26 ms·
Smartphones with Qualcomm chip secretly send personal data to Qualcomm
- jruohonen 3y agoThis kind of restates what was discussed here yesterday. Android's constant leaking of data to Google is hardly any news, but Qualcomm's firmware doing the same in plain text to izatcloud.net is newsworthy. Apparently Apple is doing the same. Someone has a nice geolocation database of practically everyone in the world.
- stonekyx 3y ago> Apparently Apple is doing the same. Just curious, where did you find this?
- mschuster91 3y agoEveryone operates an AGPS service these days. Without it, you'd have to wait at least 12.5 minutes from a fully cold start (and likely, if you missed a data packet, double or triple that) until the GPS receiver has all the almanac data [1]. [1] https://en.wikipedia.org/wiki/GPS_signals#Almanac https://en.wikipedia.org/wiki/GPS_signals#Almanac
- mrfumier 3y agoIn my old Nokia N95, the AGPS data was downloaded when starting the GPS app. No need to require a constant background download.
- prmoustache 3y agothis. I may actually use gps once or twice a week only, disable geolocalisation when it is possible on all apps I am using. There is no justifiable reason to say gps is not possible without this. Besides you should be able to decide you don't mind waiting 15 minutes to get full gps service.
- rcxdude 3y agoAlso there's not really any good justification for the amount of data sent with the AGPS request. It can be a super plain HTTPS request with nothing else, instead of sending basically all of the tracking data from the device, including from what I can tell the IMEI which google doesn't even let app developers access anymore.
- ianburrell 3y agoThere is no private data in the request. The request is HTTP and authors could have analyzed them and discovered there is nothing in them. Instead, they published a list of things that Qualcomm privacy policy could include.
- rcxdude 3y agoDo you have an actual copy of a example request (with all headers) from an manufacturer's ROM? There's a lot of discussion but no-one has actually posted the full HTTP request, but there is a lot of stuff which indicates there might be a lot more information in the request on official ROMs (especially those using qualcomm's daemon). I know grapheneOS keeps it to the bare minimum required.
- ianburrell 3y agoThe response post I was reading (and got posted here) didn't include any details. I can't tell if they actually looked at the response or were depending on someone else. But that is better than the original article that didn't even look. Why would you expect any private data to be sent when requesting static file? That would slow down both the client and server.
- rcxdude 3y agoI don't know why they would do it, apart from the obvious that it allows some tracking. Here's some more detail I managed to find on it (from /e/OS development): https://gitlab.e.foundation/e/backlog/-/issues/5765 https://gitlab.e.foundation/e/backlog/-/issues/5765 . At least it seems the IMEI is not included (at least in this specific example), but a serial number and a bunch of other information about the phone is.
- trustingtrust 3y agoiPhone involves a lot of telemetry which Apple sends it to itself. We don’t know what kind of contract Apple has with Qualcomm but if it involves Apple anonymising and sending the data to Qualcomm for using its chips then it’s likely going to be the same just in a different form. I’m pretty sure Qualcomm would like some kind of telemetry from its partners it sells chips to.
- Bud 3y agoThat's actually not likely at all. There's no reason for Apple to trash its reputation by doing something stupid like this for Qualcomm's benefit.
- trustingtrust 3y agoTelemetry is something like : this is the history of modem signals etc. Something Qualcomm might have in its contract.
- smoldesu 3y agoThe iPhone has plenty of it's own telemetry like OCSP and Find My. No need to play cats vs dogs here.
- jruohonen 3y agoI might be wrong; it was merely speculated in the article due to the fact that Qualcomm chips are used also in Apple smartphones. An audit would be needed.
- circuit10 3y ago> Qualcomm chips are used also in Apple smartphones The main SoC definitely isn’t, Apple design their own SoCs, are you talking about some other chip?
- stacktrust 3y ago5G modem.
- circuit10 3y agoI thought it might be something like that, but in this case isn’t it the main SOC doing it?
- dagmx 3y agoThe article authors continuously conflate the SoC with the OS distro. it’s almost certainly part of the distro since they claim you can block it. If it was the chipset, you wouldn’t be able to.
- dlivingston 3y ago> Apparently Apple is doing the same. I need a source for this, because my personal security model rests on the idea that Apple is NOT doing something like this.
- 77pt77 3y agoWhy would they not? Why do you think that is a reasonable assumption?
- alex_suzuki 3y agoBecause for Apple, there‘s a financial incentive for keeping the „we care about your privacy“ narrative alive.
- 0cf8612b2e1e 3y agoWhat do you do if Apple is violating your privacy? Go to Google?
- hospitalJail 3y agoUh... They have 0 transparency and were caught in PRISM handing over data to the government. They have worked with multiple authoritarian regimes to give data on their customers. Number 1 in marketing according to ChatGPT.
- dagmx 3y agoThis seems like a really shallow dive into what’s going on, and seems to exist largely to plug their own hardware? For example, how is the chipset getting “List of the software on the device” unless the chipset is aware of the operating system? They don’t actually do any packet data analysis to see what it includes as far as I can tell, so other than seeing some packets go through, the rest feels like idle speculation. Also, why didn’t they try GrapheneOS which is what their own devices use? Surely if the goal is to try and deduce that the chipset is involved, rather than a driver, then that’s the logical place to start?
- mschuster91 3y ago> They don’t actually do any packet data analysis to see what it includes as far as I can tell, so other than seeing some packets go through, the rest feels like idle speculation. That's enough under GDPR, which is the point of the article. Even though the GDPR requires active informed consent, there are still so many layers openly sharting on that requirement, and no one holds the big players accountable.
