Live data from Hacker News

Smartphones with Qualcomm chip secretly send personal data to Qualcomm

nitrokey.com

281–290 of 346 posts

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#281
post #240

Earlier quoted context omitted.

> Teslas use stronger ssh keys than you do SSH !?! This supports my point - a remote command prompt is much more functionality than what is required to unlock doors. It's not really appropriate to talk about this level of control as if it's merely a necessity for remote door unlocking. You're the one engaging in histrionics here - sour grapes about the lopsided relationship that was included with functionality you en…

I'm not sure if you're aware, but SSH is a flexible protocol of which "terminal emulation" is just one use case (you can implement bespoke command/response actions, I've written an SSH server before FWIW). I don't have the specifics on hand, but even assuming they can get a "terminal to your car", the resulting access is only capable of doing what the environment allows it to do. I highly doubt `spyontheuser -vvvvvvv…

> SSH is a flexible protocol of which "terminal emulation" is just one use case

I had hoped we weren't going to go down this path. It's not the responsibility of the free world to try to pry the exact details from closed systems to demonstrate their exact insecurities. Based on the functionality they have (remote update) plus the various bits that have been reported about their infrastructure (remember that reddit post about MSWin+bubblegum?) plus the general pattern when any proprietary system says "trust us we're sooper sequre", Tesla (any every other centralized system) really does not deserve any benefit of the doubt that they have done work to actually design a telemetry/privilege minimizing system.

> If the evidence shows Tesla is being dishonest and operating in a way that is not in accordance with their privacy policy

Meh. The penalty for violating privacy policies in the US is zilch, and even if it weren't such policies are generally non-binding and can be retroactively changed at any time. Without a privacy law ala the GDPR, the sensible thing to do is to assume that any piece of information you feed into the surveillance industrial complex will be stored indefinitely and may eventually be used against you.

> What I'm advocating for is making [trust] decisions based on facts and evidence

I feel like we could have some common ground here, but your previous arguments have carved off way too much in defense of lazily-implemented centralized control, based on seeing no evil. If it's possible to architect systems such that they don't backhaul information to their manufacturer or give their manufacturer ongoing control, then we should criticize those that do - regardless of the pragmatism of using them anyway because they are the least worst option and/or beneficial in other aspects.

I myself use many things that compromise my own privacy through suboptimal implementations, but I'm not going to sit here and defend the companies because they haven't been caught doing anything too hostile at the moment. Rather I accept that they're inherently attackers that I've chosen to trust (NSA definition) with some amount visibility into and control over my activities due to other benefits they provide - while remaining generally interested in more secure alternatives.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#282
post #246

Earlier quoted context omitted.

What’s the privacy issue with accelerometer?

One I could think of is you could use accelerometer data to know if the phone is moving, and how: is it just being lifted and interacted with, is the user walking or running, are they in a car. For a high profile target you might also be able to track their approximate location if you know their starting point and their acceleration profile - speed up, slow down, turns, time taken. Enough, at least, to execute an amb…

With enough data and a high SNR, you don't even need the starting point or the velocity profile. Just the turns and distances are enough in combination with a map to uniquely identify most journeys. The problem with applying that more globally is sensor drift.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#283

Earlier quoted context omitted.

Yes but at some point combustion engine cars will probably be banned.

Perhaps, but by the time this happens, I'll probably have died of old age. And if it happens sooner, then I expect that there will be electric cars that, either as designed or through aftermarket modifications, won't phone home. And if that doesn't happen, then I guess I won't be using a car. Which is probably the best idea in terms of environmental impact, anyway.

Just snip the LTE antenna in a Tesla and you have an offline car. I can't claim to know if Tesla has built in any actively hostile features like the car going into a maintenance required mode if it's been too long since a ping home, but I do know that the car is fully operational without connectivity (not including features that required connectivity, like navigation data, of course). There are even physical RFID keys.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#284

Earlier quoted context omitted.

I think you guys are ALL missing the point. Imagine if you bought a brand new car but later found out it had a stolen engine? This is probably why Qualcomm is collecting data from its chipsets. Qualcomm gets a 5% royalty (5% of the cost of the entire handset) payment from each vendor. Qualcomm needs to know if a vendor is lying about the number of chipsets it has used. They need to know if the vendor claims 10M cheap…

How do you cheat with a physical object like that? Isn’t Qualcomm selling them the chips? It’s not a windows install, it’s a physical item they buy. Don’t they just pay by the unit?

They might pay more for a unit that goes in an expensive phone than in a cheap phone, even if it's the same unit

There are all kinds of licensing agreements that go along with physical products. For example a book or videotape that is licensed to be used in a library costs more than a book or videotape for personal consumption

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#285
post #86

Earlier quoted context omitted.

> Imagine if you bought a car from somebody, and they secretly kept a spare key and periodically used your car to run their personal errand. This is happening already. Teslas can be controlled remotely, and it does not have to be the owner of said Tesla. Yes, somehow people are okay with that. The world we live in gets scarier and scarier every year.

