12 ms·
NitroKey disappoints me
- biomcgary 3y agoAre A-GPS files tied to location or the same for everyone? Hopefully, the latter.
- VWWHFSfQ 3y agoI'm fairly sure they're just static files
- amluto 3y agoHow would the server even know the client’s location? By IP address? That would make GPS work poorly when using a VPN or a wireless network with unusual routing. edit: y’all are reading this backwards. My point is that the Qualcomm server does not know the location of the client and therefore cannot usefully send anything other than a static file.
- jcrawfordor 3y agoThe data isn't location based, it's the same for everyone. The GPS control center updates it once an hour or so, but it's applicable globally. As the article explains, GPS satellites broadcast it, but at a low bitrate so it takes a long time to receive. Much faster to just download it from the internet. Because of the architecture of GPS in phones (which is basically a historic artifact, the chipset is expected to provide NMEA sentences and the OS doesn't want to be more deeply involved than that) AGPS needs to happen at a fairly low level.
- tialaramex 3y agoIn principle AGPS can send the GPS radio data to a remote server and have the server do the difficult maths then send back your position. This is apparently a thing somebody actually designed, however since "doing difficult maths" is now very cheap you'd obviously just do that on the phone.
- iudqnolq 3y agoIt's not that unreasonable an assumption. Qualcomm offers a different opt-in service under the same name that does use location data. Basically your phone uploads sensor data like cell tower strength and WiFi strength, and their service estimates your location. The your device locally uses gyro/accelerometer to fine-tune. See Qualcomm Location Service (formerly “IZat Location Services” or “IZat”) on https://www.qualcomm.com/site/privacy/services https://www.qualcomm.com/site/privacy/services
- MartijnBraam 3y agoThis is basically a copy of a signal broadcast worldwide by the GPS satellites. Just static data.
- radicalbyte 3y agoYou can transfer a lot of information in a request, it's one of the oldest tricks in the book. Whilst I also had a bad taste in my mouth once I got to them shilling their product (it was a double-check - wait a sec this Nitro phone they're talking about it's their own bloody phone?) that doesn't change the fact that this unexpected behaviour is a problem. What we need to see is the actual HTTP requests, either from Nitro or - even better - from a third party who verify it.
- jcrawfordor 3y agoNitro's product also does it, but maybe they download the file from themselves or another vendor. Every internet-connected GPS device does it, and this has been the case since even before smartphones took off. If they don't, first fix in a day will take 10-15 minutes of solid reception. Some GPS chipsets will perform A-GPS internally using a baseband IP stack, but most smartphones actually don't and expect a daemon to handle it since the OS has more sophisticated ways of deciding what network connection to use for the download. This is the most common case for Android, the OS downloads the file and uses a kernel module to provide it to the GPS chipset. The chipset vendors, including Qualcomm here, provide this service as part of their userspace components. An IIOT LTE module I use has an onboard IP stack and AGPS implementation since it's intended for use in contexts where there isn't necessarily a conventional OS connected to it, maybe just a serial data logger or whatever. The A-GPS requests it makes contain so little data it's a bit comical, the bare minimum for a valid HTTP request. Another reason it's nice to have the OS do it is since that tends to get you access to a more complete HTTP library.
- radicalbyte 3y agoThanks (and to Maarten too, for some reason I can't reply to his post) that explains it. Nitro have made rather large claims; if they're real security experts then they need to share the details or GTFO.
- kotaKat 3y agoStatic data for the entire system. A-GPS files are just a digital ephemeris[1], a form of trajectory tables for the satellites over (upcoming) time, so it knows when to expect certain satellites (and thus certain transponder frequencies to pick first in its search for signals to lock onto and triangulate from). [1] https://en.wikipedia.org/wiki/Ephemeris https://en.wikipedia.org/wiki/Ephemeris
- andrewaylett 3y agoA-GPS provides a current almanac, showing where all the satellites actually are. Without it, a cold start requires hunting for signals across a much wider range. As I understand it, older GPS receivers rely on finding a single satellite and waiting to acquire a full almanac from it while smartphones have enough compute to probably get a lock on multiple satellites without a complete dataset. The satellites will eventually broadcast the complete almanac and ephemerides, so a warm start shouldn't take as long. D-GPS uses the known location and current readings from a nearby fixed receiver to increase the accuracy of your receiver, and does rely on knowing that you're in the vicinity, but it's not a feature of consumer phones.
- snvzz 3y agoIP packets should not be sent or received behind our backs, and certainly firmware should not be bypassing the operating system to do this. Whether it is useful for A-GPS does not matter. It must be done on top of the operating system or not done at all.
