Google urges Android phone users to switch off Wi-Fi calling
scrippsnews.com
scrippsnews.com
1) not all phones
2) chipsets in phones vary by where they are sold.
3) only exynos chipset phones are affected. in some economies. sold by some vendors. Not all models with a given name and code number (pixel 7, samsung 22) will be affected. "it depends"
4) not all manufacturers declare their chipset so
5) it is almost impossible for anyone but the cogniscenti to know if they are exposed to the problem, and a huge amount of FUD is flying around right now about exactly which models, which versions, which economy variants are affected, patched, can be patched, will be patched
6) the "turn off" button has been removed from some phones, presumably at the behest of the carriers to have to gatekeep VoLTE and VoWIFI and decide if they want it on or not, and do not always permit users to decide this for themselves.
Also not being stuck on an ancient version of Android - though I don't know what the custom ROM community for that phone is like, perhaps some soul is still porting newer versions to it.
https://redmine.replicant.us/projects/replicant/wiki/GalaxyS...
which seems to be outdated by about 5 years now
https://redmine.replicant.us/projects/replicant/wiki/DeviceS...
i admire how long devices could be used, if they just were to receive security updates...
If hardware manufacturers published a list of their own patches to the source tree (rather than the typical "single commit/zip file of the entire linux kernel") then it would make community maintenance of old devices much easier.
Some older but popular models still have community maintained ROMs. I try save them from the scrap heap if I can. The main annoyance is battery life and having to keep Micro-USB chargers around.
Phones (as they are today) are a massive exercise in insecurity and privacy violation, to the point where they are actually banned in some settings.
Hardware switch lets you disable wifi completely - I own one phone like this actually, you can flip about 6-8 different seperate switches this way.
Then just wait untill patch becomes available/you have time to configure properly, then this becomes trivially resolved, instead of pulling teeth to get your carrier to push an update, replace your whole phone, etc...
A cursory Google search indicates that exynos modems don't support CDMA (apparently it's too expensive to license from Qualcomm) and are largely sold outside the USA. As a Verizon customer in the US, I believe this means I'm in the clear.
Like another commenter, a side effect of responding to this article was discovering that the March 2023 security patch is available (even though I didn't get a notification about it).
1. I've not seen anyone explain whether this could be exploited by anyone with access to phone lines (i.e. Twilio users) or not and if it would be trivial to try the vuln with every phone number you could find in any DB. If those things are the case, it seems like the chances would be very high that this would be or has already been exploited and affecting every unpatched phone.
2. It seems like Project Zero mistakenly thought that Google devices were already patched when they made their announcement ("affected Pixel devices have received a fix"). Whoops! Thanks for giving attackers a heads up.
3. When contacting Google support (specifically Fi) multiple CS reps told me repeatedly this was all fake news and that Project Zero was unaffiliated with Google. They assured me there was no problem, and if there was a vulnerability, it would be communicated on the Fi website (which has no service status or security pages and has never published any outages or vulnerabilities in the past).
4. The delayed March update for Pixel 6 phones doesn't even show up when you open the software update panel (which shows a checking animation that I assume does nothing). You have to manually check again. Who knows when the folks who are unaware of this vulnerability will actually be prompted to install the patch.
Google have guaranteed at least one person and their family to never purchase another Google product or service.
I hate CS reps. I used to work as one but I never lied. If I didn’t know something and I couldn’t find it in my knowledge base I contacted the on-site staff to relay the caller’s question/concern.
They did that when they waited more than a month to patch the phone call bug in Pixel 6 series. What if someone has an emergency? Nope, Google thought that can wait.
What does "at the baseband level" mean in terms of remote attack vector? Do they need to be physically nearby with an antenna or could they be across the world connecting through VOIP?
And why do they need to know a phone number? If it's that they need a nearby antenna + knowledge of a phone number, it sounds like this vulnerability might not be a big deal, and it would be great if they communicated that clearly. Alternatively, if the vulnerability is accessible from any remote phone connection, knowledge of a phone number wouldn't matter because attackers would spam the attack against millions of numbers.
That seems like a convenient assertion not based on evidence.
Without trying to sound confrontational, it appears as if you are a current employee of Google, which might have colored your comment and should probably have been disclosed.
