Live data from Hacker News

Vulnerabilities in chips in 37% of smartphones

blog.checkpoint.com

41–50 of 63 posts

Re: Vulnerabilities in chips in 37% of smartphones

#41
post #30
post #7

The time for open source chips is now. Efabless.com

I, too, consider it naive to think that a relatively unorganized bunch of people are going to make good chips, write good drivers and support the whole lot for free, and deliver a product that's competitive. There's so much stacked against it. Case in point: Linux on the desktop.

The kernel group is extremely well organized, and lots of other groups are too.

Re: Vulnerabilities in chips in 37% of smartphones

#42
post #29
post #7

The time for open source chips is now. Efabless.com

Anyone familiar with ASICs? If I wanted a 8 x AND gate, what would that cost, ballpark figure? I'm just trying to get a handle on the costs and figure that might be a good measure.

If you wanted an 8xAND gate I would recommend the 74LS30. There, saved you a bunch of money.

Re: Vulnerabilities in chips in 37% of smartphones

#43
post #3

There are so many attack vectors now on phones ranging from the SIM Card (which has an OS as well) to all the baseband chips to the actual OS and the different app privileges (like the old SMS listening port). What's interesting to me about the Taiwanese tech industry is their nimbleness and how MediaTek pivoted from a primarily DVD chip maker to dumb phone chip provider running on Pluto OS to now a smartphone chipma…

Do esims mitigate or eliminate an attack vector?

SIM attacks target vulnerable/unnecessary applets that some clueless providers leave there, which can also affect esims according to some articles. And since no one bothers to setup actual SIM PINs anymore that too probably doesn't help.

Re: Vulnerabilities in chips in 37% of smartphones

#44
post #25

Earlier quoted context omitted.

That would be the free market way. Apple has a track record of patching even low level issues for a very long time after sale. If that is something you care about, then you buy the product that supports that. Perhaps we should also block malware infected devices from using the internet as well to stop there negative external effect on the rest of us.

I care about phone security but also about privacy from corporate entities and control of my own devices. Our sorta-free market does not serve this demand. Voting with money just doesn't do anything to counter supply-side solidarity. I.e. leveraging the indisputable utility of their products to force hostile spyware and dark patterns onto people and abuse them. As for disconnecting malware hosts, we could only block…

For voting with money, consider Librem 5: https://puri.sm/librem-5.

Re: Vulnerabilities in chips in 37% of smartphones

#45

My approach with phones is to install apps only from very mainstream well known publishers (for Android, I limit apps mainly to those from Google). Other than the stock Google apps for web browser, email, maps, and phone/contacts/calendar I don't find I need many apps. All computing devices have vulnerabilites. If you feel you need to use them regardless, you can avoid a lot of exploits by not installing random apps…

If the vulnerability is in the chip it doesn't matter what apps you install. Even with a bare OS you're vulnerable.

That's the same 'logic' that anti-maskers use. It's not about absolutes, just because something is theoretically vulnerable doesn't mean you need to throw caution to the wind.

Re: Vulnerabilities in chips in 37% of smartphones

#46
post #34

Earlier quoted context omitted.

(Yes, ) But without the current privacy policies, thanks. (Context: I was informed two years ago, by resellers, that Toyota was sending data from the cars to their own servers - just this very capability embedded in the car already some find completely unacceptable - and that they intended to demand the signature of agreements loose about privacy.)

Agreed. That's why I bought an old car and restored it to new state rather than to go with the more current crop. A couple of near misses on account of software bugs that tried to kill me were enough to convince me to opt out, and that's before I got into tracking the vehicle and sending other data.

> near misses on account of software bugs that tried to kill me

Absolutely.

Engineering issues (samples of episodes reported): * steering wheel not responding (and user driving on motorway); * car unlock mechanism not responding (and user in the desert); * necessary electronics placed in external rear view mirror... Security issues: * steering wheel remotely hijackable through BT security hole... Now add the privacy issues.

This is largely OT in the current submission, but we should have a good exploration and discussion about these matters in other pages. The big issue is: alternatives. Surely many of us have been finding themselves with a problem of options.

Re: Vulnerabilities in chips in 37% of smartphones

#48

My approach with phones is to install apps only from very mainstream well known publishers (for Android, I limit apps mainly to those from Google). Other than the stock Google apps for web browser, email, maps, and phone/contacts/calendar I don't find I need many apps. All computing devices have vulnerabilites. If you feel you need to use them regardless, you can avoid a lot of exploits by not installing random apps…

> you can avoid a lot of exploits by not installing random apps from publishers you've never heard of.

That is a false sense of security. Bluetooth, web browser, messaging, wifi networks are all very powerful vectors and likely the main vectors for attacking devices.

Re: Vulnerabilities in chips in 37% of smartphones

#49
post #35
post #32

Earlier quoted context omitted.

> I, too, consider it naive to think that a relatively unorganized bunch of people are going to make good chips, It's naive to thing that relatively unorganized bunch of people wrote the most popular OS in existence.

It's much less of a consumer choice, and it's backed by some pretty deep pockets.

It is consumer choice, without any doubt.

If IT people didn't like Linux, it wouldn't have chances.

Re: Vulnerabilities in chips in 37% of smartphones

#50
post #29

Earlier quoted context omitted.

Anyone familiar with ASICs? If I wanted a 8 x AND gate, what would that cost, ballpark figure? I'm just trying to get a handle on the costs and figure that might be a good measure.

If you wanted an 8xAND gate I would recommend the 74LS30. There, saved you a bunch of money.

I think maybe GP means 'what does it cost to get a simple design on a die say for sake of argument 8xAND', i.e. something very small and simple like that, so that it's all fixed cost.
Post reply on HN