- bogle 3y agoNOYB [https://noyb.eu/en https://noyb.eu/en] do their best to hold big tech's feet to the fire (and they exist on donations so we can all help out).
- solarkraft 3y ago> how is the chipset getting “List of the software on the device” unless the chipset is aware of the operating system? The chipset is aware of the operating system, or rather the other way around. Manufacturers use kernel modifications and user space libraries provided by Qualcomm for their chipsets.
- MichaelZuo 3y agoRight, it's the OS that is bolted on top, so the chipset is aware of everything that the OS is and some more besides.
- chaosbolt 3y agoContrary to mediatek chips who openly send it to China or apple chips who also openly send it to Apple, and of course let's not forget the intel management engine ;)
- aeadio 3y agoMediaTek is not Chinese. You might be thinking of HiSilicon.
- chaosbolt 3y agoOh you're right. TIL. I just assumed because it's used a lot in Chinese phones.
- Eduard 3y agoI checked http://izatcloud.net http://izatcloud.net (unencrypted!) Which resolves to 161.189.173.187, a mainland China IP address, with hostname ec2-161-189-173-187.cn-northwest-1.compute.amazonaws.com.cn https://whatismyipaddress.com/ip/161.189.173.187 https://whatismyipaddress.com/ip/161.189.173.187
- joemazerino 3y agoInteresting research. I have booted up Pixels using Qualcomm chips and have not seen the elusive izaticloud. The one issue with using GrapheneOS's connectivity check is that you're broadcasting to the network that you're someone of interest. An Android phone connecting to Google isn't great for privacy but it is normal. An Android phone connecting to a GrapheneOS domain isn't.
- Tepix 3y agoPerhaps they only send this data once?
- flotzam 3y agoThat's why it's configurable in Settings > Network & internet > Internet connectivity check: GrapheneOS / Standard (Google) / Disabled
- joemazerino 3y agoYep, adding a toggle is a must-have.
- phh 3y ago> The one issue with using GrapheneOS's connectivity check is that you're broadcasting to the network that you're someone of interest. An Android phone connecting to Google isn't great for privacy but it is normal. An Android phone connecting to a GrapheneOS domain isn't. Thanks that's an interesting thought. I had similar thoughts, but going the other way around. I was wondering whether you gave more entropy be not using Google's generate_204, than by using it (= do more IPs do generate_204 calls). But after trying to compute some estimates, I ended up thinking that not sending generate_204 was still better than sending it. But yes, as you point out, the entropy provided by pinging /another/ generate_204 is much much higher. At this point, it depends if you want to lower the information you send to Google, or your carrier. PS: Just in case, Android's connectivity check pings a "generate_204" endpoints that as mentioned literally just responds with a 204
- matheusmoreira 3y ago
- the_third_wave 3y agoThat's why you install a firewall on your phone and disallow all outgoing traffic by default - possible with Android, impossible with iOS as far as I know - and keep those drivers away from the 'net. Yes, the device works, you just see loads of 'connection errors' in logcat but those just tell me things work as intended by me by not working as intended by the likes of Qualcomm. As to aGPS being necessary this depends on how often you use GPS. Without aGPS it takes a while for the device to lock after a total cold start but once it has locked it should be able to reacquire lock within a short timeframe. As long as you do not move more than 100 km from the position you were when you last switched off GPS, the clock is within 20 seconds and you're not breaking any speed limits you'll get a fix within a few minutes assuming the receiver can see some satellites. In other words, GPS works fine without aGPS.
- jsiepkes 3y ago> That's why you install a firewall on your phone and disallow all outgoing traffic by default If it's being done by the firmware on the Qualcomm SOC then a firewall in Android is not going to save you.
- the_third_wave 3y agoThe firmware on the SOC does not connect directly to the 'net, it interfaces with Android to do so. Android uses the Linux kernel and the Linux IP stack. That IP stack uses Netfilter [1] for filtering and packet mangling. The firewall uses iptables to define Netfilter rulesets which control which data gets sent where, which application is allowed to send data - this includes the kernel (and modules) itself. Block all outgoing traffic - which I do by default - and no data goes out. Try it if you don't believe this, you'll find out it is how things work. So yes, Android - or rather the Linux kernel on which Android is built - is going to "save me" in that I am in control over which application (including whatever Qualcomm uses) gets to send data. Apple users are out of luck since iOS does not allow this type of filtering but Android does. [1] https://www.netfilter.org/ https://www.netfilter.org/
- jsiepkes 3y ago
- codetiger 3y agoIt is not mentioned in the article on how often this data is sent. It gives a different perspective it is too often.
- nwcs 3y agoHere is the technical data of what is really going on - it is not sinister, rather these are files needed by the GPS chipset: https://wwws.nightwatchcybersecurity.com/tag/qualcomm/ https://wwws.nightwatchcybersecurity.com/tag/qualcomm/
- wrs 3y agoAnd it isn’t the case that the baseband processor is somehow accessing wifi without the knowledge of the kernel. That was a bizarre accusation.
- freedomben 3y agoIt may have a reasonable explanation of benefits it provides, but so does Intel Management Engine and nearly every privacy-invading feature ever. I know you didn't personally design it so I'm not asking you these questions, more just thinking through this (although anybody knows the answers I'd appreciate hearing them so I can be more informed). Why does this need to be built in at such a low level that not even flashing a new OS can see it/stop it? Why can't it be something users can opt in to, or at a minimum opt out of? Whether sinister or not, it's a "call home" mechanism built into to the lowest levels of the hardware, an area where users are powerless, even though they "own" the device.