With that out of the way, and the obvious “please ask before quoting me in a news article and absolutely do not treat this as any sort of official Google thing”, this bug is quite serious and of the kind you would typically see in a targeted attack. As I mentioned above, you don’t really want to be noisy with how you’re using an exploit because then people will catch on and try to defend against it. Plus, you generally want a specific thing from the person you’re targeting. Hacking into a million phones and getting value out of it is pretty hard. For targeted attacks things like personal information and specific assets are valuable. On a wide scale, what are you going to do? Steal credit card numbers and wallet keyphrases for a handful of popular clients? Why not just try to pwn the app itself, or phish people, which is a lot less effort?
I don’t want to sound like I’m making this claim because it sounds better if it’s not used for widespread attacks. It absolutely can be used for this, which is why its capabilities are very concerning. But the reasoning behind this is based on what the market for exploits looks like, not just speculation. Large-scale uses of them are typically cheap reuses of n-days by unsophisticated attackers (which is something I do actually deal with personally). In the very rare cases you see actual 0-days used (I can actually mention one now, search for “Pinduoduo”!) they are not of the baseband variety but typically sandbox escapes and abuse of APIs that allow for background execution, accessibility access, and the like.
> you don’t really want to be noisy with how you’re using an exploit because then people will catch on and try to defend against it
My initial reaction was that the vulnerability was already published so why would they care, but I can also imagine how the actual payload could be something to hide as well. That said, couldn't an exploit simply turn off security updates? It sounds like this vuln has full access to everything on the phone.
> In the very rare cases you see actual 0-days used
But that's the issue--it's not a 0-day. It was publicized before the patch went out for millions of users. Was the patch force-updated for everyone else? If not, that number of unpatched users is probably an order of magnitude greater.
This isn't an issue of some state-level actors sitting on a secret 0-day, it's a use-it-or-lose-it moment for anyone who's heard about it straight from Google's mouth.
Full access to SMS 2fa and email accounts seems like everything. That gives you access to most people's bank accounts. You could search emails for crypto accounts and MITM non-SMS 2fa apps if you have root access to the phone. Sending money requests to contacts using real names. I could think of a million ways to use root access. I don't know the cost of exploiting this vulnerability, but I know that sort of access is valuable to a lot of people.
Why wouldn't this have been a goldrush to exploit by unsophisticated attackers? Maybe I'm missing something?
Customer service? What customer service? :P
> That said, couldn't an exploit simply turn off security updates?
Sure, but I was thinking more along the lines of if you have a widespread issue then people will write about it and how to restart the device to clear the infection, turn off remotely exploitable surface area, etc. For example I know a lot of people would turn off iMessage when the effective power stuff was going on since it was so easy to exploit and used widely to troll.
> Why wouldn't this have been a goldrush to exploit by unsophisticated attackers? Maybe I'm missing something?
Right, this isn’t an 0-day anymore, because Google knows about it. Some of the bugs also have patches available, making those effectively public. Apparently, some are not fixed yet and also easy to exploit, for which Project Zero has made a rare exception for and not disclosed.
In general, if an exploit remains unpatched for a while, it will actually start being exploited by opportunistic attackers. Some exploits are actually really easy to launch, because they are simple or someone left a PoC online. Those can and do get spammed en masse by things like ad networks and generic malware.
For more complex exploits, or partial patches, you’ll often need a sophisticated attacker to actually design the exploit once the bug is known. Those ones are not generally in the business of hacking a million people and trying to get their credit card information. Top vulnerability developers are frighteningly fast in how quickly they can make a working exploit out of a patch that they diffed to my knowledge it’s more reliably lucrative and safer for them to sell it to people who use them for targeted attacks, so that’s what they do.
Anyways, here I suspect the answer is “the ones that are public are hard to exploit” and “the ones that are not public might actually be dangerous and were withheld for exactly that reason”.
Do you have a source for the fact that Pixel devices don't yet have a fix? The post we're commenting on is actually just blogspam, with its only real source being the initial project zero disclosure [0], which still asserts this to be the case...
[0] https://googleprojectzero.blogspot.com/2023/03/multiple-inte...
[0] https://googleprojectzero.blogspot.com/2023/03/multiple-inte... [1] https://9to5google.com/2023/03/20/pixel-6-march-2023-update/
I am curious whether attacks on this can be blocked at the carrier level.
Worst case you could do carrier level forwarding (via website or code so the call never hits your phone) to another number that you can also use on your device independent of the modem call handling. Obvious candidates would be Google Voice, Zoom Phone or other VOIP options. Google and Zoom may be the simplest options unless you're already using a SIP provider with a decent app, standalone SIP apps seem to be a weak area for app development. Last time I looked Zoiper and Grandstream Wave seemed like the best options not tied to specific VoIP providers.
