8 ms·
Spying on a smartphone remotely by the authorities: feasibility and operation
- qup 3y agoIs there some kind of vote bot ring or something? This is a question with one short answer (at the time of my comment). It's hard to imagine why it made the top on its own merits.
- superchroma 3y agoMost likely, moderation is on pause at Stack Exchange due to ongoing feuds with management.
- generalizations 3y agoI agree, and it's not even a good answer.
- freecodyx 3y agoBut it’s a good question. I want to know. I am assuming this is not possible. The only thing i know of is capable of doing so is pegasus. But it’s very expensive afak.
- anonym29 3y agoYou don't know what code is running on your baseband processor, do you? Do you know what other hardware your baseband processor has the ability to inspect?
- zozbot234 3y agoIn most SoC's the answer is 'everything' because there's no such thing as an IOMMU.
- anonym29 3y agoDing ding ding, we have a winner!
- paulryanrogers 3y agoHow big a concern is this if the data is encrypted by the kernel or user space?
- Veserv 3y agoEncryption does not help in this case. They have complete remote control over the entire CPU so they can just run the decryption code directly. Encryption only helps if the endpoints that can get access to the plaintext are not compromised.
- ignoramous 3y agoThere are atleast 2 more exception levels with higher privileges than the Kernel on arm64.
- moyix 3y agoI was under the impression that most modern (past few years) SoCs like Exynos, Qualcomm, Apple silicon all had IOMMU support. Sometimes it’s misconfigured to be too permissive but that’s getting better. Qualcomm SMMU: https://www.qualcomm.com/content/dam/qcomm-martech/dm-assets/documents/whitepaper_0.pdf https://www.qualcomm.com/content/dam/qcomm-martech/dm-assets... Apple: https://support.apple.com/lt-lt/guide/security/seca4960c2b5/web https://support.apple.com/lt-lt/guide/security/seca4960c2b5/... Samsung (vuln indicating it wasn’t configured correctly, but they still do have and use an IOMMU): https://nvd.nist.gov/vuln/detail/CVE-2022-39854 https://nvd.nist.gov/vuln/detail/CVE-2022-39854
- numpad0 3y agoWhy's IOMMU thrown around so casually in this forum as if it's a silver-bullet explosive reactive armors? They'd be running something like 30 years old giant main loop with "// don't remove this line, build breaks" comments everywhere, not like Rust microservices on formally verified microkernel. The main CPU/application processor/main CPU might be running better secured Unix/Linux and might be able to protect itself from peripheral CPUs, but that's not the point; a phone had always been a pair (minimum) of computers, traditionally referred to as Application Processor(AP) and Baseband Processor(BP), of only the slightly faster one is exposed to the user, and it's unclear what is going on inside the other one or how to handle it. That's the problem.
- freecodyx 3y agoOk but we are talking remotely enabling camera and microphone. The baseband is only responsible of intercepting traffic. This needs kernel injection.
- Veserv 3y agoIt costs about 2-5M$ to buy or develop a new weaponized zero-click vulnerability that would allow you to simultaneously hack all 1,000,000,000 iPhones in use. So around 1/20 of a cent per iPhone.
- abwizz 3y agoeven for the single use case, 5M$ is not that far fetched in terms of opportunity cost.
- joebiden2 3y agoNo, it's not a bot ring. I assume you think that because I posted links to stackexchange quite a few times the last few months. Instead, I just skim over stackexchange.com as part of my feed and when there's something what I assume HN interests, I post it here. I don't care much about Karma. I posted this specific topic since I find it kind of hilarious that police should now lawfully be able to do something they are almost surely not able to do. And I enjoy discussions to such topics here on HN, because most of the time the viewpoints mentioned here are at least of the same quality of the answers on stackexchange.
- qup 3y agoIt seemed ridiculous to me that it could make the top of HN. It was a question with no discussion, yet. If it had a discussion or even a good answer, it would have made perfect sense. I assumed the goal would be stack overflow karma, as that's actually valuable.
- throwawayadvsec 3y agoOr maybe it's the perfect place to discuss this kind of topics. An Ask HN with the same kind of question could have reached the front page.
- godelski 3y agoIt rose to the top because of the question, the link about France, and because new posts get higher weights. It is at 79pts and 59 comments currently and about to fall off the front page. But also on the front page is a post with 6pts and 1 comment (1hr old), 17 points and 2 comments (2 hrs), 7pts and 2 comments (30 minutes). and a few more. Just a slow Saturday.
- GeekyBear 3y agoCan the thing France just made legal be done? > French police should be able to spy on suspects by remotely activating the camera, microphone and GPS of their phones and other devices, lawmakers agreed late on Wednesday, July 5. https://www.lemonde.fr/en/france/article/2023/07/06/france-set-to-allow-police-to-spy-through-phones_6044269_7.html https://www.lemonde.fr/en/france/article/2023/07/06/france-s... Why would anyone stir up the civil libertarians if the thing you are making legal is not possible?
