11 ms·
Wait until your learn what a country or local government/police can do remotely to the baseband firmware of your phone with a court order... 10-20 years ago th
by qbasic_forever 4y ago
Wait until your learn what a country or local government/police can do remotely to the baseband firmware of your phone with a court order...
10-20 years ago the FBI was regularly remotely programming firmware to listen in and record cell phone microphones to capture conversations of suspects. IIRC a mafia case hinged on data gathered in this way so it is not some abstract theoretical or crackpot theory (https://www.cnet.com/news/privacy/fbi-taps-cell-phone-mic-as-eavesdropping-tool/ https://www.cnet.com/news/privacy/fbi-taps-cell-phone-mic-as...).
It's only gotten worse as phones have gotten more capable. You don't own squat about the device in your pocket at all times.
- matheusmoreira 4y agoAre attacks like these still possible? I've read here on HN that hardware makers are isolating the baseband processor as much as possible to prevent attacks like these. Surely there are countermeasures?
- ActorNightly 4y agoMost modern phones have signed firmware for everything, so the FBI would have to go to the manufacturer and court order them to hand over the signing key. Or take advantage of a leaked key.
- matheusmoreira 4y agoWhat I meant was chips are increasingly being isolated at the hardware level so that they cannot access other peripherals directly. This would make them resistant to compromised firmware attacks. People are discussing that in this thread: https://news.ycombinator.com/item?id=33958252 https://news.ycombinator.com/item?id=33958252 It looks like the implementation isn't perfect yet but it's a start.
- autoexec 4y agoI really wouldn't be surprised if some three letter agency hasn't shown up to every one of the major chip manufactures out there and forced them to install backdoors for them.
- azeemh 4y agointel's ime is a perfect example
- kasabali 4y agoSo drug lords throwing mobile phones out of the car window after each call is just a movie trope?
- nine_k 4y agoEach phone takes time to be detected, identified, and tampered with. So it may make sense to activate a new burner phone, talk about something sensitive, and destroy it right afterwards, before the law enforcement understands what phone was that.
- 1337biz 4y agoCall me paranoid but I would assume that intelligence services keep a special eye on newly activated non-smartphones.
- izacus 4y agoAbility to detect and correlate these switches has been documented in Snowden leaks years ago.
- jethro_tell 4y agoSure, but can they get a warrant and tap it in <24 hours? IDK, but that sure raises the barrier to entry.
- sgjohnson 4y agoWhen have intelligence services used warrants? They gather evidence illegally and pass it to law enforcement who then do parallel construction.
- ethbr0 4y agoWhenever they don't want Congress up their ass. Four things can simultaneously be true, despite seeming contradictory: 1) Prudent opsec against nation-state adversaries dictates that you assume 0 time for them to have a tap on a device. 2) In reality, it takes >0 time, because people processes aren't instantaneous. 3) Intelligence services sometimes break the letter of the law. 4) Intelligence services usually follow the law, because it's less hassle.
- kornhole 4y agoI rotate burner SIM's. I never make calls with the SIM. Instead I use jmp.chat if I need to use OTA calls or SMS. I am in airplane mode 99% of the time and use WIFI instead of cellular. I never activate cellular near my home. I am always connected to VPN so that the traffic cannot be analyzed. My phone is anonymous without any identifiers. I think all this mitigates the baseband attacks, but tell me if I am missing something.
- bobsmooth 4y agoWrap your phone in aluminum foil when you're not using it.
- jvanderbot 4y agoYour location data. Tower associations can still happen with data "off", since there's plenty of "listen" components. All your home wifi connections are well Geo-located, thanks to other Android users picking up the ESSID as they walk / ride / drive past your house. Your shopping / outings? Forget it, fully known. VPNs hide the content of connections, at least from MITM / eavesdroppers, but server-side data scrapes are quite effective at figuring out who you are (or what your phone is ... see below). Nothing really does a good job of hiding the fact that you are connected to a VPN except TOR, and where that connection originates (e.g., your wifi network, which is well Geo-located, remember?). And de-anonymization of VPN connections to identify downstream connections are possible, IIRC. Details about your phone are well recorded (MAC, SID, etc) And always remember, your phone can be implicated based on location data, which will implicate you once it's discovered you own the phone. And that's as simple as looking up the SIM purchase / use.
