Live data from Hacker News

Smartphones with Qualcomm chip secretly send personal data to Qualcomm

nitrokey.com

21–30 of 346 posts

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#21
This seems like much bigger news than it's being received as. Sure, other chip makers do sketchy things, but is that really where we're at in 2023? We're so beaten down by proprietary user-disrespecting hardware/software that we just shrug it off?

This makes me mad. I'm so sick of this type of thing. It's a horrible time too because the embedded 5G chips are about to be part of everything, sending telemetry back about where they are and what they're being used for. I think it's utterly ridiculous that if you aren't ok with this type of thing, then you have to go way out of the mainstream to find products, and often there's no viable option. "Ownership" now means nothing.

Imagine if you bought a car from somebody, and they secretly kept a spare key and periodically used your car to run their personal errand. Would you be ok with that so long as they always had it back before you needed it so you never knew they were doing it?

That's what is happening when you "buy" a device and the device maker uses it to run code that serves only themselves (without receiving permission), to the detriment of your privacy. I can only hope RISC-V combined with people willing to care can lead to a return to a time when people actually own stuff and ownership is something we respect.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#22
post #3

This seems like a really shallow dive into what’s going on, and seems to exist largely to plug their own hardware? For example, how is the chipset getting “List of the software on the device” unless the chipset is aware of the operating system? They don’t actually do any packet data analysis to see what it includes as far as I can tell, so other than seeing some packets go through, the rest feels like idle speculatio…

According to GrapheneOS: "HTTPS connections are made to fetch PSDS information to assist with satellite based location. These are static files and are downloaded automatically to improve location resolution speed and accuracy. No query or data is sent to these servers".

https://grapheneos.org/faq#default-connections

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#23
If the data is as they say sent via http then surely they can show a sample request with what data is _actually_ sent from the device instead of the list of what Qualcomm says might be sent (which was probably drafted by CYA lawyers instead of engineering)?

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#24

This kind of restates what was discussed here yesterday. Android's constant leaking of data to Google is hardly any news, but Qualcomm's firmware doing the same in plain text to izatcloud.net is newsworthy. Apparently Apple is doing the same. Someone has a nice geolocation database of practically everyone in the world.

> Apparently Apple is doing the same.

I need a source for this, because my personal security model rests on the idea that Apple is NOT doing something like this.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#25
post #19

Here is the technical data of what is really going on - it is not sinister, rather these are files needed by the GPS chipset: https://wwws.nightwatchcybersecurity.com/tag/qualcomm/

And it isn’t the case that the baseband processor is somehow accessing wifi without the knowledge of the kernel. That was a bizarre accusation.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#28

This seems like much bigger news than it's being received as. Sure, other chip makers do sketchy things, but is that really where we're at in 2023? We're so beaten down by proprietary user-disrespecting hardware/software that we just shrug it off? This makes me mad. I'm so sick of this type of thing. It's a horrible time too because the embedded 5G chips are about to be part of everything , sending telemetry back abo…

It is upsetting, but I am not sure how it can be countered. I am genuinely asking what is the alternative here. We go back to the lack of trust. You basically have to assume everything is trying to communicate with mothership. You mention RISC-V, but was it ever really tested against the same proposition?

I miss the dumb everything days, where the manufacturer simply could not spare compute power on additional features like telemetry.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#29
> In spite of its reputation for bolstering users' privacy, all Fairphone models contain a Qualcomm chip probably loaded with the AMSS blobware. The Fairphone has therefor the same issue with sharing of personal data with the Qualcomm XTRA Service.

When calling out a specific brand like that, I was surprised by the "probably".

Why not first confirm it, such as by testing, or by getting a statement from the brand or Qualcomm?

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#30
post #19

Here is the technical data of what is really going on - it is not sinister, rather these are files needed by the GPS chipset: https://wwws.nightwatchcybersecurity.com/tag/qualcomm/

It may have a reasonable explanation of benefits it provides, but so does Intel Management Engine and nearly every privacy-invading feature ever.

I know you didn't personally design it so I'm not asking you these questions, more just thinking through this (although anybody knows the answers I'd appreciate hearing them so I can be more informed).

Why does this need to be built in at such a low level that not even flashing a new OS can see it/stop it? Why can't it be something users can opt in to, or at a minimum opt out of? Whether sinister or not, it's a "call home" mechanism built into to the lowest levels of the hardware, an area where users are powerless, even though they "own" the device.

Post reply on HN