Live data from Hacker News

Smartphones with Qualcomm chip secretly send personal data to Qualcomm

nitrokey.com

191–200 of 346 posts

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#191

This is all assumptions. Just because izatcloud.net is owned by Qualcomm = they must be exfiltrating personal data? c'mon! Then you go and peddle your own NitroPhone as a "Qualcomm free" alternative? You're just gaslighting your customers to buy. This is a very short-sighted article based on lax assumptions and NO WIRESHARK to back it up. Just because a firmware makes a call home doesn't mean it's sending your person…

Now imagine it was anything but an American (or allying) company. Oooo, much scarier.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#192
post #3

This seems like a really shallow dive into what’s going on, and seems to exist largely to plug their own hardware? For example, how is the chipset getting “List of the software on the device” unless the chipset is aware of the operating system? They don’t actually do any packet data analysis to see what it includes as far as I can tell, so other than seeing some packets go through, the rest feels like idle speculatio…

Yeah, it manages to subvert its own message by transparently trying to be as scary as possible by being vague and jumping to its own conclusions, in what is clearly a sales pitch. It would be enough to say "hey, did you know that most phones send tracking data to the manufacturer when you download AGPS information? Our phone doesn't do that", instead of saying "oh, this phone makes a connection to a Qualcomm, server even on an open-source ROM, but we couldn't find which bit was making that connection so it must be the firmware. Also we won't actually show what data the phone was sending despite it being unencrypted. buy our phone instead!". I don't know what they did to investigate what was going on in the ROM they used but it clearly wasn't very much as it's something the ROM authors are clearly aware of: https://community.e.foundation/t/connections-to-izatcloud-ne... (this is the first result on google for "e/OS" "izatcloud"). It's annoying because it's pretty unnecessary to add the unsubstantiated claims to actually deliver their core marketing message, they just felt the need to put down the use of open-source ROMs on other hardware.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#193

Earlier quoted context omitted.

Piss of Elon and in the morning your car could be parked some couple of miles away OR FSD buggs out on the highway OR someone reports you for something and they disable your car to aprehend you. Good bye high speed chases.

Disabling engines remotely by police has been a thing since at least 2010, in pretty much every modern car.

Got a spec on that? I am aware onstar can... its also possible to unplug it or the antenna.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#194
post #124

This is all assumptions. Just because izatcloud.net is owned by Qualcomm = they must be exfiltrating personal data? c'mon! Then you go and peddle your own NitroPhone as a "Qualcomm free" alternative? You're just gaslighting your customers to buy. This is a very short-sighted article based on lax assumptions and NO WIRESHARK to back it up. Just because a firmware makes a call home doesn't mean it's sending your person…

> This is a very short-sighted article based on lax assumptions and NO WIRESHARK to back it up. Just because a firmware makes a call home doesn't mean it's sending your personal data. Sorry, but you're the one who is missing the point. The very act of making a network request gives away your geolocation + time of use https://kieranhealy.org/blog/archives/2013/06/09/using-metad...

Which every iPhone and Android phone do all the time. You agreed to it when you agreed to the terms of use and all that legal crap they hide behind. I'm not saying I'm ok with it. I'm saying I know it's been going on since 2009 and no one with the ability to change it, cares.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#195
post #78

Earlier quoted context omitted.

> What else do you need ? Evidence/details of the very specific claims that go beyond that.

Even if there is no evidence today, they can start doing it at any moment. Are you fine with that? Are you checking your connections every day?

There isn't actually evidence of that. These connections are actually being done by the OS, which you can control if you are using an open-source ROM. Just because on OS doesn't currently change the defaults from the manufacturer doesn't mean others are the same (in fact, grapheneOS goes to some lengths to strip as much of the identifying information vanilla android sends as they can, proxies this through their own server, and gives you an option of disabling it altogether). The default behaviour of AGPS on android is concerning and a big privacy violation, but this article felt the need to add some extra BS to scare you into buying their hardware specifically.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#197
post #182

A quite overblown article from a company pitching their own "secure phone". They installed a custom OS which apparently includes Qualcomm's indoor positioning service iZat, but is missing the EULA item to allow the user to enable/disable the service. iZat exists for at least 6 years, and the vendors who implemented it usually have a separate checkbox in their startup wizard to allow it to work. Example screenshot aft…

why do you shoot the messenger? yeah they did a bit of advertisement to their phone, who cares. what matters is that now even freaking basic hardware pushes your data wherever they want without asking you. I really wonder if this had been a Chinese company the kind of comments we would have seen here.

Because the part about is being the hardware is false. This behaviour is entirely part of the OS. It's still bad, especially if the OSS ROM is not making users aware of it (though neither really are the manufacturers: burying this shit in a pages-long policy which the user cannot freely decline does not qualify for GDPR consent either). It's very easy to make android look bad from a privacy point of view, you don't need to make things up to do so.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#198

This seems like much bigger news than it's being received as. Sure, other chip makers do sketchy things, but is that really where we're at in 2023? We're so beaten down by proprietary user-disrespecting hardware/software that we just shrug it off? This makes me mad. I'm so sick of this type of thing. It's a horrible time too because the embedded 5G chips are about to be part of everything , sending telemetry back abo…

How can we ever trust tech companies again? The whole model needs to be scrapped to one which is actually controlled by and accountable to the public.

Trust hasn't mattered for a while. Growth and profit are the pope and king. The "whole model" runs on these companies. They have civilization by the balls, and we have to live with it unless we throw almost every computer advancement from this millenium out.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#199
Why all the handwringing on this exactly? This data is necessary for product improvements. Seeing it in aggregate improves troubleshooting and tuning to specific operator's networks as well as end-to-end performance analysis.

If the list of data in this article wasn't exposed by Qualcomm, then it's exposed in other ways like via SS7 in certain scenarios or to the OS and apps. Granted, app permissions are at least a user choice but we all know how that works these days. At least Qualcomm's using it to improve their product and not just harvesting for advertisers.

Also, like others have said, this is a shallow blogspam article trying to sell a "secure" phone. Ick.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#200
post #12

Interesting research. I have booted up Pixels using Qualcomm chips and have not seen the elusive izaticloud. The one issue with using GrapheneOS's connectivity check is that you're broadcasting to the network that you're someone of interest. An Android phone connecting to Google isn't great for privacy but it is normal. An Android phone connecting to a GrapheneOS domain isn't.

That's why it's configurable in Settings > Network & internet > Internet connectivity check: GrapheneOS / Standard (Google) / Disabled

Yep, adding a toggle is a must-have.
Post reply on HN