Edit: Obviously this will then involve using that app for receiving calls, but you should be fine making outbound calls with your regular number.
Edit2: if using Zoom keep in mind that it limits the number of devices you can be simultaneously signed in on which may impact either receiving calls on your phone or being on Zoom conferences from larger devices like tablets.
The initial reporting on Project Zero's findings was pretty clear that this was the case.
>"Tests conducted by Project Zero confirm that those four vulnerabilities allow an attacker to remotely compromise a phone at the baseband level with no user interaction, and require only that the attacker know the victim's phone number," Willis wrote in a breakdown of the security flaws.
Willis suggests turning off Wi-Fi calling and Voice-over-LTE (VoLTE) to protect against baseband remote code execution, if you're using a vulnerable device powered by Samsung's silicon.
https://www.theregister.com/2023/03/17/android_google_projec...
The problem is that that's a very sterile way to say "turn off all voice calling features on affected devices" unless I'm misunderstanding how modern cell networks function. Without VoLTE in pretty sure devices need to fall back to 3G (effectively off in most of the world) or 2G (not much better, though it's still around on one carrier in a lot of places for longer distance coverage as I understand it).
Maybe my understanding is completely off, but this seems like writing an article about terrible flaws in automotive wheel bearings and closing with "we recommend that everyone avoid doing things that require use of wheel bearings."
Your threat model might be different but I don't get out of bed for anything but RCE personally, let alone spend a penny.
It bums me out that them doing this hasn’t been effective in shaming everyone else into following suit.
Just like if your lawnmower exploded with a known flaw, you would sue the lawnmower manufacturer.
Plenty of apps and networking in Europe and Asia.
I wonder if Apple views the "iPod" branding as being more associated with gaming and consumption and therefore less important from a security standpoint. I don't think I necessarily would agree with such a stance when the exact same hardware can carry sensitive stuff like a password manager, banking and medical apps, and so-on. But I imagine their telemetry showed that that overwhelmingly wasn't the case, so it was easy not to prioritize it.
Even after official support completely ends, Apple tends to go back and issue patches for active exploits. The nine year old iPhone 5s just got another security update a couple of months ago.
It was released May 2019, and it just received its latest security update (15.7.3) January 23, 2023. Presumably that is not the last security update for iOS 15.
I’m not aware that Android gets anything like this, even in the era of Google Play Services.
(Yes, I know: get a better ad blocker, etc. — I'd rather have fewer weak links, though, and a lack of basic OS updates is a pretty big weak link.)
For sure, if you're paranoid or a high-value target, update, buy a new phone. But normal users don't need to care unless there's actually something on the line.
https://twitter.com/maddiestone/status/1395004346996248586
Not sure what to say about encouraging users to throw caution to the wind. We got to this point of such good exploit mitigation because it's good for everyone for these devices to be secured.
An average user installing apps from Play Store has nothing to worry about for those. That's kind of the point.
It's great for these devices to be patched - I'd love it if Google would take more control over the ecosystem to be able to patch this sort of thing, but it's much worse for users to just throw out otherwise working devices with limited-to-no real-world security issues.
Yes, this is still a risk - if you tend to install random apks from the internet and disable Play Protect or run across an undetected modification of the relevant exploit code. But most users don't do that.
If you can use Windows without it getting full of malware, you can handle unpatched Android LPEs too.
Keep in mind, Webview, browsers, email clients, etc are patched via app update mechanisms.
Personally I have never seen any friends or relatives get malware on their phone that gets outside the app sandbox (ie. Uninstalling the bad app seems to solve the issue). Compare that to MS Windows where it seems common for regular users to have malware infested systems.
With the state of software development today, I'd be more worried about how many other holes they've added in the process of fixing something or introducing unwanted new "features"[1].
Here's some interesting statistics to look at and compare...
https://www.cvedetails.com/product/462/Microsoft-Windows-98s... - 30 RCEs in 7 years
https://www.cvedetails.com/product/739/Microsoft-Windows-Xp.... - 276 RCEs in 20 years
https://www.cvedetails.com/product/32238/Microsoft-Windows-1... - 664 RCEs in 8 years
https://www.cvedetails.com/product/102217/Microsoft-Windows-... - 157 RCEs in 2 years
More relevantly:
https://www.cvedetails.com/version-list/1224/19997/1/Google-...
However that ignores the fact that publicly known exploits are more dangerous for the average user than zerodays.
