12 ms·
"Strip out the baseband" of a dongle and you won't have a device that can connect to the network, authenticate, shift cells or anything else. It's like strippin
by bwooce 13y ago
"Strip out the baseband" of a dongle and you won't have a device that can connect to the network, authenticate, shift cells or anything else. It's like stripping the firmware off your disk drive.
Fully support the initiative for an open baseband. One reason it's not open is the (fairly legit) fear that intentional and unintentional DoS attacks would occur, affecting everyone in the area. It's really really simple to be an obnoxious cellular network citizen and it's pretty damn hard to police.
Baseband bugs that impact networks are common too due to the complexity. I saw a function point analysis of GSM vs 3G once, seem to remember 1-2 orders of magnitudes difference. Ahh Function Points, you flawed devil of a management metric.
- rdl 13y agoThe idea is that your "high side" device is a phone, with all your apps, etc. It communicates over a well defined interface (USB seems like the best, but bt or wifi could be adequate given certain considerations) to a fully-functional mifi dongle or whatever which does normal cell/public-wifi/etc. functionality. No compromise of the external cell modem can get at high side data. The current "baseband can DMA your main device" is absurd; security processors (only on iOS and BB and maybe WP, really) help a little, but not enough. Yes, it is two small boxes right now, but there's no reason you couldn't build a "baseband firewall" which puts baseband in one area, a firewall in between, and the regular phone, with only a well defined open interface in between.
- dobbsbob 13y agoSnapdragon and every other baseband coming out has them on an 'all in one' chip which is application CPU and baseband sharing direct memory. Unless you have a microscope you can't build a hw firewall. Cryptophone uses an older Samsung to do this but has no SIM protection. The firewall isn't foolproof either it only detects extended use of the baseband cpu without the application cpu being busy then shuts down the device, which makes it a brick open to denial of service. A hardened Android build is fine for most shady activity and avoiding dragnet surveillance. If you are a drug lord or foreign spy use a laptop or tablet with ostel or silent circle, internal mic removed and running hardened free software, your dongle should have TurboSIM or similar wrapper that can be coded to reject OTA updates and not reply to silent tracking SMS. Marlinespike is also working on a new Whispercore, I have a forensics resistant project, and there is of course Cryptophone GSMK. Is the project you're talking about the build that runs Xen then boots Android in phony isolation because the snapdragon chip can still access memory. Another problem is simply walking around with 2 phones which is an opsec indicator for feds that you are up to something and req targeted surveillance. They have full automated access to every cell tower db to look for this as per snowden docs dumped on cell meta data
- rdl 13y agoThe idea is you don't use baseband functionality at all in the main high-side device. It can be a PDA, connected over USB to a separate radio. There's no way the radio can do anything particularly evil except if there are implementation bugs over USB (API problems with whatever interface you build between them, most likely), but at least that can be inspected by end users and problems found/fixed. These highly-integrated devices are basically inimical to decent security. No (that project was an earlier version of blackphone/geekphone, actually! from what I've heard)
- chillingeffect 13y agoI believe you have the right idea. To isolate audio/message encryption in one box, stream it via IP to cellular (LTE/4G/etc) towers in another box. Then, the customer puts those two boxes into one box. It could basically be done today with an Android PDA running VoiP app only, connected over wifi to a cellular hotspot in one's pocket. The next evolution would be to replace the wifi with a wired network.
- rdl 13y agoI'm probably going to submit this + some specific privacy/location/etc. protecting services as a turnkey thing to DC/BH 2014. Also looking at a kickstarter for something on the "travel router which isn't a complete piece of crap" front.
- agwa 13y agoI'm curious what you'd like to see in a travel router. Is it mainly the software or hardware you think needs work, or both? On the software front, I have an OpenWRT image which I think works pretty well for travel which I've been meaning to publish (routes all traffic over an OpenVPN tunnel and can act simultaneously as a WIFI client to the hotel network and as an access point for your own network). The hardware is nothing special (WRT54GL) and it would definitely be nice if it were more portable. I'd love to hear your thoughts and will be looking forward to that kickstarter.
- ansible 13y agoFully support the initiative for an open baseband. I would love to live in a world where this can happen. But we don't live in that world. The carriers have paid billions of dollars for exclusive use of their frequency bands. And their hundreds of billions of dollars of revenue depend upon smooth operation of all devices on the network using those bands. They will use whatever means to protect this. OK, so let's talk to the FCC (and all the other agencies around the world), and get some other frequency band we can use for our totally open phones. Well... there aren't any open ones left in the good range of approximately 700MHz to 2GHz. This is the part of the frequency spectrum that has decent carrying capacity, good penetration, and not too high power requirements. It is basic physics. Go lower in frequency, and you can't carry enough bits to be useful. Go higher in frequency and you start getting stopped by walls and such. All the good bands have been allocated in the USA and elsewhere for TV, existing carriers, military, satellite, and so on. At a minimum, you'd need tens of billions to lobby for and buy a decent chunk of spectrum. And you need to get the current users moved off, which they won't like. All we have left are the 'crap' bands like 2.4GHz (microwave oven interference). 5GHz isn't too bad (not a lot of other interferers) but it is short range with the current regulations. Another open band for unlicensed use at 60GHz gets stopped by walls, air (oxygen)...
- IgorPartola 13y agoI don't understand. If I come to a carrier and say "Here's a codebase for your baseband. It's OSS, well tested, secure, and supported. Buy support from me." why won't they go for it. Surely, an OSS solution is cheaper for them than developing an in-house crap solution that I'm sure it is now. Also, is there any harm in just open sourcing their baseband code? It seems to me that it's worthless without the license to use the frequency anyways, so who cares if the code is open from a losing business point of view. On the other hand, things like security review are to the carriers' and manufacturers' benefit, no?
- npsimons 13y agoIronically, the market seems to be not optimizing for optimal net revenue (income minus costs, where here you're minimizing costs), but for control. This is partly because of the control freak nature of these companies, partly because the government demands it, but also, again ironically, because of long term thinking: if these companies can lock people out and control them, that helps to guarantee future profits. The free market can sometimes be a cruel bitch bent on the end-user's oppression.
- hrjet 13y ago> Fully support the initiative for an open baseband. How do you ensure that the manufacturer doesn't modify the baseband code?