Vulnerabilities in chips in 37% of smartphones
blog.checkpoint.com
blog.checkpoint.com
What's interesting to me about the Taiwanese tech industry is their nimbleness and how MediaTek pivoted from a primarily DVD chip maker to dumb phone chip provider running on Pluto OS to now a smartphone chipmaker. Surprised the folks at Intel never tried to acquire them.
Intel needs a reliable door into the phone industry. Currently they don't have anything to offer and people will think twice before choosing Intel chipsets if it's not sure Intel will even stay in the market. Acquiring MediaTek would bypass that.
IIRC, MediaTek is the largest SoC vendor by volume. Hardly the definition of "doing not so well".
Yes, the MediaTek quality is ... not exactly the greatest, I agree. But that is where Intel could shine... Intel would save the money to invest in starting in a green field, and provide MediaTek with a (desperately needed) injection of quality.
Intel had 100 reliable doors in the past, and they foregone all of them.
Even today, Intel would have no problem making something well sellable.
Absolutely.
Engineering issues (samples of episodes reported): * steering wheel not responding (and user driving on motorway); * car unlock mechanism not responding (and user in the desert); * necessary electronics placed in external rear view mirror... Security issues: * steering wheel remotely hijackable through BT security hole... Now add the privacy issues.
This is largely OT in the current submission, but we should have a good exploration and discussion about these matters in other pages. The big issue is: alternatives. Surely many of us have been finding themselves with a problem of options.
https://www.phonearena.com/news/world-first-tsmc-4nm-chipset...
Should also be more affordable than the Qualcomm equivalent.
This is not an ARM environment designed for high security.
https://www.blackhat.com/docs/us-17/wednesday/us-17-Johnson-...
All computing devices have vulnerabilites. If you feel you need to use them regardless, you can avoid a lot of exploits by not installing random apps from publishers you've never heard of.
- leaking your location
- having your conversations intercepted
- having your messages intercepted
- having yourself impersonated
- having your contacts lifted
There are so many options.
That is a false sense of security. Bluetooth, web browser, messaging, wifi networks are all very powerful vectors and likely the main vectors for attacking devices.
It doesn’t help, that there are so many different smartphone vendors, and the most of them are pursuiting only for sales. New chips are coming constantly, and old ones get forgotten, left unpatched.
Is the future of the smartphone market of secure phones only in the hands of big ones (Apple et al)?
Perhaps we should also block malware infected devices from using the internet as well to stop there negative external effect on the rest of us.
As for disconnecting malware hosts, we could only block what we could identify & verify as malicious.
Not having that should be an absolute bar to a device making it onto anyone's "recommended" list.
At which point device makers would prioritize not getting panned by reviewers and losing many sales just because they couldn't be bothered to get their drivers into the kernel tree.
Customers are actively hostile to updates, because they hate UI changes.
If you want customer uptake of updates to be higher, uncouple them from UI updates.
Right now most Android devices come with a custom Linux kernel, and you can't just use the vanilla kernel instead because it doesn't have the drivers for the hardware. Which means that when the OEM stops supporting the custom kernel and it has vulnerabilities in it, you can't replace it with anything on that hardware, so your choices are to stay vulnerable or throw away the hardware.
If they'd spend a minimum effort to get their drivers into the mainline kernel tree, the hardware would work with any version of the kernel without needing special support from the OEM, so then it would keep working with new third party kernels indefinitely -- even if the OEM goes out of business.
But reviewers don't distinguish between the devices that have this and the ones that don't, and don't tell consumers why it's important, so consumers buy devices as if it doesn't matter, when it does.
Efabless.com
Do you still recommend the 74LS30 for that?
It's naive to thing that relatively unorganized bunch of people wrote the most popular OS in existence.
If IT people didn't like Linux, it wouldn't have chances.
You mean it's fully doable and going to become a standard in practice for our peers?
I work on a website that gets responses from a representative sample of the population (age, gender, education, geographical spread, are all balanced; other factors unfortunately not). Linux usage is about 2%.
Considering the amount of very casual users, the usual paretian distribution, the heavy introduction of mobile OS in accessing the web, and the (witnessed) presence of engineers who adopt the motto "Outside work I want to use a Mac to convince me that no issues ever exist", the number makes some sense. I would have computed double as an estimation.