5 ms·
Surely the main processor could query the sub processors for relevant info like current state? if this isn't possible then the HW/SW world of phones makes no s
by dewster 10y ago
Surely the main processor could query the sub processors for relevant info like current state? if this isn't possible then the HW/SW world of phones makes no sense.
- digi_owl 10y agoAnd if the subprocessor is compromised, what is the chance that it would not lie? When it comes to these things there is no such thing as "too paranoid" (sadly).
- dewster 10y agoHW & SW just happens in the middle of the night by elves? Mistakes were made? For a tech board I expect a bit more ownership of the problem here. This is OUR domain and we should act like it.
- yourad_io 10y agoThe point is that there is such complexity in your average smartphone, that strictly enforcing radio silence with software from within is practically impossible. Let's forget everything aside from GSM for a moment. The GSM/LTE/whatever radio runs very closed source firmware. This communicates with the very closed source CPU and other subsystems, controlled by the very closed source OS. On top of that you run various other closed source apps, opening potentially malicious documents and browsing potentially malicious links. In theory nothing goes wrong. When you hit 'airplane mode', the OS tells the radios to STFU. In practice, anything could go wrong - maliciously or not. Your phone could have been "jailbroken" without your knowledge by a 0-day exploit, effectively negating the OS security. Once the bad guys are in your OS, they may as well update your baseband firmware to do whatever they want. Or any of the other firmware/drivers/ICs that they are able to access. Or CPU microcodes. Anything. Ideally you would have a phone with a physical switch, powering off all radios. Not politely instructing them to please cease functioning, but actually power them the f... off. This almost never happens. I have a hardware switch on my laptop - this doesn't actually cut the power to the wireless radios. If/when the firmware is compromised, it is as useless as the Wifi LED indicators. So, great, you'll say - implement that rather than build a whole new system to babysit your smartphone stack. Make a hardware switch that powers off all radio subsystems. Even if that were possible, your iPhone would not like a subsystem disappearing from existence. It isn't designed to handle that contingency and will surely fail in spectacular ways. Hence, tapping into debug ports/buses/etc and trying to monitor traffic that way. The analog way[1] may make more sense, but usability would probably be restricted. I'm fairly certain Snowden has heard of faraday cages. [1] https://www.amazon.com/FawkesBOX-Smart-phone-Faraday-Cage/dp/B00QQUQTV2 https://www.amazon.com/FawkesBOX-Smart-phone-Faraday-Cage/dp...
- dewster 10y ago> The point is that there is such complexity in your average smartphone, that strictly enforcing radio silence with software from within is practically impossible. Change is never impossible for something we ourselves design and manufacture. >The GSM/LTE/whatever radio runs very closed source firmware. This seems like a problem that could be fixed. >Your phone could have been "jailbroken" without your knowledge by a 0-day exploit, effectively negating the OS security. Probably sounds quaint, but run SW from a ROM. >Make a hardware switch that powers off all radio subsystems. Even if that were possible, your iPhone would not like a subsystem disappearing from existence. It isn't designed to handle that contingency and will surely fail in spectacular ways. You seem to be saying that the iPhone SW can't be altered to tolerate the disappearance of a subsystem, I just don't believe this is true. It's a poor excuse to do nothing. If humans are incapable of writing secure SW, then put in one or more physical switches that powers down all transmitters, and write SW that can adapt to this. Don't tell me that's impossible or even all that difficult.
- Sylos 10y ago>>The GSM/LTE/whatever radio runs very closed source firmware. >This seems like a problem that could be fixed. The problem is that it's illegal to reflash the firmware, because the Radio Frequency Giveaway Committee* is scared that people would abuse that to send on frequencies that they haven't permitted. *Probably not the official name.
- jonknee 10y agoYes, all these problems could be fixed if you make all your own hardware. Snowden doesn't manufacturer iPhones though, so he's left with a clever hardware hack.
- yourad_io 10y ago> Probably sounds quaint, but run SW from a ROM Even your CPU accepts firmware updates - in the form of microcode updates. There is no ROM any more :/ It wouldn't fix much either - find a bug/vuln in the ROM and those devices are owned "for life", since they can't be patched. > You seem to be saying that the iPhone SW can't be altered to tolerate the disappearance of a subsystem, I just don't believe this is true. It's a poor excuse to do nothing. I'm describing the situation as I see it today. It could; it won't. Apple has no incentive. Their shit is super secure already, haven't you heard? > If humans are incapable of writing secure SW We kind of are. Consumers don't really care until their inbox lands on wikileaks. @hillary waves