Live data from Hacker News

Spying on a smartphone remotely by the authorities: feasibility and operation

security.stackexchange.com

11–20 of 98 posts

Re: Spying on a smartphone remotely by the authorities: feasibility and operation

#11

Earlier quoted context omitted.

But it’s a good question. I want to know. I am assuming this is not possible. The only thing i know of is capable of doing so is pegasus. But it’s very expensive afak.

You don't know what code is running on your baseband processor, do you? Do you know what other hardware your baseband processor has the ability to inspect?

In most SoC's the answer is 'everything' because there's no such thing as an IOMMU.

Re: Spying on a smartphone remotely by the authorities: feasibility and operation

#12

This answer is dangerously naïve. Phone basebands and radios are full of vulnerabilities, if you don't want your phone to be a potential surveillance device given any minimally sophisticated adversary you should either turn off the radio or preferably shut it off entirely and remove the battery.

Hypothesis B: it's not dangerously naïve, it's deliberate misinformation designed to coax technical but unskeptical people into lowering their guard against this class of threat.

Re: Spying on a smartphone remotely by the authorities: feasibility and operation

#13
post #8
post #7

This question has been in my head recently. How feasible is it really? The answer in the link isn’t comprehensive. Is it really out of the question for manufacturer’s to ship a particular version of a device and software for a target country? Nation states have a history of backdooring or weakening particular technologies.

Baseband backdoor. No need to target the OS or the primary CPU.

Any signs of these in the wild?

I know it is a valid threat, but even in the cases that set this precedent there was a team of 140 and they did not leverage a baseband exploit.

Re: Spying on a smartphone remotely by the authorities: feasibility and operation

#14

This answer is dangerously naïve. Phone basebands and radios are full of vulnerabilities, if you don't want your phone to be a potential surveillance device given any minimally sophisticated adversary you should either turn off the radio or preferably shut it off entirely and remove the battery.

Hypothesis B: it's not dangerously naïve, it's deliberate misinformation designed to coax technical but unskeptical people into lowering their guard against this class of threat.

Of course, but see Hanlon's razor.

Re: Spying on a smartphone remotely by the authorities: feasibility and operation

#15

Earlier quoted context omitted.

You don't know what code is running on your baseband processor, do you? Do you know what other hardware your baseband processor has the ability to inspect?

In most SoC's the answer is 'everything' because there's no such thing as an IOMMU.

Ding ding ding, we have a winner!

Re: Spying on a smartphone remotely by the authorities: feasibility and operation

#16
post #8

Earlier quoted context omitted.

Baseband backdoor. No need to target the OS or the primary CPU.

Any signs of these in the wild? I know it is a valid threat, but even in the cases that set this precedent there was a team of 140 and they did not leverage a baseband exploit.

How could we know for sure? Basebands are 100% proprietary, we have no idea how they operate and even less of an idea of how their operation might be subverted.

Re: Spying on a smartphone remotely by the authorities: feasibility and operation

#17

Earlier quoted context omitted.

Hypothesis B: it's not dangerously naïve, it's deliberate misinformation designed to coax technical but unskeptical people into lowering their guard against this class of threat.

Of course, but see Hanlon's razor.

Sounds like the perfect cover for malice, lol

If ((Assume it's stupidity) == (discount/ignore the risk)), then assuming it's stupidity is never the safer assumption, even if it's empirically more likely to be the correct assumption, no?

All boils down to an individual's threat model at the end of the day anyway, though.

Re: Spying on a smartphone remotely by the authorities: feasibility and operation

#18
post #8

Earlier quoted context omitted.

Baseband backdoor. No need to target the OS or the primary CPU.

Any signs of these in the wild? I know it is a valid threat, but even in the cases that set this precedent there was a team of 140 and they did not leverage a baseband exploit.

Absence of evidence is not evidence of absence, especially when searching for evidence left behind by competent adversaries (e.g. NSA, GCHQ, etc) who have a strong motivation to remain undetected.

Re: Spying on a smartphone remotely by the authorities: feasibility and operation

#19

Earlier quoted context omitted.

Any signs of these in the wild? I know it is a valid threat, but even in the cases that set this precedent there was a team of 140 and they did not leverage a baseband exploit.

How could we know for sure? Basebands are 100% proprietary, we have no idea how they operate and even less of an idea of how their operation might be subverted.

This is why I'm an open source advocate. It's not that open source automatically makes software/firmware trustworthy, it's that closed source empirically guarantees the software/firmware can never be deemed trustworthy.

Re: Spying on a smartphone remotely by the authorities: feasibility and operation

#20

Earlier quoted context omitted.

Any signs of these in the wild? I know it is a valid threat, but even in the cases that set this precedent there was a team of 140 and they did not leverage a baseband exploit.

Absence of evidence is not evidence of absence, especially when searching for evidence left behind by competent adversaries (e.g. NSA, GCHQ, etc) who have a strong motivation to remain undetected.

> Absence of evidence is not evidence of absence

But it is also not evidence of the thing for which there is absence of evidence.

EDIT:

> especially when searching for evidence left behind by competent adversaries (e.g. NSA, GCHQ, etc) who have a strong motivation to remain undetected.

No, there is no “especially”; absence of evidence means no basis for any affirmative belief, period, equally for any fact proposition. Arguing for “especially... ” is exactly arguing for a case where absence of evidence is evidence for the thing for which there is an absence of evidence.

Post reply on HN