- luca020400 3y agoLeaving aside the opt-in/opt-out possibility. You can remove the services that download the extra GPS data, nothing stops you from doing that, aside making GPS unusable :)
- cuu508 3y agoHow?
- luca020400 3y agoYou have to manually strip the QCOM additions in the vendor side. It's just a matter of removing files, but I wouldn't expect to do it without some knowledge how the whole thing works in Android, without breaking GPS as a whole.
- freedomben 3y agoThis seems like much bigger news than it's being received as. Sure, other chip makers do sketchy things, but is that really where we're at in 2023? We're so beaten down by proprietary user-disrespecting hardware/software that we just shrug it off? <rant because I hoped for more outrage on this and am not seeing it> This makes me mad. I'm so sick of this type of thing. It's a horrible time too because the embedded 5G chips are about to be part of everything, sending telemetry back about where they are and what they're being used for. I think it's utterly ridiculous that if you aren't ok with this type of thing, then you have to go way out of the mainstream to find products, and often there's no viable option. "Ownership" now means nothing. Imagine if you bought a car from somebody, and they secretly kept a spare key and periodically used your car to run their personal errand. Would you be ok with that so long as they always had it back before you needed it so you never knew they were doing it? That's what is happening when you "buy" a device and the device maker uses it to run code that serves only themselves (without receiving permission), to the detriment of your privacy. I can only hope RISC-V combined with people willing to care can lead to a return to a time when people actually own stuff and ownership is something we respect. </rant>
- A4ET8a8uTh0 3y agoIt is upsetting, but I am not sure how it can be countered. I am genuinely asking what is the alternative here. We go back to the lack of trust. You basically have to assume everything is trying to communicate with mothership. You mention RISC-V, but was it ever really tested against the same proposition? I miss the dumb everything days, where the manufacturer simply could not spare compute power on additional features like telemetry.
- freedomben 3y ago> You mention RISC-V, but was it ever really tested against the same proposition? Good point, there's no reason a manufacturer couldn't build it in. My thought was more along the lines of lower barrier of entry that would enable more competition (Qualcomm is near monopoly and has pretty anti-competitive practices that make it super hard to compete with them), and hopefully there will be more transparent options out there. As a user of GPS I'd like the option of enabling something like this because the old days of taking forever to sync with the satellites did suck. But I want to be able to decide for myself, not have the decision forced upon me by the chip's firmware. > I miss the dumb everything days, where the manufacturer simply could not spare compute power on additional features like telemetry. Oh man, me too. The nostalgia for this burns like a fire in my soul.
- figgyc 3y agoIf the data is as they say sent via http then surely they can show a sample request with what data is _actually_ sent from the device instead of the list of what Qualcomm says might be sent (which was probably drafted by CYA lawyers instead of engineering)?
- heap_perms 3y agoRight? That would be much more interesting, and I wonder why they didn't show packet data. They already went through the work of setting up wireshark, might as well peek into the packet data to see what's going on.
- jaywalk 3y agoThis caught my attention as well. They go out of their way to mention that the requests are HTTP, not HTTPS, which allows spying by all sorts of nefarious types. And then... they don't show the requests. It leads me to believe they are exaggerating all of this.
- nerpderp82 3y agoWouldn't that be an illegal wiretap?
- 2Gkashmiri 3y agoYet huawei is being banned in suspicion while Qualcomm with active spying (oops, telemetry) is fine. Cool
- neilv 3y ago> In spite of its reputation for bolstering users' privacy, all Fairphone models contain a Qualcomm chip probably loaded with the AMSS blobware. The Fairphone has therefor the same issue with sharing of personal data with the Qualcomm XTRA Service. When calling out a specific brand like that, I was surprised by the "probably". Why not first confirm it, such as by testing, or by getting a statement from the brand or Qualcomm?
- kayson 3y agoDid I miss something in the article? They see the connections were made, it was plain http, but they didn't actually show any of the real payload/data? Instead they quoted the list of what Qualcomms policy says could be collected? Seems like low hanging fruit... Disclaimer: work at Qualcomm but have nothing to do with any of this
- yabones 3y agoYeah, I'd be interested to see what's _inside_ the request, not just that it was made. Was it a connectivity self-test or empty GET request? That's not ideal, but fairly benign. Or was it a "phone home" reporting the device's ID, SN, IMEI, etc? That's a lot worse. Or, did it truly contain PII or geolocation data? that's really bad. It matters a LOT what's inside the request, and it seems a little dishonest to not include it in the report.
- gabereiser 3y agoThis is all assumptions. Just because izatcloud.net is owned by Qualcomm = they must be exfiltrating personal data? c'mon! Then you go and peddle your own NitroPhone as a "Qualcomm free" alternative? You're just gaslighting your customers to buy. This is a very short-sighted article based on lax assumptions and NO WIRESHARK to back it up. Just because a firmware makes a call home doesn't mean it's sending your personal data. Does it have access to all the hardware? It should, it's a MF'ing driver for a CPU. Name me another CPU that doesn't have access to the hardware via it's user-space blob? The consequences outlined in the article are true for EVERY mobile device, laptop, tablet, consumer electronics w/ wifi. Wireshark logs or you're just doomsday speculating. Show me the call to izatcloud.net with more than just http header identities every AdTech/MarTech company is already capturing from your web traffic and deanonymizing you.
