Live data from Hacker News

Tell HN: Your Android carrier can remotely turn settings on

news.ycombinator.com

281–290 of 299 posts

Re: Tell HN: Your Android carrier can remotely turn settings on

#281

Earlier quoted context omitted.

And a smart enough person would also know that there's a long chain of caveats to this specious claim, significant enough that being a criminal and getting away with it is much more compelling.

None of the caveats include hypothetically being thrown in prison though. Being a criminal and getting away with it is significantly harder than phoning in your job as part of a capitalist machine

You're on a forum that's thematically dedicated to the idea of being a "hacker" in spirit; to a lot of people, the easy boring path isn't attractive.

"Why do this risky exciting dangerous thing over there when you could come over here and be a flacid lifeless drone with me at Bezos' personal blowjob-drone company. Marry the first person you meet, have some kids, yay stability!"

Re: Tell HN: Your Android carrier can remotely turn settings on

#282
post #130

Earlier quoted context omitted.

For other use cases, I'd probably agree with you. But you being startled and confused during an emergency because you didn't see the instructions on time can be very dangerous for everyone around you. It's not just on you.

If there is emergency, I'm sure you'll find out very soon that something is happening. We are usually not living in lone solitudies.

the same applies when the device is off, or i left it at home. unless there is a law that requires me to carry a functioning, powered device to receive emergency alerts at all times, there is no reason why a device should be required to receive alerts just because it is capable of receiving them. if i turn of alerts on my device, then it's no different from a device that doesn't have the capability to receive alerts.

Re: Tell HN: Your Android carrier can remotely turn settings on

#283

Earlier quoted context omitted.

The baseband is an entirely separate SoC that is a blackbox outside of the control of GrapheneOS. And your radios are solely under the control of that system. GrapheneOS just asks it nicely to do things on its behalf. All of these privacy focussed phone OSes tread lightly on the fact that there are a grand total of zero modern open source basebands in existence.

Agreed. We can only mitigate by tactics: -not associating the device ID's to personal ID's. -only using cellular in limited situations. -rotating the SIMs periodically with other family members

You don’t get to choose those things if you don’t choose what the radio does. Swapping SIMs around doesn’t accomplish that. The hardware and software that the baseband has entirely within the confines of its own black box is enough to track you.

Re: Tell HN: Your Android carrier can remotely turn settings on

#284

Earlier quoted context omitted.

jmp.chat can be paid for with a virtual card and not tied to any ID. However I have it associated to my real ID in this case as it is the number everybody knows. I use the word 'mitigate' not 'solve' since closed source baseband modems are a problem. Cellular traffic is off in airplane mode, but the baseband could be exploited if someone wanted to find me AND knew which IMEI to target. Because the IMEI has never been…

>I run my own VPN and share it with a few other people. How confident are you in your VPN server configuration skills? Gaining access through mis-configured self-hosted boxes is the easiest attack vector usually as most people who self-host aren't experts in the software they are using leading to leaks. Besides that, do you keep a list of packages installed on your box, open ports, etc? How about security patches and…

We're talking about the FBI here. They see traffic coming from a server. The ask who's server it is, your host tells them your name and address. The FBI asks the host for physical access to the server, and installs whatever monitoring they want regardless of your patch schedule. The FBI asks them to keep this off the access logs, and they do.

Re: Tell HN: Your Android carrier can remotely turn settings on

#285

Earlier quoted context omitted.

> It's only gotten worse as phones have gotten more capable I wish my cellphone would not have all those sensors for this reason...

The camera and mic are pretty easy to destroy if you want to get rid of them!

There's a bunch of other sensors though... also don't forget that there is often more then one microphone... like on the Pixel 7

Re: Tell HN: Your Android carrier can remotely turn settings on

#286
post #278

Earlier quoted context omitted.

Nobody is looking for me. I don't have any regular commute either. I just make sure not to use cellular at my house since that would narrow the owner of the SIM down to one of the people living in this house.

Do you own a car with OnStar or SeriusXm ?

No. I ride a bike.

Re: Tell HN: Your Android carrier can remotely turn settings on

#287
post #270

Earlier quoted context omitted.

Governments hijacking infrastructure is not remotely the same as governments hijacking personal devices.

You are at mercy of the whims of your local government. You don't like it? Then fight to join the local government.

No post body was provided.

Re: Tell HN: Your Android carrier can remotely turn settings on

#288
post #280

Earlier quoted context omitted.

Governments hijacking infrastructure is not remotely the same as governments hijacking personal devices.

They are not hijacking your personal device. Your personal device is letting you know your carrier does not provide an option for this setting.

No post body was provided.

Re: Tell HN: Your Android carrier can remotely turn settings on

#289

Earlier quoted context omitted.

>I run my own VPN and share it with a few other people. How confident are you in your VPN server configuration skills? Gaining access through mis-configured self-hosted boxes is the easiest attack vector usually as most people who self-host aren't experts in the software they are using leading to leaks. Besides that, do you keep a list of packages installed on your box, open ports, etc? How about security patches and…

We're talking about the FBI here. They see traffic coming from a server. The ask who's server it is, your host tells them your name and address. The FBI asks the host for physical access to the server, and installs whatever monitoring they want regardless of your patch schedule. The FBI asks them to keep this off the access logs, and they do.

You might be assuming I am trying to evade an APT or I am of any interest to them. That is a fun rabbit hole to go down, and I realize they could spend resources to pursue these avenues. Other comments summarily say that if you try to protect your privacy too much, you automatically become a person of interest. The measures employed by an APT to target and monitor someone at these levels are expensive. They do have abundant resources, but they would be wasting much money and lose focus if they targeted every privacy seeking person. After spending thousands of dollars, they would find nothing interesting on me other than someone with above average tech knowledge who just doesn't like to be followed around. The suggestion that I am flagging myself for surveillance is ridiculous. If I am wrong, I hope they do surveil me to learn this themselves.

Re: Tell HN: Your Android carrier can remotely turn settings on

#290

Wait until your learn what a country or local government/police can do remotely to the baseband firmware of your phone with a court order... 10-20 years ago the FBI was regularly remotely programming firmware to listen in and record cell phone microphones to capture conversations of suspects. IIRC a mafia case hinged on data gathered in this way so it is not some abstract theoretical or crackpot theory ( https://www.…

I rotate burner SIM's. I never make calls with the SIM. Instead I use jmp.chat if I need to use OTA calls or SMS. I am in airplane mode 99% of the time and use WIFI instead of cellular. I never activate cellular near my home. I am always connected to VPN so that the traffic cannot be analyzed. My phone is anonymous without any identifiers. I think all this mitigates the baseband attacks, but tell me if I am missing s…

There is no such thing as anonymous. There is only more difficult. A government that controls enough endpoints (e.g. your country's backbone) can infer identity.
Post reply on HN