6 ms·
Probably just showing my ignorance, but there is a processor running in the phone, and it is connected to the various chips on the board, and you can run your o
by dewster 10y ago
Probably just showing my ignorance, but there is a processor running in the phone, and it is connected to the various chips on the board, and you can run your own apps that could query the chips directly? If the OS disallows this, I'd be hacking the OS, rather than the hardware.
How did we get to this point, where our personal computing devices are completely out of our basic control? We live in bizarro world.
- dcposch 10y agoThey explain in the article: your phone may be compromised, and an app running on the main processor has no reliable way to tell. That's why they're using a completely separate piece of hardware.
- dewster 10y agoOK, I agree, we should wash our technical hands and let some poor schmuck in exile clean up all of our technical security messes.
- solipsism 10y agoWhy are you reacting like this to someone who's just telling you facts? You want to do something that's not possible. If your hardware is compromised (well), you can't fix that with software.
- dewster 10y agoMy reaction is because no one here seems to have any sense of ownership for the products they design, which are a key part of the security issues and abuses we are currently experiencing. If you participate in the design of a phone that broadcasts its position in dangerous situations without the user knowing this, and subsequently gets them killed, maybe you're so far down the line and organizationally have so many people between you and them that you don't notice the small amount of blood on your hands. Just by existing we all cause trouble, but I'd like to see a bit more ethical sense among those who are directly enabling the current oppressive state.
- solipsism 10y agoThat's not my point (although the fact that you consider "HW/SW engineers" some kind of cohesive group who can make decisions together is kind of laughable). My point is that people are telling you what software cannot possibly do. And rather than look for alternative, you start railing against their lack of ownership of the problem. Share with us what you're doing to fight the problem, aside from posting on HN. If it can solve all the problems, I'm sure we'll all join up.
- dewster 10y agoIf someone came to me and told me one of my inventions/products could get someone killed, I'd move heaven and earth to fix whatever was wrong. That same message, when presented to a large enough group where the responsibility is sufficiently diffused, is simply shrugged off. This is human nature and as such can be relied upon to supply endless weaponry and surveillance tools to our betters. It's Snowden's fault that he has, in this environment where having minimal conscience is an asset, an over developed sense of ethics. Which unfortunately can't make up for the rest of our lack of it.
- solipsism 10y agoSo just complaints, no solutions? Let your actions speak for themselves.
- digi_owl 10y agoIn this day and age, no computer is just a CPU. Each radio effectively have their own CPU and accompanying firmware. The phone OS is as much in control of that radio (at best) as your laptop is in control of the ISP router.
- dewster 10y agoSurely the main processor could query the sub processors for relevant info like current state? if this isn't possible then the HW/SW world of phones makes no sense.
- digi_owl 10y agoAnd if the subprocessor is compromised, what is the chance that it would not lie? When it comes to these things there is no such thing as "too paranoid" (sadly).
- dewster 10y agoHW & SW just happens in the middle of the night by elves? Mistakes were made? For a tech board I expect a bit more ownership of the problem here. This is OUR domain and we should act like it.
- yourad_io 10y agoThe point is that there is such complexity in your average smartphone, that strictly enforcing radio silence with software from within is practically impossible. Let's forget everything aside from GSM for a moment. The GSM/LTE/whatever radio runs very closed source firmware. This communicates with the very closed source CPU and other subsystems, controlled by the very closed source OS. On top of that you run various other closed source apps, opening potentially malicious documents and browsing potentially malicious links. In theory nothing goes wrong. When you hit 'airplane mode', the OS tells the radios to STFU. In practice, anything could go wrong - maliciously or not. Your phone could have been "jailbroken" without your knowledge by a 0-day exploit, effectively negating the OS security. Once the bad guys are in your OS, they may as well update your baseband firmware to do whatever they want. Or any of the other firmware/drivers/ICs that they are able to access. Or CPU microcodes. Anything. Ideally you would have a phone with a physical switch, powering off all radios. Not politely instructing them to please cease functioning, but actually power them the f... off. This almost never happens. I have a hardware switch on my laptop - this doesn't actually cut the power to the wireless radios. If/when the firmware is compromised, it is as useless as the Wifi LED indicators. So, great, you'll say - implement that rather than build a whole new system to babysit your smartphone stack. Make a hardware switch that powers off all radio subsystems. Even if that were possible, your iPhone would not like a subsystem disappearing from existence. It isn't designed to handle that contingency and will surely fail in spectacular ways. Hence, tapping into debug ports/buses/etc and trying to monitor traffic that way. The analog way[1] may make more sense, but usability would probably be restricted. I'm fairly certain Snowden has heard of faraday cages. [1] https://www.amazon.com/FawkesBOX-Smart-phone-Faraday-Cage/dp/B00QQUQTV2 https://www.amazon.com/FawkesBOX-Smart-phone-Faraday-Cage/dp...
- jokoon 10y ago> How did we get to this point The point happened when those devices were being common enough so that there is a good enough opportunity to use it as an intelligence and information gathering tool. Not saying it's right or wrong, but until around 2010, smartphones were not mainstream enough for the government to be interested. If you're a government and you have a lot of resources, things get done pretty quickly, especially in sensitive matters like this one.
- heartsucker 10y agoYou can buy unlocked Android phones and run whatever custom Android ROM you want (Cyanogenmod, Paranoid Android, etc.). The situation isn't as dire as you make it seem.
- dewster 10y agoI'm curious as to why Snowden didn't simply recommend everyone go this route instead of bending over backwards trying to fix the iPhone?
- heartsucker 10y agoI was more responding to this: > our personal computing devices are completely out of our basic control I can't speak about the security of the latest iOS versus the latest custom ROMs. There may be a reason he didn't recommend these. Or maybe he knows some people are too attached to Apple to move away and is trying to do the best he can for them.
- dewster 10y agoI wonder why Apple isn't responding to this directly? It would seem like a natural since they've given a lot of lip service to security issues lately.
- heartsucker 10y agoMy guess: they can't respond to everything, so with some randomness legitimate security concerns don't get an official response.
- jonknee 10y agoAnd that does nothing about the baseband which is responsible for all the radio communication. The baseband of your unlocked Android phone is still closed source.
- SixSigma 10y agoGo for you life, build your own phone https://www.sparkfun.com/products/9533 https://www.sparkfun.com/products/9533