[HN Gopher] Spying on a smartphone remotely by the authorities: ...
       ___________________________________________________________________
        
       Spying on a smartphone remotely by the authorities: feasibility and
       operation
        
       Author : joebiden2
       Score  : 100 points
       Date   : 2023-07-08 14:49 UTC (8 hours ago)
        
 (HTM) web link (security.stackexchange.com)
 (TXT) w3m dump (security.stackexchange.com)
        
       | erealquestionis wrote:
       | To me the real question is. Technical feasibility aside.
       | 
       | Would the cell phone manufacturers (Apple, Samsung, Motorola,
       | Nokia, Xiaomi, etc) say no when faced with the possibility of
       | losing market share in France. Because of a law pushed through
       | under the cover of security. Many a liberties have slipped under
       | that blanket cover called security.
       | 
       | I think they will put in this feature if it's not already there.
        
         | nickserv wrote:
         | Wouldn't be surprised if it's just a toggle they activate when
         | building the ROM...
        
         | abecedarius wrote:
         | Google Search withdrew from China when China went over the
         | line, as they saw it.
        
         | lyu07282 wrote:
         | I think the way it probably works is that if the US gov. wants
         | to root someones phone anywhere in the world they just do it
         | via some API given to them by apple/google directly.
         | 
         | If a foreign country wants to do it to someone on foreign soil
         | (like the saudis to bezos did [1]) they exploit some
         | vulnerability brought on the free market (like the
         | whatsapp/video message exploit chain the saudis used, or
         | exploits like the NSO zero-click iMessage exploit [2]).
         | 
         | If a foreign country wants to spy on its own citizens who
         | protest the government, they could just use the local phone
         | carriers capability to silently ping, update firmware or change
         | system settings remotely, those are intentionally part of the
         | mobile standards (including intentionally weak encryption) so
         | governments can spy on its people.
         | 
         | [1] https://www.wired.com/story/bezos-phone-hack-mbs-saudi-
         | arabi... [2] https://www.wired.com/story/apple-imessage-zero-
         | click-hacks/
        
       | ofslidingfeet wrote:
       | We already know for a fact that they can surveil virtually all
       | smart devices including appliances and televisions due to the
       | Vault 7 leaks, and this would tend to be corroborated by the
       | national geospatial intelligence agency telling congress that
       | they have a high resolution 3d map of the entire globe's events
       | at any given time.
        
         | aftbit wrote:
         | Here is a link to Vault 7 on WikiLeaks:
         | https://wikileaks.org/vault7/
         | 
         | Here's a link to Wikipedia's article on the leaks:
         | https://en.wikipedia.org/wiki/Vault_7
         | 
         | The only one that mentions televisions is Weeping Angel (cool
         | name) which attacks Samsung F Series Smart Televisions. Likely
         | they can indeed target other devices but I'm not sure I'd go as
         | far as saying that Vault 7 shows that they can target
         | "virtually all smart devices".
         | 
         | Or am I missing something? Can anyone provide more concrete
         | evidence?
        
           | ofslidingfeet wrote:
           | I probably just got confused, but thank you for linking to
           | the information about Vault 7 directly so that anyone can
           | simply appraise for themselves whether or not I seem
           | confused.
           | 
           | That's what I love about HN and Reddit, and similar websites:
           | All the helpful counterpoint, especially when someone
           | criticizes the intelligence community. Thank you so much!
        
       | bambax wrote:
       | A little OT but strongly related: in France you can go to prison
       | if you refuse to give your phone's password to the police
       | (nothing like a "free country", I guess).
       | 
       | Is there a way to set up a phone so that typing a "special"
       | password puts the phone in an alternate state with different apps
       | and content, etc. (and possibly erase the regular content)?
        
         | ElDji wrote:
         | You simply comply and give your phone PIN that somehow doesn't
         | work.
        
         | flangola7 wrote:
         | - I presume that's considered willful destruction of evidence
         | and interfering with an official investigation, and worse
         | charges than whatever you were probably facing (unless you
         | really did fuck up and committed something bad).
         | 
         | - Investigators are not going to be typing your password into
         | the running original device, they're going to be trying it
         | against an offline clone of the encrypted storage. All that
         | will happen is the decryption won't succeed and they'll tell
         | you that it was the incorrect password and continue holding you
         | until you give it up.
         | 
         | - This is hardly unique to France, US courts have jailed
         | suspects for refusing to provide passwords in numerous cases.
         | https://arstechnica.com/tech-policy/2017/03/man-jailed-indef...
        
