Live data from Hacker News

Tell HN: Your Android carrier can remotely turn settings on

news.ycombinator.com

201–210 of 299 posts

Re: Tell HN: Your Android carrier can remotely turn settings on

#201

Earlier quoted context omitted.

> If they were, they wouldn't have been criminals in the first place. What does intelligence have to do with whether someone is a criminal? There are dumb criminals and smart criminals; I'm not sure what the correlation here is.

I think most criminals are dumb. Quick google search shows average IQ of a criminal is 85.

Average IQ of all criminals, or criminals that got caught?

Re: Tell HN: Your Android carrier can remotely turn settings on

#202

Earlier quoted context omitted.

I am a reporter, and I cover crime. Occasionally, I cover a story whose publication might endanger people. Think cases involving gang violence and/or individuals cooperating with law enforcement. Before I publish those stories, I contact the lead detective on the case to ask whether that concern has merit, and whether certain people’s names, for example, should be anonymized. In one of those conversations, I was aske…

You'd think the criminals would at least watch The Wire for some basic OpSec.

A big part of The Wire is the uniqueness of the discipline the criminals have, and ultimately how it stems from 1-2 people at the top.

Also, public telephones are no longer an option.

Re: Tell HN: Your Android carrier can remotely turn settings on

#203
post #98

> I must say I strongly dislike losing control over my own device. It feels dystopian to me. Even with a rooted device where perhaps you personally coded up the ROM you are still missing a piece which is the binary blob that runs the baseband radio. That firmware is, afaik, not something which exists in any sort of open-source or rootable manner. It's a closed blob running proprietary software on your phone, and it r…

I don't believe this is entirely true anymore. Yes, years ago, the baseband processor (and firmware) had full DMA capabilities to the RAM ostensibly managed by the OS, and could do nefarious things if it wanted to. But I believe nowadays the baseband is a bit more isolated, and communication with it is mediated by the CPU and OS. Some manufacturers likely still implement the "old" architecture, though.

You would hope but to a large extent SMMUs are still not meaningfully deployed in consumer smartphones. Even when they do exist, the bounding enforced upon them are so expansive that it's essentially pointless. For example, one device I found had an SMMU in front of its BT/WiFi chip but, unfortunately, the driver on the AP side configured the SMMU to have access to all of system memory. Baffling.

Re: Tell HN: Your Android carrier can remotely turn settings on

#204

Earlier quoted context omitted.

From https://grapheneos.org/faq : "Connecting to your carrier's network inherently depends on you identifying yourself to it and anyone able to obtain administrative access. Activating airplane mode will fully disable the cellular radio transmit and receive capabilities, which will prevent your phone from being reached from the cellular network and stop your carrier (and anyone impersonating them to you) from trackin…

BTW habitually switching at the same time and place is terrible opsec. It leaks a ton of information.

It is the same general location about half a mile from home where I flip over. This is to ensure location from cell tower triangulation does not identify my home and therefore me.

Re: Tell HN: Your Android carrier can remotely turn settings on

#205

Earlier quoted context omitted.

Sure, but can they get a warrant and tap it in <24 hours? IDK, but that sure raises the barrier to entry.

When have intelligence services used warrants? They gather evidence illegally and pass it to law enforcement who then do parallel construction.

Whenever they don't want Congress up their ass. Four things can simultaneously be true, despite seeming contradictory:

1) Prudent opsec against nation-state adversaries dictates that you assume 0 time for them to have a tap on a device.

2) In reality, it takes >0 time, because people processes aren't instantaneous.

3) Intelligence services sometimes break the letter of the law.

4) Intelligence services usually follow the law, because it's less hassle.

Re: Tell HN: Your Android carrier can remotely turn settings on

#206

These are emergency broadcast alerts. Different countries have different laws on these - and in some countries you might not even be able to disable them. Just because its listed under "Apps & notifications"/"Wireless emergency alerts", it doesn't mean they are "user settings". Its not necessarily the local "carrier" that turned the settings on, its more that connecting to a cell tower in a particular jurisdiction ca…

It doesn't really matter what the laws say. When I tell my computer to do something, I expect it to be done, no questions asked. If I tell it to violate a law, I expect that law to be violated. I have free will and the computer must obey that will, not impose somebody else's will on me.

You’re using a utility and you must accept the terms to use that utility. There’s probably some verbiage in your carrier agreement about it.

You can’t disable 911/112 just because you don’t like it either.

Re: Tell HN: Your Android carrier can remotely turn settings on

#207

Wait until your learn what a country or local government/police can do remotely to the baseband firmware of your phone with a court order... 10-20 years ago the FBI was regularly remotely programming firmware to listen in and record cell phone microphones to capture conversations of suspects. IIRC a mafia case hinged on data gathered in this way so it is not some abstract theoretical or crackpot theory ( https://www.…

I rotate burner SIM's. I never make calls with the SIM. Instead I use jmp.chat if I need to use OTA calls or SMS. I am in airplane mode 99% of the time and use WIFI instead of cellular. I never activate cellular near my home. I am always connected to VPN so that the traffic cannot be analyzed. My phone is anonymous without any identifiers. I think all this mitigates the baseband attacks, but tell me if I am missing s…

You are going in the wrong direction. Lean into the surveillance. Use it to create an alibi.

Re: Tell HN: Your Android carrier can remotely turn settings on

#208

Earlier quoted context omitted.

Your location data. Tower associations can still happen with data "off", since there's plenty of "listen" components. All your home wifi connections are well Geo-located, thanks to other Android users picking up the ESSID as they walk / ride / drive past your house. Your shopping / outings? Forget it, fully known. VPNs hide the content of connections, at least from MITM / eavesdroppers, but server-side data scrapes a…

From https://grapheneos.org/faq : "Connecting to your carrier's network inherently depends on you identifying yourself to it and anyone able to obtain administrative access. Activating airplane mode will fully disable the cellular radio transmit and receive capabilities, which will prevent your phone from being reached from the cellular network and stop your carrier (and anyone impersonating them to you) from trackin…

I appreciate the extra information. I'm still skeptical on any phone except the OS/HW combo the faq was written against (which by the way was not in your original post)

Re: Tell HN: Your Android carrier can remotely turn settings on

#210

Wait until your learn what a country or local government/police can do remotely to the baseband firmware of your phone with a court order... 10-20 years ago the FBI was regularly remotely programming firmware to listen in and record cell phone microphones to capture conversations of suspects. IIRC a mafia case hinged on data gathered in this way so it is not some abstract theoretical or crackpot theory ( https://www.…

I rotate burner SIM's. I never make calls with the SIM. Instead I use jmp.chat if I need to use OTA calls or SMS. I am in airplane mode 99% of the time and use WIFI instead of cellular. I never activate cellular near my home. I am always connected to VPN so that the traffic cannot be analyzed. My phone is anonymous without any identifiers. I think all this mitigates the baseband attacks, but tell me if I am missing s…

> if I am missing something

It's the day you miss something that your effort was pointless. Even if your solution is always secure, it only takes one slip up to ruin everything

Any threat as large as youre trying to protect against, if interested in you, can just wait for you to make a mistake.

Post reply on HN