The second operating system hiding in every mobile phone (2013)
osnews.com
osnews.com
In the meantime, is there a refactor/rewrite of that '90 code bash that is full of bugs and unused functions? And if so, do any phone manufactures use that improve "firmware"?
This is on the RF manufacturers: Qualcomm, MediaTek, Spreadtrum, Samsung LSI & HiSilicon (Huawei).
Both the two major phone vendors --- Google and Apple --- have teams of people who are acutely aware of the baseband thread, many of whom are equally as talented as RPW.
Further, though the article seems carefully written enough to avoid the misconception, the basebands on modern phones don't get direct access to AP memory, but are instead connected over a high-speed serial connection with a limited command set.
That's good to know; for some reason I had an idea that it was all done via DMA.
Any idea about how exploitable that command set is?
Also, for trust to be thrown out the window, a lot of changes would probably need to happen both in baseband software and in the networks themselves. Not seeing that happening anytime soon.
I read that it can not be removed not even by reinstalling the OS. But it looks like PC manufacturers like Lenovo found a way to hide the same rootkit in their BIOS.
https://security.stackexchange.com/questions/53698/detecting...
The FCC will require signed builds on radio hardware shortly after that.
Best outcome is to have a vetted open source baseband project with reproducible builds so we can verify our signed binaries.
They aren't understood since standards such as LTE are very complex, tying in RF hardware, DSP in ASICs, and software.