5 ms·
Nope: http://arstechnica.com/security/2014/03/virtually-no-evidence-for-claim-of-remote-backdoor-in-samsung-galaxy-phones/ http://arstechnica.com/security/2014/
by kppi 12y ago
Nope: http://arstechnica.com/security/2014/03/virtually-no-evidence-for-claim-of-remote-backdoor-in-samsung-galaxy-phones/ http://arstechnica.com/security/2014/03/virtually-no-evidenc...
- pessimizer 12y ago>1) There is virtually no evidence for the ability to remotely execute this functionality. The write-up states, "As the modem is running proprietary software, it is likely that it offers over-the-air remote control that could then be used to issue the incriminated RFS messages and access the phone's file system." summary: there's no evidence of how it can be used, because it's all closed source. >2) The amount of data that can be read or written to by this functionality is very limited. On all affected models except the original Galaxy S, which was released 4 years ago, the affected radio software is running under the "radio" user. As a result, this can only be used to access data specifically related to radio functionality, plus information stored on the SD card (because this is also readable by every application on the phone). summary: it can read and write to all that the radio user is allowed to access, and your entire SD card. >3) The specifics of the vulnerability suggest that it was poorly programmed legitimate functionality rather than a secret backdoor. The authors had to leverage a directory traversal flaw in the handling of modem commands in order to cause the radio software to write outside of the /efs/root directory, which contains radio-related files. This suggests that the intended purpose of this functionality was rather mundane and not at all malicious, and that it was simply poorly implemented. summary: the backdoor was poorly written, and allowed complete access when combined with a known exploit. Nope?
- eli 12y agoI think the "Nope" refers to headline, which is not supported by facts. If there's no evidence that it was intentional then you can't call it a backdoor. Otherwise every security flaw (or potential security flaw) is a backdoor.