Live data from Hacker News

Smartphones with Qualcomm chip secretly send personal data to Qualcomm

nitrokey.com

321–330 of 346 posts

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#321
post #265

Earlier quoted context omitted.

> I'm uncomfortable with their data collection Again, I have no idea what you mean by "their data collection". What data are they collecting and how specifically is it being used in an untrustworthy, and harmful way? Our interests are aligned to get to the bottom of how Tesla handles data, because I don't want to own a car that is spying on me and you want a world where the internet doesn't exist (only half tongue in…

> What data are they collecting As I understand it, they are collecting data about the operation of the cars. > and how specifically is it being used in an untrustworthy, and harmful way? I didn't claim that it was. I was expressing my objection at it being collected. I have the same objection to similar data collection by software, electronics, etc. Allowing data collection is an act of trust. Tesla (like most compa…

> As I understand it, they are collecting data about the operation of the cars.

You're missing the part where it's not inherently linked to your PII without your consent (for example during a troubleshooting session).

> Since you are claiming I have opinions that I do not have, I clearly have done a terrible job explaining what my opinion is.

/eyeroll. I said I was playing.

Okay. I understand what you're saying. Removing all other noise, you just don't want data collected and Tesla hasn't done anything to earn your trust.

My response is simply that I think this is a blanket assessment that comes from an uninformed position about how Tesla's product actually works vs other car manufacturers vs tech companies in general, and that you're unfairly lumping Tesla in with #abusivebigtech. There's a lot of security research and evidence that supports the conclusion that Tesla does give a shit about both the security of their platform and the privacy of their users. In the absence of evidence suggesting Tesla abuses user trust, I do not presume guilt because that's a pretty harmful MO. Since your argument is essentially "but they're big tech", I can't help drawing the conclusion that your position on this topic boils down to that of a HN curmudgeon.

---

Anyway... car manufacturers aside, I'm also really struggling to understand what your proposed solution is where service providers don't have any data about users. (Let's not even get into in-product functionality like needing to uniquely key a user's account or send them communications.) Serious question: have you ever built a product? Not having any data whatsoever is great (I've tried it, trust me I used to think very much like you do)... for about 30 seconds until one of your users has a problem. They write in and oh shit now you've got their email. Let's sweep that under the rug for a second, you read their request for support and what do you do? You have absolutely no way to help them so your response is limited to "we don't collect software telemetry in any way sorry frustrated user, you're SOL". That's generally understood to be a wholly unacceptable response from a company the user is paying for a working product, so what privacy conscious companies with good product experiences do is [ask the user if they can] collect anonymous diagnostic and usage information. This gets you a little further, but you still can't do anything to help that user who wrote in because you can't find their telemetry since it's all totally anonymous. So you realize the lesser of two evils is to collect anonymized telemetry. This data doesn't contain the user's PII, but if the user consents, they can share the necessary identifier with the company when they submit the support request, and voila you can investigate and solve the user's issue, leaving the user happy.

The point is that you can't just unilaterally obliterate all data collection and remote connections and end up in a perfect world. You have to have a conversation with users about what data is collected and whether it's okay for it to be collected. I think this idea that the "good" state for software products is zero data and anything more than that is abusive is in fact harmful. It's harmful to product user experiences and it's harmful to protocols and standards when they weirdly hyper focus on specifying things in ways where access to unique identifiers is either nonexistent or controlled (rather than just designing for user permission). It gives incredible power to central authorities when you tell everyone they can't know anything about anyone, unless they're a blessed platform. Anyway I'm rambling at this point, but I'm really just curious how your vision for software actually works in practice. I don't see it without some radical shift where everyone refers to each other by the mnemonic version of their public keys or something incredibly foreign.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#322

Earlier quoted context omitted.

Also there's not really any good justification for the amount of data sent with the AGPS request. It can be a super plain HTTPS request with nothing else, instead of sending basically all of the tracking data from the device, including from what I can tell the IMEI which google doesn't even let app developers access anymore.

There is no private data in the request. The request is HTTP and authors could have analyzed them and discovered there is nothing in them. Instead, they published a list of things that Qualcomm privacy policy could include.

Do you have an actual copy of a example request (with all headers) from an manufacturer's ROM? There's a lot of discussion but no-one has actually posted the full HTTP request, but there is a lot of stuff which indicates there might be a lot more information in the request on official ROMs (especially those using qualcomm's daemon). I know grapheneOS keeps it to the bare minimum required.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#323

Earlier quoted context omitted.

Because the part about is being the hardware is false. This behaviour is entirely part of the OS. It's still bad, especially if the OSS ROM is not making users aware of it (though neither really are the manufacturers: burying this shit in a pages-long policy which the user cannot freely decline does not qualify for GDPR consent either). It's very easy to make android look bad from a privacy point of view, you don't n…

Worth to note that on a manufacturer implementation the consent is not buried in some pages-long policy. It's an explicit, separate item, which contains "sends your location data" and "may operate even when no apps are running" in the first paragraph. Example: https://lgk20.com/wp-content/uploads/2021/09/57-60.jpg

My phone (from Sony) uses this and is making these requests, and I can neither find anything in settings which would allow me to opt out, nor do I remember such an example during set-up (and I always go out of my way to refuse such things).

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#325

Earlier quoted context omitted.

Worth to note that on a manufacturer implementation the consent is not buried in some pages-long policy. It's an explicit, separate item, which contains "sends your location data" and "may operate even when no apps are running" in the first paragraph. Example: https://lgk20.com/wp-content/uploads/2021/09/57-60.jpg

My phone (from Sony) uses this and is making these requests, and I can neither find anything in settings which would allow me to opt out, nor do I remember such an example during set-up (and I always go out of my way to refuse such things).

