Live data from Hacker News

Smartphones with Qualcomm chip secretly send personal data to Qualcomm

nitrokey.com

161–170 of 346 posts

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#161
post #3

This seems like a really shallow dive into what’s going on, and seems to exist largely to plug their own hardware? For example, how is the chipset getting “List of the software on the device” unless the chipset is aware of the operating system? They don’t actually do any packet data analysis to see what it includes as far as I can tell, so other than seeing some packets go through, the rest feels like idle speculatio…

Yea, I'm pretty confused by this write up and a bit skeptical. I would really like to see better information about what they're seeing to conclude that the allegations are credible.

I worked with aGPS a bit when I started my career. As I recall at that time, the chipsets only accessed the aGPS service if something asked the chipset for the current GPS coordinates of the device. The chipset could avoid the long load times of the locations by using the network to assist the GPS and get the current state. And because this is part of the cellular network standards, this would just be another thing the chipset did when working with the network, like receiving an SMS, or registering with the network so it can be notified of an incoming call or packet of data.

I wasn't aware that aGPS could also be done over WIFI, but I suppose it makes sense that it can. That might involve the OS as well, as other comments have pointed out to get to the WIFI network.

So I'm not ready to jump on that Qualcomm chipset is the culprit, or this is nefarious, unless we're sure there is no software process asking the chipset for the GPS coordinates / triggering an aGPS call, and that the identifying information alleged is actually in those messages and this isn't just some generic policy statement. And that this actually always goes over wifi, and when connected to a cellular network, it doesn't use the network operators aGPS. The network operator already knows all the alleged details based on the global standards of how a cellular device communicates with the network.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#162
post #113

Earlier quoted context omitted.

I’m trying to discern your point. If it’s about cars having a data connection then my point makes no sense, obviously. But your comment was in response to someone complaining about “remote control” which is just “remote unlock” (that’s all Tesla does remotely in the context of GGP). So that’s how I interpreted your response.

It seems you're being deliberately obtuse. There is a clear and obvious difference between "well someone can break that" and "someone has built a backdoor into this thing you purchased, for their own use".

No, there is just no foundation to the claim that there is a backdoor in Teslas for their own use. There’s remote unlock and remote software updates, both features that are for my benefit and use. And they don’t come with some naïve backdoor that attackers can exploit. They’re cryptographically secure and don’t expose me to vulnerabilities.

There’s a difference between the government legislating obscure and weak backdoors into all microchips so the NSA can spy on you, and a car company providing features consumers want, agree to, and pay for, in a secure way. One is a surveillance platform, the other is a good product. It’s silly to equivocate the two. Thats what I’m responding to.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#163

Earlier quoted context omitted.

> but I won't be owning cars that are too new. Nobody will "own" their car, anyway.

I will, because there is a wealth of used cars that don't have any of that stuff in them.

Yes but at some point combustion engine cars will probably be banned.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#164
I had closed the HN thread, but after reading this line, I reopened it:

>During operation, the covert operating system (AMSS) has complete control over the hardware, microphone and camera.

W-T-F

Microphone and camera control?! If this is true, it's a government spy's wet dream, and a privacy nightmare.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#165

Earlier quoted context omitted.

I will, because there is a wealth of used cars that don't have any of that stuff in them.

Yes but at some point combustion engine cars will probably be banned.

Perhaps, but by the time this happens, I'll probably have died of old age. And if it happens sooner, then I expect that there will be electric cars that, either as designed or through aftermarket modifications, won't phone home.

And if that doesn't happen, then I guess I won't be using a car. Which is probably the best idea in terms of environmental impact, anyway.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#166
post #4

Earlier quoted context omitted.

> Apparently Apple is doing the same. Just curious, where did you find this?

I might be wrong; it was merely speculated in the article due to the fact that Qualcomm chips are used also in Apple smartphones. An audit would be needed.

> Qualcomm chips are used also in Apple smartphones

The main SoC definitely isn’t, Apple design their own SoCs, are you talking about some other chip?

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#168
post #162

Earlier quoted context omitted.

It seems you're being deliberately obtuse. There is a clear and obvious difference between "well someone can break that" and "someone has built a backdoor into this thing you purchased, for their own use".

No, there is just no foundation to the claim that there is a backdoor in Teslas for their own use . There’s remote unlock and remote software updates, both features that are for my benefit and use. And they don’t come with some naïve backdoor that attackers can exploit. They’re cryptographically secure and don’t expose me to vulnerabilities. There’s a difference between the government legislating obscure and weak bac…

> just no foundation to the claim that there is a backdoor in Teslas for their own use.

If it's not for their own use, whose use is it for? It's literally just for their use. They may promise that they won't use that backdoor for purposes that aren't for your benefit, but that's just their promise. And how do they define "for your benefit"?

How secure from other attackers that back door is is only one aspect. It's important (and important to remember the truism that "if there's a way to access it legally, there's a way to access it illegally"), but not the only issue. Even if we assume that hackers really can't get in that way, the backdoor and the data collection are still unacceptable to me.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#169

This seems like much bigger news than it's being received as. Sure, other chip makers do sketchy things, but is that really where we're at in 2023? We're so beaten down by proprietary user-disrespecting hardware/software that we just shrug it off? This makes me mad. I'm so sick of this type of thing. It's a horrible time too because the embedded 5G chips are about to be part of everything , sending telemetry back abo…

How can we ever trust tech companies again? The whole model needs to be scrapped to one which is actually controlled by and accountable to the public.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#170
post #36

Earlier quoted context omitted.

This article just has little to no information in it, at least not enough to get all up in arms about. Supposedly this nefarious information is sent in the clear but no analysis was done to see what it actually happening? They're just guessing? The whole article is "Qualcomm privacy policy says they can do xyz" and then extrapolating from there.

Every time there’s some giant violation of privacy, the rejoinder is “well, it was in the privacy policy, you all agreed to it.” The moral of the story is that we have “to extrapolate from there.” And they have clever lawyers to write their privacy policies. We don’t, so we have to “round up” in a sense unless we want to be blamed for agreeing to things. The Qualcomms of the world created this situation, we just have…

Also, where in hell is anyone even expected to find the privacy policy of a part of their product? In the box manuals before turning on? By then it's too late. It's not possible to agree to something you're not made aware of.
Post reply on HN