5 ms·
Agreed, having modems not sharing memory with the CPU would already be a big progress.
by herogreen 7y ago
Agreed, having modems not sharing memory with the CPU would already be a big progress.
- mondoshawan 7y agoSadly, the modems are on PCIe, so this means they are sharing memory and address space with the host iMX8.
- djsumdog 7y agoYea, if feels like if you wanted that kind of isolation, you'd actually need a second SoC on there with its own memory and some kind of communication back to the main processor.
- V4ASt2 7y agoSadly, you're wrong, and the phone modem is on the USB bus precisely for that reason.
- mondoshawan 7y agoSadly I am happy to be corrected! :D
- moosingin3space 7y agoYou can use an IOMMU to isolate DMA to a separate security domain. This is how Qubes OS works.
- mondoshawan 7y agoNo iommu on the imx8mq.
- moosingin3space 7y agoThat's unfortunate, since an IOMMU is an excellent solution to this kind of problem, especially when one considers all the potential Linux USB stack vulnerabilities that can be exploited if you assume the modem is untrustworthy.
- deleted 7y ago[deleted]
- megous 7y agoIt's nice, but not enough. Modem will still have access to a lot of things, like all unencrypted communication, all metadata, content of all regular calls and SMS, etc. It's nice that it can't control other devices in the SoC, but that's of little value. Modem, given it's connected over USB can also immitate any other USB device, including keyboards, pointer devices, storage devices, display devices, etc. and actually control the UI. It can even try to exploit Linux USB stack/drivers by providing specially crafted USB messages to less used/tested USB drivers. It's somewhat disappointing people repeat this thing about direct memory access as the only way modem can attack the device. It's not nearly enough to use USB. A lot of other mitigations are needed, if you don't trust the modem.
- lperkins2 7y agoI raised a concern about USB isolation about a year ago, both about the modem launching a fake USB attack and potential issues with USB peripherals via the USB C port. The underlying issue is that, unlike bluetooth, USB devices are approved and enabled automagically by the kernel. In general this is desired since you really want your USB keyboard to work on system setup, or you can't do anything with the computer (unless, like me, you have a PS/2 keyboard). Also, the USB device gets initialized by the BIOS/UEFI on a typical computer, which means it could launch an attack before the kernel is even loaded. Good news is neither you nor I are the first to spot this problem, and there is already a project which adds authentication/pairing for USB to the linux kernel. It doesn't solve the boot-time issue, but it does solve the USB stick (or USB 3g/4g card) pretending to be a keyboard+hdmi monitor issue.
- megous 7y agoIt's already in Linux https://www.kernel.org/doc/html/latest/usb/authorization.html https://www.kernel.org/doc/html/latest/usb/authorization.htm...