I don't know which Sony device you have, but the setting is probably in [Settings]-[About Phone]-[Usage info settings].

The question about data-collection is asked during initial setup (iirc depending on Android version it's either on the very first page of the startup wizard labeled "Important Information", or it's shown as a Notification after the Wizard is completed), but I admit Sony has a quite elaborate list of License Agreements and they make it quite "frictionless" to just confirm everything.

Anyway, I can't tell how Sony implemented it across all its models and years, but to stay on-topic, community-OS's are not really a benchmark for End-User License Agreements on privacy-data (which is what that company in this article was benchmarking against its commercial product)

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#326
post #218

Earlier quoted context omitted.

Good luck though. Even the PinePhone has a Qualcomm, and it is probably one of the most promising devices for privacy. (that said, I'm not sure this particular service is used, especially if you use a custom firmware which provides an open source replacement to many of the original firmware components. GPS does not work very well until the userspace itself sends an xtra A-GPS file to the modem)

The pine phone is absolute trash, if you want the ultimate in privacy peep the ObeliskOne. www.obeliskone.com

Wow, that's a lot of buzzwords and very flashy designs but very few details for a 3k$+ Android phone from 2 years ago running... on a Qualcomm chip. With no source code (the absolute bare minimum for privacy) in sight.

No thanks. What's better about it than a regular Android phone with one of those privacy-oriented OS, privacy-wise?

Also, two comments on HN, both about this phone?

Do you have anything constructive to say about the PinePhone? "Absolute trash" does not really cut it.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#327
post #285
post #86

Earlier quoted context omitted.

Let me put it into perspective. 1) AFAIK Teslas cannot be driven remotely. But even if they could Tesla is not using cars for errands, like wtf c’mon. And if they wanted to do that and paid me for it, I might be interested in helping the environment. 2) Tesla is able to remotely unlock a vehicle if they verify the owner. This replaces a call to a locksmith and/or the towing company and is way more convenient. So yes,…

> And if they wanted to do that and paid me for it, I might be interested in helping the environment. Let me put it into perspective: making your Tesla (a heavy vehicle probably driving 1 person) drive more is not helping the environment. If you want to help the environment, don't drive a Tesla, find something that burns less energy (like a smaller car, or public transports, or an electric bike).

Don’t be a nitwit. Ride/time-sharing a car is better than the alternative where gas vehicles are performing the same miles on the road. If timeshared vehicles reduce the number of cars needed per person, then we are winning. Also if they displace ICE miles we are also winning. My family only uses 1 car, which is 100% less than tue average American household. Kindly check your bitching.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#328

Earlier quoted context omitted.

The firmware on the SOC does not connect directly to the 'net, it interfaces with Android to do so. Android uses the Linux kernel and the Linux IP stack. That IP stack uses Netfilter [1] for filtering and packet mangling. The firewall uses iptables to define Netfilter rulesets which control which data gets sent where, which application is allowed to send data - this includes the kernel (and modules) itself. Block all…

> The firmware on the SOC does not connect directly to the 'net, it interfaces with Android to do so. Do you have any documentation on this? Even firmware such as Intel ME or UEFI implementations connect directly to the Internet itself. So I have a hard time believing the firmware on a Qualcomm SOC does not directly connect to the Internet itself.

No, I do not have any documentation on this nor do I expect any documentation from the likes of Qualcomm where they claim not to exfiltrate data without prior agreement to be all that convincing. What I do have is experience in using firewalls on Android devices for as long as I've used those (about 12 years). I regularly use packet sniffers to see what these devices send to the 'net both to check whether my own stuff is working OK and to check for unwanted traffic. Setting the firewall to block outgoing traffic before enabling network connectivity has always been effective, this includes devices using Qualcomm modems. I use WiFi for these tests just like described in the article as testing for unwanted traffic going over the 3/4/5G connection is only possible if you have a private 4/5G network which I do not (yet) have. I tend not to use 3/4/5G data though - I only have a single device on which I have data enabled and paid for, the rest goes through life using only WiFi. If Qualcomm has made a deal with all mobile operators to push their telemetry through 3/4/5G even on accounts which have data disabled (as in 'not paid for' as well as 'function disabled in Android') they're in for a world of hurt when that news is brought to the light. I assume they have no such agreements as it would not make any sense seeing how easy it is to just use Android and iOS to push that data back to the mothership - which seems to be what they are doing. They are far from the only ones doing this, it is actually the main reason why I block outgoing traffic by default. Just give it a try sometimes, take a device and hook it up to the network through WiFi. Use a packet sniffer on the router to intercept everything coming from that device and feed the result to something like Wireshark. Do the same with that device with a firewall filtering all outgoing traffic and compare the results.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#329

Earlier quoted context omitted.

There is no private data in the request. The request is HTTP and authors could have analyzed them and discovered there is nothing in them. Instead, they published a list of things that Qualcomm privacy policy could include.

Do you have an actual copy of a example request (with all headers) from an manufacturer's ROM? There's a lot of discussion but no-one has actually posted the full HTTP request, but there is a lot of stuff which indicates there might be a lot more information in the request on official ROMs (especially those using qualcomm's daemon). I know grapheneOS keeps it to the bare minimum required.

The response post I was reading (and got posted here) didn't include any details. I can't tell if they actually looked at the response or were depending on someone else. But that is better than the original article that didn't even look.

Why would you expect any private data to be sent when requesting static file? That would slow down both the client and server.

Post reply on HN