Snapdragon chip flaws put 1B Android phones at risk of data theft
arstechnica.com
arstechnica.com
> A billion or more Android devices are vulnerable to hacks that can turn them into spying tools by exploiting more than 400 vulnerabilities in Qualcomm’s Snapdragon chip, researchers reported this week.
> The vulnerabilities can be exploited when a target downloads a video or other content that’s rendered by the chip. Targets can also be attacked by installing malicious apps that require no permissions at all.
> From there, attackers can monitor locations and listen to nearby audio in real time and exfiltrate photos and videos. Exploits also make it possible to render the phone completely unresponsive. Infections can be hidden from the operating system in a way that makes disinfecting difficult.
There's plenty of good reasons to use an iOS device (and some good reasons to avoid one), but I wouldn't think that CPU bug would be a particularly strong reason on either side.
The original iPhone SE is about to start it's sixth year of OS updates and security patches.
Which works out to less than $70 per supported year.
That's a legitimate advantage over the Android ecosystem.
my 10 year old motorola nexus is running android 10 -which is the current version. you install the new os on android by downloading an app, which installs the new os on reboot. it takes 15 minutes, and gramma can do it.
next you'll tell me mac laptops are better because you can't put windows 10 on your old hp laptop, because hp's system image for it only goes to windows 7.
Also, many Android devices don’t even have unlockable bootloaders. This makes your first statement patently false. There is no way for me to install any updates to my abandoned Acer tablet as the bootloader is locked and the device is abandoned.
It may be true to say “many Android devices can be updated through community projects” but you’re glossing over a lot of complexity.
I
Easy enough for grandma, maybe not so much.
This is pretty important when we're taking about a billion devices. The amount of people who do this is irrelevant and thus 99% or more of these users will be vulnerable until their phone stops working or the Facebook app no longer supports such an old version, forcing them to get a new one [assuming new Snapdragon chips fix the issue].
Deary me.
I think the distinction is pretty clear.
Kinda proves my point: chain of exploits.
installing an os on your phone is not simple. but it is harder than installing it on your laptop. and because installing it on a laptop is hard, people don't buy copies of windows and never have.
i am not glossing over complexity. but this is not complexity. anything apparently is complexity to you if it's not "buy small computer, and literally do nothing." yes, doing something is "complexity." opening a door requires keys. too complex.
us somewhat technical people, like this entire site and literally a third of the population, can follow xda directions. my gramma can watch a 15 minute youtube video and just click exactly what it says. the complexity is not complex.
as far as unlockable bootloaders, there are some. i can count on one hand, out of the hundreds of phones I can buy. if by many you mean 2%, sure. i guess that 2% means don't use 98% of phones. strange how apple is unlockable on 100% of their phones, yet that 2% is "worse."
When you play pretend with fake information, the only thing you are doing with the narrative is making yourself look like you're spreading narrative. this works for fox news watchers like yourself. not on a forum with a bunch of downvoting nerds.
In addition, it’s not about community projects being inferior. I’m a big believer in FOSS, strive to run nothing but FOSS, and avid contributors and publisher of FOSS. It’s about support. And, for the record, Ubuntu and Redhat are corporate projects though they depend and include many community projects and offer their products for free. Lineage is a community project.
Corporations do heavily use open source, but they also pay vendors for support. The average user also expects support from their vendor. Either their mobile provider or phone manufacturer. If they unlock and install LineageOS, they get none.
Your assumptions are way off base. First about the public’s likelihood to do what you’re recommending and second about me.
For the record, I’m one of the original members of TeamWin, helped write TWRP, have contributed to CyanogenMod. I’m not some uninformed schmuck. I definitely know how to flash a ROM.
so again you're moving the goalpost. the claim of the op was old phones from apple are superior because they get vendor security patches, and android does not. which is factually false.
But most phones in the United States sold within the last decade had the bootloaders locked so you can’t install another rom even if you knew how to do it.
> When the bootloader is unlocked, the device loses certain DRM security keys. That means you can't purchase content from Sony's storefronts and a few licensed features won't work, but it apparently also means basic features of the phone are negatively affected. A Sony rep has confirmed that some advanced camera algorithms on the new generation of devices like the Z3 and Z3 Compact are protected by DRM. If you unlock the phone, those features stop working. Apparently that causes photos in low-light to be noisier and poorly balanced.
> This isn't the first time Sony's bootloader unlock has come with some major drawbacks—unlocking past devices could actually break camera functionality (this was technically a bug). There have always been a few proprietary features that stop working, but the difference in image quality this time is allegedly noticeable.
> Update: Sony has updated the text of the bootloader unlock warning on its website to be clear about the camera impact. It reads, "...the removal of DRM security keys may affect advanced camera functionality. For example, noise reduction algorithms might be removed, and performance when taking photos in low-light conditions might be affected."
So don’t give me this nonsense that Android phones live forever.
cyanogen? there are a hundred other builds. google your phone model and custom rom.
they don't live forever but they do live over 10 years on the latest android. which beats apple and their security patches any day.
There was no cyanogen or other alternative supported. It’s not a matter of googling more. They didn’t support the phone model.
> and literally any 10 year old android phone can run not just the latest security patches but even the latest android.
Not in my experience. Some models work decently, others have major stability issues.
oh look, i googled 'best custom rom for nexus 6' and every result has good roms.
If the batteries were user replaceable, it would have been a perfect story.
Sending the device back to the manufacturer (authorised service center) can be inconvenience(data formatting, TOTP apps etc.) at best to security breach(malware install, device imaging etc.) at worst.
Also, if indeed a user decides to replace the battery on their own, an iPhone is the least repairable phone out there and getting worse with every iteration.