- oefnak 3y agoI block the ads, how could I block this? Also, just because evil ad companies exist, why should we accept this?
- gabereiser 3y agoYou can't. Every call you make to a server includes your browser's user-agent/client-hints as well as your IP. Those cookie consent screens are provided by 3rd party but integrated via 1st party. So the company's website you visit doesn't even have to know it's going on, all they have to do is setup the MarTech correctly with the vendor and create a DNS entry. This, while being used to track you, could be used for good - it's not. Some companies are trying to own some of this to prevent nefarious uses of the data but in the end it's been the wild west of data tracking for the last 10 years or so.
- gabereiser 3y agoChallenge: Open up your favorite website (not HN :D) and watch the XHR's and network calls in your browser's devtools. How many of those are for the same origin? How many of those are ad calls being blocked by your extension (which also has access to your data)? How many of them are calls for a single pixel gif? Some javascript? favicon.ico? Do some spelunking on WHOIS for each of those domains. All it takes is one of them to proxy the headers. Proxy the headers and check if ad was served by looking at logs of both ad request and page request, if no ad request was found, require them to disable adblocker...
- rickdeckard 3y agoA quite overblown article from a company pitching their own "secure phone". They installed a custom OS which apparently includes Qualcomm's indoor positioning service iZat, but is missing the EULA item to allow the user to enable/disable the service. iZat exists for at least 6 years, and the vendors who implemented it usually have a separate checkbox in their startup wizard to allow it to work. Example screenshot after a quick google search: https://lgk20.com/wp-content/uploads/2021/09/57-60.jpg https://lgk20.com/wp-content/uploads/2021/09/57-60.jpg
- beebeepka 3y agoDo you also trust the Intel Management Engine and AMD Secure Processor? Because I see no reason to. It's almost like all these companies were compelled to implement these features by a caring government. Maybe it's for the children
- colinsane 3y agoIME’s a poor analogy for what’s happening here. the article ends with > Affected users could try blocking the Qualcomm XTRA Service using a DNS-over-TLS cloud-based block service, or re-route this traffic yourself to the proxy server from GrapheneOS […] if these requests were being made below the OS, akin to IME, you wouldn’t be able to substitute the DNS like that. unless they mean that you could reroute things upstream of the phone — but most users don’t deploy their own fleet of LTE towers, so i doubt that’s what they meant.
- mk89 3y agowhy do you shoot the messenger? yeah they did a bit of advertisement to their phone, who cares. what matters is that now even freaking basic hardware pushes your data wherever they want without asking you. I really wonder if this had been a Chinese company the kind of comments we would have seen here.
- rcxdude 3y agoBecause the part about is being the hardware is false. This behaviour is entirely part of the OS. It's still bad, especially if the OSS ROM is not making users aware of it (though neither really are the manufacturers: burying this shit in a pages-long policy which the user cannot freely decline does not qualify for GDPR consent either). It's very easy to make android look bad from a privacy point of view, you don't need to make things up to do so.
- pkphilip 3y agoSomething like this should result in an automatic ban being applied on the manufacturer and phones using their chipset.. but here we are and there is absolutely no noise about this. Shameful
- beembeem 3y agoI guess they didn't perform a basic web search: https://www.qualcomm.com/news/onq/2014/09/izat-location-technology-your-future-mobile-concierge https://www.qualcomm.com/news/onq/2014/09/izat-location-tech... https://investor.qualcomm.com/news-events/press-releases/detail/1106/qualcomm-expands-market-leading-izat-location-platform-to https://investor.qualcomm.com/news-events/press-releases/det...
- LobsterJohnson 3y agoQuestion about people in the industry: Is this like "yeah it was a team of 50 programers and then 200 testers involved in making the chip that new about this". Or is it like "fucking brown-nose Dylan who got a bonus to stfu and implement it".
- fifteen1506 3y agoProbably the second, but I don't work in the industry.
- Springtime 3y agoAn odd article. They find traffic from one domain, don't disclose what the traffic is despite being unencrypted, then make speculation that it's extracting a list of things based on a privacy policy Qualcomm provided—when the authors could have just documented what they found to begin with to inform the reader based on evidence. Then they conspicuously plug their phone, which doesn't have a Qualcomm chip, and linking to its store. I'd like to see more presented before being accepting of such a story.
- Bud 3y agoIt's entertaining that this article clumsily lumps Apple in with Google regarding this stealth data collection, but without offering a single shred of evidence that Apple is doing this at all, let alone doing it secretly.
- ementally 3y agoA reddit thread about CalyxOS making connections to xtrapath1.izatcloud.net . https://old.reddit.com/r/CalyxOS/comments/pym8l1/calyxos_connects_to_xtrapath1izatcloudnet/ https://old.reddit.com/r/CalyxOS/comments/pym8l1/calyxos_con...
- RecycledEle 3y agoThere has been talk of a war on encryption. I wish to point out this alternative: Let's increase transparency instead. Require all data sent and received to be in a common well-documented format (XML.) Require the following be documented in the XML (1) The program sending it, (2) the program receiving it, (3) what it means, and (4) what it is used for. There should be a single place to go to see all data coming and going so the administrative user of the device can review all data coming and going. A lot less shenanigan's would happen online if every value sent and received had to be well documented with Because that a new Windows install sends and receives so much complicated garbage that that networking people can not understand what is going on, this would require rewriting everything. I'm willing to do it.
