It is running under QSEE (Qualcomm) and/or MobiCore (Trustonic) OS, which is separate from your Android OS. It is left untouched by custom ROMs.
It is running under QSEE (Qualcomm) and/or MobiCore (Trustonic) OS, which is separate from your Android OS. It is left untouched by custom ROMs.
https://www.qualcomm.com/products/izat
Scroll down to "Cloud-Based Assistance" and "Built Right In."
Even if there was a separate OS running in parallel with Android, how could it access the wireless-networks-based and satellite-based location data? I thought that access to these things is controlled by Android.
In other words, when I turn off e.g. satellite location data in Android, can IZat (which, according to your post, runs outside of Android) or other similar spyware keep secretly using it anyway? That would be quite worrying.
I suppose that the location data can be collected by sniffing the low-level communication between the radio device and Android kernel, provided that it has been enabled in Android first. But even then, how could this location data be transferred out of the device? Are these "parallel-running" OSs also able to somehow "tap into" Android's network layer and send the collected data out?
"Even if there was a separate OS running in parallel with Android, how could it access the wireless-networks-based and satellite-based location data? I thought that access to these things is controlled by Android."
There is a separate OS running in parallel with Android and it is running on the very hardware that makes the network connections to the cellular network that you are speaking of.
In fact there are two - the OS and software stack that run on the baseband processor and the OS and software (java apps) that run on your SIM card, which is a full blown computer with its own memory and processor, etc. In fact, your carrier can upload new java programs to your SIM card without your knowledge at any time.
Your final question is a good one - many (most ?) implementations give the baseband processor DMA to the main, application processor. So you are hopelessly owned. Deeply, profoundly, hopelessly owned.
1. Linux Kernel / Android OS, running on main ARM CPU in "normal mode"
2. QSEE or Trustonic OS, running on main ARM CPU in "trusted execution environment" mode, in parallel with "normal mode"
3. OKL4 / REX Kernel + AMSS OS, running on the baseband CPU (modem)
4. SIM card processor, although it is very limited (typically 32k RAM) and acts only as a MITM for SMS's, not cellular data
5. The OS running on the Wi-Fi card
All the core silicon is wrapped up in huge quantities of NDAs and licensing agreements. You buy a baseband, and the mfg gives you a blob you can either use, or not use the baseband.
Since then, things went really bad, really fast, just no one noticed.
That's why I don't mind being "that guy" in social situations when these issues are brought up.
> how could it access the wireless-networks-based and satellite-based location data?
The OS is either running on the same hardware as Android or has the same direct hardware connections.
> I thought that access to these things is controlled by Android.
Only for things executing within Android. This is just a fancy UI - Android doesn't actually control the hardware.
> In other words, when I turn off e.g. satellite location data in Android, can IZat (which, according to your post, runs outside of Android) or other similar spyware keep secretly using it anyway?
Yes.
> I suppose that the location data can be collected by sniffing the low-level communication between the radio device and Android kernel, provided that it has been enabled in Android first.
You shouldn't think of it as between the radio device and Android but rather between the radio device and the CPU. A CPU that another OS can and is running on. Android is not special here.
> But even then, how could this location data be transferred out of the device?
The same way Android sends data out of the device. The OS asks the CPU asks the radio to transmit some data. Bog standard.
> Are these "parallel-running" OSs also able to somehow "tap into" Android's network layer and send the collected data out?
Yeah but like I said its not Android's network layer. Android is a guest on top of the system just like any other OS running.
These OS images are untouched by your custom ROM because they're black box.
https://www.youtube.com/watch?v=31D94QOo2gY
The baseband is a completely different RTOS as well. And then there's also TrustZone running in the SOC as well.