3 ms·
These open source / DIY mobile devices rely on an IC to perform the telephony side of things. In this example, a SIM800C made by SIMCom which could require addi
by cri5ti 3y ago
These open source / DIY mobile devices rely on an IC to perform the telephony side of things. In this example, a SIM800C made by SIMCom which could require additional "features" to pass certifications. How would you ensure there is no existing backdoor in the chip's firmware?
- fsflover 3y ago> How would you ensure there is no existing backdoor in the chip's firmware? What is the worst thing that backdoor could do?
- distract8901 3y agoRealistically, snoop on every byte passed between your phone's processor and the modem's chipset. Wort-worst case, injecting code into the phone's CPU through another backdoor or some other exploit. Basically, taking complete control of the modem and potentially using that as a launch point for a more detailed attack. Besides that, in the US at least, your phone's cell modem does have a backdoor. Every single one of them, no exceptions. Your telco can remotely update your modem's firmware and there is absolutely nothing you can do to stop it. Telcos are allowed/required to have total control of the firmware of any modem attached to their network. Source code is never, ever available. All cell modems are a total black box. This also applies to terrestrial internet connections. Your cable modem or DSL has a firmware blob provided by your telco, no matter who you bought the modem from.
- fsflover 3y agoMost of these attacks can be mitigated by having a modem separated by a well-documented interface and a kill switch. These are exactly what I have on my phone.
- distract8901 3y ago> How would you ensure there is no existing backdoor in the chip's firmware? Basically, you can't. See my other comment in this thread. If your modem is used in the USA (and likely elsewhere), your cell service provider won't allow it on the network unless it's running firmware that they approve of. Period. This usually means firmware blobs provided by them with absolutely no means of inspecting what it does. If it's on the network, it has a backdoor. No exceptions. This is why there are no open source modems. It's not a legal possibility.