Re: Privacy Concerns with UbuntuPhone
Paul Campbell <[email protected]>
| Newsgroups | gmane.org.user-groups.linux.dunedin.general |
|---|---|
| Message-ID | <3286187.031SSGvrFj@rata> |
On Tue, 22 Apr 2014 15:24:56 Danyl Strype wrote: e a proprietary baseband? > > Paul: > >> it's likely that cell companies would not allow phones with easily > >> hackable baseband stacks on their networks (they wouldn't let you have > >> a SIM). the problem is that cell services use protocols that depend on > >> all phones playing nicely with each other << > This is a horrific situation, comparable to being forced to run a > proprietary network driver in order to be allowed access to an > internet connection, and it sounds like security by obscurity yes very definitely not only don't we know if that firmware is malicious (say spying or the NSA/GCSB/etc), we also don't know whether or not it's buggy and full of security holes >. If the > baseband hardware and software are proprietary, how can the cell > companies know whether it's going to play nicely or not until the > first phone with that baseband joins the network? If the hardware had > publicly documented specs, and the software were free code, the cell > companies would be able to run tests and audit the code. The cell companies (and manufacturers) set up conformance labs and pay for conformance testing - the test the behaviour of the phones rather than looking at the insides > Correct me if I'm wrong, but we're talking about firmware here. Not > just something a user can muck around with from a GUI. Even in a 100% > free phone, to change the firmware you'd have to flash the chip, the > same way you jailbreak an iPhone, right? So yes, a hacked phone could > cause problems, but I can't see why a 100% free baseband is any more > likely to be a problem in that respect than a proprietary one. it's code like any other, it may or may not be running on the same CPU (or another CPU on the same die) as the rest of the code - in particular it may be able to bypass the MMU and all the OS checks and protection that are done with it > Paul: > >> one hacked phone could easily bring down a cell tower or two << > > Sound like yet another good reason to replace the cell phone network > with a modern, more resilient network, running ethernet over wifi? wifi's just the same - just takes one node (or microwave oven) not playing by the rules at the lowest level - remember the wifi band is a free for all, not just for wifi, your neighbour can do anything they like there, not using the wifi protocols provided they meet the emission level and frequency rules - we just happen to mostly use it for wifi Petition the government for "white space" legislation - the basic idea is that ALL spectrum should be usable like the wifi band, provided we all promise to play well with others (smart software to find unused spots on the fly) > Paul: > >> I think the real solution to this problem is hardware architecture that > >> isolates the baseband part of the phone and treats it as potentially > >> hostile (rather than giving it free range through memory) << > This would certainly be an improvement, and the ArduPhone Jim mentions > would prevent many of the potential unintended consequences where > proprietary modules have access to personal data like address books, > call logs, saved texts/emails etc. Has this approach been considered > for the UbunutPhone, Thomi? I think that Ubuntu probably want to port to as many platforms as possible, they are probably limited by the hardware currently being produced for mass market phones (ie android), while they could get changes made to 1 or 2 particular phones no one is likely to spin all the silicon from all the chip companies just for them > >> There's probably no need to compromise the baseband, as by design and > >> desired operation is is a spy unit, and the telco already has all your > >> data (aka 'metadata', which just means 'data' in this context). << > I'm sorry, I just don't accept this. I can have an end-to-end > encrypted voice conversation across the internet with an AspireOne and > Trisquel, where no part of the software or hardware stack is a "spy > unit" (that I know of). I see no good reason this shouldn't be > possible with a handheld PC, instead of a desktop or laptop, and no > reason to accept the presence of modules designed to be spy units in > any computer I use. yes and that unchecked baseband firmware can bypass the MMU, dip into memory and steal your private keys and pass phrases Basically you need hardware you control and can verify - and hardware costs money :-( the tendency in the hardware biz is to push everything into one package to save power and money - that means your baseband processor is probably already in the same SoC as your GUI/OS CPUs, if it isn't already timeslicing on them BTW that "verify" is important - I was in China a couple of weeks ago and saw the insides of the Chinese cell phone recycling infrastructure, walked through a building a big block long full of stalls and workshops (called "the dodgy cell phone market" by the western hardware hackers who were showing us around) - phones came in one end, were rendered into their component parts, and made back into whole phones at the other - people honestly do not know what's in their phones, even if for some reason you trust Samsung and Apple you still don't know what you really have and where the chips have come from. (having said this recycling phones is fundamentally a good thing, every else but the west people fix broken phones, we throw ours away - we should make sure they get to places like this in China and India so that they live another life) Paul _______________________________________________ DunLUG mailing list [email protected] http://lists.ethernal.org/listinfo/dunlug DunLUG Wiki - http://dunlug.kallisti.net.nz/