Live data from Hacker News

Smartphones with Qualcomm chip secretly send personal data to Qualcomm

nitrokey.com

301–310 of 346 posts

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#301
post #44

That's why you install a firewall on your phone and disallow all outgoing traffic by default - possible with Android, impossible with iOS as far as I know - and keep those drivers away from the 'net. Yes, the device works, you just see loads of 'connection errors' in logcat but those just tell me things work as intended by me by not working as intended by the likes of Qualcomm. As to aGPS being necessary this depends…

This completely bypasses the OS. The kernel never even sees it. Addendum: To the people downvoting, the article is clear: > During operation, the covert operating system (AMSS) has complete control over the hardware, microphone and camera. The Linux kernel and deGoogled /e/OS end-user operating system function as a slave on top of the hidden AMSS operating system.

Complete control over the hardware, microphone and camera may allow more data to be gathered by e.g. turning on the microphone and recording everything it detects but the data still needs to get off the device somehow. The hidden AMSS operating system could theoretically be used to open a covert channel through 3/4/5G independent of the user's mobile subscription but that is not what this article is about - read it again if you missed it:

> We also didn't place a SIM-card in the phone either so it could only send and receive data over the WIFI network which we are monitoring with Wireshark. Wireshark is a professional software tool which allows us to monitor and analyze all traffic being sent over the network.

If the claims of Qualcomm using its hidden AMSS operating system for data exfiltration were true it would not matter whether the device has a SIM card installed or not. Even without a SIM card the thing is still able to reach cell towers, it still has an IMEI, it can still be used to call emergency services (112 or 911 etc), it just won't have an IMSI. Mobile operators are by law mandated to enable connectivity to emergency services to all devices so those connections are passed to their destination. Without an IMSI they do not know who to bill for connectivity so they do not pass any other traffic for such devices. Even with a SIM and thus an IMSI there is no guarantee the subscriber has paid for data so again the operator will only provide connectivity when there is some account to bill it to.

> After we provided our WiFi password in the setup wizard, the router assigned our /e/OS de-Googled phone a local IP address and it started generating traffic.

The data is exfiltrated through WiFi - which goes through the Linux kernel, using the Linux driver for the WiFi hardware. A default block for outgoing traffic puts an end to this just as surely as removing the battery does bar any covert manipulations of the device.

Realise that those who wrote this article are trying to sell you something, hence this rather poor article which tries to insinuate Qualcomm has somehow managed to get mobile operators to cooperate in a scheme to send private customer data through a covert channel. Realise also that they claim their 'Nitrokey' device does not contain a Qualcomm modem. That is quite possible... but it does contain a radio modem and the accompanying RT OS to control it - radio firmware delivered as a blob to be installed on that Nitrophone which is nothing more than a rebranded Google Pixel - using a Samsung Exynos 5300 modem - with GrapheneOS installed.

This is a sales pitch, nothing else.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#302
post #114

Earlier quoted context omitted.

This operating system, know as firmware running in the DSP. That's the only sane way to have a working device that needs to handle signals. It's not hidden in any way, and the kernel/Android actively talks with it, configures it, turns it on/off.

But the kernel does not know what it does. In fact, the article claims: > During operation, the covert operating system (AMSS) has complete control over the hardware, microphone and camera

Yes, it claims AMSS can control hardware. It also claims data is exfiltrated. Read carefully and you'll see it does not claim the data is exfiltrated through AMSS - they're using WiFi for their experiment which has nothing to do with AMSS, the mobile radio firmware.

Correlation does not equate causation but they want you to think it does so you run to their web shop to buy a rebranded Google Pixel 7 (with Samsung's Exynos 5300 radio modem and accompanying firmware which has just as much control over the hardware as Qualcomm's AMSS has...).

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#303
post #19

Here is the technical data of what is really going on - it is not sinister, rather these are files needed by the GPS chipset: https://wwws.nightwatchcybersecurity.com/tag/qualcomm/

It may have a reasonable explanation of benefits it provides, but so does Intel Management Engine and nearly every privacy-invading feature ever. I know you didn't personally design it so I'm not asking you these questions, more just thinking through this (although anybody knows the answers I'd appreciate hearing them so I can be more informed). Why does this need to be built in at such a low level that not even flas…

> Why does this need to be built in at such a low level that not even flashing a new OS can see it/stop it? Why can't it be something users can opt in to, or at a minimum opt out of? Whether sinister or not, it's a "call home" mechanism built into to the lowest levels of the hardware, an area where users are powerless, even though they "own" the device.

