But spyware which can do so exists in endless amounts, including from companies focused on selling it to governments.
Hence also why in recent years physical microphone switches, or e.g. stuff like (I think it was) Apple laptops "physically" disconnecting the microphone/camera if you close the lid have been become increasingly more common and in demand. (Through the demand comes more from bad actors using it then from people being afraid the government spies on them AFIK, but technically there is 100% no difference)
Sounds like an upside to me.
I just did some brief research, and it seems that it was the case prior to some point in time between 2008 and 2019, but it is now hard-wired. It is discussed near the end of https://daringfireball.net/2019/02/on_covering_webcams
The engineer quoted in the article pointed out that it may be possible (at least in 2019) to briefly turn the camera on - flashing the led too quickly for someone to see.
I didn't find a discussion of this issue in the May 2022 Apple Platform Security guide.
A lot of firmware, and firmware signature validation, is ... not very well done.
Practically it's often not worth it (you already had root+ access. It's doable, but not simple and less uniform applicable.).
But there have been known cases of viruses tryign to persist themself in the firmware of connected devices (which in this context includes all internal devices including the motherboard).
And for new macs the off switch for microphone/mic if the lid is closed is hard wired using some "dump circuit logic switch" AFIK.
The problem with lights (even if hard wired) is that you might still find ways to brake them, like finding a way to fry them without braking the camera or switching on/off so fast that it isn't really visible but you still get some image/sound you might be able to post process to a point where it's usable even if not grate. You probably can prevent this with further hard wired circuits, like a hard wired "super slow de-bouncer" which in a on-1->off-2->on makes sure 2 is prevented if not at least Xs passed since 1. And which in a off-2->on-3->off cycle makes sure the LED is on for at least Ys (the camera can be switched off faster, just not on again). But I don't think apple has something like that. At that points the question is why not put in physical switches like e.g. on Framework laptops or some older ThinkPads.
Not just phones looks like.
For the very strange who accept driving the new "smartphones with wheels".
Including, note, the cars with the embedded telephone as mandated by the european union past 2018 - the e-call systems. Some articles went "there could be privacy issues, but it is a remote eventuality": now you see that someone could push as normal an eavesdropper in your car.
But the last time I read reported unhandable blabbering devoid of awareness and mental competence, attributed to a "minister of the republic", was just minutes ago. When you hear utterings like "it will save lives" - completely alien to conscience of quality of life, good reason, cleanness and propriety, rejection of absurdity, collaterals etc. - I am afraid they may actually "believe" that (or, better, just "sit on that", "hold on that", "cling to that" in some internal economy).
My memory may be failing me or confusing things so please correct me, but I seem to recall reading somewhere that the baseband lives segregated (with only a narrow communication cannel, kinda as if it were a remote machine) from the remainder of the hardware, so while it could be made to run stuff itself it has no way to physically access to main cpu, ram, mic, nor cams (barring, of course, any vulnerability on the comm channel that would land an exploit in the main OS+hardware).
GPS is another matter, but then again it's baseband so it gotta communicates with towers, so that's a done deal already that does not even require baseband access.
If I were buying into marketing I would not even have asked the question above in hopes of getting a hard reference to these kinds of details.
† e.g the following tidbits:
> The SEP is designed to be mutually isolated from the main CPU (AP); neither can compromise the other.
> No runtime blobs are designed to have total system access (no ME, no PSP, no TrustZone, nothing of that sort). Almost all blobs are running behind IOMMUs or similar firewalls, with the sole exception of the GPU firmware*. All code running on the main CPUs is under the control of the OS.
> AS machines use a large number of auxiliary firmware blobs, each dedicated to a specific purpose and running on a separate CPU core. This is better than having a smaller number of kitchen sink blobs (like Intel ME), since each blob can only affect a particular subsystem (e.g. display, storage, camera), which makes it harder for multiple blobs to collude in order to compromise the user in a meaningful way. For example, the blob running inside the keyboard controller has no mechanism to communicate with the blob running on the WiFi card, and thus cannot implement a keylogger surreptitiously; the blob running on the display controller similarly has no way to communicate with the network, and thus can't implement a secret screen scraper.
> From a security perspective, these machines may possibly qualify as the most secure general purpose computers available to the public which support third-party OSes, in terms of resistance to attack by non-owners. This is, of course, predicated on some level of trust in Apple, but some level of trust in the manufacturer is required for any system (there is no way to prove the non-existence of hardware backdoors on any machine, so this is not as much of a sticking point as it might initially seem).
