For Wi-Fi you can tweak the driver, if you want. But you can do the same with a network card that you buy for a couple of dollars so what's the point? Transmitting on the 2.4Ghz is something everyone can do if he wants.
It's nonsense what you said. There nothing evil you can do by unlocking a phone. In Android an unlock triggers a factory reset, that will prevent accessing people personal data (and it's not really necessary if you have disk encryption, that every modern phone has as a default), so the concern of accessing people data doesn't exist.
The concern about: but then a criminal can steal your phone and use it. Yes, there is. We can require to unlock the phone requesting a code from a website of the manufacturer so they can prove that you bought the phone, as some manufacturers do. But in reality, does it make sense? You can nowaday get a phone that is more powerful than the PC that I used 5 years ago for 200$, I mean 8 core CPU, 8Gb of RAM, 256Gb internal flash, in the following years the price will probably go even lower. Should I care? They only thing that I care is that whoever stoles the phone cannot access my personal data, and this is achieved by the disk encryption, everything else to me is useless, I would just buy another phone, but in reality is more probable that I will loose or break my phone that someone steals it.
He's being sarcastic. It's think of the children but with electronics and PII.
Typically you have the modem that has its own microcontroller inside that runs its own firmware, that is encrypted. On Android phones you have a partition for the radio firmware, that you should really never touch (since doing so you can brick your device). Of course there will be a shared memory area between the radio and the main CPU to talk, but that is only for communication, then the radio microcontroller has its own RAM to implements its functions.
If someone actually tried to write their own radio firmware and made a mistake, there very soon would be.
Messing around with radio transmission is not a game. Make enough noise on the wrong frequency and now you're interfering with communications for emergency services responding to a disaster or air traffic control guiding flights in crowded airspace, with a very real danger of loss of life. And there is no way for anyone to stop you until they've physically tracked down the source of the bad transmission, which can take hours.
I am very much in favour of rights to repair and against almost any restriction on what individuals can do with their own hardware, but giving people who don't know what they're doing unrestricted access to a radio transmitter on that basis is a bit like giving everyone in your city a button that detonates the nuke because you believe in a right to bear arms. At some point, you need to draw a line and say only qualified people past this point, or very bad things start to happen.
I have been witness to the kind of search I mentioned. Usually it happens because of a freak hardware failure, not a malicious act or negligence. Unfortunately the innocence of all involved does not reduce the severity of the potential consequences. As I said, this stuff is not a game.
I can go buy a bunch of passives off of ebay and make a noisy oscillator that will kill everything for a couple blocks but nobody seems to do it.
1. How far off the bell curve do we need to go? Do we trade all rights to do anything for diminishing returns in safety?
2. These modifications are happening right now. Bad instances are usually caught by EMS system tests or by people reporting gaps in cell coverage, etc, and are generally purpose build jammers. There are not many instances of frequency overlap. For most goods, especially consumer telecommunications equipment, other bands are protected by the fact the equipment is given a specific range to operate in anyway.
I've been on HN for more than a decade. You can check my comment history to see that I contribute sensibly. I have no reason to make anything about this up, but I'm obviously not going to doxx myself by providing the kind of proof that would be convincing. You're free to take me at my word or to disbelieve me, but if you aren't interested in substantial discussion in good faith, please consider simply ignoring a comment and moving on to something that interests you more.
The answer to your question is that I once spent some time working with a network operator and on a day when I happened to be around their operations centre there was an active incident like this.
If memory serves, it turned out that the rogue device was a relatively new model that a customer had bought and was trying to use normally but something wasn't reliably operating within spec. That model would have had to pass certification to be permitted on the network but apparently this specific unit had drifted and as a result it was dumping bad data all over a control channel that was in use across a large geographical area, causing severe disruption to connectivity for everyone.
At that time some safety-critical services were using this network for communications in the field so this kind of outage was a very big deal. There were multiple vehicles with detection equipment on the road, systematically trying to narrow down the source of the interference, but of course they had trouble coordinating with the operations centre themselves because of the same disruption. I don't know everything that was going on, but I did learn that in my country there is a legal power to gain access to premises in this kind of situation and it sounded like the required formalities and officials were being arranged just in case.
As I recall, it took most of an afternoon to track down the source of the interference and get it switched off. In the end it was mostly dumb luck that it was found. I didn't quite follow what happened but possibly a detection vehicle that was out of contact with the operations centre had decided to patrol in its area until it could find another way to call in and while it was doing that it drove right past the building where the rogue unit was located and its detection equipment lit up like a Christmas tree.
The customer was entirely innocent and had no idea it was their unit causing all the trouble nor any reason they should have known. I don't know exactly what happened to that model, the manufacturer or the certification process it had managed to pass despite the defect. For sure there were serious repercussions.
This all happened some time ago and the protocols and networks have since changed but the physics hasn't. That's why I have such strong views about regulation and only allowing people who know what they're doing to have full control over transmission equipment. As the above incident shows, things can still go badly wrong even without that. If there had been a major incident requiring coordination between first responders in the field during that downtime it could have been disastrous. Minimising the risk of similar failures due to carelessness by someone who didn't fully understand their equipment and the systems and protocols they were working with just seems like common sense to me.
Maybe you disagree but I think the fact that the cause of the incorrect transmission was a hardware fault in that particular anecdote is relevant only if we don't think a user with the ability to freely modify firmware as we were discussing could cause exactly the same effect either negligently or maliciously. Otherwise, the argument being made is merely that not many people actually modify firmware in dangerous ways, in which case I refer you to the nuclear analogy in my original comment.
