Live data from Hacker News

Smartphones with Qualcomm chip secretly send personal data to Qualcomm

nitrokey.com

231–240 of 346 posts

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#233
post #209

Earlier quoted context omitted.

You're right RISC-V just existing won't save us. I mentioned in a sibling comment, but my hope is that it leads to more competition so there are at least options. It probably is naive since these days there are tech startups and tech giants, and any startup that starts to gain traction will go for an exit strategy to be acquired, then it will killed. So things are probably not going to get much better. Perhaps though…

> my hope is that it leads to more competition so there are at least options There are already lots of options within the ARM instruction set. The problem is that Qualcomm makes the best modems and the best (non-Apple) processors and uses their wireless patents and chip lead to squash competition. > Perhaps though, with RISC-V options there could be a real solid open source option (aka a Linux phone) The issue isn't…

Do any of the alternative options that you list have a battery life of more than 4 hours of usage? If not then, indeed, we have no real options.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#234

Earlier quoted context omitted.

> Qualcomm chips are used also in Apple smartphones The main SoC definitely isn’t, Apple design their own SoCs, are you talking about some other chip?

5G modem.

I thought it might be something like that, but in this case isn’t it the main SOC doing it?

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#235

Interesting research. I have booted up Pixels using Qualcomm chips and have not seen the elusive izaticloud. The one issue with using GrapheneOS's connectivity check is that you're broadcasting to the network that you're someone of interest. An Android phone connecting to Google isn't great for privacy but it is normal. An Android phone connecting to a GrapheneOS domain isn't.

GrapheneOS has settings to disable connectivity checks or use common Google servers in order to blend in.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#236
post #86

Earlier quoted context omitted.

Let me put it into perspective. 1) AFAIK Teslas cannot be driven remotely. But even if they could Tesla is not using cars for errands, like wtf c’mon. And if they wanted to do that and paid me for it, I might be interested in helping the environment. 2) Tesla is able to remotely unlock a vehicle if they verify the owner. This replaces a call to a locksmith and/or the towing company and is way more convenient. So yes,…

> wtf c’mon 100% agree. WTF. I'm losing a bit of faith recently in HN, a significant number of people seem to have gone full tinfoil hat. Edit: downvote all you want, nutters, but this entire discussion is mostly people ranting about things we don't even know to be true, with the justification "well if they aren't for sure doing it now, they will!" What happened to being data driven?

You seem to be assuming that the only reason someone would downvote you is because they are tin foil hatters, or "nutters". I did not downvote you, but I could understand someone doing so for either or all of these reasons:

1. Your comment was kind of a "me too" comment that added nothing (or little) of substance to the conversation. On HN these types of comments are typically downvoted, regardless of topic or whether the voter is wearing a tinfoil hat.

2. You complained about the downvoting, and in addition added a personal insult to the downvoters. Personal insults are typically downvoted on HN as well.

3. You dismissed and strawmanned the "entire discussion" as "mostly people ranting about things we don't even know to be true." This type of thing is also frequently downvoted as it doesn't add anything substantive.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#238
Sooo what this is nothing new.. What you wanna live in a MediaTek world? No thanks... If you truly know how to manipulate the SoC you can mitigate this as well but people are lazy inherently so, carry on! For a bit of color, the technical manual for the Snapdragon Cortex line is 8,767 pages long, you expect some chinese engineer who hates his life and hates you cause the PLA force him to design a certain way is going to read this manual?

Learn how to mitigate security cause you are not going to win the battle head on, simple truth that is hard to swallow.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#239

That's why you install a firewall on your phone and disallow all outgoing traffic by default - possible with Android, impossible with iOS as far as I know - and keep those drivers away from the 'net. Yes, the device works, you just see loads of 'connection errors' in logcat but those just tell me things work as intended by me by not working as intended by the likes of Qualcomm. As to aGPS being necessary this depends…

vpn/sentry is back on the market

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#240
post #137

Earlier quoted context omitted.

Citation/examples needed. There have been numerous talks at security conferences and solid research done on the security of Teslas. I don’t think you realize how sophisticated these things are. The infotainment system and the CAM bus are not the same software, for example. And attackers aren’t gaining remote access to them either (Teslas use stronger ssh keys than you do). So I’m not sure how this mega backdoor FUD e…

> Teslas use stronger ssh keys than you do SSH !?! This supports my point - a remote command prompt is much more functionality than what is required to unlock doors. It's not really appropriate to talk about this level of control as if it's merely a necessity for remote door unlocking. You're the one engaging in histrionics here - sour grapes about the lopsided relationship that was included with functionality you en…

I'm not sure if you're aware, but SSH is a flexible protocol of which "terminal emulation" is just one use case (you can implement bespoke command/response actions, I've written an SSH server before FWIW). I don't have the specifics on hand, but even assuming they can get a "terminal to your car", the resulting access is only capable of doing what the environment allows it to do. I highly doubt `spyontheuser -vvvvvvv` is one of the available commands. If it is I want to know too and would also be rightfully pissed.

Yeah. I'm not so naive to try and argue `unlock` is the only thing Tesla can do to your car remotely. Like I've said, they can update your car if you agree. If they can update the car then they can do whatever the hell the hardware allows, in theory. This is true for anything (software/firmware/younameit) that can be updated. Are you reading this on a computer with a modern OS?

I never said we shouldn't be critical of centralization and eroded notions of ownership. I am rebutting the sensationalized "Tesla has a persistent backdoor to your car and is using it to spy on you" spin on the issue. At this point in my life I'm becoming more of a tech pragmatist. One thing that has become clear to me over the years is that people don't want to be single points of failure. Putting people in that position yields poor products/user experiences. I believe there's a way to legislate and lay ground rules for ownership and access to consumer hardware that allows custody to be responsibly shared between a company and a consumer. I don't believe we're socially there yet, but making up fake news about how companies are spying on users and can't be trusted doesn't help progress the dialog. (TFA is another example of not advancing the dialog, which is how this all ties in.)

Trust is always an issue and always present. We have to make trust decisions. What I'm advocating for is making decisions based on facts and evidence, not FUD and slippery slope speculation. What I'm arguing is that it's important whether Tesla is acting in a way that is culpably deceitful and has given users reasons to not Trust them. If the evidence shows Tesla is being dishonest and operating in a way that is not in accordance with their privacy policy, then yeah grab the pitch forks I'll be there right next to you. This goes for anybody asking for trust, not just #companieselonmuskhastouched.

Otherwise name an EV that isn't cloud connected, is somehow innately more trustworthy, and that saves me 5k/year on gas.

Post reply on HN