Live data from Hacker News

Smartphones with Qualcomm chip secretly send personal data to Qualcomm

nitrokey.com

341–346 of 346 posts

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#341
post #108

Earlier quoted context omitted.

Leaving aside the opt-in/opt-out possibility. You can remove the services that download the extra GPS data, nothing stops you from doing that, aside making GPS unusable :)

How?

You have to manually strip the QCOM additions in the vendor side. It's just a matter of removing files, but I wouldn't expect to do it without some knowledge how the whole thing works in Android, without breaking GPS as a whole.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#342
post #114

Earlier quoted context omitted.

But the kernel does not know what it does. In fact, the article claims: > During operation, the covert operating system (AMSS) has complete control over the hardware, microphone and camera

Yes, it claims AMSS can control hardware. It also claims data is exfiltrated. Read carefully and you'll see it does not claim the data is exfiltrated through AMSS - they're using WiFi for their experiment which has nothing to do with AMSS, the mobile radio firmware. Correlation does not equate causation but they want you to think it does so you run to their web shop to buy a rebranded Google Pixel 7 (with Samsung's E…

Yep, everything you said is correct.

The AMSS has control of the hardware, but there's different components, each implementing different functionality, they may be able to talk with each other using various IPC mechanism, and they do, but mostly using Android as a middleman ( Linux )

WiFi ( known as cnss on QCOM ) is implemented in a different block than GPS, they don't have direct communication in place. It's routed via the Linux kernel ( and userspace processes )

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#343
post #154

Earlier quoted context omitted.

And the cameras being integrated so the driving would break if you'd neutralize them.

And the laws are written such that replacing the software responsible for sending the camera feeds back to Tesla with a FOSS equivalent is illegal , because you're less trusted than the spying psychopathic corporation.

And such people are ridiculed in the news.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#345
post #242

As the article mentions, this is for assisted GPS. I've worked quite a bit with this system on android and implemented (or rather fixed) it for a custom android device. I've also worked with separate Qualcomm modems in the past. They are basically a whole small Linux computer in a package. You supply voltage, antennas, and connect via serial or USB, and then you can send AT commands to control it. On the one hand it…

> When a custom ROM, even a "degoogled" one, is made, you include a customized kernel and custom drivers, and the AGPS URLs are part of this "driver". Thanks, this should be the top comment. Both, Sony and Google, provide driver downloads for their smartphones[1][2]. In this case, the tested "de-Googled" OS (/e/OS) did exactly what it promised to do: removed all network connections made by Google – and not by Qualcom…

Literally hours after your post I'm reading this: Founder of GrapheneOS Daniel Micay hit with a Swatting Attempt https://nitter.takebackourtech.org/i/status/1650947535500898...

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#346
post #345
post #242

Earlier quoted context omitted.

> When a custom ROM, even a "degoogled" one, is made, you include a customized kernel and custom drivers, and the AGPS URLs are part of this "driver". Thanks, this should be the top comment. Both, Sony and Google, provide driver downloads for their smartphones[1][2]. In this case, the tested "de-Googled" OS (/e/OS) did exactly what it promised to do: removed all network connections made by Google – and not by Qualcom…

Literally hours after your post I'm reading this: Founder of GrapheneOS Daniel Micay hit with a Swatting Attempt https://nitter.takebackourtech.org/i/status/1650947535500898...

It seems that there is something very wrong with the entire Android privacy community, because fighting between different open-source projects in this space never stops.

From the technical point of view, only Daniel Micay's GrapheneOS currently takes security really seriously by providing constant system updates. It seems that you either have to use GrapheneOS, or buy an iPhone, if you care about both – security and privacy.

The people who are attacking Daniel Micay often incorporate a lot of his work into their own projects. And, naturally, that might make many of them feel inferior or even incompetent – if they are doing this for years to stay in the competition.

Post reply on HN