Live data from Hacker News

Smartphones with Qualcomm chip secretly send personal data to Qualcomm

nitrokey.com

101–110 of 346 posts

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#101

That's why you install a firewall on your phone and disallow all outgoing traffic by default - possible with Android, impossible with iOS as far as I know - and keep those drivers away from the 'net. Yes, the device works, you just see loads of 'connection errors' in logcat but those just tell me things work as intended by me by not working as intended by the likes of Qualcomm. As to aGPS being necessary this depends…

The article is about the hardware chip directly sending these information, not through drivers. It is not about iOS or Android or any other OS.

The download is done from the Android side.

It's a privileged app ( a service in Android lang ) that once fetched sends the data to the modem, where GPS is actively implemented, and augmented by such extra data.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#102
post #86

Earlier quoted context omitted.

> Imagine if you bought a car from somebody, and they secretly kept a spare key and periodically used your car to run their personal errand. This is happening already. Teslas can be controlled remotely, and it does not have to be the owner of said Tesla. Yes, somehow people are okay with that. The world we live in gets scarier and scarier every year.

Let me put it into perspective. 1) AFAIK Teslas cannot be driven remotely. But even if they could Tesla is not using cars for errands, like wtf c’mon. And if they wanted to do that and paid me for it, I might be interested in helping the environment. 2) Tesla is able to remotely unlock a vehicle if they verify the owner. This replaces a call to a locksmith and/or the towing company and is way more convenient. So yes,…

On the other hand, Teslas cannot be driven remotely YET. Enabling this functionality is a core goal of the Tesla company. It remains to be seen if it is abused once it actually works. Ford has already applied for patents for cars that will self repossess for example.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#103
post #3

This seems like a really shallow dive into what’s going on, and seems to exist largely to plug their own hardware? For example, how is the chipset getting “List of the software on the device” unless the chipset is aware of the operating system? They don’t actually do any packet data analysis to see what it includes as far as I can tell, so other than seeing some packets go through, the rest feels like idle speculatio…

> how is the chipset getting “List of the software on the device” unless the chipset is aware of the operating system? The chipset is aware of the operating system, or rather the other way around. Manufacturers use kernel modifications and user space libraries provided by Qualcomm for their chipsets.

Right, it's the OS that is bolted on top, so the chipset is aware of everything that the OS is and some more besides.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#104
I think there should be a law saying you can't sign certain digital privacy rights away, much like you can't sell yourself into slavery.

But the only fool-proof solutions are mathematical/technological ones where privacy invasions aren't possible.

As far as catching child molesters, the cops should simply kick down their doors the old-fashioned way.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#105
post #44

That's why you install a firewall on your phone and disallow all outgoing traffic by default - possible with Android, impossible with iOS as far as I know - and keep those drivers away from the 'net. Yes, the device works, you just see loads of 'connection errors' in logcat but those just tell me things work as intended by me by not working as intended by the likes of Qualcomm. As to aGPS being necessary this depends…

This completely bypasses the OS. The kernel never even sees it. Addendum: To the people downvoting, the article is clear: > During operation, the covert operating system (AMSS) has complete control over the hardware, microphone and camera. The Linux kernel and deGoogled /e/OS end-user operating system function as a slave on top of the hidden AMSS operating system.

This operating system, know as firmware running in the DSP.

That's the only sane way to have a working device that needs to handle signals.

It's not hidden in any way, and the kernel/Android actively talks with it, configures it, turns it on/off.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#106
post #86

Earlier quoted context omitted.

> Imagine if you bought a car from somebody, and they secretly kept a spare key and periodically used your car to run their personal errand. This is happening already. Teslas can be controlled remotely, and it does not have to be the owner of said Tesla. Yes, somehow people are okay with that. The world we live in gets scarier and scarier every year.

Let me put it into perspective. 1) AFAIK Teslas cannot be driven remotely. But even if they could Tesla is not using cars for errands, like wtf c’mon. And if they wanted to do that and paid me for it, I might be interested in helping the environment. 2) Tesla is able to remotely unlock a vehicle if they verify the owner. This replaces a call to a locksmith and/or the towing company and is way more convenient. So yes,…

"Into perspective" is exactly wrong, because it means accepting all the tenuous assumptions used to justify the design in the first place.

The problem is not that an automaker wanted to have functionality that could legitimately unlock cars for legitimate customers. The problem is that creating this functionality entailed making a much larger backdoor that will invariably be abused by independent attackers, police, the company itself, etc - to do much more than merely unlock the doors.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#107

This seems like much bigger news than it's being received as. Sure, other chip makers do sketchy things, but is that really where we're at in 2023? We're so beaten down by proprietary user-disrespecting hardware/software that we just shrug it off? This makes me mad. I'm so sick of this type of thing. It's a horrible time too because the embedded 5G chips are about to be part of everything , sending telemetry back abo…

[deleted]

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#108

Earlier quoted context omitted.

It may have a reasonable explanation of benefits it provides, but so does Intel Management Engine and nearly every privacy-invading feature ever. I know you didn't personally design it so I'm not asking you these questions, more just thinking through this (although anybody knows the answers I'd appreciate hearing them so I can be more informed). Why does this need to be built in at such a low level that not even flas…

Leaving aside the opt-in/opt-out possibility. You can remove the services that download the extra GPS data, nothing stops you from doing that, aside making GPS unusable :)

How?

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#109
I think it would be meaningful to introspect that data since clearly it's not encrypted using https - this would be trivial with a MITM proxy on the gateway.

All of this to push your own platform without any data backing it up aside from an http connection and privacy policy. Pretty alarmist. Not that anyone is advocating for unauthorized connections to the manufacturer of your hardware, but the author should at minimum capture what is being sent (if anything) and what is being received in return. From what I can see this is a preseed for GPS data that speeds up GPS acquisition time by sharing the latest constellation data so the phone doesn't have to sit there for 5-30 seconds listening for enough satellite beacons to determine the position. It should not require any input data to provide it's function - that request should be a simple GET to an endpoint that has no extra query params or headers.

If you want to be concerned about something, be concerned about the very likely fact there is nation-state level backdoors sitting in that very same firmware (or hardware itself) that isn't using observable channels to operate. The plethora of "chatter" on the cellular network just to receive phone calls is orders of magnitude more than this request, and much of it is handled in the radio firmware invisibly which also has root-level access to much of the system.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#110
post #93

Earlier quoted context omitted.

I've been fighting this stuff for years. At some point, the best way to fight is just to stop giving them money. The cost/benefit ratio of having a smartphone is no longer favorable, so I won't have one. That seems like a reasonable stance. I don't know what's unwise about it -- whether or not I own a smartphone will not affect the world in any way.

> whether or not I own a smartphone will not affect the world in any way But it will: in addition to not giving money to Qualcomm and co, I am giving money to the alternatives and constantly reminding all banks and organizations that alternative systems exist apart from the duopoly (whenever they offer me their apps).

I figure that to the extent anybody is paying attention, I am reminding everyone that there is at least some business being lost because of their abusive practices.

I don't need to go to all the hassle of trying to validate what phones and apps are safe or not to make the point.

Post reply on HN