- RektBoy 4y agoIn my country, this one girl is buying prepaid SIMs and selling them on darknet. Which is fully legal. Still she got notified from our intelligence agency, lol. They're butt-hurt a lot from this.
- kornhole 4y agoFrom https://grapheneos.org/faq https://grapheneos.org/faq: "Connecting to your carrier's network inherently depends on you identifying yourself to it and anyone able to obtain administrative access. Activating airplane mode will fully disable the cellular radio transmit and receive capabilities, which will prevent your phone from being reached from the cellular network and stop your carrier (and anyone impersonating them to you) from tracking the device via the cellular radio. The baseband implements other functionality such as Wi-Fi and GPS functionality, but each of these components is separately sandboxed on the baseband and independent of each other. Enabling airplane mode disables the cellular radio, but Wi-Fi can be re-enabled and used without activating the cellular radio again. This allows using the device as a Wi-Fi only device." When I am at home, I am WIFI only. When I am out, WIFI & bluetooth are off. This takes some discipline at first but then just becomes habit. I know the spot on my commute home where I switch my settings.
- Blue111 4y ago> It's only gotten worse as phones have gotten more capable I wish my cellphone would not have all those sensors for this reason...
- javajosh 4y agoThe camera and mic are pretty easy to destroy if you want to get rid of them!
- bonestamp2 4y agoThat's not a bad idea... then just connect an external mic (headset) when you need one.
- dividuum 4y agoTime to put on that tin foil hat and read: https://dl.acm.org/doi/abs/10.1145/3309074.3309076 https://dl.acm.org/doi/abs/10.1145/3309074.3309076 :-)
- Blue111 4y agoThere's a bunch of other sensors though... also don't forget that there is often more then one microphone... like on the Pixel 7
- abdullahkhalids 4y agoAre you saying that a phone manufactured in 2022 can have its firmware remotely changed to record microphones? Specifically can your whatsapp/signal audio calls be recorded by FBI remotely in this manner?
- smoldesu 4y agoHonestly, a phone manufactured in 2006 is probably vulnerable to a similar attack. The larger point is that state-sized threat actors (and the carriers they work with) have a crazy level of control that cannot be underestimated. Especially in 2022, it's hard to look at any sufficiently complex smartphone and assume it's not vulnerable to sufficiently motivated threat actors.
- nix23 4y ago>whatsapp/signal Hint, it's not the application you use but the microphone/speaker itself.
- qbasic_forever 4y ago> Are you saying that a phone manufactured in 2022 can have its firmware remotely changed to record microphones? Yes, court records show the FBI has and continues to explicitly do this. Leaks from folks like Snowden show the NSA/CIA have done this too. > Specifically can your whatsapp/signal audio calls be recorded by FBI remotely in this manner? The baseband firmware is at a level 'below' the operating system of the phone. It can directly access peripherals and intercept them, so it could be reading your microphone and passing it along to the higher level OS at the same time. WhatsApp/Signal thinks it's secure, and if you look at its app signature or anything else it looks exactly like the normal app you expect. However your data is still getting intercepted at the lower level and recorded for a state/government actor.
- abdullahkhalids 4y agoI am not at all familiar with the hardware design of phones, so I want to be very clear in my understanding. Are you saying that the electrical signals from the microphone and to the speakers pass through the baseband chip before/after going to the main chip on the phone? Or that the baseband chip has separate access to the microphone and speakers?
- neets 4y agoAh so that's the hack they were doing in the show Person of Interest
- zizee 4y agoI was talking to someone who was charged with a fairly minor crime, and they said the first advice their very expensive/experienced lawyer gave them is to no longer trust their phone is not recording them, as the local police (australian) use this ability quite freely.
- intelVISA 4y agoRidiculous, when has a blackbox co-processor with DMA to your entire device caused problems..?