Live data from Hacker News

Smartphones with Qualcomm chip secretly send personal data to Qualcomm

nitrokey.com

271–280 of 346 posts

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#271
post #224

Earlier quoted context omitted.

> which manufacturers let you choose the 3rd party remote access authorized agent? None that I'm aware of. > Tesla comms are encrypted. Which is very good, but still leaves the problem of Tesla getting the data. > if you’re taking such a stance I hope it’s based on informed data and consistent principles and not cringy FUD. I'm taking this stance because the history of the tech industry's practices in this area is fu…

I think we're on the same page about it being totally reasonable and fair for individuals to have their own tolerances and security postures. We need more principled people in the world, keep it up! Let me put it this way. In this case, specifically, what you're claiming is pretty outrageous and, if true, sounds like something I should take more seriously too. If you can give me examples of Tesla abusing users' trust…

> In this case, specifically, what you're claiming is pretty outrageous and, if true, sounds like something I should take more seriously too.

I have made no specific claims, I think. If I did, they were unintentional. What I'm claiming is more general: that in the tech industry, data collection on users has been so widely abusive that I am not comfortable trusting any company with data collection by default. Specific companies can earn my trust, of course. No car company has done that, therefore I trust none of them with my data.

Is this the claim you're referring to?

> But honestly it just sounds more like you're saying "yuck Tesla, I wouldn't trust them to build a respectful product"

I do not intend to be singling Tesla out except insofar as Tesla (as I understand it) engages in more data collection than other car manufacturers. That said, I'm a bit more suspicious of Tesla just because of Musk. Not a lot more suspicious, but some.

> while ignoring the fact that you're likely posting this from a smartphone

I'm not. But I also have mentioned here that when my current smartphone dies, I won't be replacing it with another -- specifically because it's become so difficult to render them safe that it absorbs too much of my time and energy. That makes the cost/benefit of a smartphone too unfavorable for my tastes.

But with the smartphone I currently have, I do not use it for very much online stuff -- certainly not for web browsing -- anyway, because of safety concerns.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#272
post #209

Earlier quoted context omitted.

> my hope is that it leads to more competition so there are at least options There are already lots of options within the ARM instruction set. The problem is that Qualcomm makes the best modems and the best (non-Apple) processors and uses their wireless patents and chip lead to squash competition. > Perhaps though, with RISC-V options there could be a real solid open source option (aka a Linux phone) The issue isn't…

Do any of the alternative options that you list have a battery life of more than 4 hours of usage? If not then, indeed, we have no real options.

I have the /e/OS Fairphone 4 and the battery life is pretty good. To be fair, I've only owned the smaller versions (Galaxy Mini) and non-flagship phones before, so this one is quite a bit bulkier in comparison. With my low usage, over a year after purchase the battery still lasts for multiple days. My previous phones I used to charge every night, anyway.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#273

Earlier quoted context omitted.

this. I may actually use gps once or twice a week only, disable geolocalisation when it is possible on all apps I am using. There is no justifiable reason to say gps is not possible without this. Besides you should be able to decide you don't mind waiting 15 minutes to get full gps service.

Also there's not really any good justification for the amount of data sent with the AGPS request. It can be a super plain HTTPS request with nothing else, instead of sending basically all of the tracking data from the device, including from what I can tell the IMEI which google doesn't even let app developers access anymore.

There is no private data in the request. The request is HTTP and authors could have analyzed them and discovered there is nothing in them. Instead, they published a list of things that Qualcomm privacy policy could include.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#274
post #67

Earlier quoted context omitted.

> Imagine if you bought a car from somebody, and they secretly kept a spare key and periodically used your car to run their personal errand. This is happening already. Teslas can be controlled remotely, and it does not have to be the owner of said Tesla. Yes, somehow people are okay with that. The world we live in gets scarier and scarier every year.

> The world we live in gets scarier and scarier every year. One could accurately summarize progress since the Industrial Revolution as asking whether we could (and how), and not whether we should (and why). You can see this expressed in the growing focus on STEM education vs. the liberal arts and results in things like remote-controlled Teslas. Cave Johnson said, "science isn't about why; it's about why not". The tra…

Yes to liberal arts, absolutely, but it’s not liberal arts that’s trying to stick its oar in to the place of science in society. It’s made up bullshit ‘social science’ that’s one step away from parapsychology and crystal healing.

Liberal arts is a natural ally and fellow traveller with science and technology. In fact much of early science grew out of liberal arts endeavours. Geometry from sculpture and perspective in art and architecture. Chemistry from developing pigments for painting.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#275
post #52

This seems like much bigger news than it's being received as. Sure, other chip makers do sketchy things, but is that really where we're at in 2023? We're so beaten down by proprietary user-disrespecting hardware/software that we just shrug it off? This makes me mad. I'm so sick of this type of thing. It's a horrible time too because the embedded 5G chips are about to be part of everything , sending telemetry back abo…

> This seems like much bigger news than it's being received as. This has been widely known for more than a decade (Sorry I can't provide with a source. I was expecting Google search-in-the-past feature to work, but it doesn't). As to whether the privacy policy has been declared properly or not, it depends on the OEM: See for instance https://www.bsr.at/mediafiles/Handbuch/CipherLab/User_Guide_... which shows Qualcomm…

> > This seems like much bigger news than it's being received as.