Well, I'm not. If he wants to daily drive Windows 98 because it had fewer documented RCE vulns, godspeed to him---and he probably will be more secure, just by virtue of good ol' security through obscurity---but that is not a reasonable solution for 99.999howevermanyninesyouwant% of computer users today.
The rate of finding exploits and what the definition of a vulnerability is really what has changed - now the definition of is much broader while at the same time, exploitability has dropped off due to mitigation in modern operating systems, compilers and CPUs. Overall, we get far more exploits, but far less of significance.
but.. their old phone is still operating fine, it isn't even affected by the Samsung modem exploit, and best-of-all the pixel 2 is well supported by many third-party Android roms.
Parent literally has one of the best supported older phones available for third party OS installation (which, incidentally, is what parent was asking about..)
so, in the interest of e-waste/recycling/keeping old things going I hope they reconsider the value of their already-owned hardware and how it may still continue to serve them.
>so, in the interest of e-waste/recycling/keeping old things going I hope they reconsider the value of their already-owned hardware and how it may still continue to serve them.
In the interest of security, both theirs and the people they communicate with, I hope they consider upgrading their device to something that has a very long lifespan of active security updates.
Every year I'm more disappointed by Google on pretty much every front. They really do seem to have jumped the shark.
If I do decide to upgrade...
Unfortunately I can't stand iOS. No kidding, I'd rather have a Nokia 5110. I've tried repeatedly, thinking "I'm just not used to it", but there's too much about the design philosophy that I find actively obnoxious. Strangely, I don't have this problem with macOS.
Maybe I can find another Android vendor with a better support policy, or if none of them are any good then just suck it up and buy the very newest of whatever to at least push the planned death of my device back a couple more years.
I'm getting a bit sick of this treadmill. I don't buy the defence some people offer that it's too much work to support the older devices. Having a security-only backports release series for old devices would be _trivial_ compared to the enormous piles of money Google sets on fire for shits and giggles on a daily basis. It's planned obsolescence, plain and simple.
That's how i feel with iOS and macOS, the whole design philosophy and UX feel alien to me, and makes me hate every actual issue I encounter even more.
> I'm getting a bit sick of this treadmill. I don't buy the defence some people offer that it's too much work to support the older devices. Having a security-only backports release series for old devices would be _trivial_ compared to the enormous piles of money Google sets on fire for shits and giggles on a daily basis. It's planned obsolescence, plain and simple.
From what I've understood, it's mostly the hardware components' vendors' fault - Qualcomm and co that provide the SoC and modem. It's their firmware which isn't kept up to date by the manufacturer (because it isn't easy to do so), thus phone lifecycle is inherently limites. There have been massive recent advances in that area though, with on one hand more vendors (MediaTek, Samsung) that could maybe be forced to compete and thus have to differentiate from one another, but also big changes to Android and the way updates are done, to keep firmware/driver/kernel updates as simple as possible to develop and roll out. We can see the effects with multiple Android vendors (e.g. Google, Samsung) now supporting phones for much longer. So hopefully soon things will improve.
[1] https://www.cnet.com/tech/mobile/iphone-se-4-reportedly-back...
That's not really the same thing as "updates for at least 5 years". The date the device first went on sale in the US isn't particularly relevant. They'll still sell it to you long after that, and then end support not long after it's out of warranty. That's what happened to mine.
The lessons I'm learning here (if I'm running a first party OS) are:
- Check very carefully how long different vendors actually support their devices. Google is pretty rubbish on this front, it turns out.
- Always buy the latest model when buying a new phone, even if it doesn't have anything I need, or I'll just have to "upgrade" twice as frequently instead.
For Lineage OS, they maintain the kernels released by the vendors and backport patches to them. But this often means that the backports only address the publicized CVEs and might gloss over a lot of changes between kernel versions that might not have had famous bugfixes. A lot of patches don't end up in a kernel, and often while the version number reads of that of a modern kernel, only a small percentage of the patches in that kernel release was applied compared to the upstream kernel. For this it's important to note that the kernel doesn't have a clean separation between "bugfix" and "CVE fix" for patches, this is already a problem that their officially maintained LTS versions have.
From the security point of view you are definitely better off than staying on something that's unpatched, but I have to mirror what parker_mountain is saying. It's way _way_ better to just get an iPhone as that also gives you modem security updates for half a decade. I am really unhappy about the lack of freedom these devices give me, but I have switched to an SE one year ago. It's just such an incredibly good TCO for really good security.