- matt3210 3y agoThis is irritating but as long as it’s not part my data usage it won’t effect my purchasing choice much.
- finikytou 3y agothis news was a direct ban of chinese made phones but because it is qualcomm it is fine. we can safely assume there are backdoors into every american-made electronics
- dragonelite 3y agoPretty much it just pick your poison and want to keep a secret keep it in your head unless you let them chip up that place too.
- StingyJelly 3y agoThe situation is likely far less scary. The article seems to intentionally overblow the accusations without going into any depth in order to push the advertisement for their phone. Talking about /e/os /their competitor/ in the beginning to make them seem less-competent: >Surprisingly, the deGoogled phone's first connection is to google.com. >This makes us wonder. /e/OS did replace Google’s connectivity check, but did they somehow miss out to replace the Google Play Store URL? /e/os has microG so I'd guess it's on by default and this is "google device registration" that is necessary for safetynet. Then in the main part they talk about AGPS. Instead of showing the unencrypted traffic that supposedly contains the private information, they just quote qualcomms privacy policy. They make a big deal about the phone requesting agps data even when the location is turned off (unlike theirs amazing one that only requests the agps data when you turn the location on.) My phone also requests agps data only when I turn the location on and it sucks because If I don't have internet access, without fresh agps data the phone can take a really long time to get GPS fix (Especially in bad conditions like snowy forest where I wanted o check if I was still on the right trail but couldn't get fix at all.). It's an oversight on /e/os side not to proxy the agps requests but it can be done. Many service providers do it which seems worse and if you want, you can easily tell android to use a different server, just follow this reddit post: https://old.reddit.com/r/privacy/comments/cldrym/how_to_degoogle_lineageos_in_2019/ https://old.reddit.com/r/privacy/comments/cldrym/how_to_dego... I'd love to see more competition in mobile cpu space but fearmongering about qualcomm being evil without any substance is not the right thing to do. What is far more worrying is that both qualcomm and exinos chipsets have terrible track record when it comes to vulnerabilities.
- szundi 3y agoIs this actually made by parts of the SDK software, is it?
- FredPret 3y agoI think there should be a law saying you can't sign certain digital privacy rights away, much like you can't sell yourself into slavery. But the only fool-proof solutions are mathematical/technological ones where privacy invasions aren't possible. As far as catching child molesters, the cops should simply kick down their doors the old-fashioned way.
- tgtweak 3y agoI think it would be meaningful to introspect that data since clearly it's not encrypted using https - this would be trivial with a MITM proxy on the gateway. All of this to push your own platform without any data backing it up aside from an http connection and privacy policy. Pretty alarmist. Not that anyone is advocating for unauthorized connections to the manufacturer of your hardware, but the author should at minimum capture what is being sent (if anything) and what is being received in return. From what I can see this is a preseed for GPS data that speeds up GPS acquisition time by sharing the latest constellation data so the phone doesn't have to sit there for 5-30 seconds listening for enough satellite beacons to determine the position. It should not require any input data to provide it's function - that request should be a simple GET to an endpoint that has no extra query params or headers. If you want to be concerned about something, be concerned about the very likely fact there is nation-state level backdoors sitting in that very same firmware (or hardware itself) that isn't using observable channels to operate. The plethora of "chatter" on the cellular network just to receive phone calls is orders of magnitude more than this request, and much of it is handled in the radio firmware invisibly which also has root-level access to much of the system.
- jruohonen 3y agoI agree; it was quite a bad article promoting their own "secure" phone. As for your last paragraph, it is hardly a secret that smartphones cannot be trusted in general. It is already a common practice to leave phones out when attending some meetings. I am not sure whether even diplomats and such truly trust the hardened phones their governments give them when located in certain countries. Fortunately, I do not have to worry about such things myself. A good read on these matters: https://www.direkt36.hu/en/putyin-hekkerei-is-latjak-a-magyar-kulugy-titkait-az-orban-kormany-evek-ota-nem-birja-elharitani-oket/ https://www.direkt36.hu/en/putyin-hekkerei-is-latjak-a-magya...
- vkdelta 3y agoand another large Wi-Fi Wireless chipmaker secretly sends data to their mothership + shares with ISPs. What can do you? very little, since the code is binary and it is buried in their FW. Even with Opensource SW, it is hard to get rid of the binary blob.
- julienreszka 3y agoI hate this stock
- s1k3s 3y agoI wonder why they didn't actually post the data that's being sent over. Especially because it says: > Investigating this further we can see that the packages are sent via the HTTP protocol and are not encrypted using HTTPS, SSL or TLS. So why not just post the actual data, instead of: > To clarify, here a list of the data Qualcomm !!may collect!! from your phone according to their privacy policy: Also, how does Qualcomm's privacy policy affect me as a user directly? I didn't agree to that. Or do I "accept" it because it gets passed over by manufacturers?
- dragonelite 3y agoIs this news?
