Live data from Hacker News

Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

blog.checkpoint.com

41–50 of 120 posts

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#43

Earlier quoted context omitted.

From Apple's perspective Qualcomm has been insufficient for a long time for many reasons, the security issues here would only be one of the many factors involved in the decision to do their own development. For what it is worth, a modern chip as complex as the A* series is essentially guaranteed to have vulnerabilities. Maybe not 400, but definitely not 0.

This is a thing I think people constantly underestimate... Intel's cores are not necessarily dramatically more broken than everyone else's chips, they just pay for more auditing and public research.

This is very much an opinion, not a fact. "Intel is only in trouble because they got caught, AMD is surely incompetent as well, but hasn't been found out".

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#46
post #35

Earlier quoted context omitted.

> they just pay for more auditing and public research. Who is Intel paying to audit their chips?

Anyone who wants to report something via their bug bounty program. https://www.intel.com/content/www/us/en/security-center/bug-...

Auditing/public research and bug bounties are not really the same category.

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#47
post #42

If the US government hadn't sanctioned Huawei, we could have an alternative to these chips.

There are other alternatives, e.g. Samsung.

Yeah because Samsung has so much better history of fixing security issues...

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#48
post #41

Shouldn't proper IOMMU usage prevent this? In theory when properly configured the DSP or GPU should be unable to touch system RAM outside of buffers that are specifically assigned to them. I'm not very familiar with the status of IOMMU on Android devices.

It's dependent on the SoC whether there's IOMMUs at all and whether they're rigged up to all the bus masters in the system. A lot don't have them as it was seen as a virtualization feature rather than a security feature for the longest time.

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#49

Earlier quoted context omitted.

This is a thing I think people constantly underestimate... Intel's cores are not necessarily dramatically more broken than everyone else's chips, they just pay for more auditing and public research.

> they just pay for more auditing and public research. Did Intel finance the research that turned up any of the major headline vulnerabilities over the last few years (meltdown, spectre)?

They did not.

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#50

Earlier quoted context omitted.

From Apple's perspective Qualcomm has been insufficient for a long time for many reasons, the security issues here would only be one of the many factors involved in the decision to do their own development. For what it is worth, a modern chip as complex as the A* series is essentially guaranteed to have vulnerabilities. Maybe not 400, but definitely not 0.

This is a thing I think people constantly underestimate... Intel's cores are not necessarily dramatically more broken than everyone else's chips, they just pay for more auditing and public research.

The most "broken" thing about Intel's chips was discovered by Google
Post reply on HN