Live data from Hacker News

Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

blog.checkpoint.com

111–120 of 120 posts

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#111
post #21

Time to switch to open source: https://en.wikipedia.org/wiki/Pinephone https://en.wikipedia.org/wiki/Librem_5

An Open Source OS can help, sure, and is a start. A DSP is a programmable hardware device. Both phones to which you linked use variants of ARM processors and then use third-party baseband systems. You're not getting rid of closed-source hardware vulnerabilities by replacing Android or iOS.

The Pinephone at least isolates the baseband from the main CPU and memory.

https://www.pine64.org/2020/01/24/setting-the-record-straigh...

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#112

Would having an open source chip with a rolling release be more secure? Like as soon as the vulnerability is discovered you would push the fix and the next generations would already be fixed. Or would such frequent changes to the chip design be to difficult to mass produce, due to having to modify the production process? This is coming from a point of view that Linux is quite a success and thus maybe the same philoso…

Hardware is different in that it can't be updated once it's leaves the factory and has to be "right first time".

Not quite true: https://en.wikipedia.org/wiki/Intel_Microcode

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#113

Earlier quoted context omitted.

This is a thing I think people constantly underestimate... Intel's cores are not necessarily dramatically more broken than everyone else's chips, they just pay for more auditing and public research.

This is very much an opinion, not a fact. "Intel is only in trouble because they got caught, AMD is surely incompetent as well, but hasn't been found out".

I dont think it has much to do with competence, the order of complexity in these chips are reaching super human levels of intellect to decipher. Finding vulnerabilities is hard but safeguarding against them is even harder. Take 'spectre' for instance, it is a fundamental problem with the speculative architecture can't really get rid of it.

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#115
post #88

Earlier quoted context omitted.

Because (a) it would let you root your device, allowing you to do what you want with it (b) it would make these 400 vulnerabilities especially dangerous

(c) it would prevent most banking and finance apps from working.

Best to use a bank which treats you like an adult and trusts you to make grown-up decisions about using a rooted device. Monzo fits into this category.

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#117
post #99

Earlier quoted context omitted.

My point is that there is more academic research on Intel processors than AMD. For a hacker, an Intel vulrability would of course be more lucrative than a AMD one.

"Intel" has another meaning, especially when placed next to the word "security". The number of results from your two google searches is meaningless.

That's a good point, about half the results go away when you add "processor" to the query. Interestingly, the same happens for the AMD query so the ratio is still similar.

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#119

Google has pushed the patch for this back to October. I wonder what will happen to downstream vendors (Samsung, CopperheadOS)?

You mean GrapheneOS.

I'm referring to businesses because they have SLAs or other customer obligations. AFAICT Graphene isn't a business but is a FOSS project without customer support requirements or obligations.
Post reply on HN