Live data from Hacker News

Spying on a smartphone remotely by the authorities: feasibility and operation

security.stackexchange.com

31–40 of 98 posts

Re: Spying on a smartphone remotely by the authorities: feasibility and operation

#31

We already know for a fact that they can surveil virtually all smart devices including appliances and televisions due to the Vault 7 leaks, and this would tend to be corroborated by the national geospatial intelligence agency telling congress that they have a high resolution 3d map of the entire globe's events at any given time.

Here is a link to Vault 7 on WikiLeaks: https://wikileaks.org/vault7/

Here's a link to Wikipedia's article on the leaks: https://en.wikipedia.org/wiki/Vault_7

The only one that mentions televisions is Weeping Angel (cool name) which attacks Samsung F Series Smart Televisions. Likely they can indeed target other devices but I'm not sure I'd go as far as saying that Vault 7 shows that they can target "virtually all smart devices".

Or am I missing something? Can anyone provide more concrete evidence?

Re: Spying on a smartphone remotely by the authorities: feasibility and operation

#32

Earlier quoted context omitted.

Of course, but see Hanlon's razor.

Sounds like the perfect cover for malice, lol If ((Assume it's stupidity) == (discount/ignore the risk)), then assuming it's stupidity is never the safer assumption, even if it's empirically more likely to be the correct assumption, no? All boils down to an individual's threat model at the end of the day anyway, though.

I’m always amazed at how many people don’t understand this. Hanlon’s Razor is just a way to sound smart while indulging in self-soothing biases.

Re: Spying on a smartphone remotely by the authorities: feasibility and operation

#33

Earlier quoted context omitted.

This is why I'm an open source advocate. It's not that open source automatically makes software/firmware trustworthy, it's that closed source empirically guarantees the software/firmware can never be deemed trustworthy.

And yet there have been plenty of long standing security issues in Linux… Why would you think that a bunch of people volunteering their time would be more motivated to look for security issues and even those that are found, how many would be disclosed responsibly instead of being sold to places like Pegasus?

>And yet there have been plenty of long standing security issues in Linux…

• See the first half of my second sentence.

>Why would you think that a bunch of people volunteering their time would be more motivated to look for security issues

• So they're not harmed by the vulnerabilities. I'm on a big tech red team. I routinely look for (and report) vulns in open source software that I use - for my own selfish benefit.

>and even those that are found, how many would be disclosed responsibly instead of being sold to places like Pegasus?

• Not all of them, that's a fair point. But I'd rather have the ability to look for them in source than need to look for them in assembly.

• Keep in mind that the alternative you're proposing (that proprietary code can be more trustworthy than open source code) is pretty much immediately undermined by the fact that the entities who produce proprietary code are known to actively cooperate and collaborate with the adversary - look no further than PRISM for an example. Microsoft, for instance, didn't reluctantly accept - they were the first ones on board and had fully integrated years before the second service provider to join (yahoo, iirc).

• If you want to start a leaderboard for "most prolific distributor of vulnerable code", let's see how the Linux project stacks up against Adobe and Microsoft. I wouldn't even need to research that one to place a financial bet against "team proprietary".

Re: Spying on a smartphone remotely by the authorities: feasibility and operation

#34

Earlier quoted context omitted.

You don't know what code is running on your baseband processor, do you? Do you know what other hardware your baseband processor has the ability to inspect?

In most SoC's the answer is 'everything' because there's no such thing as an IOMMU.

I was under the impression that most modern (past few years) SoCs like Exynos, Qualcomm, Apple silicon all had IOMMU support. Sometimes it’s misconfigured to be too permissive but that’s getting better.

Qualcomm SMMU: https://www.qualcomm.com/content/dam/qcomm-martech/dm-assets...

Apple: https://support.apple.com/lt-lt/guide/security/seca4960c2b5/...

Samsung (vuln indicating it wasn’t configured correctly, but they still do have and use an IOMMU): https://nvd.nist.gov/vuln/detail/CVE-2022-39854

Re: Spying on a smartphone remotely by the authorities: feasibility and operation

#35

Earlier quoted context omitted.

This is why I'm an open source advocate. It's not that open source automatically makes software/firmware trustworthy, it's that closed source empirically guarantees the software/firmware can never be deemed trustworthy.

And yet there have been plenty of long standing security issues in Linux… Why would you think that a bunch of people volunteering their time would be more motivated to look for security issues and even those that are found, how many would be disclosed responsibly instead of being sold to places like Pegasus?

Nobody said that FOSS was perfect, only better.