           | godelski wrote:
           | On point 3, while I agree he shouldn't be required to give up
           | his password, we should note that they did find child porn on
           | other devices and that there is testimony from another
           | witness of more porn on those hard drives. I'm just saying
           | that this is a bit different than there being no sufficiently
           | prosecutable evidence and the courts requiring it. In fact,
           | that's why they claim his 5th Amendment rights aren't
           | violated (though obviously the length of his sentence relies
           | upon that). He could currently be prosecuted under the
           | current evidence, and that matters.
           | 
           | https://cdn.arstechnica.net/wp-
           | content/uploads/2017/03/rawls...
        
           | vhcr wrote:
           | About point 2, modern devices have a secure enclave, which
           | means that copying the encryption key is pretty much
           | impossible.
        
             | flangola7 wrote:
             | Impossible for the average thief, not impossible for
             | government or Fortune 500 actors. There are private
             | contractors in business solely dedicated to developing and
             | licensing enclave cracks, and popping them is routine
             | procedure for most law enforcement departments, even
             | smaller ones.
             | 
             | Fundamentally you can't have a key and the data inside the
             | same physical box and expect encryption to remain intact.
             | Enclaves are just security through obscurity on steroids.
        
           | bambax wrote:
           | > _Investigators are not going to be typing your password
           | into the running original device, they 're going to be trying
           | it against an offline clone of the encrypted storage_
           | 
           | Oh no, absolutely not. We're not talking about
           | "investigators" here, just random cops in a random precinct
           | who have zero infrastructure, zero knowledge about anything,
           | and aren't pursuing any serious "investigation".
           | 
           | They will absolutely type your password into the running
           | device. They're doing this all the time.
        
       | rolph wrote:
       | nuggets to supplement discussion
       | 
       | https://en.wikipedia.org/wiki/Baseband_processor
        
       | GeekyBear wrote:
       | Can the thing France just made legal be done?
       | 
       | > French police should be able to spy on suspects by remotely
       | activating the camera, microphone and GPS of their phones and
       | other devices, lawmakers agreed late on Wednesday, July 5.
       | 
       | https://www.lemonde.fr/en/france/article/2023/07/06/france-s...
       | 
       | Why would anyone stir up the civil libertarians if the thing you
       | are making legal is not possible?
        
         | wombat-man wrote:
         | I would assume this is possible. If the gov wants to bad
         | enough, I'd guess most OSes have a way to remotely control and
         | observe. A state has resources to research 0days, bank them,
         | and use them as needed. But probably not worth using unless
         | it's for a high value target.
        
           | dvhh wrote:
           | Considering most mobile phone operator would require you to
           | install additional software to be able to use their network
           | and that they would most likely cooperate with the authority
           | if asked by the justice department.
        
             | nickserv wrote:
             | That's not the case in France.
             | 
             | You can use any unlocked phone with any operator (assuming
             | it can connect to EU cellular networks of course). Nothing
             | in particular to do, just put in the SIM and it works.
             | 
             | I've never bought a phone from an operator, but I think
             | it's also possible to switch operators without switching
             | phones quite easily, no software update required.
        
           | Simorgh wrote:
           | Well, what would be considered a high-value target?
           | 
           | Even if warrants are initially mandated for a specific
           | search, couldn't this erode into, 'it's just a quick scan'?
           | 
           | What if it's 'useful' to 'quick scan' their own President?
           | 'Confirming their security'.
           | 
           | Could this evolve into a subtle shift in the balance of
           | power? In other words, a political crisis?
           | 
           | Where the intelligence agencies have informational advantages
           | over any elected office.
           | 
           | From information into knowledge, you could easily have behind
           | the scenes figures who have unmatchable insight and ability
           | to coordinate.
           | 
           | Suddenly every target has value...
        
             | wombat-man wrote:
             | This is a rambling post...
             | 
             | I don't know what argument you're trying to make.
             | Governments will research 0days because other governments
             | are doing it, and it's best if you find them first and work
             | out a defense. You know, in case you want to mess with
             | someone's nuclear centrifuges and to avoid having yours
             | screwed with.
             | 
             | Do you think that it should not be legal for the government
             | to investigate a crime?
             | 
             | The system is made up of people, some of them may abuse
             | their access. Other laws, in theory, will hold them to
             | account.
        