Also, I thought I recognised your username. I use at least one of your crates. Thanks for those, too! :)
Good security when you cannot turn WiFi and mobile data off because it has to talk to mothership ?
LineageOS has improved a lot over the years, and Android 12 (10+ with GSI images) finally has a working OTA update workflow.
But honestly, the "Android is not Android" problem is hard to communicate and endusers have so many pitfalls.
If you tell them "oh yeah I actually use RethinkDNS as an adblocker, combined with Fennec via F-Droid and its uBlock Origin extension that only somewhat works on mobile due to their messy UI" then you lost already 99% of users that will never figure out how to flash their device with the custom ROM, let alone understand what you just said.
It's so sad that you also have to tell them "but use only one of maybe 10 devices, all other Android devices are either totally outdated with their kernel or cannot be supported anymore"... and when I read your comment I kind of have to agree with your point.
iPhones have zero maintenance. It's a golden cage but it's a well built one, and most users just don't want to spend days and weeks learning how to maintain their smartphone.
Sure, I have to take some responsibility for poor digital hygiene or whatever, but I don't think that negates Google's awful management of this. I shouldn't _have_ to be vigilant/proactive to stay safe in something as basic as this.
Aside: Google spams me with all kinds of noise in notifications these days; couldn't they at very least put something in there saying "by the way, your device is now EOL; buy a new one"? Ockham's razor suggests to me that a _lot_ of people are running unsupported devices still, and Google doesn't want the collective backlash of putting that uncomfortable reality in people's faces.
However, DivestOS might be very different from the stock OS from Google. You might consider using LineageOS with Google Apps (MindTheGapps) if so.
* https://divestos.org/pages/devices#device-walleye
My Pixel 7 didn't show an update was available (last checked 30 minutes ago) but when I manually checked it found it and downloaded it.
I am not sure I am even going to be able to get calls without wifi calling on. Kind of a nightmare.
Thanks for your help.
(This is what I recall on the top of my head though, so you might want to double check this info)
Wifi calling is under Settings -> Connections, second item, just under wifi networks
[1] https://calyxos.org/news/2023/03/18/another-march-update/
Edit: I mean Pixel phones sold in the USA, I'm not sure about the other ones on the list. My 6 Pro does not have a VOLTE toggle.
I just don't see the benefit in 2023. It made sense back when cellular networks were less mature. It also made sense when it could cut down on your wireless bill.
But all you have to do is walk out of your house while on a phone call and realize how much the feature is degrading overall reliability.
The LTE network on my phone has less downtime than my home Internet. Heck, for some people their LTE network is faster than their home network.
I'm struggling to figure out where Wi-Fi calling is helpful. On a cruise ship?
But even then, its really not too crazy to find yourself inside any kind of building and not having strong cellular connectivity. Lots of commercial buildings I've been in have had some pretty poor cellular connectivity in any internal room; they've got tons of concrete and plumbing and wiring all throughout it!
i'm in the bahamas now and had a nice conversation with someone who won't install whatsapp. 6 months ago I was in Colombia and was able to take care of some banking problems back home.
Plus, texts are delivered and sent while you're away.
(And...I do know people in the US who are in cell weak spots that wifi calling solves)
Where I live, I basically agree, but as far as I can tell Wi-Fi calling is much better audio quality.
I don't doubt your experience, carriers can absolutely be stupid/frustrating in how they operate their networks, but there's usually little excuse for this. These days its all the same possible codecs, its the same kind of handshake. There's little excuse to not support wideband codecs in regular phone calls with VoLTE and what not.
Travel outside the country on a budget
Maybe a house that doesn't get cell reception inside, especially older ones with thick walls. Or one that doesn't get cell reception outside either. ??? was that difficult?
>A Tech Mogul’s Castle Is His Home -- Unless There’s No Cell Signal
https://www.latimes.com/archives/la-xpm-2003-feb-13-fi-wozni...
I have been using wifi calling on ATT with iPhones for many years, and I have no complaints.
And when you're new to an area, your carrier probably has your entire region colored as 'Excellent' on their coverage map, even though the only places you can actually get a signal is if you stand in the middle of the highway interchange out on the west side of town or up on one of the rooftops downtown. You have to ask around among the locals to find out which carrier _actually_ works in your town so you know which to switch to. Until then, wi-fi is your only comm link unless you can still find an old payphone.
And naturally if you're just visiting or passing through, you're not going to want to change carriers every time you stop at a new town.
(Side note: it does mean that I can't receive SMS messages at home, since Verizon doesn't deliver SMSs over wifi calling.)