It's done by the ROM, at the OS level, not the chipset. Some custom ROMs will proxy this request to mask your IP.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#304
post #243
post #203

I love a lot of the work of Nitrokey, but I cannot get behind the Nitrophone. Firstly, the Nitrophone is just a Pixel 4A which contains a Qualcomm Snapdragon 765G CPU. I am confused at how the author claims it is free of Qualcomm control. They are unquestionably an active participant in mass surveillance efforts and there are much more covert ways of doing that when you control a CPU, like making your random number g…

Regarding the first point: Their current offerings are based on more current Pixel devices (6a, 7, 7 Pro), which use Google's chips, which in turn IIRC are mostly Samsung Exynos with a sprinkle of Google. That way they are only shooting their first product into the foot.

Good catch. I was reading nitophone blog posts that still reference the older hardware.

Still, there is nothing stopping Exynos from doing the same, but I grant it is better they are running from qualcomm.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#305
Reading the article thinking of GrapheneOS on my Pixel 7 with tensor G2, then they say NitroPhone not based on Qualcomm and equipped with GrapheneOS, getting confused then see what they sell is just a pre-flashed Pixel. A price of $1299 for P7 pro doesn't even contain desoldered microphone, and that's a $400 addition. That sounds salty and shady. Also, the test sounds and reads shallow.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#307

This is all assumptions. Just because izatcloud.net is owned by Qualcomm = they must be exfiltrating personal data? c'mon! Then you go and peddle your own NitroPhone as a "Qualcomm free" alternative? You're just gaslighting your customers to buy. This is a very short-sighted article based on lax assumptions and NO WIRESHARK to back it up. Just because a firmware makes a call home doesn't mean it's sending your person…

Now imagine it was anything but an American (or allying) company. Oooo, much scarier.

This is the heart of the political struggle. Most commenters mention the privacy part, which is valid, but the real meat is the war of nations over data. RESTRICT act or whatever it’s called to ban TikTok because all the congressional members’ grandkids are hooked on it and could care less about their grandparents. Data tracking is already taking place. Your personal data is out there already. When you search for butt cream and then go browse Facebook, they know what you searched for. It’s not that they are reading your browser history, instead they are reading your web logs from some 3rd party tracker server.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#308

Earlier quoted context omitted.

> the covert operating system (AMSS) has complete control over the hardware, microphone and camera. The Linux kernel and deGoogled /e/OS end-user operating system function as a slave on top of the hidden AMSS operating system So they can also exfiltrate audio and video

This is why Snowden removes the microphone from his phones.

Wait a minute: how does it function as a good ol' phone?

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#309

This seems like much bigger news than it's being received as. Sure, other chip makers do sketchy things, but is that really where we're at in 2023? We're so beaten down by proprietary user-disrespecting hardware/software that we just shrug it off? This makes me mad. I'm so sick of this type of thing. It's a horrible time too because the embedded 5G chips are about to be part of everything , sending telemetry back abo…

Getting mad won't fix it. You putting quotes around words such as "buy" and "ownership" push people away from your view, and any view like it, unless they have already adopted it that view or a similar one. if you want this to change, stop ranting, stop scare-quoting normal English words because you disagree with the way they are used, and approach the problem logically. asking rhetorical questions and being angry is…

> the entire article could be BS designed to enrage people and to see how far it spreads before it is fact-checked.

this turned out to be the case.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#310

Earlier quoted context omitted.

Is it big news? It might be, but we haven't seen the packet captures yet. I'm not trusting this shallow analysis (from a source I don't have any particular reason to trust) without seeing more details or corroboration.

As mentioned, it's now 2023 and the Snowden revelations were in... 2013, right? There have been at least a hundred similar news events since. The "healthy skepticism" bit on the subject is misdirected at this point. Backwards, really.

That said, the article is disappointing.
Post reply on HN