Live data from Hacker News

Americans’ Cellphones Targeted in Secret U.S. Spy Program

online.wsj.com

71–73 of 73 posts

Re: Americans’ Cellphones Targeted in Secret U.S. Spy Program

#71

Earlier quoted context omitted.

Can you provide some technical documentation that supports your assertion that the baseband and the application processor are sharing memory space? I thought they use different processors that are supporting essentially independent operating systems.

They're independent operating environments, but that doesn't mean their memories are isolated. It's commonly accepted that most mobile SoCs operate this way. See the diagram/text on page 2 of https://www.usenix.org/system/files/conference/woot12/woot12... . To the extent that a specific Qualcomm processor might avoid such a design, it's impossible to know due to their longstanding culture of security through obscurit…

Your information is out of date.

Modern Qualcomm basebands are restricted by an MMU and isolated from the main OS. Carriers wanted this because baseband exploits were such a common way for phones to get rooted. Additionally they have been hardened considerably in recent times, apparently modern Qualcomm basebands are much, much harder to hack than they once were. And they run now on a proprietary CPU design called, I think, Hexagon, which makes even just disassembling the thing a bit tricky.

Re: Americans’ Cellphones Targeted in Secret U.S. Spy Program

#72

At a certain point, everyone will realize this has to stop. I've started to wonder though, if the way to beat the government at this is not to try and stop them, but to encrypt things in such a way that they can no longer use technology like this. Personally, one thing I like about open source software, is I can host pretty much whatever I want, whenever I want. If this development path continues, I'd imagine that ev…

It's already fixed (I think) from UMTS upwards. In GSM (2G) the tower authenticated the handset but not vice versa. In UMTS+ the authentication is mutual. To impersonate a cell tower you would therefore need to be able to sign with the carriers signing keys. One of the most interesting and unreported aspects of these Stingray boxes is how they handle the 2G/3G divergence here. In the USA there's also CDMA to think ab…

The ars technica article I link here:

https://news.ycombinator.com/item?id=8607062

discusses police departments purchasing equipment that will work with phones that can't be forced to 2G (partly in anticipation of carriers switching 2G off).

Re: Americans’ Cellphones Targeted in Secret U.S. Spy Program

#73

Earlier quoted context omitted.

They're independent operating environments, but that doesn't mean their memories are isolated. It's commonly accepted that most mobile SoCs operate this way. See the diagram/text on page 2 of https://www.usenix.org/system/files/conference/woot12/woot12... . To the extent that a specific Qualcomm processor might avoid such a design, it's impossible to know due to their longstanding culture of security through obscurit…

Your information is out of date. Modern Qualcomm basebands are restricted by an MMU and isolated from the main OS. Carriers wanted this because baseband exploits were such a common way for phones to get rooted. Additionally they have been hardened considerably in recent times, apparently modern Qualcomm basebands are much, much harder to hack than they once were. And they run now on a proprietary CPU design called, I…

I can believe this, because they do have an interest in preventing any random party from taking over a phone. Unfortunately, there is a large gap between being resistant to exploits, and convincing the world that you're resistant to exploits through open review.

BTW do you mean "rooting" in the longstanding sense of general exploitation, or in the recent narrow sense of the owner of a device obtaining control of it? There's of course an overlap between these two, but insight into the specific business motivation would be interesting.

Post reply on HN