- wombat-man 3y agoI would assume this is possible. If the gov wants to bad enough, I'd guess most OSes have a way to remotely control and observe. A state has resources to research 0days, bank them, and use them as needed. But probably not worth using unless it's for a high value target.
- Simorgh 3y agoWell, what would be considered a high-value target? Even if warrants are initially mandated for a specific search, couldn’t this erode into, ‘it’s just a quick scan’? What if it’s ‘useful’ to ‘quick scan’ their own President? ‘Confirming their security’. Could this evolve into a subtle shift in the balance of power? In other words, a political crisis? Where the intelligence agencies have informational advantages over any elected office. From information into knowledge, you could easily have behind the scenes figures who have unmatchable insight and ability to coordinate. Suddenly every target has value…
- wombat-man 3y agoThis is a rambling post... I don't know what argument you're trying to make. Governments will research 0days because other governments are doing it, and it's best if you find them first and work out a defense. You know, in case you want to mess with someone's nuclear centrifuges and to avoid having yours screwed with. Do you think that it should not be legal for the government to investigate a crime? The system is made up of people, some of them may abuse their access. Other laws, in theory, will hold them to account.
- vxxzy 3y agoThis question has been in my head recently. How feasible is it really? The answer in the link isn’t comprehensive. Is it really out of the question for manufacturer’s to ship a particular version of a device and software for a target country? Nation states have a history of backdooring or weakening particular technologies.
- anonym29 3y agoBaseband backdoor. No need to target the OS or the primary CPU.
- euniceee3 3y agoAny signs of these in the wild? I know it is a valid threat, but even in the cases that set this precedent there was a team of 140 and they did not leverage a baseband exploit.
- zozbot234 3y agoHow could we know for sure? Basebands are 100% proprietary, we have no idea how they operate and even less of an idea of how their operation might be subverted.
- anonym29 3y agoThis is why I'm an open source advocate. It's not that open source automatically makes software/firmware trustworthy, it's that closed source empirically guarantees the software/firmware can never be deemed trustworthy.
- scarface_74 3y agoAnd yet there have been plenty of long standing security issues in Linux… Why would you think that a bunch of people volunteering their time would be more motivated to look for security issues and even those that are found, how many would be disclosed responsibly instead of being sold to places like Pegasus?
- zozbot234 3y agoThis answer is dangerously naïve. Phone basebands and radios are full of vulnerabilities, if you don't want your phone to be a potential surveillance device given any minimally sophisticated adversary you should either turn off the radio or preferably shut it off entirely and remove the battery.
- anonym29 3y agoHypothesis B: it's not dangerously naïve, it's deliberate misinformation designed to coax technical but unskeptical people into lowering their guard against this class of threat.
- zozbot234 3y agoOf course, but see Hanlon's razor.
- anonym29 3y agoSounds like the perfect cover for malice, lol If ((Assume it's stupidity) == (discount/ignore the risk)), then assuming it's stupidity is never the safer assumption, even if it's empirically more likely to be the correct assumption, no? All boils down to an individual's threat model at the end of the day anyway, though.
- rgrieselhuber 3y agoI’m always amazed at how many people don’t understand this. Hanlon’s Razor is just a way to sound smart while indulging in self-soothing biases.
- mdp2021 3y agoThe practice of assessing whether a tempting evaluation of "malice" can instead cover evidence of structural faults is part of the effort towards seeing things as they are. And keeps you away from paranoia.
- ofslidingfeet 3y agoWe already know for a fact that they can surveil virtually all smart devices including appliances and televisions due to the Vault 7 leaks, and this would tend to be corroborated by the national geospatial intelligence agency telling congress that they have a high resolution 3d map of the entire globe's events at any given time.
- aftbit 3y agoHere is a link to Vault 7 on WikiLeaks: https://wikileaks.org/vault7/ https://wikileaks.org/vault7/ Here's a link to Wikipedia's article on the leaks: https://en.wikipedia.org/wiki/Vault_7 https://en.wikipedia.org/wiki/Vault_7 The only one that mentions televisions is Weeping Angel (cool name) which attacks Samsung F Series Smart Televisions. Likely they can indeed target other devices but I'm not sure I'd go as far as saying that Vault 7 shows that they can target "virtually all smart devices". Or am I missing something? Can anyone provide more concrete evidence?
- ofslidingfeet 3y agoI probably just got confused, but thank you for linking to the information about Vault 7 directly so that anyone can simply appraise for themselves whether or not I seem confused. That's what I love about HN and Reddit, and similar websites: All the helpful counterpoint, especially when someone criticizes the intelligence community. Thank you so much!
