4 ms·
What convinced you that they are able to read the screen?
by dotty- 3y ago
What convinced you that they are able to read the screen?
- deleted 3y ago[deleted]
- bordercases 3y agoSomeone should write a Wikipedia article on a glibly labeled law to the effect of, "any opportunity for forensic information to be exploited, will be done so."
- gryn 3y agoyou need to write it elsewhere so that can be used as a source for the wikipedia article.
- DaiPlusPlus 3y agoBaseband chipsets. * For example, see https://news.ycombinator.com/item?id=10905937 https://news.ycombinator.com/item?id=10905937 * Mobile-phone baseband chipsets are proprietary and secret a.f. and part of that is down to the carrier's insistence. * Baseband chipsets run software that the carrier ships OTA to the phone. * While baseband chipsets are ostensibly part of the wireless modem and meant to simply provide a service to the rest of the phone it looks like they generally have some form of access to the phone's main memory bus (just like any other PCIe device in a PC) and so could read the framebuffer (assuming it's backed in RAM at all) - or at least the back-buffers of the screens of running applications. * Even 6-7 years ago, there existed definite causes for concern in (at least) the 32-bit version of iOS - but I can't find any hard evidence that the baseband chip in Apple Silicon-era phones wouldn't have at least some access. See https://github.com/userlandkernel/baseband-research https://github.com/userlandkernel/baseband-research
- pvg 3y agoThe comment you linked doesn't support your argument, it pretty much says the opposite. walled-off from the rest of the phone (somehow) from what I can tell it looks like A useful search term here is IOMMU, the major phone platforms have readily available documentation describing the architecture and its security goals.
- autoexec 3y agoHaving nothing at all to go by except for the platform's documentation and if we're lucky a pinky promise that they'd never backdoor their chips or devices if the state strong armed them into it seems to require a whole lot of faith. It'd be a lot nicer to have verifiable/auditable hardware and software so that we could be reasonably confident what it was capable of and could see exactly what it was doing instead of having to trust the black box.
- pvg 3y agoHaving nothing at all to go by except for the platform's documentation and if we're lucky a pinky promise We have way, way, way more than that. Both the GP and you are arguing about the security deficiencies of modern phones as you've imagined them, rather than as they are but that gap is trivial to close with relatively little reading.
- DaiPlusPlus 3y ago> you are arguing about the security deficiencies of modern phones as you've imagined them, rather than as they are I appreciate the strength of your conviction - but I'm not an phone industry insider, and have no access to the kinds of reading-material I assume you're pointing to - for example, Qualcomm put their docs behind a verify-your-employer-wall (which is outrageous): https://www.qualcomm.com/products/technology/modems/snapdragon-modems-4g-lte-x12 https://www.qualcomm.com/products/technology/modems/snapdrag... ...if Qualcomm's attitude towards openness and transparency is representative of the mobile comms industry in general then they have little hope of correcting any misinformation or misconceptions other technology folk like ourselves might have, let alone the general public.
- pvg 3y agoNo, this doesn't require access to internal documentation of anything, just googling a little. Like the sibling comment points out, the whole baseband thing is a bit of a messageboard trope and has been for about decade. This is one of these things you can sort of guess from first principles! I.e. how likely is it that this well-known problem (the potential security implications of DMA/memory mapped peripherals) has remained completely unmitigated and unaddressed by smartphone designers for 10+ years?
- roenxi 3y agoConvinced is a strong word, but phones are typically running code that is not user controlled in an environment where they are always expected to be connected to the internet. Given the amount of spying that has been revealed (a lot of it seeming to be superficially illegal) it seems reasonable to assume that phones are compromised in all manner of ways unless proven otherwise. I'd prefer to be pleasantly surprised. Anything that makes it more expensive for the government to read someone's communications is a bonus. Ideally panopticon states will remain uneconomic.
- mr_spothawk 3y ago"convinced" is absolutely the word, and my reasoning is posted as a sibling to your message
- pizzafeelsright 3y agoOS level and apps can record the screen. With root access the State or someone who knows the triggers could issue a capture and store to a remote site without user knowledge. A GPS transponder with microphone and camera under the control of billionaires seems like a mistake
- mr_spothawk 3y agoI can highlight text on the application switching screen (swipe up on android, press and hold over text on any of the applications in that view, you can highlight text that's otherwise not highlightable) Likewise, you can highlight text on screenshots.