- wepple 3y ago> IP packets should not be sent or received behind our backs I like this idea in principle, but I have bad news for you if you ever want to own literally any modern device - phone, laptop, tablet, car, TV, rice cooker etc The only solution is some kind of network-level allowlisting which would be impossible to maintain, and stop working the second you’re outside a known network (ie LTE)
- MartijnBraam 3y agoThis is not even done by firmware, it's just part of qualcomms android userspace.
- snvzz 3y agoI see no reason why Android shouldn't handle A-GPS itself. Qualcomm's userspace shouldn't be doing this.
- charcircuit 3y agoThis isn't happening behind your back. A-GPS isn't a secret feature in phones.
- wepple 3y agoMaybe NitroKey are surfacing something useful and potentially concerning, but they way they do it is so cheap that it completely turns me off their brand. It’s a bunch of negativity-hype with a “so buy our phone” tacked on. If you handed a Nitrophone to any competent security researcher, I bet they’d find a ton of issues. Same with the NitroKey; that feature list is far too extensive to not have issues.
- DANmode 3y agoSo everyone is considering the same points: are you saying this in knowledge of their published audits?
- wepple 3y agoI am Edit: to elaborate, I think it’s great that they published audits, that should be a minimum baseline but in fact it’s a fairly rare thing at this point. Also Cure53 are no joke, they have some great people who generally do good work. That said, having spent a decade doing security assessments in a past life, they’re point in time and always have a particular scope and are time-limited. A researcher or adversary has more time, a broader (infact infinite) scope, and lacks a lot of the restrictions of a formal security assessment.
- flangola7 3y agoAren't Nitrophones just rebranded GrapheneOS Pixels?
- kornhole 3y agoYes they provide the service of flashing GrapheneOS onto a Pixel for people who are not confident enough to do it themselves. I think they kick back some of the revenue to the GrapheneOS project. It is a needed service for people who want the most secure, private, yet functional phone but not the hassle of setting it up.
- deleted 3y ago[deleted]
- dchest 3y agoThe author didn't address the list of things the devices allegedly sent when downloading A-GPS files, from the original article: 1. Unique ID 2. Chipset name 3. Chipset serial number 5. XTRA software version 6. Mobile country code 7. Mobile network code (allowing identification of country and wireless operator) 8. Type of operating system and version 9. Device make and model 10. Time since the last boot of the application processor and modem 11. List of the software on the device 12. IP address
- MartijnBraam 3y agoThat's not a list of things allegedly sent. That's a list the lawyers put in a legal document to not get sued in case it happens.
- flas9sd 3y agoa-gps/supl ("xtra"?) and qcoms izat api (in-building location services using indeed accesspoint info) are mixed in both HN threads. If izat triggers in customroms and sends plain http needs to be shown, but the .so libs are on device firmware partitions if not actively deleted. On older devices lineage mounts them unmodified from stockrom into /vendor/
- not2b 3y agoThe author claims that none of the above information is actually sent, other than the IP address which is unavoidable to download a static file. I don't know who is right because I haven't seen the actual intercepted HTTP traffic.
- iudqnolq 3y agoIt is odd that neither article quotes from the policies linked from the domain they're talking about. I think the relevant section is "Qualcomm GNSS Assistance Service" on https://www.qualcomm.com/site/privacy/services https://www.qualcomm.com/site/privacy/services > The Qualcomm GNSS Assistance Service downloads to your device a data file from QTI containing the predicted orbits of the Global Navigation Satellite System (GNSS) satellites. The Qualcomm GNSS Assistance Service also uploads a small amount of data to us comprised of: a randomly generated unique software ID that is not associated to you or to other IDs, the chipset name and serial number, the Qualcomm GNSS Assistance Service software version, the mobile country code(s) and network code(s) (allowing identification of country and wireless operator), the type of operating system and version, device make and model, the date and time of connection to the server, the time since the last boot of the application processor and modem, and a list of QTI software on the device. > As with any internet connection, we will also receive the IP address the device used to send us data. We use the data we collect to evaluate, maintain, and improve the performance of our systems and to determine general location (but not specific geolocation). We do not sell (as that term is defined under the California Consumer Privacy Act) the full IP address, unique software ID, or chipset serial number, and we share personal data only under the limited circumstances described in this Policy.
- kotaKat 3y agoAlso to mention... A-GPS is extremely crucial to the underpinnings of the e911 system. Having rapid fixes means quicker positioning data being sent over the wire to the 911 center.