         | kelipso wrote:
         | More than likely what happened is they made it so it's easily
         | doable by barely trained cops and then they secretly lobbied to
         | make it legal.
        
       | vxxzy wrote:
       | This question has been in my head recently. How feasible is it
       | really? The answer in the link isn't comprehensive. Is it really
       | out of the question for manufacturer's to ship a particular
       | version of a device and software for a target country? Nation
       | states have a history of backdooring or weakening particular
       | technologies.
        
         | anonym29 wrote:
         | Baseband backdoor. No need to target the OS or the primary CPU.
        
           | squarefoot wrote:
           | Exactly, and we're talking about governments, not competing
           | companies. "You wanna sell phones or build infrastructure
           | here? Fine, here's a truckload of appliances to put in the
           | middle of each pipe; no questions please". There are many
           | ways a government can ruin businesses even without swatting
           | their offices or raise public anger, they just need to apply
           | different bureaucratic pressure where it is needed so that
           | for example a permit, tax installment or reduction, whatever
           | that otherwise would take 6 months will require say 5 years
           | or more.
        
           | aftbit wrote:
           | Are basebands not sandboxed at all? There's no conceivable
           | reason that my baseband should be able to access my camera,
           | microphone, or the contents of my display in normal
           | production use, as that's all filtered through the CPU
           | typically. Why not have an MMU that limits the baseband to
           | DMA in a specific chunk of memory and reduce the attack
           | surface dramatically? It's not just effective against nation
           | states. With such a protection, 0-click OTA attacks targeting
           | the baseband would have a much smaller blast radius.
        
             | Veserv wrote:
             | Historically the baseband was the primary processor with
             | full control and the CPU was subordinate. This is because
             | the baseband code was developed by the chip manufacturer so
             | they gave themselves full control over the system to make
             | it easier for themselves.
             | 
             | This may no longer be the case right now as the primacy of
             | the CPU has become increasingly obvious, but it should
             | still be the default assumption since having the baseband
             | in control lowers costs to the chip manufacturer which is
             | their lifeblood.
        
           | euniceee3 wrote:
           | Any signs of these in the wild?
           | 
           | I know it is a valid threat, but even in the cases that set
           | this precedent there was a team of 140 and they did not
           | leverage a baseband exploit.
        
             | aSockPuppeteer wrote:
             | I only have my experience with this so it requires you to
             | have a phone that is off and without a battery or in a
             | faraday(foil) shielded bag. Be in an area your government
             | doesn't want regular people to be (unacknowledged military
             | base), turn on the phone.
             | 
             | I've done this many times so I know how long it takes to
             | power on my phone to a "usable" state on my iphone and
             | android.
             | 
             | I can't take my phone inside where I work and they have
             | mobile phone detectors which set off alarms if you bring
             | one near any door or the inner facility fence. I put my
             | phones inside a foil cooler bag with ice packs so they
             | won't overheat inside the car.
             | 
             | My guess is that there was a cell site simulator and it was
             | setup to take over any phone which comes in the area. I got
             | the same result with my android and iphone. Phone boots,
             | weird hang where all indicators appear but I cannot
             | interact with the phone. Wait at least one minute then I
             | can use the phone.
             | 
             | I think this is why governments don't like China developed
             | 5G technology. It doesn't have their default back doors.
        
             | zozbot234 wrote:
             | How could we know for sure? Basebands are 100% proprietary,
             | we have no idea how they operate and even less of an idea
             | of how their operation might be subverted.
        
               | anonym29 wrote:
               | This is why I'm an open source advocate. It's not that
               | open source automatically makes software/firmware
               | trustworthy, it's that closed source empirically
               | guarantees the software/firmware can never be deemed
               | trustworthy.
        
               | scarface_74 wrote:
               | And yet there have been plenty of long standing security
               | issues in Linux...
               | 
               | Why would you think that a bunch of people volunteering
               | their time would be more motivated to look for security
               | issues and even those that are found, how many would be
               | disclosed responsibly instead of being sold to places
               | like Pegasus?
        
               | yjftsjthsd-h wrote:
               | Nobody said that FOSS was perfect, only better.
        