> This has been widely known for more than a decade (Sorry I can't provide with a source. I was expecting Google search-in-the-past feature to work, but it doesn't).

Yep. Nitrokey's post was disappointing but understandable from a marketing perspective.

The thing that needs more discussion is the closed source stuff Android OEMs / ODMs run at higher ARM privileges rendering all of Google's grand ceremony around Android security moot (other than on Pixels may be).

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#276

This seems like much bigger news than it's being received as. Sure, other chip makers do sketchy things, but is that really where we're at in 2023? We're so beaten down by proprietary user-disrespecting hardware/software that we just shrug it off? This makes me mad. I'm so sick of this type of thing. It's a horrible time too because the embedded 5G chips are about to be part of everything , sending telemetry back abo…

Is it big news? It might be, but we haven't seen the packet captures yet. I'm not trusting this shallow analysis (from a source I don't have any particular reason to trust) without seeing more details or corroboration.

As mentioned, it's now 2023 and the Snowden revelations were in... 2013, right? There have been at least a hundred similar news events since. The "healthy skepticism" bit on the subject is misdirected at this point. Backwards, really.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#277

This seems like much bigger news than it's being received as. Sure, other chip makers do sketchy things, but is that really where we're at in 2023? We're so beaten down by proprietary user-disrespecting hardware/software that we just shrug it off? This makes me mad. I'm so sick of this type of thing. It's a horrible time too because the embedded 5G chips are about to be part of everything , sending telemetry back abo…

Just imagine what would happen if Qualcomm had a Chinese owner.

I see the Anglosphere has moved on from being terrorized by the Middle East to China.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#278
post #96
post #87

Earlier quoted context omitted.

Did you know a locksmith can unlock your car, too? You should add cars with physical keyed entry to your list too.

What a strange point. The ability to break into a car is rather different than having a constant data connection to the car.

Most new cars do have a constant data connection though, including directly to the main CAN bus, where it has been proven that people can steal your car without a key or even disable it remotely. You shouldn't buy any of those cars either...

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#279
post #54

This is all assumptions. Just because izatcloud.net is owned by Qualcomm = they must be exfiltrating personal data? c'mon! Then you go and peddle your own NitroPhone as a "Qualcomm free" alternative? You're just gaslighting your customers to buy. This is a very short-sighted article based on lax assumptions and NO WIRESHARK to back it up. Just because a firmware makes a call home doesn't mean it's sending your person…

I block the ads, how could I block this? Also, just because evil ad companies exist, why should we accept this?

Your Android would need to be connected to an external firewall at all times through which you can monitor and control traffic. pfsense / firewalla are some of the popular firewall devices. Don't forget to remove the SIM card (airplane mode isn't enough). May need a wifi / cellular jammer too, to be absolutely sure the device will always connect via home router / firewall.

You could use an on-device firewall app, too; but OEMs / ODMs can always bypass it as they pretty much control not only the software but the hardware, as well.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#280
post #52

Earlier quoted context omitted.

> This seems like much bigger news than it's being received as. This has been widely known for more than a decade (Sorry I can't provide with a source. I was expecting Google search-in-the-past feature to work, but it doesn't). As to whether the privacy policy has been declared properly or not, it depends on the OEM: See for instance https://www.bsr.at/mediafiles/Handbuch/CipherLab/User_Guide_... which shows Qualcomm…

> > This seems like much bigger news than it's being received as. > This has been widely known for more than a decade (Sorry I can't provide with a source. I was expecting Google search-in-the-past feature to work, but it doesn't). Yep. Nitrokey's post was disappointing but understandable from a marketing perspective. The thing that needs more discussion is the closed source stuff Android OEMs / ODMs run at higher AR…

> The thing that needs more discussion is the closed source stuff Android OEMs / ODMs run at higher ARM privileges rendering all of Google's grand ceremony around Android security moot (other than on Pixels).

You're mentioning security, which is interesting, because here it's not a question of security (don't get me wrong, izat did have security flaws in the past, and I wouldn't bet that modern devices are all properly corrected), but only to who you are sending your private data to.

It's also fun that you mention Google doing security around Android... because the vast majority of people do send their private data to Google!

My personal take is that if we want to control who we send our data to, we need to start from the easy steps: I personally use a modified Android to send the least amount of data to Google. Disabling gps xtra is pretty easy. I think I already have it disabled, but I'll check.

Post reply on HN