Live data from Hacker News

Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

blog.checkpoint.com

91–100 of 120 posts

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#91
post #88

Earlier quoted context omitted.

Because (a) it would let you root your device, allowing you to do what you want with it (b) it would make these 400 vulnerabilities especially dangerous

(c) it would prevent most banking and finance apps from working.

Not "W[h]y [you] would ... want [to do this]" lol ;)

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#92
post #58
post #51

Earlier quoted context omitted.

That is never going to happen, when Treble came out we thought it would change, but since they don't force OEMs to actually deliver updates, everything stayed the same. When questioned about this on the Android Platform 11 AMA last month, they stated that they think OEMs freedom is what makes Android a rich ecosystem. So there you have it. Can check by yourself on Reddit.

Google did it with their Chromebook. So it is possible.

Naturally it is possible, but they aren't willing to do so with Android.

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#93
post #51

Earlier quoted context omitted.

That is never going to happen, when Treble came out we thought it would change, but since they don't force OEMs to actually deliver updates, everything stayed the same. When questioned about this on the Android Platform 11 AMA last month, they stated that they think OEMs freedom is what makes Android a rich ecosystem. So there you have it. Can check by yourself on Reddit.

Treble was meant to be the key to making android roms easy to support but now the ROM scene is a fraction of what it was 5 years ago.

The architecture is a cool design, where Linux gets encapsuble in a kind of micro-kernel where classical drivers are "legacy" drivers, and Treble drivers get their own process, can be implemented in C++ or java, talking with the kernel via Android IPC.

However not forcing OEMs to provide updates, even with Project Mainline and GSI now as Treble updates, doesn't change anything from consumer point of view.

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#94

Time to switch to open source: https://en.wikipedia.org/wiki/Pinephone https://en.wikipedia.org/wiki/Librem_5

That's not a panacea. OpenSSL was completely open source, and it took, what, 2-3 years for Heartbleed to be discovered and rectified? And it's a major building block of the internet.

For open source to help, people have to actually review the code.

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#95
post #88

Earlier quoted context omitted.

Because (a) it would let you root your device, allowing you to do what you want with it (b) it would make these 400 vulnerabilities especially dangerous

(c) it would prevent most banking and finance apps from working.

Just use the website.

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#97
post #88

Earlier quoted context omitted.

Because (a) it would let you root your device, allowing you to do what you want with it (b) it would make these 400 vulnerabilities especially dangerous

(c) it would prevent most banking and finance apps from working.

You can use Xposed and Magisk to make them work

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#98
post #94

Time to switch to open source: https://en.wikipedia.org/wiki/Pinephone https://en.wikipedia.org/wiki/Librem_5

That's not a panacea. OpenSSL was completely open source, and it took, what, 2-3 years for Heartbleed to be discovered and rectified? And it's a major building block of the internet. For open source to help, people have to actually review the code.

Nothing is a panacea. FLOSS is just the right direction. At least you can fix the bugs with it without waiting for vendors, sometimes forever.

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#99

Earlier quoted context omitted.

ok, but what's the ratio of the number of Intel cpus running on something worth hacking compared to the number of amd CPUs?

My point is that there is more academic research on Intel processors than AMD. For a hacker, an Intel vulrability would of course be more lucrative than a AMD one.

"Intel" has another meaning, especially when placed next to the word "security". The number of results from your two google searches is meaningless.

Re: Over 400 vulnerabilities on Qualcomm’s Snapdragon chip

#100

Earlier quoted context omitted.

From Apple's perspective Qualcomm has been insufficient for a long time for many reasons, the security issues here would only be one of the many factors involved in the decision to do their own development. For what it is worth, a modern chip as complex as the A* series is essentially guaranteed to have vulnerabilities. Maybe not 400, but definitely not 0.

Isn't this why apple doesn't trust the CPU with secure functions and has dedicated hardware for it? So a vuln in the cpu won't expose the encryption keys bypassing face id.

Hard to tell anyone's intentions, but that's probably, at least partially, a side effect.

Apple seem to use security primarily for two things, marketing, and to ensure they have control over the platform, and the developers who write applications for it.

Maybe that's three things? Anyway, the totality of what they do in security isn't user centric enough that the reason for external security hardware would be to primarily increase the user security. Obviously they have to do this (increase user security) to make it palatable to the customer, but there's a certain asymmetry in their actions that makes it seem unlikely that actual increased user security was the original goal.

Post reply on HN