Let me put it into perspective. 1) AFAIK Teslas cannot be driven remotely. But even if they could Tesla is not using cars for errands, like wtf c’mon. And if they wanted to do that and paid me for it, I might be interested in helping the environment. 2) Tesla is able to remotely unlock a vehicle if they verify the owner. This replaces a call to a locksmith and/or the towing company and is way more convenient. So yes,…

> And if they wanted to do that and paid me for it, I might be interested in helping the environment.

Let me put it into perspective: making your Tesla (a heavy vehicle probably driving 1 person) drive more is not helping the environment.

If you want to help the environment, don't drive a Tesla, find something that burns less energy (like a smaller car, or public transports, or an electric bike).

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#286
post #280

Earlier quoted context omitted.

> > This seems like much bigger news than it's being received as. > This has been widely known for more than a decade (Sorry I can't provide with a source. I was expecting Google search-in-the-past feature to work, but it doesn't). Yep. Nitrokey's post was disappointing but understandable from a marketing perspective. The thing that needs more discussion is the closed source stuff Android OEMs / ODMs run at higher AR…

> The thing that needs more discussion is the closed source stuff Android OEMs / ODMs run at higher ARM privileges rendering all of Google's grand ceremony around Android security moot (other than on Pixels). You're mentioning security, which is interesting, because here it's not a question of security (don't get me wrong, izat did have security flaws in the past, and I wouldn't bet that modern devices are all proper…

> You're mentioning security, which is interesting, because here it's not a question of security

I mention security because, by running blobs (sometimes entire OSes) in TrustZone EL3 / Hypervisor EL2 rings, OEMs / ODMs can pretty much do anything they want, including connecting to WiFi / LTE networks to phone home, analyse contents of the RAM, scan UFS / eMMC, track inputs / keys, and what-not; all without Android (Kernel EL1 + Userspace EL0) ever knowing anything about it.

> It's also fun that you mention Google doing security around Android... because the vast majority of people do send their private data to Google!

Agree. One good thing about Google tightening up Android APIs (and CCD certifications) in the name of security (and compatibility) is it only leaves Google with the keys to snoop on users. Careful "De-googling" of the ROM can take one a long way, indeed.

> My personal take is that if we want to control who we send our data to, we need to start from the easy steps: ...

And install the Rethink Firewall (network monitor) while you're at it, phh (:

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#287
This is old news. Smartphones have been using A-GPS for many years. The izatcloud.net domain was registered in 2012. The gpsonextra.net domain was registered in 2006.

Here's a decent summary from 2013:

https://forum.xda-developers.com/posts/41576274/

One could just as easily download these A-GPS files ("GPS almanacs") oneself instead of letting Google Play Services or GrapheneOS or whatever do it. There's no need to send any data to any server. Just send a minimal HTTP request.

   GET /xtra3grc.bin HTTP/1.1
   Host: xtrapath2.izatcloud.net
   Connection: close
It's really easy to block A-GPS when using Location. NetGuard can certainly do it. Not using A-GPS might mean GPS is slower to start up in some instances. But it's not very long IME.

In those instances, I use an app from F-Droid called GPSTest to let me know when GPS is ready.

It would be nice if we compiled our smartphone OS ourselves, then we could edit configuration files, like the one that enables A-GPS, and/or remove code we do not like. XDA seems to be the closest to that ideal.

https://android.googlesource.com/platform/hardware/qcom/gps/...

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#288

That's why you install a firewall on your phone and disallow all outgoing traffic by default - possible with Android, impossible with iOS as far as I know - and keep those drivers away from the 'net. Yes, the device works, you just see loads of 'connection errors' in logcat but those just tell me things work as intended by me by not working as intended by the likes of Qualcomm. As to aGPS being necessary this depends…

> That's why you install a firewall on your phone and disallow all outgoing traffic by default If it's being done by the firmware on the Qualcomm SOC then a firewall in Android is not going to save you.

The firmware on the SOC does not connect directly to the 'net, it interfaces with Android to do so. Android uses the Linux kernel and the Linux IP stack. That IP stack uses Netfilter [1] for filtering and packet mangling. The firewall uses iptables to define Netfilter rulesets which control which data gets sent where, which application is allowed to send data - this includes the kernel (and modules) itself. Block all outgoing traffic - which I do by default - and no data goes out. Try it if you don't believe this, you'll find out it is how things work.

So yes, Android - or rather the Linux kernel on which Android is built - is going to "save me" in that I am in control over which application (including whatever Qualcomm uses) gets to send data. Apple users are out of luck since iOS does not allow this type of filtering but Android does.

[1] https://www.netfilter.org/

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#289

Earlier quoted context omitted.

> wtf c’mon 100% agree. WTF. I'm losing a bit of faith recently in HN, a significant number of people seem to have gone full tinfoil hat. Edit: downvote all you want, nutters, but this entire discussion is mostly people ranting about things we don't even know to be true, with the justification "well if they aren't for sure doing it now, they will!" What happened to being data driven?

