Live data from Hacker News

Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

blog.checkpoint.com

81–90 of 120 posts

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#81

Earlier quoted context omitted.

Aside from the massive maintenance effort: what is keeping the community from taking all the driver code from the tons of official and unofficial code dumps and bringing them to mainline?

You can't just drop leaked code in to the kernel due to legal reasons. And even if the vendor does provide an open source dump of the source you still can't just drop it in to the kernel because it will not meet the code quality standards for linux. Vendors just hack it until it works and call it a day since they don't have to worry about unmaintainable code if they never plan to maintain it.

You definitely can drop crappy drivers to the kernel devs for later improvement as somebody else's problem. It is called "staging".

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#82
post #42

Earlier quoted context omitted.

There are other alternatives, e.g. Samsung.

Yeah because Samsung has so much better history of fixing security issues...

That's why we need all of them, instead of sanctions on either one of them.

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#84

Earlier quoted context omitted.

This is a thing I think people constantly underestimate... Intel's cores are not necessarily dramatically more broken than everyone else's chips, they just pay for more auditing and public research.

> they just pay for more auditing and public research. Did Intel finance the research that turned up any of the major headline vulnerabilities over the last few years (meltdown, spectre)?

A quick survey of the papers published in 2019 and later (i.e., post Meltdown/Spectre, inclusive) listed at [1] indicate that Intel contributed financial support to the majority of them. ARM was the second-most corporate contributor, followed by AMD.

[1]: https://gruss.cc/

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#85

I wonder if Apple/others knew about such vulnerabilities, and passed up on using the chip as a risk? Or, was it just dumb luck that they avoided this?

The implication is that Apple's own chips are somehow bug-free, which they probably aren't.

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#88
post #87

Do any of these vulnerabilities let us unlock the bootloader?

Way would you want that?

Because (a) it would let you root your device, allowing you to do what you want with it (b) it would make these 400 vulnerabilities especially dangerous

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#89
post #88
post #87

Earlier quoted context omitted.

Way would you want that?

Because (a) it would let you root your device, allowing you to do what you want with it (b) it would make these 400 vulnerabilities especially dangerous

(c) it would prevent most banking and finance apps from working.
Post reply on HN