- joecool1029 3y agoIt helps, it's not extremely crucial. There are other methods that don't require the handset's cooperation: - https://www.mpirical.com/glossary/lmu-location-measurement-unit https://www.mpirical.com/glossary/lmu-location-measurement-u... - https://www.etsi.org/deliver/etsi_ts/136100_136199/136111/11.00.00_60/ts_136111v110000p.pdf https://www.etsi.org/deliver/etsi_ts/136100_136199/136111/11...
- stingrae 3y agoall these methods aren't super reliable. The combination of all of them is required for what people have come to expect from GPS.
- stingrae 3y agoAlso people want GPS to work seamlessly in locations where GPS is unreliable. Dense urban canyons, inside big buildings and a myriad of other locations. AGPS is absolutely necessary for this. Without this, people will wonder why the phone's "GPS" is bad (it takes a long time to get position and it is inaccurate in many cases).
- magicalhippo 3y agoWas just looking at NitroKey after realizing my SoloKey v2[1] won't come for yet another few months. Given that they use similar firmware, the headline scared me a bit. However the article is about their marketing of an entirely different device, not their new Yubikey replacement. The wait continues... not super-surprised though, crowd funding hardware is super-risky and I knew that. [1]: https://solokeys.com/ https://solokeys.com/
- atoponce 3y agoI was very disappointed in that Kickstarter. Yubikey ran a 54% off discount May 4th last year and not knowing when I would get my v2 SoloKeys, I purchased two. I had them within the week and have since integrated them into all my accounts. I debated backing out of the Kickstarter as the Yubikeys were working so well for me, but decided to stick with it and see what the SoloKey experience would be like. Yeah, disappointing. I ordered USB-A and USB-C keys. The USB-A key doesn't make a good connection with the USB port. It needs to be carefully held to register with the OS, otherwise it doesn't get power.
- toastal 3y agoThere's OnlyKey. Mine have been fine.
- ibotty 3y agoI guess I was very lucky to get my solokey v2s a few month ago. I do like them. I am a bit disappointed that they have problems for other backers.
- fsflover 3y agoWhy not try Librem Key (which is rebranded NitroKey with free firmware)?
- dang 3y agoRelated ongoing thread: Smartphones with Qualcomm chip secretly send personal data to Qualcomm - https://news.ycombinator.com/item?id=35698547 https://news.ycombinator.com/item?id=35698547 - April 2023 (263 comments)
- dmbche 3y agoStraight, concise, clear and to the point. Thanks!
- s1k3s 3y agoI've criticized the original article for lack of information here: https://news.ycombinator.com/item?id=35698547#35703662 https://news.ycombinator.com/item?id=35698547#35703662 However, this blog post takes it too far: > It proceeds to not show the contents of this HTTP request because it would show that it's not at all interesting. It does not contain any private data. You don't know that, nor do you take any steps to actually prove your claim. This blog post is just as bad as the original post for not providing any evidence to your claims. To add to that: OP seems to summarize the HN comments section without even citing it. I'm double disappointed :)
- MartijnBraam 3y agoI have not even seen the HN comment section before writing this post
- fredgrott 3y agoNot to mention that AGPS is decades old by now. How many of you fell for the original article's narrative?
- WirelessGigabit 3y agoWell, a device can get the time via GPS only. If for whatever reason the system's time is just SO wrong then there's a change the HTTPS connection might fail because of certificate not valid yet / expired. For this I think it's OK for it to be served over HTTP.
- smileybarry 3y agoIt also allows for transparent carrier caching, might even be why it's HTTP in the first place.
- WirelessGigabit 3y agoBut is this a file that you want to have cached? Honest question! Not sure how often this is updated.
- marcus_holmes 3y agoEvery 10 minutes according to the article
- aaronmdjones 3y agoThe almanac is broadcast every 12.5 minutes. It is only updated about once a week.
- yellowapple 3y agoReminds me of your typical "Windows support" impersonator telling people to look at all the spooky errors and warnings in Event Viewer and "all I need is for you to install this remote access tool and I can fix all your problems for you".
- lifeisstillgood 3y agoSo, presumably if I bought one of their phones and turned it on, I would wait ten minutes to get a GPS fix instead of it using a almanac and working out the lat and long of three cell towers at certain signal strength? Does anyone know if it's possible to get at this info from user side ? Some API access? sounds fun
- MartijnBraam 3y agoYou don't even need the cell towers. You need _very_ good gps reception though, so outside without tall structures nearby. Then you have the issue that you need to keep the GPS active enough to keep the almanac updated. Which is usually not happening due to power management.
- prince707 3y ago/e/OS answered at /e/OS answered at https://community.e.foundation/t/qualcomm-chipsets-data-collection-linked-to-the-a-gps-service-in-e-os/48982 https://community.e.foundation/t/qualcomm-chipsets-data-coll...