Earlier quoted context omitted.
I am not willing to live in a state of eternal outrage. It's an incredibly unpleasant place to be and what's the point? My outrage changes nothing, and I don't need to be outraged to do whatever is in my power to change things. Not giving these bastards money is a good start.
This article finally pushed me over to thinking that we need to start pushing for some laws to limit this sort of thing. It's just pervasive, and "not giving [them] money" is completely ineffective. And for some companies, like Google or Facebook, it's pretty hard for a consumer to actually give them money in the first place, nor is practical [0] to not use their products. [0] practical , not possible .
Smartphones with Qualcomm chip secretly send personal data to Qualcomm
201–210 of 346 posts
Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm
#202Earlier quoted context omitted.
In my old Nokia N95, the AGPS data was downloaded when starting the GPS app. No need to require a constant background download.
this. I may actually use gps once or twice a week only, disable geolocalisation when it is possible on all apps I am using. There is no justifiable reason to say gps is not possible without this. Besides you should be able to decide you don't mind waiting 15 minutes to get full gps service.
Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm
#203Firstly, the Nitrophone is just a Pixel 4A which contains a Qualcomm Snapdragon 765G CPU. I am confused at how the author claims it is free of Qualcomm control. They are unquestionably an active participant in mass surveillance efforts and there are much more covert ways of doing that when you control a CPU, like making your random number generator not actually that random, potentially compromising -all- TLS, or only activating firmware location tracking features when particular domains or traffic is observed. There are countless ways to hardware backdoor a device that are not as crude and obvious as the ones this article observed.
Secondly, the sole signing key for phone software is under the exclusive control of Daniel Micay who is an undeniably brilliant engineer, but I suggest looking into how they communicate online and comments by anyone who has ever worked with them before. Supply chain integrity for GrapheneOS stops and ends with one person, who has rejected all attempts by me and others to pursue reproducible builds etc for accountability.
Third, GrapheneOS still contains many proprietary blobs with full control over various portions of the hardware. The GrapheneOS team has no choice, because the supported hardware components have not been reverse engineered yet and cannot function without them. The only blob-free Android is Replicant OS but it only runs on reverse engineered but sadly ancient devices long out of production and ancient builds of Android missing many years of security patches. The state of open and private mobile computing is truly a shit show.
Fourth, even if you had a fully trusted hardware and software stack, a device that connects to cell towers, even a dumb phone, will be pinged by three or more towers at a time. All of them collude to log the location of every single phone connected. The only way out is living on Wifi only with airplane mode full time.
Fifth, even if you open source hardware and software you -still- have to worry about state sponsored supply chain attacks at the factories.
Bunnie had it right in his talk on this. https://hackaday.com/2019/12/29/36c3-open-source-is-insuffic...
The only way forward is to essentially go back in time to decisions we made back in the 90s and start over again, which is what the Precursor project seeks to do.
That is the only hope I have for a high trust messaging device in my pocket any time soon. There is an alpha matrix client, so fingers crossed.
Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm
#204Earlier quoted context omitted.
> This is a very short-sighted article based on lax assumptions and NO WIRESHARK to back it up. Just because a firmware makes a call home doesn't mean it's sending your personal data. Sorry, but you're the one who is missing the point. The very act of making a network request gives away your geolocation + time of use https://kieranhealy.org/blog/archives/2013/06/09/using-metad...
Which every iPhone and Android phone do all the time. You agreed to it when you agreed to the terms of use and all that legal crap they hide behind. I'm not saying I'm ok with it. I'm saying I know it's been going on since 2009 and no one with the ability to change it, cares.
Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm
#205- Unique ID - Chipset name - Chipset serial number - XTRA software version - Mobile country code - Mobile network code (allowing identification of country and wireless operator) - Type of operating system and version - Device make and model - Time since the last boot of the application processor and modem - List of the software on the device - IP address
The A-GPS system downloads current satellite orbits (Ephemeris) from Qualcomm instead of waiting for all relevant satellites to transmit all of them on their own. This reduces the time it takes to fix the position.
I would've preferred that they show the actual data transferred, instead of what the policy says they may transfer.
Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm
#206That's why you install a firewall on your phone and disallow all outgoing traffic by default - possible with Android, impossible with iOS as far as I know - and keep those drivers away from the 'net. Yes, the device works, you just see loads of 'connection errors' in logcat but those just tell me things work as intended by me by not working as intended by the likes of Qualcomm. As to aGPS being necessary this depends…
This completely bypasses the OS. The kernel never even sees it. Addendum: To the people downvoting, the article is clear: > During operation, the covert operating system (AMSS) has complete control over the hardware, microphone and camera. The Linux kernel and deGoogled /e/OS end-user operating system function as a slave on top of the hidden AMSS operating system.
Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm
#207Earlier quoted context omitted.
> Imagine if you bought a car from somebody, and they secretly kept a spare key and periodically used your car to run their personal errand. This is happening already. Teslas can be controlled remotely, and it does not have to be the owner of said Tesla. Yes, somehow people are okay with that. The world we live in gets scarier and scarier every year.
> The world we live in gets scarier and scarier every year. One could accurately summarize progress since the Industrial Revolution as asking whether we could (and how), and not whether we should (and why). You can see this expressed in the growing focus on STEM education vs. the liberal arts and results in things like remote-controlled Teslas. Cave Johnson said, "science isn't about why; it's about why not". The tra…
this is yet another face of Moloch
Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm
#208If one particular vendor has 25% Black market Qualcomm chips inside for which Qualcomm never gets a royalty then I think they would definitely be getting a phone call from Qualcomm pretty soon...
Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm
#209Earlier quoted context omitted.
Sorry, but trying to be optimistic about RISC-V is only going to lead to more pain. It's just an instruction set architecture and it's still going to be made in large SoC fabs by Qualcomm-class companies that want to save a buck on ARM licensing. There's no way to win here.
You're right RISC-V just existing won't save us. I mentioned in a sibling comment, but my hope is that it leads to more competition so there are at least options. It probably is naive since these days there are tech startups and tech giants, and any startup that starts to gain traction will go for an exit strategy to be acquired, then it will killed. So things are probably not going to get much better. Perhaps though…
There are already lots of options within the ARM instruction set. The problem is that Qualcomm makes the best modems and the best (non-Apple) processors and uses their wireless patents and chip lead to squash competition.
> Perhaps though, with RISC-V options there could be a real solid open source option (aka a Linux phone)
The issue isn't the ARM instruction set. We have Linux smartphones (beyond Android) that you can buy today. You can buy a PinePhone and run Ubuntu Touch, postmarketOS, Mobil, LuneOS, and more. You can buy a Librem or Volla Phone or Fairphone. If you want out of the duopoly of Apple and Google, there are devices you could have shipped to you today!
The problem isn't the ARM instruction set and getting RISC-V processors wouldn't make much of a difference for Linux (or FOSS in general) on smartphones. The ARM instruction set isn't what is keeping the tech giants in power.
Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm
#210Earlier quoted context omitted.
> The world we live in gets scarier and scarier every year. One could accurately summarize progress since the Industrial Revolution as asking whether we could (and how), and not whether we should (and why). You can see this expressed in the growing focus on STEM education vs. the liberal arts and results in things like remote-controlled Teslas. Cave Johnson said, "science isn't about why; it's about why not". The tra…
> Cave Johnson +1 for the Aperture ref.
Aperture Science
We do what we must
because we can.
For the good of all of us.