- bambax 3y agoA little OT but strongly related: in France you can go to prison if you refuse to give your phone's password to the police (nothing like a "free country", I guess). Is there a way to set up a phone so that typing a "special" password puts the phone in an alternate state with different apps and content, etc. (and possibly erase the regular content)?
- ElDji 3y agoYou simply comply and give your phone PIN that somehow doesn’t work.
- flangola7 3y ago- I presume that's considered willful destruction of evidence and interfering with an official investigation, and worse charges than whatever you were probably facing (unless you really did fuck up and committed something bad). - Investigators are not going to be typing your password into the running original device, they're going to be trying it against an offline clone of the encrypted storage. All that will happen is the decryption won't succeed and they'll tell you that it was the incorrect password and continue holding you until you give it up. - This is hardly unique to France, US courts have jailed suspects for refusing to provide passwords in numerous cases. https://arstechnica.com/tech-policy/2017/03/man-jailed-indefinitely-for-refusing-to-decrypt-hard-drives-loses-appeal/ https://arstechnica.com/tech-policy/2017/03/man-jailed-indef...
- vhcr 3y agoAbout point 2, modern devices have a secure enclave, which means that copying the encryption key is pretty much impossible.
- flangola7 3y agoImpossible for the average thief, not impossible for government or Fortune 500 actors. There are private contractors in business solely dedicated to developing and licensing enclave cracks, and popping them is routine procedure for most law enforcement departments, even smaller ones. Fundamentally you can't have a key and the data inside the same physical box and expect encryption to remain intact. Enclaves are just security through obscurity on steroids.
- numpad0 3y agoWhat's the path of least resistance to find RCE on baseband?
- alexawarrior 3y agoAny broadband chip since 3G ships with proprietary drivers which have backdoors. I tried to build an open phone, worked for one of the major telcos, and could never get around the driver issue in trying to make an open phone. BUT sophisticated attackers like US or Israeli governments (and I assume Russian or Chinese but I don’t have direct experience with these) don’t need these backdoors, getting anywhere near your phone is enough to root it to allow installation of spyware, according to my CSO who worked in naval intelligence. There are simply too many vulnerabilities for there to be a hardened device in the consumer space. Some are better than others (Apple) but as Bruce Schneier says, if you are worried about this sort of thing you really have to be totally disconnected from the internet and exchange encrypted physical media.
- seba_dos1 3y agoDepends on where you put the line between "open phone" and "baseband blackbox". Drivers are not an issue for phones like Librem 5 or PinePhone since they're using a separate modem module connected to the main SoC via USB and communicating over AT and QMI interfaces to which there are perfectly open drivers. The modem itself remains a vulnerable proprietary blackbox, but it does not have any access to your OS and you can cut it out from power while keeping the rest of the phone intact. Open basebands are not something we're anywhere close to having though, for many reasons.
- erealquestionis 3y agoTo me the real question is. Technical feasibility aside. Would the cell phone manufacturers (Apple, Samsung, Motorola, Nokia, Xiaomi, etc) say no when faced with the possibility of losing market share in France. Because of a law pushed through under the cover of security. Many a liberties have slipped under that blanket cover called security. I think they will put in this feature if it's not already there.
- nickserv 3y agoWouldn't be surprised if it's just a toggle they activate when building the ROM...
- abecedarius 3y agoGoogle Search withdrew from China when China went over the line, as they saw it.
- lyu07282 3y agoI think the way it probably works is that if the US gov. wants to root someones phone anywhere in the world they just do it via some API given to them by apple/google directly. If a foreign country wants to do it to someone on foreign soil (like the saudis to bezos did [1]) they exploit some vulnerability brought on the free market (like the whatsapp/video message exploit chain the saudis used, or exploits like the NSO zero-click iMessage exploit [2]). If a foreign country wants to spy on its own citizens who protest the government, they could just use the local phone carriers capability to silently ping, update firmware or change system settings remotely, those are intentionally part of the mobile standards (including intentionally weak encryption) so governments can spy on its people. [1] https://www.wired.com/story/bezos-phone-hack-mbs-saudi-arabia/ https://www.wired.com/story/bezos-phone-hack-mbs-saudi-arabi... [2] https://www.wired.com/story/apple-imessage-zero-click-hacks/ https://www.wired.com/story/apple-imessage-zero-click-hacks/
- xk_id 3y agoNot to undermine the plausibility of your suggestions, but I like to wonder how answers like this read like to someone with direct experience and knowledge.
- l8_to_catch_up 3y agoI know for a fact that my electronics (including smartphone) is being monitored (including this post) by my government. That probably doesn't surprise others. What isn't as known is that the government also intrudes into chats with other people on social media. They don't just monitor, but actively interfere. Edit: By the way, Nokias and other dumbphones (without physical off-switches -- the PinePhone has them, but good luck getting one) can also get their mic and GPS remotely activated. The partial solution is to get one with a removable battery and remove the battery whenever not in use. iPhones can be hacked into through IMEI if you connect them, but are useful, encrypted offline-only PDAs if you don't install any app. Also, if your electronics are being spied on by the government to this degree, chances are you are also being physically monitored.
