Live data from Hacker News

Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

blog.checkpoint.com

101–110 of 120 posts

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#101
post #99

Earlier quoted context omitted.

My point is that there is more academic research on Intel processors than AMD. For a hacker, an Intel vulrability would of course be more lucrative than a AMD one.

"Intel" has another meaning, especially when placed next to the word "security". The number of results from your two google searches is meaningless.

That number is literally the most meaningful number there. Meltdown caused more scare than all of these 400 bugs described here, just because intel is not expected to have any sort of vulnerability and the people who really care about security chooses intel(not talking about self described privacy pundits on HN, but military and banks). There had been much more research on intel security than all other chips combined.

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#102

Earlier quoted context omitted.

"If you want half the world's hackers to audit your code, put it in an Apple product. If you want all the world's hackers to audit your code, put it in a Nintendo product."

Please tell me where this came from, and that it's not just something you made up?

It came from GPT-3.

Just kidding.

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#103

Earlier quoted context omitted.

Still getting updates for my one plus 6. YMMV.

Still getting updates for my 7 year old ipad air 2. About to get ios 14 as well. Android has warped peoples perspectives on how long a device would get updated. On PC you can just keep installing updates until the device can't keep up anymore.

The iPad Air 2 was introduced just under six years ago. But even the original iPad Air, which was introduced nearly seven years ago, still gets security updates. The last update was released less than a month ago. It's stuck on iOS 12, though.

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#104
Would having an open source chip with a rolling release be more secure? Like as soon as the vulnerability is discovered you would push the fix and the next generations would already be fixed. Or would such frequent changes to the chip design be to difficult to mass produce, due to having to modify the production process?

This is coming from a point of view that Linux is quite a success and thus maybe the same philosophy could be used for hardware?

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#106

Would having an open source chip with a rolling release be more secure? Like as soon as the vulnerability is discovered you would push the fix and the next generations would already be fixed. Or would such frequent changes to the chip design be to difficult to mass produce, due to having to modify the production process? This is coming from a point of view that Linux is quite a success and thus maybe the same philoso…

first you have to have open source chip, and then have fabs willing to want to make it (and someone willing to pay them up front), and have phone makers want to use it..

And no changing chips every few months possibly breaking compatibility (people working around your bugs) is not a feature that a lot of hw designers want.

This may change eventually. I have high hopes for RISC V but we will see

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#107

Would having an open source chip with a rolling release be more secure? Like as soon as the vulnerability is discovered you would push the fix and the next generations would already be fixed. Or would such frequent changes to the chip design be to difficult to mass produce, due to having to modify the production process? This is coming from a point of view that Linux is quite a success and thus maybe the same philoso…

Hardware is different in that it can't be updated once it's leaves the factory and has to be "right first time".

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#108

Seriously I'm beyond pissed at the state of Android, patches and open-source compliance. If we are lucky 10% of current phone models will get any form of update. The rest will be vulnerable for years until the devices finally break. And that's only the Qualcomm stuff. There is another CPU vendor beginning with M who is big in el-cheapo hardware - look at their Android kernel leaks, wherever you dig you find horrid, H…

Still getting updates for my one plus 6. YMMV.

Be quite,Don't let Trump know!

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#110
post #87

Do any of these vulnerabilities let us unlock the bootloader?

Way would you want that?

For one thing, I hate the idea that such vulnerabilities can be used against me (e.g. to exfiltrate my data), but they cannot be used in any way to help me, such as allowing me to sideload a third-party ROM (such as LineageOS) and continue to use the phone I paid $1000 for after the OEM decides they don't feel like supporting it anymore.
Post reply on HN