3 ms·
It's actually strictly worse: even if they had an IOMMU and the drivers were implemented correctly, phone vendors provide remote access tools as part of their f
by twothreeone 3y ago
It's actually strictly worse: even if they had an IOMMU and the drivers were implemented correctly, phone vendors provide remote access tools as part of their firmware stack (e.g., see https://www.fsf.org/blogs/community/replicant-developers-find-and-close-samsung-galaxy-backdoor https://www.fsf.org/blogs/community/replicant-developers-fin...). To reiterate one of the other commenters, as long as users don't control what code runs on the baseband, they do not in fact have ownership of the device. The same holds for anything else that has a baseband (such as most modern cars). This sentiment is publicly communicated by telco's and manufacturers and convenient for regulators.
- JoshTriplett 3y agoThat's true, but as long as the baseband doesn't have access to the rest of the device, there is at least a limit to how much damage it can do, which is a good incremental step. If it can't exploit the OS, then worst case, it has access to network traffic (just like the next router in the chain, which is why all the traffic should be encrypted), and it has the ability to help locate the device against the user's wishes (but so do the cell towers). Rewriting baseband firmware is also a great opportunity to make it Open Source, and I hope that happens as well.
- twothreeone 3y agoIt looks like https://osmocom.org/projects/baseband https://osmocom.org/projects/baseband is still somewhat active.. they mainly develop for the TI Calypso (Motorola C123 and some others). My understanding is that all "modern" (meaning 3G and up) modems are basically sealed black boxes.