Live data from Hacker News

Smartphones with Qualcomm chip secretly send personal data to Qualcomm

nitrokey.com

331–340 of 346 posts

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#331
post #321

Earlier quoted context omitted.

> What data are they collecting As I understand it, they are collecting data about the operation of the cars. > and how specifically is it being used in an untrustworthy, and harmful way? I didn't claim that it was. I was expressing my objection at it being collected. I have the same objection to similar data collection by software, electronics, etc. Allowing data collection is an act of trust. Tesla (like most compa…

> As I understand it, they are collecting data about the operation of the cars. You're missing the part where it's not inherently linked to your PII without your consent (for example during a troubleshooting session). > Since you are claiming I have opinions that I do not have, I clearly have done a terrible job explaining what my opinion is. /eyeroll. I said I was playing. Okay. I understand what you're saying. Remo…

> You're missing the part where it's not inherently linked to your PII without your consent (for example during a troubleshooting session).

No, I'm not missing that. It's just not a significant point to me, in large part because I think that the definition of "PII" is too narrow. For instance, I consider the identity of the specific car I drive as being PII.

> you just don't want data collected and Tesla hasn't done anything to earn your trust.

Yes, exactly. And that's not a special stance about Tesla. It's my stance with most companies.

> I think this is a blanket assessment that comes from an uninformed position about how Tesla's product actually works

I'm sure that's true. But, honestly, I have no motivation to spend the time and energy to inform myself about how Tesla handles this stuff. To do so in any meaningful way is a moderate research project that I'd have to have some real reason to engage in. I don't think it's unreasonable to follow a larger heuristic until there's some reason to pay attention to a particular product or company.

> I can't help drawing the conclusion that your position on this topic boils down to that of a HN curmudgeon.

Draw whatever conclusion you wish. I haven't arrived at my attitude arbitrarily or through some sort of "big tech bad" mentality. It's due to years of actual experience.

> Serious question: have you ever built a product?

Not that it matters, but yes, many. Several rather successful ones. The odds are reasonable that you're even using one or two of them.

> You have absolutely no way to help them so your response is limited to "we don't collect software telemetry in any way sorry frustrated user, you're SOL".

This just isn't true at all. I've never had to say anything like that. Blanket telemetry is not necessary to help customers with malfunctions -- if it were, then all the software that I (and everyone else) sold and supported before telemetry was even possible would have been impossible to support.

That said, I have occasionally gathered telemetry as part of the support process. But it's on a case-by-case basis with the full cooperation of the customer, not a blanket thing the I subject all customers to.

And, to be clear, I'm not opposed to telemetry in general. I'm opposed to forcing it on people, or engaging in it without their informed consent.

> I think this idea that the "good" state for software products is zero data and anything more than that is abusive is in fact harmful.

My position is certainly not that all data collection is abusive. My position is that our industry has been widely abusive in terms of data collection.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#332
post #290

Earlier quoted context omitted.

> SSH is a flexible protocol of which "terminal emulation" is just one use case I had hoped we weren't going to go down this path. It's not the responsibility of the free world to try to pry the exact details from closed systems to demonstrate their exact insecurities. Based on the functionality they have (remote update) plus the various bits that have been reported about their infrastructure (remember that reddit po…

> It's not the responsibility of the free world to try to pry the exact details from closed systems to demonstrate their exact insecurities. Actually you're wrong. It is the responsibility of the person making an accusation to back up their accusation with credible evidence and facts. That's how things work in the free world, at least. Presumption of guilt is just too dangerous and detrimental to a free society and s…

> It is the responsibility of the person making an accusation to back up their accusation with credible evidence and facts.

This isn't tenable for security, especially in light of computational complexity. Rather it is up to the party claiming "trust me" to show that they are trustworthy. One major way of doing this is to publish source code that is easier to audit than having to reverse engineer. There is a long history of proprietary companies claiming to be secure while actually being an absolute mess internally. In the face of that dynamic, it is reasonable to be suspect of proprietary systems a priori.