You seem to be assuming that the only reason someone would downvote you is because they are tin foil hatters, or "nutters". I did not downvote you, but I could understand someone doing so for either or all of these reasons: 1. Your comment was kind of a "me too" comment that added nothing (or little) of substance to the conversation. On HN these types of comments are typically downvoted, regardless of topic or whethe…

I mean no disrespect, but with nearly 20K "karma" points on HN, I know the rules, and when I'm flouting them a bit. I rarely do, and not the more serious ones. But this whole discussion is such a shit show, filled with so much "of course they're all bad" nonsense that I sacrificed some of that pointless karma to agree with someone in that regard.

I recognize your username from this thread, you were one of the accounts that came to mind as a big bandwagon offender of the "it's all bad and there can be no nuance" rhetoric :).

Have a good day! And I mean that quite sincerely. It's a beautiful spring day here and I'm just visiting my desk momentarily after spending the last hour waking up the swimming pool and preparing it for this weekend. Time to go back outside and forget about the Internet for a while.

Other than this reply, I've ceased posting in this discussion and hidden it to avoid the temptation.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#290
post #240

Earlier quoted context omitted.

I'm not sure if you're aware, but SSH is a flexible protocol of which "terminal emulation" is just one use case (you can implement bespoke command/response actions, I've written an SSH server before FWIW). I don't have the specifics on hand, but even assuming they can get a "terminal to your car", the resulting access is only capable of doing what the environment allows it to do. I highly doubt `spyontheuser -vvvvvvv…

> SSH is a flexible protocol of which "terminal emulation" is just one use case I had hoped we weren't going to go down this path. It's not the responsibility of the free world to try to pry the exact details from closed systems to demonstrate their exact insecurities. Based on the functionality they have (remote update) plus the various bits that have been reported about their infrastructure (remember that reddit po…

> It's not the responsibility of the free world to try to pry the exact details from closed systems to demonstrate their exact insecurities.

Actually you're wrong. It is the responsibility of the person making an accusation to back up their accusation with credible evidence and facts. That's how things work in the free world, at least. Presumption of guilt is just too dangerous and detrimental to a free society and so presumption of innocence is ingrained in our entire legal and judicial framework.

I'm not defending Tesla in the face of evidence that they are naive and abusive. There's simply not evidence in the first place that they're naive and abusive (and if there is, you've certainly failed to procure it). There is, in fact, the opposite, as reported by security researchers and as stated in their privacy policy.

> Tesla (any every other centralized system) really does not deserve any benefit of the doubt that they have done work to actually design a telemetry/privilege minimizing system.

It's not the benefit of the doubt. I was literally in the room at Defcon when Kevin Mahaffey and Marc Rodgers gave the talk that kicked off the Tesla bug bounty and security research program in 2015. And they had good things to say. Certainly their impression was not "this shit's dubious IDK if we can trust Tesla's security engineering" which you seem to be implying is your default impression because Tesla is #bigtech.

    https://www.cnet.com/roadshow/news/tesla-hackers-explain-how-they-did-it-at-def-con-23/
And the story only grows from there. I maintain that, to my current working knowledge, Tesla takes security and privacy seriously and invests commendable resources into making sure its platform is secure. They invest in and support security researchers. And their data collection and privacy behavior is above board in all places where they sell cars.

Here are some privacy policy excerpts:

> Your Tesla generates vehicle, diagnostic, infotainment system, and Autopilot data. To protect your privacy from the moment you take delivery, Tesla does not associate the vehicle data generated by your driving with your identity or account by default. As a result, no one but you would have knowledge of your activities, location or a history of where you’ve been. Your in-vehicle experiences are also protected. From features such as voice commands, to surfing the web on your touchscreen, your information is kept private and secure, ensuring the infotainment data collected is not linked to your identity or account.

> Tesla enables you to control what you share. Within your vehicle’s touchscreen you may enable or disable the collection of certain vehicle data (Software > Data Sharing), including Autopilot Analytics & Improvements and Road Segment Data Analytics. If you choose to enabled data sharing, your vehicle may collect the data and make it available to Tesla for analysis. This analysis helps Tesla improve its products, features, and diagnose problems quicker. The collected information is not linked to your account or VIN and does not identify you personally.

Do you have evidence that Tesla is not honoring its privacy policy? If you want to change my mind, show me the data on how Tesla's systems are insecure/naive/user-hostile and I'm happy to continue the conversation.

PS

Consider this: you can buy a Tesla in the EU, no? You think Tesla has code like `if user.country == "USA" && user.state != "CA" { user.abuse() }`? I think it's actually more likely that, since Tesla is a global company, that they have a better security and privacy story than most strictly-USA focused companies. I actually trust small US startups far less than mature multinational corporations with my data. I've been at both and large companies have swaths of lawyers making sure people are in compliance with the law where small startups have trendy founders that prefer to ask forgiveness rather than ask permission.

Post reply on HN