Live data from Hacker News

Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

blog.checkpoint.com

21–30 of 120 posts

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#21

Time to switch to open source: https://en.wikipedia.org/wiki/Pinephone https://en.wikipedia.org/wiki/Librem_5

An Open Source OS can help, sure, and is a start. A DSP is a programmable hardware device. Both phones to which you linked use variants of ARM processors and then use third-party baseband systems. You're not getting rid of closed-source hardware vulnerabilities by replacing Android or iOS.

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#22

There seems to be some confusion on the authors' behalf about what a DSP is, and what an SoC is ("software" on chip, as they call it...) I'm just nitpicking, of course.

I think you have a point here. When they say "DSP chip" instead of "DSP core inside the Snapdragon chip" it makes me wonder what else they got wrong. I don't think the oversimplified language is any more approachable here.

(As it happens I read the slides and this is a legit vulnerability but you'd never know it from the press release.)

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#23

Seriously I'm beyond pissed at the state of Android, patches and open-source compliance. If we are lucky 10% of current phone models will get any form of update. The rest will be vulnerable for years until the devices finally break. And that's only the Qualcomm stuff. There is another CPU vendor beginning with M who is big in el-cheapo hardware - look at their Android kernel leaks, wherever you dig you find horrid, H…

Still getting updates for my one plus 6. YMMV.

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#24
post #21

Time to switch to open source: https://en.wikipedia.org/wiki/Pinephone https://en.wikipedia.org/wiki/Librem_5

An Open Source OS can help, sure, and is a start. A DSP is a programmable hardware device. Both phones to which you linked use variants of ARM processors and then use third-party baseband systems. You're not getting rid of closed-source hardware vulnerabilities by replacing Android or iOS.

Agree, we need open source hardware (like RISC-V) to mature in order to eliminate this class of vulnerabilities. I haven't heard much on mobile class RISC-V SOCs though.

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#25

Seriously I'm beyond pissed at the state of Android, patches and open-source compliance. If we are lucky 10% of current phone models will get any form of update. The rest will be vulnerable for years until the devices finally break. And that's only the Qualcomm stuff. There is another CPU vendor beginning with M who is big in el-cheapo hardware - look at their Android kernel leaks, wherever you dig you find horrid, H…

Still getting updates for my one plus 6. YMMV.

That phone is barely 2 years old from a reputable brand, I sure as hell hope it's still getting updates.

My older OnePlus 3 got updates for almost 4 years I think. Not bad, but it's not like apple's 5-6 years. Still, it was half the price of an iPhone with better hardware to boot so fair trade I guess.

I don't like frivolous spending on phones but I never keep a phone more than 4 years anyway. The progress of camera, microphone and speaker quality alone across 4 years is enough of a quality of life improvement for me to upgrade.

At this rate of Android security issues, my next phone will probably be the next iPhone SE but only if they update the display to a larger 1080p 90Hz panel and add an ultrawide camera lens, I don't care about anything else.

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#26

I wonder if Apple/others knew about such vulnerabilities, and passed up on using the chip as a risk? Or, was it just dumb luck that they avoided this?

From Apple's perspective Qualcomm has been insufficient for a long time for many reasons, the security issues here would only be one of the many factors involved in the decision to do their own development. For what it is worth, a modern chip as complex as the A* series is essentially guaranteed to have vulnerabilities. Maybe not 400, but definitely not 0.

This is a thing I think people constantly underestimate... Intel's cores are not necessarily dramatically more broken than everyone else's chips, they just pay for more auditing and public research.

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#27

Seriously I'm beyond pissed at the state of Android, patches and open-source compliance. If we are lucky 10% of current phone models will get any form of update. The rest will be vulnerable for years until the devices finally break. And that's only the Qualcomm stuff. There is another CPU vendor beginning with M who is big in el-cheapo hardware - look at their Android kernel leaks, wherever you dig you find horrid, H…

Still getting updates for my one plus 6. YMMV.

You are getting updates for the OS and kernel but not for device drivers. That's a big surface area for someone to hack your phone.

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#28

Earlier quoted context omitted.

From Apple's perspective Qualcomm has been insufficient for a long time for many reasons, the security issues here would only be one of the many factors involved in the decision to do their own development. For what it is worth, a modern chip as complex as the A* series is essentially guaranteed to have vulnerabilities. Maybe not 400, but definitely not 0.

This is a thing I think people constantly underestimate... Intel's cores are not necessarily dramatically more broken than everyone else's chips, they just pay for more auditing and public research.

> they just pay for more auditing and public research.

Did Intel finance the research that turned up any of the major headline vulnerabilities over the last few years (meltdown, spectre)?

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#29

Earlier quoted context omitted.

From Apple's perspective Qualcomm has been insufficient for a long time for many reasons, the security issues here would only be one of the many factors involved in the decision to do their own development. For what it is worth, a modern chip as complex as the A* series is essentially guaranteed to have vulnerabilities. Maybe not 400, but definitely not 0.

This is a thing I think people constantly underestimate... Intel's cores are not necessarily dramatically more broken than everyone else's chips, they just pay for more auditing and public research.

Even if they wouldn't, I imagine the exposure is enough. Windows, Android, Linux probably have more eyes on them than all the other software in the world, combined.

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#30

Seriously I'm beyond pissed at the state of Android, patches and open-source compliance. If we are lucky 10% of current phone models will get any form of update. The rest will be vulnerable for years until the devices finally break. And that's only the Qualcomm stuff. There is another CPU vendor beginning with M who is big in el-cheapo hardware - look at their Android kernel leaks, wherever you dig you find horrid, H…

> horrid, HORRID code

Heh, I once found a "feature" in a kernel driver in my Xperia (with a SoC from the company with a name starting in M) that allowed you to read arbitrary kernel memory from userspace, by passing the appropriate structures via a ioctl interface. Didn't even have to dig around too much.

Ah well, at least I got a t-shirt from Sony.

Post reply on HN