> Do you have evidence that Tesla is not honoring its privacy policy? If you want to change my mind, show me the data on how Tesla's systems are insecure/naive/user-hostile and I'm happy to continue the conversation.

The argument isn't that Tesla is not honoring its "privacy policy" or is currently abusing its backdoors today. Rather it's that the systems they have shipped can be easily abused tomorrow. I've used the words "insecure" and "naive" about the security of Tesla's cars versus Tesla as the attacker - a threat model that bug bounties generally don't address. I do agree that currently, Tesla is (seemingly) not doing much attacking of their customers. The point is that can change tomorrow and the software has been seemingly designed so there will be little the owners of cars can do to protect themselves.

I looked through your comment history to see where you're coming from. Surely as a Linux user you can appreciate that there is a stark difference between software that is widely expected to respect your own interests as the user (and has been decently scrutinized for this quality), and mostly opaque software that has been created by a company to chiefly serve that company's interests? Especially software that has Internet access, so that its behavior can change when the company's interests change?

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#333

Earlier quoted context omitted.

This article finally pushed me over to thinking that we need to start pushing for some laws to limit this sort of thing. It's just pervasive, and "not giving [them] money" is completely ineffective. And for some companies, like Google or Facebook, it's pretty hard for a consumer to actually give them money in the first place, nor is practical [0] to not use their products. [0] practical , not possible .

The main reason why I'm eliminating these kinds of things from my life is self-protection rather than trying to get companies to change their behavior. As you say, getting them to change outside of effective legislation is impossible. > for some companies, like Google or Facebook, it's pretty hard for a consumer to actually give them money in the first place, nor is practical [0] to not use their products. Well, the…

You also must consider that your family and community need protection as well, and they rely on those who have expertise in these highly complex topics.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#334

Earlier quoted context omitted.

How do you cheat with a physical object like that? Isn’t Qualcomm selling them the chips? It’s not a windows install, it’s a physical item they buy. Don’t they just pay by the unit?

They might pay more for a unit that goes in an expensive phone than in a cheap phone, even if it's the same unit There are all kinds of licensing agreements that go along with physical products. For example a book or videotape that is licensed to be used in a library costs more than a book or videotape for personal consumption

It exists, but are chips actually sold that way? And are major phone OEMs likely to violate such contracts to save some money?

And is it sending any data that would be then determine it if so?

It just seems pretty far fetched to me that this is at all the point. Not impossible, but very improbable.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#335
post #327
post #285

Earlier quoted context omitted.

> And if they wanted to do that and paid me for it, I might be interested in helping the environment. Let me put it into perspective: making your Tesla (a heavy vehicle probably driving 1 person) drive more is not helping the environment. If you want to help the environment, don't drive a Tesla, find something that burns less energy (like a smaller car, or public transports, or an electric bike).

Don’t be a nitwit. Ride/time-sharing a car is better than the alternative where gas vehicles are performing the same miles on the road. If timeshared vehicles reduce the number of cars needed per person, then we are winning. Also if they displace ICE miles we are also winning. My family only uses 1 car, which is 100% less than tue average American household. Kindly check your bitching.

> If timeshared vehicles reduce the number of cars needed per person, then we are winning.

Well you are winning on the fix cost of building the vehicle (obviously). But you are still moving people in a vehicle that weighs 2 tons. The fact that it is an EV does not mean that you use less energy to move that weight, does it?

So yeah, if someone decides not to buy a Tesla or equivalent because they can use your shared one, you are winning. Now if someone uses your Tesla instead of any lighter vehicle that would use less energy during its life than the Tesla (which represents a lot of vehicles, not only bikes and public transports), then you are losing.

So let me repeat this: if you buy a Tesla because you think it's a "green" move, then save your money. You should buy a Tesla because you want a cool, expensive, heavy sport vehicle. That's bad for the environment, but I guess that's the cost of being cool.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#336

Earlier quoted context omitted.