- captainmuon 3y agoAs the article mentions, this is for assisted GPS. I've worked quite a bit with this system on android and implemented (or rather fixed) it for a custom android device. I've also worked with separate Qualcomm modems in the past. They are basically a whole small Linux computer in a package. You supply voltage, antennas, and connect via serial or USB, and then you can send AT commands to control it. On the one hand it wouldn't surprise me if the Qualcomm modem accesses the network on it's own - it very much wants to be a black box - on the other hand I doubt this story for two reasons: - WiFi is implemented on the Android side. In all Android implementations I've seen, the WiFi module is part of the SoC or a separate chip, and Android runs the regular wpa_supplicant and so on. The chip cannot see the contents of packages, it only passes the bytes to the MAC (not sure if it is called that with WiFi). (Now, of course in the case of a SoC the chip could, with driver support, peel back the encryption and inject it's own traffic, just like some IPMIs can share an ethernet connection with the OS. I just have not seen this yet.) - In Android, it is usually the responsibility of the OS to fetch the AGPS data / almanach. You have a HAL consisting of a proprietary library (.so) that you get from the GPS vendor, some glue code, and a gps.conf. The gps.conf file lists the URLs to get the AGPS data. I'm not sure if the download is performed in the .so or in Java code, but anyway it is totally in the OS and not in the modem, at least in the cases I know. When a custom ROM, even a "degoogled" one, is made, you include a customized kernel and custom drivers, and the AGPS URLs are part of this "driver".
- krn 3y ago> When a custom ROM, even a "degoogled" one, is made, you include a customized kernel and custom drivers, and the AGPS URLs are part of this "driver". Thanks, this should be the top comment. Both, Sony and Google, provide driver downloads for their smartphones[1][2]. In this case, the tested "de-Googled" OS (/e/OS) did exactly what it promised to do: removed all network connections made by Google – and not by Qualcomm or anybody else. Since Pixel smartphones now use Google's own Tensor chips (which are based on Samsung Exynos), they obviously don't make any connections to Qualcomm servers. This blog post is clearly an ad for NitroPhone, which is simply a Google Pixel smartphone with a different open-source OS pre-installed. GrapheneOS[3] is only targeting Google Pixel line-up at the moment, and therefore is able to make sure that even A-GPS URLs are "de-Googled" on the latest models. But the older Google Pixel models with Qualcomm chips make exactly the same connections – from the driver, not from the firmware[4]: > GrapheneOS has modified all references to these servers to use HTTPS rather than a mix of HTTP and HTTPS. No query / data is sent to the server. [1] https://developer.sony.com/develop/drivers/ https://developer.sony.com/develop/drivers/ [2] https://developers.google.com/android/drivers https://developers.google.com/android/drivers [3] https://grapheneos.org/ https://grapheneos.org/ [4] https://www.reddit.com/r/CalyxOS/comments/pym8l1/comment/heveec5/ https://www.reddit.com/r/CalyxOS/comments/pym8l1/comment/hev...
- pinquine 3y ago[dead]
- squarefoot 3y ago"The smartphone is a device we entrust with practically all of our secrets." That is the main problem to me. Manufacturers building spyware into their products is just the consequence resulting from those products being closed paired with being connected, and the manufacturers' ability to get away with it. Putting aside conspiracies, spying people still is a lucrative business, therefore I don't expect any manufacturer to resist that opportunity. It's up to people to educate themselves about the dangers when trusting a device that is closed and goes online.
- RoyGBivCap 3y agoI had closed the HN thread, but after reading this line, I reopened it: >During operation, the covert operating system (AMSS) has complete control over the hardware, microphone and camera. W-T-F Microphone and camera control?! If this is true, it's a government spy's wet dream, and a privacy nightmare.
- jimt1234 3y agoThis felt like A Christmas Story, "Be sure to drink your Ovaltine". https://www.youtube.com/watch?v=zdA__2tKoIU https://www.youtube.com/watch?v=zdA__2tKoIU
- casenmgreen 3y agoWell, Qualcomm just fell off the map. I'll never knowingly use one of their products again.
- jraph 3y agoGood luck though. Even the PinePhone has a Qualcomm, and it is probably one of the most promising devices for privacy. (that said, I'm not sure this particular service is used, especially if you use a custom firmware which provides an open source replacement to many of the original firmware components. GPS does not work very well until the userspace itself sends an xtra A-GPS file to the modem)
- killabit 3y agoThe pine phone is absolute trash, if you want the ultimate in privacy peep the ObeliskOne. www.obeliskone.com
- jraph 3y agoWow, that's a lot of buzzwords and very flashy designs but very few details for a 3k$+ Android phone from 2 years ago running... on a Qualcomm chip. With no source code (the absolute bare minimum for privacy) in sight. No thanks. What's better about it than a regular Android phone with one of those privacy-oriented OS, privacy-wise? Also, two comments on HN, both about this phone? Do you have anything constructive to say about the PinePhone? "Absolute trash" does not really cut it.
- robhlt 3y agoThese requests aren't being made by the firmware, it's done at the OS level: https://android.googlesource.com/platform/frameworks/base/+/master/services/core/java/com/android/server/location/gnss/GnssPsdsDownloader.java https://android.googlesource.com/platform/frameworks/base/+/... The file even used to specifically refer to the XTRA service, but was updated to be vendor agnostic. GrapheneOS also calls out these requests: > HTTPS connections are made to fetch PSDS information to assist with satellite based location. https://grapheneos.org/faq#default-connections https://grapheneos.org/faq#default-connections
- hkt 3y agoWell,I'm going to send them a subject access request every thirty days for life. I suggest everyone else do the same, and make this expensive. GDPR is almost certainly engaged here too, as the article states. I'm angry enough about this to be out for blood now. This is absurd.
- tibbydudeza 3y agoNothing new. Intel runs Minix on their CPU's in their "management engine" to deal with boot security and other things which means it is able to override the host OS and even parts of the CPU itself and access the network, storage and memory independently.
