Live data from Hacker News

Vulnerabilities in chips in 37% of smartphones

blog.checkpoint.com

61–63 of 63 posts

Re: Vulnerabilities in chips in 37% of smartphones

#61

Earlier quoted context omitted.

What's really needed here is for the tech press to make this a priority when reviewing devices, which they currently don't. Right now consumers aren't aware of how important it is for the device to have drivers in the mainline kernel tree to avoid getting pwned. Not having that should be an absolute bar to a device making it onto anyone's "recommended" list. At which point device makers would prioritize not getting p…

> Right now consumers aren't aware of how important it is for the device to have drivers in the mainline kernel tree to avoid getting pwned. Customers are actively hostile to updates, because they hate UI changes. If you want customer uptake of updates to be higher, uncouple them from UI updates.

Or just stop making pointless UI changes. But that's not really the point.

Right now most Android devices come with a custom Linux kernel, and you can't just use the vanilla kernel instead because it doesn't have the drivers for the hardware. Which means that when the OEM stops supporting the custom kernel and it has vulnerabilities in it, you can't replace it with anything on that hardware, so your choices are to stay vulnerable or throw away the hardware.

If they'd spend a minimum effort to get their drivers into the mainline kernel tree, the hardware would work with any version of the kernel without needing special support from the OEM, so then it would keep working with new third party kernels indefinitely -- even if the OEM goes out of business.

But reviewers don't distinguish between the devices that have this and the ones that don't, and don't tell consumers why it's important, so consumers buy devices as if it doesn't matter, when it does.

Re: Vulnerabilities in chips in 37% of smartphones

#62
post #3

There are so many attack vectors now on phones ranging from the SIM Card (which has an OS as well) to all the baseband chips to the actual OS and the different app privileges (like the old SMS listening port). What's interesting to me about the Taiwanese tech industry is their nimbleness and how MediaTek pivoted from a primarily DVD chip maker to dumb phone chip provider running on Pluto OS to now a smartphone chipma…

MediaTek is the local industry's largest fabless chip designer. I am not quite sure the Taiwanese government would allow it to be acquired.

Nice to see you on HN. Been following your channel from the early days.

Re: Vulnerabilities in chips in 37% of smartphones

#63
post #58

Earlier quoted context omitted.

MediaTek's latest D9000 is pretty cutting edge. https://www.phonearena.com/news/world-first-tsmc-4nm-chipset... Should also be more affordable than the Qualcomm equivalent.

So this would probably be the first MediaTek chip that isn't crap, then? Whenever I looked at the options in the past, MediaTek was always the "it's cheap alright but don't expect it to be good" option.

It will still be crap because Mediatek. At least if you are interested in installing solid aftermarket firmware/ROMs and not some haphazardly mixed together 'mods' based on obsolete and vulnerable versions. It's an uphill battle, even steeper than with the other players on the market. I'd avoid it. Until they change their policy regarding openness, open source, and so on. But why would they? Has worked for them so far.
Post reply on HN