Live data from Hacker News

Smartphones with Qualcomm chip secretly send personal data to Qualcomm

nitrokey.com

221–230 of 346 posts

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#221

Contrary to mediatek chips who openly send it to China or apple chips who also openly send it to Apple, and of course let's not forget the intel management engine ;)

I checked http://izatcloud.net (unencrypted!)

Which resolves to 161.189.173.187, a mainland China IP address,

with hostname

ec2-161-189-173-187.cn-northwest-1.compute.amazonaws.com.cn

https://whatismyipaddress.com/ip/161.189.173.187

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#222

Earlier quoted context omitted.

I might be wrong; it was merely speculated in the article due to the fact that Qualcomm chips are used also in Apple smartphones. An audit would be needed.

> Qualcomm chips are used also in Apple smartphones The main SoC definitely isn’t, Apple design their own SoCs, are you talking about some other chip?

5G modem.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#224
post #147

Earlier quoted context omitted.

Replying to both of you, first off which manufacturers let you choose the 3rd party remote access authorized agent? And which won’t machine new keys if you send them a request and your vin or key code. Second, Tesla comms are encrypted. Anyway, if you don't want to use vehicles which communicate with a server then good for you. Really. But if you’re taking such a stance I hope it’s based on informed data and consiste…

> which manufacturers let you choose the 3rd party remote access authorized agent? None that I'm aware of. > Tesla comms are encrypted. Which is very good, but still leaves the problem of Tesla getting the data. > if you’re taking such a stance I hope it’s based on informed data and consistent principles and not cringy FUD. I'm taking this stance because the history of the tech industry's practices in this area is fu…

I think we're on the same page about it being totally reasonable and fair for individuals to have their own tolerances and security postures. We need more principled people in the world, keep it up!

Let me put it this way. In this case, specifically, what you're claiming is pretty outrageous and, if true, sounds like something I should take more seriously too. If you can give me examples of Tesla abusing users' trust and operating in a way that is not in accordance with their privacy policy, user consent, and/or general understanding of techno-decency, then please surface the evidence to support your claims so I can consider your argument more seriously. Otherwise what you're claiming does not align with my experience owning a Tesla and my knowledge about how they're designed and engineered.

The pragmatic in me understands that there is always a risk that a future software update will change the behavior of a product in a way that is not in my interests. That is a risk I take by using any software product and something that responsible people keep an eye on, agreed. I'm just not going to categorically avoid software that can be updated out of fear that it could start spying on me. If it starts spying on me without my consent, good bye.

I also understand that we may even have different tolerances for living with connected hardware and software. If you're the type of person that compiles their own firmware and updates their own devices offline after personally vetting the software, I'd buy your concern about trust a little more too. But honestly it just sounds more like you're saying "yuck Tesla, I wouldn't trust them to build a respectful product", while ignoring the fact that you're likely posting this from a smartphone, if you know what I mean.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#225
post #74

Earlier quoted context omitted.

It's weird how much hype is around it considering about only advantage of it is "now corporations don't have to pay central entity for ISA".

Because we all dream of sub-$1 Linux processors that boot freely without blobs and have loads of wonderful usable documentation. I kind of want to modify that old adage to now read "cheap, open, documented. You can pick two."

If you picked cheap and documented, chances are it's documented primarily in Chinese also.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#226

Earlier quoted context omitted.

>Imagine if you bought a car from somebody, and they secretly kept a spare key and periodically used your car to run their personal errand. It's worse than that. It's like you bought a house from somebody and they secretly left cameras all over the living room, bedroom, bathroom, and kitchen so they can get 'telemetry' ostensibly to improve the next house they build, for 'safety' in case there's an accident, and to '…

> the covert operating system (AMSS) has complete control over the hardware, microphone and camera. The Linux kernel and deGoogled /e/OS end-user operating system function as a slave on top of the hidden AMSS operating system So they can also exfiltrate audio and video

This is why Snowden removes the microphone from his phones.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#227
post #137

Earlier quoted context omitted.

Citation/examples needed. There have been numerous talks at security conferences and solid research done on the security of Teslas. I don’t think you realize how sophisticated these things are. The infotainment system and the CAM bus are not the same software, for example. And attackers aren’t gaining remote access to them either (Teslas use stronger ssh keys than you do). So I’m not sure how this mega backdoor FUD e…

> Citation/examples needed. https://electrek.co/2023/03/24/tesla-hacked-winning-hackers-...

> Over the last few years, Tesla has been investing a lot in cybersecurity and working closely with whitehat hackers. The automaker has been participating in the Pwn2Own hacking competition by offering large prizes and its electric cars for hacking challengers.

Tesla literally paid people 100k to pentest their car so they could fix any bugs/issues found, so that you don't get hacked.

Post reply on HN