- woozy3756 3y agoThis is always a dumb take I see by so many people. No goverment is monitoring all electronics and there is zero evidence that is the case. Sure companies collect a lot of user data and that user data could easily be given out with a request. Or maybe if you are a really big target they might use a zero day against you but they are never going to have all electronic devices connected to a botnet. You and many other people can test it right now, just run a basic traffic analyzer through your phone or PC.
- rolph 3y agonuggets to supplement discussion https://en.wikipedia.org/wiki/Baseband_processor https://en.wikipedia.org/wiki/Baseband_processor
- user6723 3y agoGoogle Play is a rootkit. Google will fully cooperate with any government. If you use GrapheneOS on a pixel device your bootloader is closed source and the system-on-chip is largely undocumented and impossible to audit without serious resources. So yeah. Shit's fucked man.
- TacticalCoder 3y ago> Google will fully cooperate with any government. I'll remind you that on previous MacOS versions (8 years ago?) researchers had discovered that the Mac laptop's integrated webcam could be turned on without the green LED turning on. So basically: the webcam turning on without the user knowing it. And way weirder: some random company somehow had the rights to sign code using that "feature". The story got pretty much killed. I'm sure if some digging had been done, you'd have found some three letter agency behind the shell company enjoying the very strange right to turn the webcam on on MacOS devices without the LED turning on. For everybody out there: rest assured though, Apple are the good guys and there's no way they have the ability to turn on the webcam of your Mac laptop today without you knowing about it. [1] [1] yes, this is sarcasm
- DANmode 3y agoRelated: https://www.digitaltrends.com/mobile/facebook-ios-camera-bug/ https://www.digitaltrends.com/mobile/facebook-ios-camera-bug...
- makeworld 3y agoCan you expand on what you mean with regards to GrapheneOS? What is the relation?
- user6723 3y agoGrapheneOS is just about the only Android distro that isn't trash.
- godelski 3y agoIANAL nor French, but reading the article, is this just saying that French police can get a warrant, issued by a judge, that allows them to tap a suspect's device (not longer than 6 months)? I just want to make sure I got the facts right. https://www.lemonde.fr/en/france/article/2023/07/06/france-set-to-allow-police-to-spy-through-phones_6044269_7.html https://www.lemonde.fr/en/france/article/2023/07/06/france-s...
- joebiden2 3y agoAs far as I understand that, since there is no explicit clause prohibiting an extension after 6 months. I think it is safe to assume that it can be extended by another 6 months provided the suspicion persists (i.e. a judge can be convinced). I'm not french myself, so take it with a grain of salt.
- collected_thot 3y agoTo add to this discussion, I must note what I don't see many mentioning here. One doesn't need to do any shady stuff with baseband or stockpile on zero day vulns. The current mobile ecosystem is such that any supported device (recieving updates and such) sends its unique identifier to the manufacturer before recieving OTA updates. And devices by default check for updates on a regular bases. Basically the manufacturer can always target and track individual devices. And provision indivisualised signed updates. Not just at the country level but targeted to specific IMEI. Coming to more concrete examples, Google is known to do AB testing with their Pixel line of devices, setting custom profiles for some users. Xiomi had previously shown capability to actively disable devices that move outside of legal sale regions. Samsung uses such capabilities for enterprise devices in Samsung's Enterprise/Knox platform. And consumer devices can be thought of as enterprise devices under the manufacturers domain. --- So the government only simply needs to send these companies warrants to target, bug and track specific devices or registered customers. Online platforms are already subjected to data requests from law enforcement which they must conform to (atleast those with supporting warrant). Some try to recuse themselves from such compelled intrusion of their customers by employing end to end encryption (e2ee). With this provision and manufacturer cooperation, they could get direct full control of the ends (personal devices). Obviating the need to "break" encryption. Why deal with a dizzying cloud of services in wide range of jurisdictions when you can have full access to citizen devices with cooperation of a handful of manufacturers. In summary, this is not just feasible, the elements for an organised remote control system are already present in current smartphone ecosystem. In form of signed updates by manufacturers that can target particular IMEI devices. One just needs this law to wade through the legality issues. A solution to avoid such sweeping surveillance capability would be to convince manufacturers to not receive identifiable data before provisioning updates. And have a public ledger of officially signed image hashes, like those of of domain certificate transparency lists.
- collected_thot 3y ago[dead]
- RecycledEle 3y agoThe vulnerabilities are built in at every level. Source: I was once a CALEA programmer. Anyone who says otherwise is an idiot, a liar, or both. Web sites that are frequently referenced are forced to censor the truth.