4 ms·
> Android is inherently always going to be insecure as long as it's running with GSM, which is fundamentally broken So because of the mostly theoretical threat
by _yy 11y ago
> Android is inherently always going to be insecure as long as it's running with GSM, which is fundamentally broken
So because of the mostly theoretical threat of baseband vulnerabilites, we shouldn't bother securing the software running on the application processor? What if I told you that x86 suffers from similar "there's an omnipotent co-processor with access to your memory" issues?
- iamsohungry 11y ago> So because of the mostly theoretical threat of baseband vulnerabilites, we shouldn't bother securing the software running on the application processor? There's nothing theoretical about the attacks on GSM: there are many attacks which have been demonstrated in the wild. [1][2] [3] And while there is a hypothetical vulnerability in the fact that closed-source processors may be backdoored, at least the AES instructions included in x86 haven't been broken yet. A comparable attack to the GSM attacks would be something like viewing a plaintext transmitted over 802.11i, which, as far as I know, hasn't happened yet. [1] http://www.gsm-security.net/faq/gsm-a5-broken-security.shtml http://www.gsm-security.net/faq/gsm-a5-broken-security.shtml [2] http://www.techrepublic.com/blog/it-security/gsm-encryption-no-need-to-crack-it-just-turn-it-off/ http://www.techrepublic.com/blog/it-security/gsm-encryption-... [3] http://yro.slashdot.org/story/13/12/14/0148251/nsa-able-to-crack-a51-cellphone-crypto http://yro.slashdot.org/story/13/12/14/0148251/nsa-able-to-c...