Live data from Hacker News

Smartphones with Qualcomm chip secretly send personal data to Qualcomm

nitrokey.com

171–180 of 346 posts

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#172

This seems like much bigger news than it's being received as. Sure, other chip makers do sketchy things, but is that really where we're at in 2023? We're so beaten down by proprietary user-disrespecting hardware/software that we just shrug it off? This makes me mad. I'm so sick of this type of thing. It's a horrible time too because the embedded 5G chips are about to be part of everything , sending telemetry back abo…

>This seems like much bigger news than it's being received as. Well, it's an ad for another phone. That doesn't take away from the truth, but it's marketing even if it's true.

I wish more ads were based on truths.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#173

This seems like much bigger news than it's being received as. Sure, other chip makers do sketchy things, but is that really where we're at in 2023? We're so beaten down by proprietary user-disrespecting hardware/software that we just shrug it off? This makes me mad. I'm so sick of this type of thing. It's a horrible time too because the embedded 5G chips are about to be part of everything , sending telemetry back abo…

It is upsetting, but I am not sure how it can be countered. I am genuinely asking what is the alternative here. We go back to the lack of trust. You basically have to assume everything is trying to communicate with mothership. You mention RISC-V, but was it ever really tested against the same proposition? I miss the dumb everything days, where the manufacturer simply could not spare compute power on additional featur…

> I miss the dumb everything days, where the manufacturer simply could not spare compute power on additional features like telemetry.

Indeed. The only "smart" things that I'm willing to have anymore are those that I've built myself. Apparently, very nearly no commercial manufacturers can be trusted anymore.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#174
These requests aren't being made by the firmware, it's done at the OS level:

https://android.googlesource.com/platform/frameworks/base/+/...

The file even used to specifically refer to the XTRA service, but was updated to be vendor agnostic.

GrapheneOS also calls out these requests:

> HTTPS connections are made to fetch PSDS information to assist with satellite based location.

https://grapheneos.org/faq#default-connections

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#175
post #86

Earlier quoted context omitted.

> Imagine if you bought a car from somebody, and they secretly kept a spare key and periodically used your car to run their personal errand. This is happening already. Teslas can be controlled remotely, and it does not have to be the owner of said Tesla. Yes, somehow people are okay with that. The world we live in gets scarier and scarier every year.

Let me put it into perspective. 1) AFAIK Teslas cannot be driven remotely. But even if they could Tesla is not using cars for errands, like wtf c’mon. And if they wanted to do that and paid me for it, I might be interested in helping the environment. 2) Tesla is able to remotely unlock a vehicle if they verify the owner. This replaces a call to a locksmith and/or the towing company and is way more convenient. So yes,…

> wtf c’mon

100% agree. WTF. I'm losing a bit of faith recently in HN, a significant number of people seem to have gone full tinfoil hat.

Edit: downvote all you want, nutters, but this entire discussion is mostly people ranting about things we don't even know to be true, with the justification "well if they aren't for sure doing it now, they will!"

What happened to being data driven?

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#176
post #127

Earlier quoted context omitted.

It is upsetting, but I am not sure how it can be countered. I am genuinely asking what is the alternative here. We go back to the lack of trust. You basically have to assume everything is trying to communicate with mothership. You mention RISC-V, but was it ever really tested against the same proposition? I miss the dumb everything days, where the manufacturer simply could not spare compute power on additional featur…

The alternative is to drop the purposeful error in GPS positioning systems. GPS has a built-in error for the civilian use, and a higher-accuracy system for military use. The concerns when it was deployed included unwanted parties using GPS as a guidance system component for missile / drone attacks, etc. This led to the early GPS enabled phones needing an enhancement to their positioning system. The early releases (th…

> GPS has a built-in error for the civilian use, and a higher-accuracy system for military use.

This was called "selective availability" and that practice stopped in 2000. There is no longer any intentional error being introduced.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#177
post #137

Earlier quoted context omitted.

"Into perspective" is exactly wrong, because it means accepting all the tenuous assumptions used to justify the design in the first place. The problem is not that an automaker wanted to have functionality that could legitimately unlock cars for legitimate customers. The problem is that creating this functionality entailed making a much larger backdoor that will invariably be abused by independent attackers, police, t…

Citation/examples needed. There have been numerous talks at security conferences and solid research done on the security of Teslas. I don’t think you realize how sophisticated these things are. The infotainment system and the CAM bus are not the same software, for example. And attackers aren’t gaining remote access to them either (Teslas use stronger ssh keys than you do). So I’m not sure how this mega backdoor FUD e…

> Citation/examples needed.

https://electrek.co/2023/03/24/tesla-hacked-winning-hackers-...

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#178

This is all assumptions. Just because izatcloud.net is owned by Qualcomm = they must be exfiltrating personal data? c'mon! Then you go and peddle your own NitroPhone as a "Qualcomm free" alternative? You're just gaslighting your customers to buy. This is a very short-sighted article based on lax assumptions and NO WIRESHARK to back it up. Just because a firmware makes a call home doesn't mean it's sending your person…

This is a bad faith take. If Google's T&Cs said they could record you anytime they like, but they given you a PCAP showing they don't, you would be outraged at their claimed legal right to do so? This is the same. Quadcomm have the capability, and the claimed legal right. It essentially doesn't matter whether they do, or do not, actually execute on it today.

> If Google's T&Cs said they could record you anytime they like, but they given you a PCAP showing they don't, you would be outraged at their claimed legal right to do so?

I would, yes. There's some reason that they claimed the legal right to do so. That they aren't actually doing it at the moment I check means nothing, because they could start doing it at any time in the future.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#179

This is all assumptions. Just because izatcloud.net is owned by Qualcomm = they must be exfiltrating personal data? c'mon! Then you go and peddle your own NitroPhone as a "Qualcomm free" alternative? You're just gaslighting your customers to buy. This is a very short-sighted article based on lax assumptions and NO WIRESHARK to back it up. Just because a firmware makes a call home doesn't mean it's sending your person…

Did you read the article? Qualcomm legal team replied saying "yes we exfiltrate data, see this privacy policy". What else do you need ?

the payload!!! even a fake one… :)

jokes aside, I also don’t understand the criticism. The author even took the effort to write Qualcomm, and they admitted to this!

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#180
Nothing new.

Intel runs Minix on their CPU's in their "management engine" to deal with boot security and other things which means it is able to override the host OS and even parts of the CPU itself and access the network, storage and memory independently.

Post reply on HN