Put another way, you're not trying to prevent people who know what they're doing and follow robust processes from developing radio transmitters, even though in extreme cases such as my anecdote that might still not be enough to prevent a system failure. Nor can you realistically stop a sufficiently resourceful adversary from using radio interference as a form of attack. What you can do is stop an enthusiastic newbie who read an article about radio once from accidentally causing people to die because their experiment meant emergency responders at an incident down the street couldn't talk to each other except face to face.
The FCC hasn't cracked down - yet. As other have pointed out that is probably because they don't see a widespread problem and so the politics aren't worth it. I'm sure someone reading this is involved with radio, I hope they take the warning (I believe their response will be a form of we already know)
The kinds of outage that can be caused by rogue transmitters are rare. Often it's a hardware failure that is to blame when they do happen. Hardware failures are also rare but when you might have millions of transmitters within a small city, sometimes you discover that rare is not the same as never!
There is always the possibility of malicious or negligent interference if an operator has the ability to modify their transmitter's behaviour sufficiently though. I would personally be OK with limiting the sale or use of equipment with those capabilities to only people who have shown they are competent, for much the same reasons that I am personally OK with restricting the use of cars to people who have passed a test. It obviously doesn't prevent all failures but it certainly lowers the risk of failures that could endanger many other people.
Who's to say this? What if i'm Apple and my ''partner'' radio chip manufacturer (cough qualcomm cough) doesn't give me access to changing the bootloader? Why wouldn't 'forced unlocked bootloader' also apply to Apple-owned devices?
Besides that, some phone will add a unremovble giant red exclamation mark on boot screen to notate the phone being unlocked to warn you `the phone is already unlocked, don't trust it unless it is done by you.`
On the phones I've used (Pixel), there is a warning that unlocking will wipe all data.
If you're really expressing concern, what do you think of e.g. modem modules for regular computers or SDR hardware?
Great question. I'm intentionally not answering it because I am not sure what I think. There are valid points on both sides. In part what I think depends on how evil evil people get.
Our ubiquitous radio devices only work because the invisible commons that is the radio spectrum noise floor is aggressively and totally managed. Intentional emitters can only be sold after testing to ensure that their output is within regulated power levels and frequencies. It is trivial for an end user with a high-power transmit-capable SDR or amateur radio to unintentionally, unknowingly, and invisibly pollute this resource, denying nearby devices (scaled to your transmit power and depending on the frequency/bandwidth) the ability to communicate. This could be some noise on your neighbor's FM car radio, or it could be the communicators used by emergency services.
Honestly, I think radio spectrum management is one of the greatest success stories of the 20th century - if air or water pollution were as effectively regulated the world would be a very different place! To be clear, I don't think that smartphones with unlockable bootloaders, likely reusing the stock radio binary blob, are actually going to bring about the apocalypse and set us back to the telegraph era.
There was a process where Apple or Samsung or whoever brought that device with their bootloader to an expensive laboratory to get their CE mark, and that process proved that combination of hardware and software to be compliant with regulations. That process may have involved modifying some hardware filters and EMI shields, and almost certainly involved adjusting parameters in radio firmware/software, which are subsequently fixed for the lifetime of the product. If you give end users the ability to modify these parameters, you're inviting them to break the law. While enforcement is currently highly effective by requiring this certification process for OEMs, it wouldn't scale if you give everyone the ability to modify their certified emitters. You at least have to consider the possibility that someone could create a "High Power Radio" app or OS that would make smartphones running it have higher-power, faster access to cell towers and cause nearby devices to lose connection; no one wants that outcome.
Personally, I think the harm caused by preventing this through locked bootloaders and disposable smartphones is a tragedy. However, I don't know what a comparably effective alternative would look like, and the current state of affairs has both inertia and the backing of major institutions with strong conflicts of interest, and will continue to be very hard to advocate against.
I don't know what the current state of affairs is with regards to radio modem firmware, but I would think that if radio-controlling software should be certified (as following regulation), that should be limited to the firmware, and the modem should only accept firmware updates cryptographically signed by the manufacturer (and possibly the regulator). The firmware should provide an interface that only permits legal use through technical means. IOW, regulation should be limited to the hardware module and the software running inside it. It shouldn't be possible for software residing on any other part of the device to run afoul.
If that's impossible for some reason (which I don't think it should be), then I would argue that other alternatives like focusing on prosecuting violations (like the app and OS you mentioned) or modifying the regulations so they can be contained within the firmware while still meeting goals should come before any idea of locking down whole devices for the regulation of a specific module.
Also,
> You at least have to consider the possibility that someone could create a "High Power Radio" app or OS that would ...
If that's possible then, it's possible now. I mean, you don't even have to consider phones. Bootloaders and OSes in regular computers are open source and unlocked. If that's a problem that can arise from unlocked devices, then it already would have been a problem since long ago.
Additionally, the discussion was not whether there should be unlocked devices, which there already are. The discussion was whether locking should be illegal.
If it ever seeped into the public consciousness how easy it is to disrupt RF communications, you can bet your callsign that some group of clowns would start doing it for their own amusement.
Much longer. It took until 2019 for checkra1n to become a thing to unlock Apple A7 to A11 devices. Apple A11 is a 2017 SoC.
A12, A13, A14 remain uncracked today.
In Android lands, bootloaders starting from quite some years ago are quite solid too, with no bypasses except when the device maker provides you the possibility to unlock it.
The kernel can only talk to the modem trough AT commands, the same commands that you would use with a 4G USB modem that you plug into any computer. The fact that are physically on the same SOC doesn't implicate nothing in terms of security.
In fact there are no security implication on unlocking a bootloader, if there were, well we would be in trouble since it's a relatively easy operation, that in most cases it's a matter of running a command from a CLI tool, and the only drawback is voiding the warranty.