Re: Spying on a smartphone remotely by the authorities: feasibility and operation

#36

Can the thing France just made legal be done? > French police should be able to spy on suspects by remotely activating the camera, microphone and GPS of their phones and other devices, lawmakers agreed late on Wednesday, July 5. https://www.lemonde.fr/en/france/article/2023/07/06/france-s... Why would anyone stir up the civil libertarians if the thing you are making legal is not possible?

I would assume this is possible. If the gov wants to bad enough, I'd guess most OSes have a way to remotely control and observe. A state has resources to research 0days, bank them, and use them as needed. But probably not worth using unless it's for a high value target.

Well, what would be considered a high-value target?

Even if warrants are initially mandated for a specific search, couldn’t this erode into, ‘it’s just a quick scan’?

What if it’s ‘useful’ to ‘quick scan’ their own President? ‘Confirming their security’.

Could this evolve into a subtle shift in the balance of power? In other words, a political crisis?

Where the intelligence agencies have informational advantages over any elected office.

From information into knowledge, you could easily have behind the scenes figures who have unmatchable insight and ability to coordinate.

Suddenly every target has value…

Re: Spying on a smartphone remotely by the authorities: feasibility and operation

#37
post #31

We already know for a fact that they can surveil virtually all smart devices including appliances and televisions due to the Vault 7 leaks, and this would tend to be corroborated by the national geospatial intelligence agency telling congress that they have a high resolution 3d map of the entire globe's events at any given time.

Here is a link to Vault 7 on WikiLeaks: https://wikileaks.org/vault7/ Here's a link to Wikipedia's article on the leaks: https://en.wikipedia.org/wiki/Vault_7 The only one that mentions televisions is Weeping Angel (cool name) which attacks Samsung F Series Smart Televisions. Likely they can indeed target other devices but I'm not sure I'd go as far as saying that Vault 7 shows that they can target "virtually all sma…

I probably just got confused, but thank you for linking to the information about Vault 7 directly so that anyone can simply appraise for themselves whether or not I seem confused.

That's what I love about HN and Reddit, and similar websites: All the helpful counterpoint, especially when someone criticizes the intelligence community. Thank you so much!

Re: Spying on a smartphone remotely by the authorities: feasibility and operation

#38

Any broadband chip since 3G ships with proprietary drivers which have backdoors. I tried to build an open phone, worked for one of the major telcos, and could never get around the driver issue in trying to make an open phone. BUT sophisticated attackers like US or Israeli governments (and I assume Russian or Chinese but I don’t have direct experience with these) don’t need these backdoors, getting anywhere near your…

Depends on where you put the line between "open phone" and "baseband blackbox". Drivers are not an issue for phones like Librem 5 or PinePhone since they're using a separate modem module connected to the main SoC via USB and communicating over AT and QMI interfaces to which there are perfectly open drivers. The modem itself remains a vulnerable proprietary blackbox, but it does not have any access to your OS and you can cut it out from power while keeping the rest of the phone intact.

Open basebands are not something we're anywhere close to having though, for many reasons.

Re: Spying on a smartphone remotely by the authorities: feasibility and operation

#39
post #2

Is there some kind of vote bot ring or something? This is a question with one short answer (at the time of my comment). It's hard to imagine why it made the top on its own merits.

But it’s a good question. I want to know. I am assuming this is not possible. The only thing i know of is capable of doing so is pegasus. But it’s very expensive afak.

It costs about 2-5M$ to buy or develop a new weaponized zero-click vulnerability that would allow you to simultaneously hack all 1,000,000,000 iPhones in use. So around 1/20 of a cent per iPhone.

Re: Spying on a smartphone remotely by the authorities: feasibility and operation

#40
post #36

Earlier quoted context omitted.

I would assume this is possible. If the gov wants to bad enough, I'd guess most OSes have a way to remotely control and observe. A state has resources to research 0days, bank them, and use them as needed. But probably not worth using unless it's for a high value target.

Well, what would be considered a high-value target? Even if warrants are initially mandated for a specific search, couldn’t this erode into, ‘it’s just a quick scan’? What if it’s ‘useful’ to ‘quick scan’ their own President? ‘Confirming their security’. Could this evolve into a subtle shift in the balance of power? In other words, a political crisis? Where the intelligence agencies have informational advantages over…

This is a rambling post...

I don't know what argument you're trying to make. Governments will research 0days because other governments are doing it, and it's best if you find them first and work out a defense. You know, in case you want to mess with someone's nuclear centrifuges and to avoid having yours screwed with.

Do you think that it should not be legal for the government to investigate a crime?

The system is made up of people, some of them may abuse their access. Other laws, in theory, will hold them to account.

Post reply on HN