4 ms·
Productized in weeks ? even firmware ? that seems really hard. How would you do it? Please share(if it's OK).
by ippisl 13y ago
Productized in weeks ? even firmware ? that seems really hard.
How would you do it? Please share(if it's OK).
- Zigurd 13y agoOpening firmware would be simple. Many devices have loadable firmware, like your phone's baseband processor. The toolchain is unlikely to be exotic, and providing build-able source code should not be a great burden. Some people hack baseband firmware for fun. They manage to reverse engineer it and inject new code with publicly available tools. Considering the grave threat to US online services' from lack of trust, you would think that some announcement in this direction might have been made. Crickets, so far.
- ippisl 13y agoAndroid is a huge,complex codebase. doesn't this mean it's hard to verify it's security ?
- deleted 13y ago[deleted]
- deleted 13y ago[deleted]
- Zigurd 13y agoAndroid has a userland made of unprivileged code running in a VM. To the extent it is different from a desktop Linux, it should have fewer userland components that could subvert system security. So, it's the same or perhaps easier to audit Android. I'd be more worried about peripherals. Telephones are hard to secure. That's why I mentioned open firmware. I'm not an expert on hardware-level security, but the combination of SoC architecture and lots of programmable cores in peripherals makes me think you would find ways of extracting information from a device that way. And the mobile baseband controls some of the audio paths in a handset. It will be interesting to see if there are any revelations about device-makers and security that come out of the heightened interest in this topic.