               | pessimizer wrote:
               | FOSS doesn't mean "volunteers." FOSS means that the
               | source is viewable, legally usable, and that changes can
               | be made and redistributed without permission from the
               | author(s).
               | 
               | Volunteers can make closed source software, massive
               | corporations and governments can make FOSS.
        
               | anonym29 wrote:
               | >And yet there have been plenty of long standing security
               | issues in Linux...
               | 
               | * See the first half of my second sentence.
               | 
               | >Why would you think that a bunch of people volunteering
               | their time would be more motivated to look for security
               | issues
               | 
               | * So they're not harmed by the vulnerabilities. I'm on a
               | big tech red team. I routinely look for (and report)
               | vulns in open source software that I use - for my own
               | selfish benefit.
               | 
               | >and even those that are found, how many would be
               | disclosed responsibly instead of being sold to places
               | like Pegasus?
               | 
               | * Not all of them, that's a fair point. But I'd rather
               | have the ability to look for them in source than need to
               | look for them in assembly.
               | 
               | * Keep in mind that the alternative you're proposing
               | (that proprietary code can be more trustworthy than open
               | source code) is pretty much immediately undermined by the
               | fact that the entities who produce proprietary code are
               | known to actively cooperate and collaborate with the
               | adversary - look no further than PRISM for an example.
               | Microsoft, for instance, didn't reluctantly accept - they
               | were the first ones on board and had fully integrated
               | years before the second service provider to join (yahoo,
               | iirc).
               | 
               | * If you want to start a leaderboard for "most prolific
               | distributor of vulnerable code", let's see how the Linux
               | project stacks up against Adobe and Microsoft. I wouldn't
               | even need to research that one to place a financial bet
               | against "team proprietary".
        
               | smoldesu wrote:
               | > Why would you think that a bunch of people volunteering
               | their time would be more motivated to look for security
               | issues
               | 
               | I don't. I trust that bad actors are less motivated to
               | insert malicious code, and I trust that transparency
               | enforces good practices. All sufficiently complex code
               | has unintended behavior, what matters to me is how you
               | stop third parties from using my device beyond my
               | control.
               | 
               | > and even those that are found, how many would be
               | disclosed responsibly instead of being sold to places
               | like Pegasus?
               | 
               | What do you think everyone else does with their no-click
               | exploits? Send them to Santa?
        
             | anonym29 wrote:
             | Absence of evidence is not evidence of absence, especially
             | when searching for evidence left behind by competent
             | adversaries (e.g. NSA, GCHQ, etc) who have a strong
             | motivation to remain undetected.
        
               | dragonwriter wrote:
               | > Absence of evidence is not evidence of absence
               | 
               | But it is also not evidence of the thing for which there
               | is absence of evidence.
               | 
               | EDIT:
               | 
               | > especially when searching for evidence left behind by
               | competent adversaries (e.g. NSA, GCHQ, etc) who have a
               | strong motivation to remain undetected.
               | 
               | No, there is no "especially"; absence of evidence means
               | no basis for any affirmative belief, period, equally for
               | any fact proposition. Arguing for "especially... " is
               | exactly arguing for a case where absence of evidence is
               | evidence for the thing for which there is an absence of
               | evidence.
        
               | anonym29 wrote:
               | I'm not asserting that it is.
               | 
               | In risk management, you shouldn't ignore known unknowns
               | like that, you should either adapt your threat model or
               | risk accept, not simply consider that risk nonexistent
               | until proven.
        
         | godelski wrote:
         | > Is it really out of the question for manufacturer's to ship a
         | particular version of a device and software for a target
         | country?
         | 
         | Another means: is it really infeasible for a nation state to
         | intercept and modify devices that are being sent to a specific
         | country/person?
        
       | zozbot234 wrote:
       | This answer is dangerously naive. Phone basebands and radios are
       | full of vulnerabilities, if you don't want your phone to be a
       | potential surveillance device given any minimally sophisticated
       | adversary you should either turn off the radio or preferably shut
       | it off entirely and remove the battery.
        
         | anonym29 wrote:
         | Hypothesis B: it's not dangerously naive, it's deliberate
         | misinformation designed to coax technical but unskeptical
         | people into lowering their guard against this class of threat.
        
           | zozbot234 wrote:
           | Of course, but see Hanlon's razor.
        