Do you have an actual copy of a example request (with all headers) from an manufacturer's ROM? There's a lot of discussion but no-one has actually posted the full HTTP request, but there is a lot of stuff which indicates there might be a lot more information in the request on official ROMs (especially those using qualcomm's daemon). I know grapheneOS keeps it to the bare minimum required.

The response post I was reading (and got posted here) didn't include any details. I can't tell if they actually looked at the response or were depending on someone else. But that is better than the original article that didn't even look. Why would you expect any private data to be sent when requesting static file? That would slow down both the client and server.

I don't know why they would do it, apart from the obvious that it allows some tracking. Here's some more detail I managed to find on it (from /e/OS development): https://gitlab.e.foundation/e/backlog/-/issues/5765 . At least it seems the IMEI is not included (at least in this specific example), but a serial number and a bunch of other information about the phone is.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#337

Earlier quoted context omitted.

They might pay more for a unit that goes in an expensive phone than in a cheap phone, even if it's the same unit There are all kinds of licensing agreements that go along with physical products. For example a book or videotape that is licensed to be used in a library costs more than a book or videotape for personal consumption

It exists, but are chips actually sold that way? And are major phone OEMs likely to violate such contracts to save some money? And is it sending any data that would be then determine it if so? It just seems pretty far fetched to me that this is at all the point. Not impossible, but very improbable.

Yes yes and maybe

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#338
post #321

Earlier quoted context omitted.

> As I understand it, they are collecting data about the operation of the cars. You're missing the part where it's not inherently linked to your PII without your consent (for example during a troubleshooting session). > Since you are claiming I have opinions that I do not have, I clearly have done a terrible job explaining what my opinion is. /eyeroll. I said I was playing. Okay. I understand what you're saying. Remo…

> You're missing the part where it's not inherently linked to your PII without your consent (for example during a troubleshooting session). No, I'm not missing that. It's just not a significant point to me, in large part because I think that the definition of "PII" is too narrow. For instance, I consider the identity of the specific car I drive as being PII. > you just don't want data collected and Tesla hasn't done…

> For instance, I consider the identity of the specific car I drive as being PII.

So VIN (vehicle identifier) is not included in the data collection, and, though Tesla collects the anonymized data by default in the US (this is not true in countries with stricter laws requiring any data collection to be opt in instead of opt out), you opt in to sharing anything that de-anonymizes it as needed. You also generally opt in to the collection of larger or more sensitive data (even in the US), on a use-case bases. I can go into settings and enable/disable road segment data, for instance. The Tesla privacy policy is a 5 min read and deliberately accessibly worded.

I know you're acting in good faith, but I see this theme reappear on HN (and generally) where people cry out for change, society responds, and then the people who asked for change are too jaded to believe that it's possible that somebody listened. Or it's "too big of a research project" to care. That's the reason I'm even arguing the point here. If we were talking about Facebook I wouldn't give it the time of day because there just isn't anything redeemable about their past actions or current product. But you're talking about how you are compelled to go buy an old used gas guzzler as your next car because there isn't a car company today that is possibly trustworthy. As a person who cares about privacy and security, and as a Tesla owner, I'm simply challenging you to maybe check your gut heuristic on Tesla, because they make a really good product, have been positively received in the security community, and have a privacy policy that reads like they care about treating your data with respect. I could be wrong in the future and you get to say I told you so. But if not, they might be a solution to your problem once you're in the market.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#339
I have been aware of this since at least 2019 and the izatcloud.net domain is on my personal dns blocklist that I maintain. I also edit the gps.conf file on my unlocked devices to remove this url. On the other hand, you never know what the proprietary HW + blobs are capable of.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#340
post #74

Earlier quoted context omitted.

It's weird how much hype is around it considering about only advantage of it is "now corporations don't have to pay central entity for ISA".

Because we all dream of sub-$1 Linux processors that boot freely without blobs and have loads of wonderful usable documentation. I kind of want to modify that old adage to now read "cheap, open, documented. You can pick two."

If it is actually cheap and open, documentation generally gets done if product lives long enough
Post reply on HN