Maybe we know a technician we trust, who can repair iPhone before our eyes, but alas independent repair shops doesn't get Apple love[1].
[1]https://www.macrumors.com/2020/02/06/apple-independent-repai...
Typing this on an iPhone SE
Wouldn't it be nice though if users could choose to patch security vulnerabilities without installing updates that deliberately slow down the phone?
Similarly, “updates that deliberately slow down the phone” sounds like a conspiracy theory. The closest we’ve come to that being real would have required a caveat “… when your battery has degraded to the point that the phone would otherwise crash”, which is an important distinction.
You must be just as friendly in person as online if you are one of the few people ever to have an Apple store employee not go the extra mile for you.
Also, the security patches arrive much slower to Android than to iOS devices.
And I am especially concerned about ARM's TrustZone, which seems to be inferior to Apple's Secure Enclave.
https://blog.zimperium.com/multiple-kernel-vulnerabilities-a...
The Road to Qualcomm TrustZone Apps Fuzzing (2019)
https://research.checkpoint.com/2019/the-road-to-qualcomm-tr...
QualPwn - Exploiting Qualcomm WLAN and Modem Over The Air (2019)
https://blade.tencent.com/en/advisories/qualpwn/
QuadRooter: New Android Vulnerabilities in Over 900 Million Devices (2016)
The software vulns demonstrate serious failures of the Qualcomm product package of course, and is only relevant from POV of how the fixes can be deployed.
Some make it more difficult than others. But 400 remote access vulnerabilities is a completely different ball game.
Arstechnica.com is sensationalizing the news, when it comes to security I would rely on actual sec researchers.
https://blog.checkpoint.com/2020/08/06/achilles-small-chip-b...
Last I heard (2018) iOS vulns were going for $1mil+
This isn't even making anything close to that claim, it seems more like a privilege escalation situation.
I continually see these comments that security in Android is crap or Apple is so much better. Right now I find it hard to pick the difference between the two. There is almost none in terms of blow me away "how the fuck can we stop continually doing this to ourselves" type exploits - like the drive by total takeover of iOS China was using to target Uighurs. That is as bad as it gets, and both Android and Apple have had their share.
There is a superficial difference in how tightly they curate their app stores. Obviously, iTunes is better policed, but hyper vigilant police always inject their own opinions into what is allowed and isn't. Some people are happy to forgo a little functionality for peace of mind. But since both iOS and Android provide guaranteed to work (if there are no bloody bugs this week) [Uninstall] button, and both have been known and delete apps they've taking a disliking to without asking or informing you, security wise the outcome is is pretty similar regardless of the app store policy.
Hold on, I'm sure I'll find one any minute now...
And now US chip is genuine security concern for rest of the world.
So whilst the security might be better, we're (tech geeks in EU/UK) don't want to pay the same price for a less performant phone sadly :/
But maybe in a few iterations!
Can you maybe shed some light on this for me, please?
It has to do with being short-handed when comparing the "same" product in the US to the one I would receive here in the UK. I rarely update my phone so if I spend £1,000+ on a flagship, I expect a flagship especially when it's available elsewhere.
(read the article or the original blog, q: "The more than 400 distinct bugs")
The grand-parent comment of dang's response is of very similar tone to the one above. I am just trying to follow what dang has said.
not clear from the writeup how many devices are affected. They fuzz-tested 'a DSP chip' (sounds like just one) and then say that Qualcomm products are used in 40% of devices.
press release focuses on exfiltrating media + GPS, not clear if this is a rootkit that can access the keyboard or take over your email.
'more than 400 vulnerable pieces of code were found' not clear to me -- maybe I don't know how fuzzing DSPs work? Do they have access to the source code because the image decoder is open source?
The 400 distinct bugs are the uniquely faulting instructions or paths uncovered by the fuzzer.
Here's the actual report: https://blog.checkpoint.com/2020/08/06/achilles-small-chip-b...
Your best bet for any details is apparently this DEF CON presentation:
Wouldn't it make sense for Qualcomm to hardware/software sandbox the memory content being processed by each part of the SoC?
Would such an attack also work on PCs with iGPUs, since they share the system memory?
But all sandboxes can have holes. The phrasing in the article actually makes it sound more like this is a software bug in the firmware and not a hardware thing per se.
GPUs likewise have a somewhat cooked visibility to DRAM and some amount of mapping and hardware DMA intermediate interfaces. But sure, a similar GPU flaw could do the same thing.
Could Google theoretically remotely disable/remove apps that they identify using the DSP in malicious ways?
It's great that Qualcomm has a fix, but most of the susceptible devices will likely never get it in an update from their manufacturers. And I wonder if there will be a performance or battery life hit like the awful performance hit in the Intel chips. That one cost me a 30% hit on my servers and resulted in 6 figures of unplanned spending to replace that lost capacity.
So a fix might not be a fix for all, if this bug is in some obscure codec or some extreme edge case that no one uses the fix might be painless, Google might even find a way to soft patch it via GPS but if it’s not then you might have devices either losing key functionality or becoming vulnerable to a pretty severe exploit.
Another question of exploitation is how much hand crafting is required for the payload and does the payload survive common encoders as most social media platforms re-encode or transcode media that is uploaded or shared through their platform even WhatsApp and other messaging apps do it by default (tho those do it to save bandwidth).
If the exploit payload survives common encoders which are used by social media platforms it would be quite a disaster once people understand how it works and can be exploited.
The patch itself also might be bypassable Apple for example fixed an exploit using SEPROM and shortly after that exploit was working again by bypassing the SEPROM boot.
Seems unlikely to me. DSP data vs DSP code - I think it's in the latter that you'll find vulnerabilities.
Somehow I doubt that is going to happen, and that's also why I don't use Android.
It will just keep being affected by being a bad phone.