             | anonym29 wrote:
             | Sounds like the perfect cover for malice, lol
             | 
             | If ((Assume it's stupidity) == (discount/ignore the risk)),
             | then assuming it's stupidity is never the safer assumption,
             | even if it's empirically more likely to be the correct
             | assumption, no?
             | 
             | All boils down to an individual's threat model at the end
             | of the day anyway, though.
        
               | rgrieselhuber wrote:
               | I'm always amazed at how many people don't understand
               | this. Hanlon's Razor is just a way to sound smart while
               | indulging in self-soothing biases.
        
               | zopa wrote:
               | Malice is not falsifiable: anything could always just be
               | another trick. So unless you want to end up believing
               | everything is malice, it's best to start with the benign
               | explanations, until you're sure they don't fit.
        
               | rgrieselhuber wrote:
               | The context here is government spying on its own
               | citizens. Not sure how that warrants starting with benign
               | explanations.
        
               | mdp2021 wrote:
               | "Stupidity" (term picked after Cipolla) is not a benign
               | explanation. The entity stuck in the ice of Cocitus, at
               | the bottom of hell, in Dante Alighieri's Commedia, is an
               | apex of impotence.
               | 
               | But yes, it is an interesting proposal (perspective) to
               | "resist from tempting explanation and picking the less
               | attractive first" - just like the grit in delayed
               | gratification.
        
               | mdp2021 wrote:
               | The practice of assessing whether a tempting evaluation
               | of "malice" can instead cover evidence of structural
               | faults is part of the effort towards seeing things as
               | they are. And keeps you away from paranoia.
        
               | anonym29 wrote:
               | Spoken like someone being paid to stigmatize rational
               | skepticism.
        
               | mdp2021 wrote:
               | I proposed rational skepticism.
        
               | rgrieselhuber wrote:
               | The notion that paranoia is the default emergent state of
               | not assuming incompetence when potential malicious
               | incentives can be easily articulated is just yet another
               | ideological presupposition.
        
               | mdp2021 wrote:
               | That part about paranoia was a half-joke. But no, it was
               | not suggested (that was not a <<notion>>) that paranoia
               | would be a <<default emergent state>>. It is tough a
               | temptation of many.
               | 
               | And while you will often be able to identify <<potential
               | malicious incentives>>, you have to put those
               | possibilities together with the rest of those which can
               | complete the set.
               | 
               | Assessments must be complete.
               | 
               | --
               | 
               | Edit: oh, by the way, importantly: _paranoia_ ( "off-
               | thought") means "delusionality", and in that sense the
               | statement <<And keeps you away from paranoia>> was
               | literal. "Be "cool" and exhaustive in assessment, and you
               | will avoid getting stuck in alluring stories". The half
               | joke was about the current use of the term (in the
               | popular interpretation of the clinical state).
        
               | rgrieselhuber wrote:
               | I think it's fair to say that money / power / sex will
               | easily account for potential malicious incentives. The
               | mindset that Hanlon's Razor fosters slows down the
               | pattern recognition process that humans have built up
               | throughout our entire existence. When building systems
               | that must be resilient against corruption, the concept of
               | zero trust serves well here.
        
               | mdp2021 wrote:
               | But you have to always check. Yes, you do slow down <<the
               | pattern recognition process that humans have built up
               | throughout>>: because it is not reliable. It becomes
               | (more) reliable through the exercise of doubt and
               | assessment.
        
         | DANmode wrote:
         | Shutting it off, if actually done, is the only way to stop
         | future upload of payload.
         | 
         | Say, a transcribed text of a conversation, for example's sake.
        
       | numpad0 wrote:
       | What's the path of least resistance to find RCE on baseband?
        
       | alexawarrior wrote:
       | Any broadband chip since 3G ships with proprietary drivers which
       | have backdoors. I tried to build an open phone, worked for one of
       | the major telcos, and could never get around the driver issue in
       | trying to make an open phone.
       | 
       | BUT sophisticated attackers like US or Israeli governments (and I
       | assume Russian or Chinese but I don't have direct experience with
       | these) don't need these backdoors, getting anywhere near your
       | phone is enough to root it to allow installation of spyware,
       | according to my CSO who worked in naval intelligence. There are
       | simply too many vulnerabilities for there to be a hardened device
       | in the consumer space. Some are better than others (Apple) but as
       | Bruce Schneier says, if you are worried about this sort of thing
       | you really have to be totally disconnected from the internet and
       | exchange encrypted physical media.
        
