Live data from Hacker News

Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

blog.checkpoint.com

51–60 of 120 posts

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#51

Seriously I'm beyond pissed at the state of Android, patches and open-source compliance. If we are lucky 10% of current phone models will get any form of update. The rest will be vulnerable for years until the devices finally break. And that's only the Qualcomm stuff. There is another CPU vendor beginning with M who is big in el-cheapo hardware - look at their Android kernel leaks, wherever you dig you find horrid, H…

That is never going to happen, when Treble came out we thought it would change, but since they don't force OEMs to actually deliver updates, everything stayed the same.

When questioned about this on the Android Platform 11 AMA last month, they stated that they think OEMs freedom is what makes Android a rich ecosystem.

So there you have it. Can check by yourself on Reddit.

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#52
post #39
post #30

Earlier quoted context omitted.

> horrid, HORRID code Heh, I once found a "feature" in a kernel driver in my Xperia (with a SoC from the company with a name starting in M) that allowed you to read arbitrary kernel memory from userspace, by passing the appropriate structures via a ioctl interface. Didn't even have to dig around too much. Ah well, at least I got a t-shirt from Sony.

The fuck? Is there any documentation for this? CVE?

I have a detailed report on HackerOne (with some proof-of-concept code), but visibility of the report is set to private. Not sure if it's possible to change it to public, to be honest.

Anyway, the issue is fixed in recent firmware versions.

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#53
post #21

Time to switch to open source: https://en.wikipedia.org/wiki/Pinephone https://en.wikipedia.org/wiki/Librem_5

An Open Source OS can help, sure, and is a start. A DSP is a programmable hardware device. Both phones to which you linked use variants of ARM processors and then use third-party baseband systems. You're not getting rid of closed-source hardware vulnerabilities by replacing Android or iOS.

Yes, you're not getting rid of closed-source hw vulnerabilities, but you get a lot of control. Librem 5 allows to replace the modem. Both phones ensure that it cannot access anything in the OS. You can also use killswitches if you require location privacy.

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#55
post #35

Earlier quoted context omitted.

> they just pay for more auditing and public research. Who is Intel paying to audit their chips?

Anyone who wants to report something via their bug bounty program. https://www.intel.com/content/www/us/en/security-center/bug-...

Famously, telegram has a bounty program- but was widely criticised for it, and for not doing a formal audit.

Criticisms here: https://news.ycombinator.com/item?id=6940665

I don’t doubt that they have more independent security analysis than just the bounty program; but using it as an argument that they’re paying people is not realistic.

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#57
I wonder how would it be like to fill application forms for over 400 CVE numbers, or reading a security advisory with the first page exclusively occupied by CVE numbers. Well, seriously speaking, they'll probably group these vulnerabilities and apply a big one.

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#58
post #51

Seriously I'm beyond pissed at the state of Android, patches and open-source compliance. If we are lucky 10% of current phone models will get any form of update. The rest will be vulnerable for years until the devices finally break. And that's only the Qualcomm stuff. There is another CPU vendor beginning with M who is big in el-cheapo hardware - look at their Android kernel leaks, wherever you dig you find horrid, H…

That is never going to happen, when Treble came out we thought it would change, but since they don't force OEMs to actually deliver updates, everything stayed the same. When questioned about this on the Android Platform 11 AMA last month, they stated that they think OEMs freedom is what makes Android a rich ecosystem. So there you have it. Can check by yourself on Reddit.

Google did it with their Chromebook. So it is possible.

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#60

Earlier quoted context omitted.

This is a thing I think people constantly underestimate... Intel's cores are not necessarily dramatically more broken than everyone else's chips, they just pay for more auditing and public research.

This is very much an opinion, not a fact. "Intel is only in trouble because they got caught, AMD is surely incompetent as well, but hasn't been found out".

A google scholar search for "amd security" turns up less than 100k results while a search for "intel security" has <2 million results.
Post reply on HN