- ifyoubuildit 3y agoWe need some things: 1) laws that enshrine the right of owners/users to circumvent bullshit like this (a right to digital self defense) and that prevent corporations from making it unreasonably difficult to do so. 2) a healthy community of hackers building the kind of contraception we need to protect ourselves from bullshit like this. I don't know what that is when it comes to an SoC, but we need it. We can't rely on the companies not to do these thing (in fact you can set your watch by it), so we should just focus on protecting the right to route around it.
- 310260 3y agoWhy all the handwringing on this exactly? This data is necessary for product improvements. Seeing it in aggregate improves troubleshooting and tuning to specific operator's networks as well as end-to-end performance analysis. If the list of data in this article wasn't exposed by Qualcomm, then it's exposed in other ways like via SS7 in certain scenarios or to the OS and apps. Granted, app permissions are at least a user choice but we all know how that works these days. At least Qualcomm's using it to improve their product and not just harvesting for advertisers. Also, like others have said, this is a shallow blogspam article trying to sell a "secure" phone. Ick.
- lrvick 3y agoI love a lot of the work of Nitrokey, but I cannot get behind the Nitrophone. Firstly, the Nitrophone is just a Pixel 4A which contains a Qualcomm Snapdragon 765G CPU. I am confused at how the author claims it is free of Qualcomm control. They are unquestionably an active participant in mass surveillance efforts and there are much more covert ways of doing that when you control a CPU, like making your random number generator not actually that random, potentially compromising -all- TLS, or only activating firmware location tracking features when particular domains or traffic is observed. There are countless ways to hardware backdoor a device that are not as crude and obvious as the ones this article observed. Secondly, the sole signing key for phone software is under the exclusive control of Daniel Micay who is an undeniably brilliant engineer, but I suggest looking into how they communicate online and comments by anyone who has ever worked with them before. Supply chain integrity for GrapheneOS stops and ends with one person, who has rejected all attempts by me and others to pursue reproducible builds etc for accountability. Third, GrapheneOS still contains many proprietary blobs with full control over various portions of the hardware. The GrapheneOS team has no choice, because the supported hardware components have not been reverse engineered yet and cannot function without them. The only blob-free Android is Replicant OS but it only runs on reverse engineered but sadly ancient devices long out of production and ancient builds of Android missing many years of security patches. The state of open and private mobile computing is truly a shit show. Fourth, even if you had a fully trusted hardware and software stack, a device that connects to cell towers, even a dumb phone, will be pinged by three or more towers at a time. All of them collude to log the location of every single phone connected. The only way out is living on Wifi only with airplane mode full time. Fifth, even if you open source hardware and software you -still- have to worry about state sponsored supply chain attacks at the factories. Bunnie had it right in his talk on this. https://hackaday.com/2019/12/29/36c3-open-source-is-insufficient-to-solve-trust-problems-in-hardware/ https://hackaday.com/2019/12/29/36c3-open-source-is-insuffic... The only way forward is to essentially go back in time to decisions we made back in the 90s and start over again, which is what the Precursor project seeks to do. That is the only hope I have for a high trust messaging device in my pocket any time soon. There is an alpha matrix client, so fingers crossed.
- linmob 3y agoRegarding the first point: Their current offerings are based on more current Pixel devices (6a, 7, 7 Pro), which use Google's chips, which in turn IIRC are mostly Samsung Exynos with a sprinkle of Google. That way they are only shooting their first product into the foot.
- lallysingh 3y agoAFAICT from the article, the A-GPS download request may (they didn't show any payload analysis of an unencrypted payload...) include: - Unique ID - Chipset name - Chipset serial number - XTRA software version - Mobile country code - Mobile network code (allowing identification of country and wireless operator) - Type of operating system and version - Device make and model - Time since the last boot of the application processor and modem - List of the software on the device - IP address The A-GPS system downloads current satellite orbits (Ephemeris) from Qualcomm instead of waiting for all relevant satellites to transmit all of them on their own. This reduces the time it takes to fix the position. I would've preferred that they show the actual data transferred, instead of what the policy says they may transfer.
- williamDafoe 3y agoIt's likely to keep track of how many black market chips tsmc is producing, and how many times Qualcomm is not getting royalties ... If one particular vendor has 25% Black market Qualcomm chips inside for which Qualcomm never gets a royalty then I think they would definitely be getting a phone call from Qualcomm pretty soon...
- deleted 3y ago[deleted]
- riedel 3y agoIf they are really compliant with the GDPR they must answer an information request. I just found the policy[1] . I guess I will write my first letter to Korea.. Also I guess I would need my unique id or chipset serial id: does anyone know how to get them? Then i would be all set to request which Qualcomm actually collected on me. Btw, using unencrypted connections allone probably is an easy gdpr violation. Qualcomm seems to have European offices, so I also wonder which national/regional data protection authority would be the right one for a complaint. Edit: found the policy [1]https://www.qualcomm.com/site/privacy/services https://www.qualcomm.com/site/privacy/services
- fancyfredbot 3y agothe NitroPhone's GrapheneOS contacts and downloads the A-GPS files from google.psds.grapheneos.org, a proxy server supplied by GrapheneOS to protect users’ privacy. Whew that's okay then. No possibility of any problems there at all.
- kats 3y ago[flagged]
- shrimp_emoji 3y agoAnd they're using it to TRACK us! /r/StallmanWasRight
- fundad 3y ago9 hours and it's still true?
- deleted 3y ago[deleted]
- rubatuga 3y agoA lot of cellular modems have a secondary processor, not surprised that it's phoning home.
