9 ms·
.. and that's what you get for allowing binary blobs (which are prime places to hide backdoors or to find 0days) into every possible level of your stack, becaus
by cryptarch 10y ago
.. and that's what you get for allowing binary blobs (which are prime places to hide backdoors or to find 0days) into every possible level of your stack, because it both makes the system less secure and makes it a lot harder to verify the security properties of a system (as you can't formally verify a CPU whose specifications you don't have and whose microcode you can't know).
Let's look at the attack surface for a bit, the average Android phone has:
1. a CPU for which no methods exist to verify the properties of its physical internals, which contains a signed microcode blob (only Intel & Co. knows what's in there)
2. a blob in TrustZone (I haven't been able to find out if the secure world in TrustZone has DMA to the insecure world, but I'm sure there's more attack surface here)
3. signed closed-source firmware blobs in multiple places in the phone, including in the baseband which handles all radio communications
4. a monolithic kernel with 7 million lines of driver code running in supervisor mode (to be fair, a lot of that can potentially be excluded at compile time)
5. closed-source userspace OS services (Play Services) required by most apps
6. apps with a native GUI have to run on the closed-source Java Runtime
7. apps are disseminated via the Play Store which has:
7a. no provisions for providing a license (e.g. "filter by license" in the search option, a dedicated spot in the app page if the license property is set, it's not rocket science)
7b. no provisions for providing the source code and validating the code you run matches the source (few people use F-Droid and that only solves the first problem)
7c. no provisions against Google serving backdoored apps
8. all apps have the possibility to communicate with other apps without user intervention (if those apps chose to allow this) via Actions, and stock apps tend allow a bunch of things through this channel
It's rotten all the way down, unverifiable by users or security experts and just not secure against any kind of targeted attack.
The Ukranians shouldn't have been using smartphones at all, and they're just unlucky to be targeted by a state level adversary first (that we know of).
This could happen to any of us if we become a nuisance to a state (or when we anger one of the employees of the companies involved in producing this shitshow).