         | seba_dos1 wrote:
         | Depends on where you put the line between "open phone" and
         | "baseband blackbox". Drivers are not an issue for phones like
         | Librem 5 or PinePhone since they're using a separate modem
         | module connected to the main SoC via USB and communicating over
         | AT and QMI interfaces to which there are perfectly open
         | drivers. The modem itself remains a vulnerable proprietary
         | blackbox, but it does not have any access to your OS and you
         | can cut it out from power while keeping the rest of the phone
         | intact.
         | 
         | Open basebands are not something we're anywhere close to having
         | though, for many reasons.
        
       | user6723 wrote:
       | Google Play is a rootkit. Google will fully cooperate with any
       | government. If you use GrapheneOS on a pixel device your
       | bootloader is closed source and the system-on-chip is largely
       | undocumented and impossible to audit without serious resources.
       | So yeah. Shit's fucked man.
        
         | TacticalCoder wrote:
         | > Google will fully cooperate with any government.
         | 
         | I'll remind you that on previous MacOS versions (8 years ago?)
         | researchers had discovered that the Mac laptop's integrated
         | webcam could be turned on _without_ the green LED turning on.
         | So basically: the webcam turning on without the user knowing
         | it. And way weirder: some random company somehow had the rights
         | to sign code using that  "feature".
         | 
         | The story got pretty much killed.
         | 
         | I'm sure if some digging had been done, you'd have found some
         | three letter agency behind the shell company enjoying the very
         | strange right to turn the webcam on on MacOS devices without
         | the LED turning on.
         | 
         | For everybody out there: rest assured though, Apple are the
         | good guys and there's no way they have the ability to turn on
         | the webcam of your Mac laptop today without you knowing about
         | it. [1]
         | 
         | [1] yes, this is sarcasm
        
           | DANmode wrote:
           | Related: https://www.digitaltrends.com/mobile/facebook-ios-
           | camera-bug...
        
       | godelski wrote:
       | IANAL nor French, but reading the article, is this just saying
       | that French police can get a warrant, issued by a judge, that
       | allows them to tap a suspect's device (not longer than 6 months)?
       | I just want to make sure I got the facts right.
       | 
       | https://www.lemonde.fr/en/france/article/2023/07/06/france-s...
        
         | joebiden2 wrote:
         | As far as I understand that, since there is no explicit clause
         | prohibiting an extension after 6 months. I think it is safe to
         | assume that it can be extended by another 6 months provided the
         | suspicion persists (i.e. a judge can be convinced).
         | 
         | I'm not french myself, so take it with a grain of salt.
        
       | qup wrote:
       | Is there some kind of vote bot ring or something?
       | 
       | This is a question with one short answer (at the time of my
       | comment). It's hard to imagine why it made the top on its own
       | merits.
        
         | superchroma wrote:
         | Most likely, moderation is on pause at Stack Exchange due to
         | ongoing feuds with management.
        
         | freecodyx wrote:
         | But it's a good question. I want to know. I am assuming this is
         | not possible. The only thing i know of is capable of doing so
         | is pegasus. But it's very expensive afak.
        
           | anonym29 wrote:
           | You don't know what code is running on your baseband
           | processor, do you?
           | 
           | Do you know what other hardware your baseband processor has
           | the ability to inspect?
        
             | freecodyx wrote:
             | Ok but we are talking remotely enabling camera and
             | microphone. The baseband is only responsible of
             | intercepting traffic. This needs kernel injection.
        
             | zozbot234 wrote:
             | In most SoC's the answer is 'everything' because there's no
             | such thing as an IOMMU.
        
               | paulryanrogers wrote:
               | How big a concern is this if the data is encrypted by the
               | kernel or user space?
        
               | ignoramous wrote:
               | There are atleast 2 more exception levels with higher
               | privileges than the Kernel on arm64.
        
               | Veserv wrote:
               | Encryption does not help in this case. They have complete
               | remote control over the entire CPU so they can just run
               | the decryption code directly.
               | 
               | Encryption only helps if the endpoints that can get
               | access to the plaintext are not compromised.
        