- deleted 3y ago[deleted]
- obsidianintel 3y agoSooo what this is nothing new.. What you wanna live in a MediaTek world? No thanks... If you truly know how to manipulate the SoC you can mitigate this as well but people are lazy inherently so, carry on! For a bit of color, the technical manual for the Snapdragon Cortex line is 8,767 pages long, you expect some chinese engineer who hates his life and hates you cause the PLA force him to design a certain way is going to read this manual? Learn how to mitigate security cause you are not going to win the battle head on, simple truth that is hard to swallow.
- sizzle 3y agoHow is any of this legal if it wasn’t overtly spelled out in a TOS or user agreement to use the chipset? I hope some legal privacy advocates are ready to take this to court if it’s as bad as everyone is saying it is. Thoughts?
- nyarlathotep_ 3y agoCan't even avoid spyware web services at the hardware level now. This is really gross. Edit: I've long since sink-holed `izatcloud.net`, and have seen countless look up to this subdomain for the duration of ownership of a Pixel 4a (running GrapheneOs). How long has this been going on for?
- 1vuio0pswjnm7 3y agoThis is old news. Smartphones have been using A-GPS for many years. The izatcloud.net domain was registered in 2012. The gpsonextra.net domain was registered in 2006. Here's a decent summary from 2013: https://forum.xda-developers.com/posts/41576274/ https://forum.xda-developers.com/posts/41576274/ One could just as easily download these A-GPS files ("GPS almanacs") oneself instead of letting Google Play Services or GrapheneOS or whatever do it. There's no need to send any data to any server. Just send a minimal HTTP request. GET /xtra3grc.bin HTTP/1.1 Host: xtrapath2.izatcloud.net Connection: close It's really easy to block A-GPS when using Location. NetGuard can certainly do it. Not using A-GPS might mean GPS is slower to start up in some instances. But it's not very long IME. In those instances, I use an app from F-Droid called GPSTest to let me know when GPS is ready. It would be nice if we compiled our smartphone OS ourselves, then we could edit configuration files, like the one that enables A-GPS, and/or remove code we do not like. XDA seems to be the closest to that ideal. https://android.googlesource.com/platform/hardware/qcom/gps/+/refs/tags/android-security-13.0.0_r4/etc/gps.conf https://android.googlesource.com/platform/hardware/qcom/gps/...
- hatsune 3y agoReading the article thinking of GrapheneOS on my Pixel 7 with tensor G2, then they say NitroPhone not based on Qualcomm and equipped with GrapheneOS, getting confused then see what they sell is just a pre-flashed Pixel. A price of $1299 for P7 pro doesn't even contain desoldered microphone, and that's a $400 addition. That sounds salty and shady. Also, the test sounds and reads shallow.
- dennis_jeeves1 3y agoI would have been surprised if they were NOT send one's personal data.
- JensenKarlsson 3y agoThe initial HTTP request that they mention to Google is not related to Qualcomm at all but rather a part of the Google Play Services implementation in microG which /e/OS uses [1]. MicroG, as many might be aware, is an open-source implementation of Google Play Services that tries to avoid leaking sensitive user data amongst other things. The request to android.clients.google.com though is required in order to checkin the device and receive a device ID and security token [2], which is needed for Firebase Cloud Messaging and push notifications [3]. The checkin include hardware details such as available features (GPS, WIFI, Microphone, EGL version) [4] but sensitive details such as HW MAC address, serial numbers and SIM operator ID are spoofed. [5, 6] Basically if you're running deGoogled and still rely on Google Services, there _will_ be a few calls to Google owned servers. MicroG avoids sending sensitive HW and user data though, more can be read in this thread: https://github.com/microg/GmsCore/issues/1508 https://github.com/microg/GmsCore/issues/1508 [1] https://doc.e.foundation/support-topics/micro-g https://doc.e.foundation/support-topics/micro-g [2] https://github.com/microg/GmsCore/blob/master/play-services-core/src/main/java/org/microg/gms/checkin/CheckinClient.java https://github.com/microg/GmsCore/blob/master/play-services-... [3] https://github.com/microg/GmsCore/blob/master/play-services-core/src/main/java/org/microg/gms/gcm/McsService.java#L525 https://github.com/microg/GmsCore/blob/master/play-services-... [4] https://github.com/microg/GmsCore/blob/master/play-services-base/core/src/main/java/org/microg/gms/common/DeviceConfiguration.java https://github.com/microg/GmsCore/blob/master/play-services-... [5] https://github.com/microg/GmsCore/blob/master/play-services-base/core/src/main/java/org/microg/gms/common/DeviceIdentifier.java https://github.com/microg/GmsCore/blob/master/play-services-... [6] https://github.com/microg/GmsCore/blob/master/play-services-base/core/src/main/java/org/microg/gms/common/PhoneInfo.java https://github.com/microg/GmsCore/blob/master/play-services-...
- sumosudo 3y agoTalpiot and Unit 8200
- prince707 3y ago/e/OS answered at https://community.e.foundation/t/qualcomm-chipsets-data-collection-linked-to-the-a-gps-service-in-e-os/48982 https://community.e.foundation/t/qualcomm-chipsets-data-coll...
- rex_lupi 3y agoI have been aware of this since at least 2019 and the izatcloud.net domain is on my personal dns blocklist that I maintain. I also edit the gps.conf file on my unlocked devices to remove this url. On the other hand, you never know what the proprietary HW + blobs are capable of.