Live data from Hacker News

Smartphones with Qualcomm chip secretly send personal data to Qualcomm

nitrokey.com

131–140 of 346 posts

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#131

Earlier quoted context omitted.

Everyone operates an AGPS service these days. Without it, you'd have to wait at least 12.5 minutes from a fully cold start (and likely, if you missed a data packet, double or triple that) until the GPS receiver has all the almanac data [1]. [1] https://en.wikipedia.org/wiki/GPS_signals#Almanac

In my old Nokia N95, the AGPS data was downloaded when starting the GPS app. No need to require a constant background download.

this.

I may actually use gps once or twice a week only, disable geolocalisation when it is possible on all apps I am using.

There is no justifiable reason to say gps is not possible without this. Besides you should be able to decide you don't mind waiting 15 minutes to get full gps service.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#132
post #78

Earlier quoted context omitted.

Did you read the article? Qualcomm legal team replied saying "yes we exfiltrate data, see this privacy policy". What else do you need ?

> What else do you need ? Evidence/details of the very specific claims that go beyond that.

Even if there is no evidence today, they can start doing it at any moment. Are you fine with that? Are you checking your connections every day?

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#133

This seems like much bigger news than it's being received as. Sure, other chip makers do sketchy things, but is that really where we're at in 2023? We're so beaten down by proprietary user-disrespecting hardware/software that we just shrug it off? This makes me mad. I'm so sick of this type of thing. It's a horrible time too because the embedded 5G chips are about to be part of everything , sending telemetry back abo…

I wonder how this will fly in an European Court with GDPR.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#134
post #39
post #3

This seems like a really shallow dive into what’s going on, and seems to exist largely to plug their own hardware? For example, how is the chipset getting “List of the software on the device” unless the chipset is aware of the operating system? They don’t actually do any packet data analysis to see what it includes as far as I can tell, so other than seeing some packets go through, the rest feels like idle speculatio…

> For example, how is the chipset getting “List of the software on the device” unless the chipset is aware of the operating system? This surely isn't "the chip" doing this. It's the driver suite provided by Qualcomm, which is (obviously) required for a functioning device. The open Android distros still need drivers, and are essentially copying these files verbatim without review. Somewhere Qualcomm has a privileged d…

Or it's some GPS receiver state visible through the requests that might allow identification of certain apps that leave some form of characteristic fingerprints in the receiver. Could be "why can't Android allow bluetooth without GPS permissions!" all over again.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#135

This seems like much bigger news than it's being received as. Sure, other chip makers do sketchy things, but is that really where we're at in 2023? We're so beaten down by proprietary user-disrespecting hardware/software that we just shrug it off? This makes me mad. I'm so sick of this type of thing. It's a horrible time too because the embedded 5G chips are about to be part of everything , sending telemetry back abo…

> Imagine if you bought a car from somebody, and they secretly kept a spare key and periodically used your car to run their personal errand.

I wouldn't say this is equivalent to them "running a personal errand". If they were remotely enlisting your device in some computational task, sure.

But modern cars do grant the car company the "keys" to your car:

- Tesla's system - GMC OnStar (since 1996!) - Ford SyncConnect (since 2017) - HondaLink - BMW Assist - VW Car-Net

Even if you don't subscribe to the service they can still remotely access your vehicle...

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#136
post #127

Earlier quoted context omitted.

It is upsetting, but I am not sure how it can be countered. I am genuinely asking what is the alternative here. We go back to the lack of trust. You basically have to assume everything is trying to communicate with mothership. You mention RISC-V, but was it ever really tested against the same proposition? I miss the dumb everything days, where the manufacturer simply could not spare compute power on additional featur…

The alternative is to drop the purposeful error in GPS positioning systems. GPS has a built-in error for the civilian use, and a higher-accuracy system for military use. The concerns when it was deployed included unwanted parties using GPS as a guidance system component for missile / drone attacks, etc. This led to the early GPS enabled phones needing an enhancement to their positioning system. The early releases (th…

> As the maps are unlikely to ever be placed inside of phone devices ...

Could you clarify what you mean? Here Maps allows you to download maps into your device and use it to navigate offline (without internet connection in devices with built-in GPS). I've been using this for (I think) more than a decade now and it works great. They also release maps updates frequently to download and update your maps. I believe Google maps has also begin offering similar offline map features.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#137
post #86

Earlier quoted context omitted.

Let me put it into perspective. 1) AFAIK Teslas cannot be driven remotely. But even if they could Tesla is not using cars for errands, like wtf c’mon. And if they wanted to do that and paid me for it, I might be interested in helping the environment. 2) Tesla is able to remotely unlock a vehicle if they verify the owner. This replaces a call to a locksmith and/or the towing company and is way more convenient. So yes,…

"Into perspective" is exactly wrong, because it means accepting all the tenuous assumptions used to justify the design in the first place. The problem is not that an automaker wanted to have functionality that could legitimately unlock cars for legitimate customers. The problem is that creating this functionality entailed making a much larger backdoor that will invariably be abused by independent attackers, police, t…

Citation/examples needed.

There have been numerous talks at security conferences and solid research done on the security of Teslas. I don’t think you realize how sophisticated these things are. The infotainment system and the CAM bus are not the same software, for example. And attackers aren’t gaining remote access to them either (Teslas use stronger ssh keys than you do). So I’m not sure how this mega backdoor FUD even plausibly exists. A car isn’t a safe either, if law enforcement has a warrant for my car, or house, they’re going to forcibly break in if needed (heck they’ll even do that for a safe). Seems better to have Tesla legally complying/cooperating with law enforcement than the alternative where people use force.

I’m not saying we should build backdoors into everything for the kids, just to be clear. But I can be a happy consumer/user of a car with remote unlock functionality that’s implemented more responsibly than your npm account without devolving into “zomg Tesla backdoors your life to give you that feature” histrionics. That’s just not true. Like you, I would love to see, just like I argue for phones, the ability for enthusiasts and/or hyper paranoid people to install their own software roots in a supported manner if they don't want another party having access or if they want to delegate to a different 3rd party. And let me turn it on/off, sure. But having a car with remote unlock is not some gateway drug selling your digital soul.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#138
post #42

Earlier quoted context omitted.

> Apparently Apple is doing the same. I need a source for this, because my personal security model rests on the idea that Apple is NOT doing something like this.

Why would they not? Why do you think that is a reasonable assumption?

Because for Apple, there‘s a financial incentive for keeping the „we care about your privacy“ narrative alive.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#139

This seems like much bigger news than it's being received as. Sure, other chip makers do sketchy things, but is that really where we're at in 2023? We're so beaten down by proprietary user-disrespecting hardware/software that we just shrug it off? This makes me mad. I'm so sick of this type of thing. It's a horrible time too because the embedded 5G chips are about to be part of everything , sending telemetry back abo…

Getting mad won't fix it.

You putting quotes around words such as "buy" and "ownership" push people away from your view, and any view like it, unless they have already adopted it that view or a similar one.

if you want this to change, stop ranting, stop scare-quoting normal English words because you disagree with the way they are used, and approach the problem logically. asking rhetorical questions and being angry is not how you get people thinking about this.

state your case, (we know it, but state it anyway) without emotion of any kind, and without unanswered questions. start by verifying what this article is claiming using your own device. the entire article could be BS designed to enrage people and to see how far it spreads before it is fact-checked.

it is very difficult to listen to someone who is ranting and who is speaking from a point of emotion unless you are emotionally invested yourself. it is much easier to ask someone to think about facts than it is to ask them to feel about emotions if you want them to think about what you are trying to say.

Post reply on HN