               | numpad0 wrote:
               | Why's IOMMU thrown around so casually in this forum as if
               | it's a silver-bullet explosive reactive armors? They'd be
               | running something like 30 years old giant main loop with
               | "// don't remove this line, build breaks" comments
               | everywhere, not like Rust microservices on formally
               | verified microkernel.
               | 
               | The main CPU/application processor/main CPU might be
               | running better secured Unix/Linux and might be able to
               | protect itself from peripheral CPUs, but that's not the
               | point; a phone had always been a pair (minimum) of
               | computers, traditionally referred to as Application
               | Processor(AP) and Baseband Processor(BP), of only the
               | slightly faster one is exposed to the user, and it's
               | unclear what is going on inside the other one or how to
               | handle it. That's the problem.
        
               | anonym29 wrote:
               | Ding ding ding, we have a winner!
        
               | moyix wrote:
               | I was under the impression that most modern (past few
               | years) SoCs like Exynos, Qualcomm, Apple silicon all had
               | IOMMU support. Sometimes it's misconfigured to be too
               | permissive but that's getting better.
               | 
               | Qualcomm SMMU:
               | https://www.qualcomm.com/content/dam/qcomm-martech/dm-
               | assets...
               | 
               | Apple: https://support.apple.com/lt-
               | lt/guide/security/seca4960c2b5/...
               | 
               | Samsung (vuln indicating it wasn't configured correctly,
               | but they still do have and use an IOMMU):
               | https://nvd.nist.gov/vuln/detail/CVE-2022-39854
        
           | Veserv wrote:
           | It costs about 2-5M$ to buy or develop a new weaponized zero-
           | click vulnerability that would allow you to simultaneously
           | hack all 1,000,000,000 iPhones in use. So around 1/20 of a
           | cent per iPhone.
        
             | abwizz wrote:
             | even for the single use case, 5M$ is not that far fetched
             | in terms of opportunity cost.
        
         | joebiden2 wrote:
         | No, it's not a bot ring. I assume you think that because I
         | posted links to stackexchange quite a few times the last few
         | months. Instead, I just skim over stackexchange.com as part of
         | my feed and when there's something what I assume HN interests,
         | I post it here.
         | 
         | I don't care much about Karma. I posted this specific topic
         | since I find it kind of hilarious that police should now
         | lawfully be able to do something they are almost surely not
         | able to do. And I enjoy discussions to such topics here on HN,
         | because most of the time the viewpoints mentioned here are at
         | least of the same quality of the answers on stackexchange.
        
           | qup wrote:
           | It seemed ridiculous to me that it could make the top of HN.
           | It was a question with no discussion, yet.
           | 
           | If it had a discussion or even a good answer, it would have
           | made perfect sense.
           | 
           | I assumed the goal would be stack overflow karma, as that's
           | actually valuable.
        
             | godelski wrote:
             | It rose to the top because of the question, the link about
             | France, and because new posts get higher weights. It is at
             | 79pts and 59 comments currently and about to fall off the
             | front page. But also on the front page is a post with 6pts
             | and 1 comment (1hr old), 17 points and 2 comments (2 hrs),
             | 7pts and 2 comments (30 minutes). and a few more. Just a
             | slow Saturday.
        
             | throwawayadvsec wrote:
             | Or maybe it's the perfect place to discuss this kind of
             | topics.
             | 
             | An Ask HN with the same kind of question could have reached
             | the front page.
        
         | generalizations wrote:
         | I agree, and it's not even a good answer.
        
       | l8_to_catch_up wrote:
       | I know for a fact that my electronics (including smartphone) is
       | being monitored (including this post) by my government.
       | 
       | That probably doesn't surprise others. What isn't as known is
       | that the government also intrudes into chats with other people on
       | social media.
       | 
       | They don't just monitor, but actively interfere.
       | 
       | Edit: By the way, Nokias and other dumbphones (without physical
       | off-switches -- the PinePhone has them, but good luck getting
       | one) can also get their mic and GPS remotely activated. The
       | partial solution is to get one with a removable battery and
       | remove the battery whenever not in use.
       | 
       | iPhones can be hacked into through IMEI if you connect them, but
       | are useful, encrypted offline-only PDAs if you don't install any
       | app.
       | 
       | Also, if your electronics are being spied on by the government to
       | this degree, chances are you are also being physically monitored.
        
         | woozy3756 wrote:
         | [dead]
        
       ___________________________________________________________________
       (page generated 2023-07-08 23:02 UTC)