4 ms·
For one example, see the Android kernel for Qualcomm HSIC baseband interface (baseband-qct-mdm-hsic.c) https://git.sphere.ly/Lloir/android_kernel_htc_evitareul
by NateLawson 11y ago
For one example, see the Android kernel for Qualcomm HSIC baseband interface (baseband-qct-mdm-hsic.c)
https://git.sphere.ly/Lloir/android_kernel_htc_evitareul/tree/f6ff40ee377b90a56adee07598af4e9448bbc694/arch/arm/mach-tegra https://git.sphere.ly/Lloir/android_kernel_htc_evitareul/tre...
The way manufacturers "mitigate" baseband to main CPU compromise is by using a protocol that allows no initiation from the peripheral device (baseband). It can only talk to the main CPU via a serial-like protocol, not access its memory directly.
Other routes, such as side channel leakage or possible flaws in the main CPU software that interpret messages received from the baseband are still a potential source of problems, but there is no such DMA capability in the HSIC protocol.
It is valid to have general distrust and annoyance with the spy agencies for their actions to create backdoors. But there is no technical basis for this article's claims, and the author should retract them.
- viraptor 11y agoThere's a difference between "what it does" and "what it can do" however. I mean, whatever well-defined interface is used, hardware design may leave other options open and unused. Kind of like vmware provides nice interface for folder sharing, but in practice can just write directly to whatever files/memory they want.
- tptacek 11y agoIt can't DMA. It's not that it chooses not to.
- seba_dos1 11y agoIt all depends on particular design. There are even some out there where baseband OS and Linux run under the same proprietary hypervisor. On modern phones it's pretty rare to be able to say with 100% certainty that the baseband OS doesn't have any access to user memory - and often you can say with 100% certainty that it can access other interesting stuff, like GPS or microphone, without any supervision from the user.