Their modem code is a security nightmare and outside Qualcomms modem teams nobody is allowed to see it.
Their modem code is a security nightmare and outside Qualcomms modem teams nobody is allowed to see it.
Even if one were to encrypt all connections, these will probably need to be decrypted on the GPU for processing.
Sadly todays qualcomm hardware has no real memory isolation at all - any bit of on-chip hardware can see all memory.
It isn't perfect, but it's far easier to do that than properly secure a multi-million lines of code codebase with a substantial amount of unpatchable hardware...
Three is even a hypervisor for hexagon but I don't think it is used.
I believe it can prevent the ARM core tampering with private radio hardware memory, but not the other way round.
XPUs + hypervisor should be enough, assuming Qualcomm enables them and configures them correctly.
This itself is kind of mind boggling how they let the device overwrite its own IOMMU configuration, effectively nullifying IOMMU's purpose, and its provided safeties.
It's like fencing your house with 10 meter high walls, but leaving the key lying in front of the gate.