Live data from Hacker News

Smartphones with Qualcomm chip secretly send personal data to Qualcomm

nitrokey.com

41–50 of 346 posts

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#41
This is all assumptions. Just because izatcloud.net is owned by Qualcomm = they must be exfiltrating personal data? c'mon! Then you go and peddle your own NitroPhone as a "Qualcomm free" alternative? You're just gaslighting your customers to buy. This is a very short-sighted article based on lax assumptions and NO WIRESHARK to back it up. Just because a firmware makes a call home doesn't mean it's sending your personal data. Does it have access to all the hardware? It should, it's a MF'ing driver for a CPU. Name me another CPU that doesn't have access to the hardware via it's user-space blob? The consequences outlined in the article are true for EVERY mobile device, laptop, tablet, consumer electronics w/ wifi.

Wireshark logs or you're just doomsday speculating. Show me the call to izatcloud.net with more than just http header identities every AdTech/MarTech company is already capturing from your web traffic and deanonymizing you.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#42

This kind of restates what was discussed here yesterday. Android's constant leaking of data to Google is hardly any news, but Qualcomm's firmware doing the same in plain text to izatcloud.net is newsworthy. Apparently Apple is doing the same. Someone has a nice geolocation database of practically everyone in the world.

> Apparently Apple is doing the same. I need a source for this, because my personal security model rests on the idea that Apple is NOT doing something like this.

Why would they not?

Why do you think that is a reasonable assumption?

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#44

That's why you install a firewall on your phone and disallow all outgoing traffic by default - possible with Android, impossible with iOS as far as I know - and keep those drivers away from the 'net. Yes, the device works, you just see loads of 'connection errors' in logcat but those just tell me things work as intended by me by not working as intended by the likes of Qualcomm. As to aGPS being necessary this depends…

This completely bypasses the OS.

The kernel never even sees it.

Addendum: To the people downvoting, the article is clear:

> During operation, the covert operating system (AMSS) has complete control over the hardware, microphone and camera. The Linux kernel and deGoogled /e/OS end-user operating system function as a slave on top of the hidden AMSS operating system.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#45

This seems like much bigger news than it's being received as. Sure, other chip makers do sketchy things, but is that really where we're at in 2023? We're so beaten down by proprietary user-disrespecting hardware/software that we just shrug it off? This makes me mad. I'm so sick of this type of thing. It's a horrible time too because the embedded 5G chips are about to be part of everything , sending telemetry back abo…

Sorry, but trying to be optimistic about RISC-V is only going to lead to more pain. It's just an instruction set architecture and it's still going to be made in large SoC fabs by Qualcomm-class companies that want to save a buck on ARM licensing. There's no way to win here.

You're right RISC-V just existing won't save us. I mentioned in a sibling comment, but my hope is that it leads to more competition so there are at least options. It probably is naive since these days there are tech startups and tech giants, and any startup that starts to gain traction will go for an exit strategy to be acquired, then it will killed. So things are probably not going to get much better.

Perhaps though, with RISC-V options there could be a real solid open source option (aka a Linux phone). It wouldn't have to be nearly as mature and polished as the duopoly, but at least something that allows people to participate in modern society (much like desktop linux is now).

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#47
post #23

If the data is as they say sent via http then surely they can show a sample request with what data is _actually_ sent from the device instead of the list of what Qualcomm says might be sent (which was probably drafted by CYA lawyers instead of engineering)?

This caught my attention as well. They go out of their way to mention that the requests are HTTP, not HTTPS, which allows spying by all sorts of nefarious types. And then... they don't show the requests. It leads me to believe they are exaggerating all of this.

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#48
A quite overblown article from a company pitching their own "secure phone".

They installed a custom OS which apparently includes Qualcomm's indoor positioning service iZat, but is missing the EULA item to allow the user to enable/disable the service.

iZat exists for at least 6 years, and the vendors who implemented it usually have a separate checkbox in their startup wizard to allow it to work.

Example screenshot after a quick google search: https://lgk20.com/wp-content/uploads/2021/09/57-60.jpg

Re: Smartphones with Qualcomm chip secretly send personal data to Qualcomm

#50

This seems like much bigger news than it's being received as. Sure, other chip makers do sketchy things, but is that really where we're at in 2023? We're so beaten down by proprietary user-disrespecting hardware/software that we just shrug it off? This makes me mad. I'm so sick of this type of thing. It's a horrible time too because the embedded 5G chips are about to be part of everything , sending telemetry back abo…

Sorry, but trying to be optimistic about RISC-V is only going to lead to more pain. It's just an instruction set architecture and it's still going to be made in large SoC fabs by Qualcomm-class companies that want to save a buck on ARM licensing. There's no way to win here.

Well hopefully it lowers some barriers to entry at least.
Post reply on HN