Unremovable malware found preinstalled on low-end smartphone sold in the US
zdnet.com
zdnet.com
This especially sucks because the people who can't afford a good phone will pay not only in having a poorer user experience but they'll have their financial and social media information stolen as soon as its used on these devices.
That means the people who can least afford (via both time and money) to deal with identity theft will be the ones hit the hardest.
The cheapest device that I trusted was the Pixel 3a, and that's because I can cleanly install GrapheneOS and not have google play install. That was $400. It was very tempting to get a $100 phone, but this was my exact worry.
For example many German (EU?) Banks now have some form of 2FA system for credit card payments which requires a Android/iPhone app which does only run on non rooted certified phones. (Through it should be noted that in Germany credit card is not the major payment method and many people don't even have one, instead dbit cards with V-Pay, giropay, etc. are dominant. )
As a site note this is also the case for their online banking Apps, but you can just use their website instead.
...unless their website also has 2FA, and relies on an Android/Apple app for auth. Or you pay them money to lug around a USB device for 2FA.
For both people who have dumbphones or run custom ROMs, despite the security risks, there should still be an SMS-2FA option.
These low-end phones, preloaded with malware, and likely running and outdated and vulnerable version of the base OS with no hope of patches...
Having a hope of being successful in our society right now in any meaningful way requires some level of access to the internet and these bare-minimum phones are it for a lot of people. Security online is a massive social issue that we can't rely on end-user awareness to solve.
This is a supply chain attack that only hurts the worse off. You're on this site which in its own way gives you a certain baseline technical merit; You're actively are aware of the threat of these low-end phones so you don't fall into that potential trap.
The people that can't make that jump between the $100 and $400 phone shouldn't have to deal with additional ongoing personal and financial repercussions from trying to participate in our modern society.
Prior discussion from 2016: https://news.ycombinator.com/item?id=10905643
So yeah, the baseband firmware is a huge vulnerability. But if you use a separate modem/router, and disable the onboard baseband, that's far less of an issue.
And with the PinePhone, it's easy: https://wiki.pine64.org/index.php/PinePhone#Killswitch_confi...
The Register reported the avaerge time to infection was 20 minutes.
https://www.theregister.co.uk/2004/08/19/infected_in20_minut...
More like "wry observation".
That said - because of the sheer number of phones in existence, on IPv4 you’re guaranteed to be running behind a giant NAT operated by your network carrier - and on IPv6 the address space is too big to port-scan (at least) but while it’s no help if attackers know your address - I understand there’s still a mix of carrier-based and handset-based network lockdown going on.
Cellular baseband is poorly secured, and it's privileged over userland. And its firmware is a closed-source blob, so it's ~impossible to fully assess the risks.
And so it's arguable that adversaries can pwn smartphones through baseband.
That's the analogy to Windows XP machines. Windows Firewall was just a stopgap. What helped most was going from dial-up modems, which are no more secure than network interfaces, to modem/routers with NAT firewalls.
So smartphones ought to have discrete cellular modem/routers. And that's an easy option for the PinePhone, given the kill switch.
This is how Charlie Miller and Chris Valasek were able to remotely compromise vehicles with a vulnerable infotainment system via a pwned femtocell.
"To find vulnerable vehicles you just need to scan on port 6667 from a Sprint device on the IP addresses 21.0.0.0/8 and 25.0.0.0/8."[0]
[0] http://illmatics.com/Remote%20Car%20Hacking.pdf, pdf page 46.
> It turns out that any Sprint device anywhere in the country can communicate [as in telnet] with any other Sprint device anywhere in the country.
So remote devices do have network connectivity to cellular baseband. At least on Sprint.
Do other cellular networks work like that?
Given that most traffic is encrypted (eg any major website via https, or mail provider with smtp-over-tls, or most apps via https), a baseband vulnerability isn't a great deal of help without an iommu bypass (AFAIK only one has ever been publicly disclosed for ios, and it took the researchers over 6 months).
IIRC correctly (from a few years back) the pixel phones also have one, but most Samsung phones did not.
They also almost certainly are used to collect personal user data and sell it.
Another bad thing is that these apps often come installed as "system apps", so you can't uninstall or disable them, or change permissions :(
I have used these instructions in the past to remove things I don't need from Samsung phone.
(There is also xda threads that talking about it as well, pointing what apps could be removed)
I am not 100% sure if "cheap" phones would allow to do this though.
We need regulation banning all this. Will never happen since malware benefits those who crave endemic surveillance.
Without specialization and trust, there would be no economy, and humanity would be immeasurably worse off.
It's ugly, it's error-prone, and the software that attempts to simplify it doesn't and is of unknown trustworthiness. A very unhappy path.
Absolutely not a reasonable option for the typical user, and an even less reasonable expectation that they should do it or should have known to.
and cautioned that the level of testing they need to do for future updates is a large expense of the project
Although I'm marginally OK with my current one (an antique that I have a google-free ROM and a lot of security installed on), it will probably die within the next couple of years. At or (hopefully) before that time, I'll have completed my move out of smartphones entirely.
My escape plan is to use the dumbest feature phone I can find and also carry a pocket computer (running standard Linux) that lacks cell capability.
I'd love to get a Cosmo but I'd hate to carry it around everywhere due to its bulkiness. I guess that might be your concern as well.