also about privacy from corporate entities and control of my own devices. Our sorta-free market does not serve this demand. Voting with money just doesn't do anything to counter supply-side solidarity. I.e. leveraging the indisputable utility of their products to force hostile spyware and dark patterns onto people and abuse them.

As for disconnecting malware hosts, we could only block what we could identify & verify as malicious.

Re: Vulnerabilities in chips in 37% of smartphones

#26
post #14

Somehow firmware updates should be enforced by consumers. It doesn’t help, that there are so many different smartphone vendors, and the most of them are pursuiting only for sales. New chips are coming constantly, and old ones get forgotten, left unpatched. Is the future of the smartphone market of secure phones only in the hands of big ones (Apple et al)?

What's really needed here is for the tech press to make this a priority when reviewing devices, which they currently don't. Right now consumers aren't aware of how important it is for the device to have drivers in the mainline kernel tree to avoid getting pwned.

Not having that should be an absolute bar to a device making it onto anyone's "recommended" list.

At which point device makers would prioritize not getting panned by reviewers and losing many sales just because they couldn't be bothered to get their drivers into the kernel tree.

Re: Vulnerabilities in chips in 37% of smartphones

#28
post #7

The time for open source chips is now. Efabless.com

Er, why do we think open source chips enhance security, when vendors spend $100mns trying to secure their devices?

I worked at an electronics place a while back and I remember there were issues in an old chip in some older products. Not talking anything major here but a few known bugs that could have been fixed. But usually nobody had the time allowed to go fix up the old firmware on old products because there were always other things to deal with that were deemed to be a higher business priority. Unfortunately there's often more money to be made by the manufacturer by making the costs of these bugs externalities on the entire market than there is to be made by fixing them. Even when vendors have large budgets to work on security work done on end of life products ends up being typically abandoned because there's just more money to be made elsewhere at the moment. Open source chips could help deal with this end of life issue.

Re: Vulnerabilities in chips in 37% of smartphones

#30
post #7

The time for open source chips is now. Efabless.com

I, too, consider it naive to think that a relatively unorganized bunch of people are going to make good chips, write good drivers and support the whole lot for free, and deliver a product that's competitive. There's so much stacked against it. Case in point: Linux on the desktop.
Post reply on HN