4 ms·
Baseband attacks are possible, but the French government would have to compel the (likely foreign) producer of baseband equipment to insert a backdoor, or do si
by pseudo0 3y ago
Baseband attacks are possible, but the French government would have to compel the (likely foreign) producer of baseband equipment to insert a backdoor, or do significant vulnerability research on closed source hardware/software to find vulnerabilities across common baseband processors.
OS level attacks seem more likely. The lazy option for a police agency would just be to purchase or develop a couple mobile browser exploits, and then serve warrants to French telcos requiring them to MitM targeted traffic. When the target tries to load something via http, redirect them to the exploit server, deliver the payload, and dump everything from their device and collect location, camera, and audio going forward.
Edit: Most people also seem to be overlooking the low-tech solution - get a warrant to break into the target's house or seize their phone during a "random" traffic stop, and use physical access to the device to do whatever.
- ThalesX 3y ago> [...] The lazy option for a police agency would just be to purchase or develop a couple mobile browser exploits, and then serve warrants to French telcos requiring them to MitM targeted traffic. [...] This seems highly unlikely to not alert someone as the camera / video / GPS icons would show up as being in use. > Most people also seem to be overlooking the low-tech solution - get a warrant to break into the target's house or seize their phone during a "random" traffic stop, and use physical access to the device to do whatever. I think people are not really overlooking, but the question is related to the remote enabling of GPS / Video / Audio interception. This kinda excludes random traffic stops or breaking into someone's house. As such, "do significant vulnerability research on closed source hardware/software to find vulnerabilities across common baseband processors" seems like a way to achieve this.
- pseudo0 3y ago> This seems highly unlikely to not alert someone as the camera / video / GPS icons would show up as being in use. You would need a privesc to dump the data from other apps due to app sandboxing anyways. And once you have root, you can disable the GPS/video/camera indicators, since they are controlled by the OS. > I think people are not really overlooking, but the question is related to the remote enabling of GPS / Video / Audio interception. This kinda excludes random traffic stops or breaking into someone's house. Initial physical access is the poor man's way of enabling long-term remote access. > As such, "do significant vulnerability research on closed source hardware/software to find vulnerabilities across common baseband processors" seems like a way to achieve this. Go present a set of options to a government bureaucrat, and tell them: A. you can build a vulnerability research program for 7-8 figures, pray that your best researchers don't get poached by Google after you train them, and maybe get something useful in five years. B. you can buy a couple of existing browser exploits and privescs for 6-7 figures, enabling remote access. C. you can use your legal powers to break into the suspect's home/office and load monitoring software on their phone with physical access. They are going to pick B or C.