> *it's worth pointing out that this firmware is not particularly large, is shipped in plain text and even with some symbols, does not have any functionality to talk via questionable interfaces (network, etc.), and is optional and not running when the OS boots (the OS must explicitly start it)
Which is an entirely different league than, say, Intel ME which completely owns the machine at the design level.
https://github.com/AsahiLinux/docs/wiki/Introduction-to-Appl...
https://github.com/AsahiLinux/docs/wiki/Apple-Platform-Secur...
https://github.com/CellularPrivacy/Android-IMSI-Catcher-Dete...
https://jon.oberheide.org/blog/2010/06/28/a-peek-inside-the-...
---------------------
Google Play Services spyware discussion
https://forum.xda-developers.com/t/guide-insanely-better-bat...
https://forum.xda-developers.com/t/app-disable-service-guide...
---------------------
"...the cellular carrier can send blobs of FORTH code right to the radio. The radio firmware also seems to have an IP stack (with TCP) so it can do its own interesting things (both bad and good)..." https://boston.conman.org/2013/01/22.2
"...easily spotted loads and loads of bugs, scattered all over the place, each and every one of which could lead to exploits – crashing the device, and even allowing the attacker to remotely execute code. Remember: all over the air. One of the exploits he found required nothing more but a 73 byte message to get remote code execution. Over the air..."
"... It’s kind of a sobering thought that mobile communications, the cornerstone of the modern world in both developed and developing regions, pivots around software that is of dubious quality, poorly understood, entirely proprietary, and wholly insecure by design." https://www.osnews.com/story/27416/the-second-operating-syst... (archive: https://archive.is/FOR5V)
https://news.ycombinator.com/item?id=6722539
https://news.ycombinator.com/item?id=6722732
https://news.ycombinator.com/item?id=6722648
https://news.ycombinator.com/item?id=6738066
https://news.ycombinator.com/item?id=6724034 <-- Seems to be higher risk with Qualcomm basebands where everything is integrated
-------------------
SIM card reader chips have their own operating system https://en.wikipedia.org/wiki/SIM_card#Design
Rooting SIM cards https://archive.is/3ZohQ
https://news.ycombinator.com/item?id=6722896
https://news.ycombinator.com/item?id=6724215
https://news.ycombinator.com/item?id=6723236
-------------------
They don't want you listening in on John Q. Senator's phone calls, but they sure do...
The scary new part is the turning on the camera/mic.
https://www.europarl.europa.eu/news/en/press-room/20230609IP...
"They want EU rules on the use of spyware by law enforcement, which should only be authorised in exceptional cases for a pre-defined purpose and a limited time."
It would have to be after compromise, which would mean its likely only used on a very small number of cases due to the sensitivity and cost of the technology involved.
Is it sensitive to compromise a phone, now that there is a national law allowing it, passed through a democratic process?
If the population does not support the law, the government could be potentially replaced.
But the most probable conclusion is that the population at large would not care.
2-2.5+ million USD depending for a full chain with persistence (lower end of range is for iOS higher end is for Android).
That is probably the lower end of the rough cost to buy that capability which you can use as many times as you want.
https://zerodium.com/images/zerodium_prices_mobiles.png
> Is it sensitive to compromise a phone, now that there is a national law allowing it, passed through a democratic process?
The technology itself is sensitive, when you buy a full chain exploit like the ones that have the public bounty price above, if it gets burnt it's useless for everyone else who bought it after its patched.
Generally exploit brokers don't like it when you burn their exploits.
Is that a lot?
In the US the major cities have police budgets of between $200 million and $5 billion
Yeah and most didn’t have this capability generally considering both the costs and the little amount of use you'd have for it.
You'd expect something more federal like the NSA, CIA or the FBI to have this kind of capability which is why its kinda a big deal when normal cops get it.
I would say most didn't have this capability because it's illegal. In France it is now legal
But we can't really predict the future and more loose rules could be introduced by the next government with a totally different agenda who might thank for the previous one for creating this legal framework.
Also, this section is weird too:
> They said sensitive professions, including doctors, journalists, lawyers, judges and MPs, would not be legitimate targets.
Apparently software engineering is not a sensitive job.
We have already been there, it's just like good old phone calls. They can be intercepted under the proper judicial supervision.
I don't have criteria to answer if this is a necessary evil or directly a blatant totalitarian push, but one needs to consider: does the French government have a bad track record of abusing the capability of eavesdropping any phone communication? has this capability been useful for law enforcement?
But any surveillance capability results in “good” as well as bad actors, frustrated with the current limits, asking for just a little more formal power or finding ways to justify informal drift in practice.
The only way to stop surveillance creep is openness and clear principles more coherent than a recursive “well they have been responsible so far, so far as we know” argument.
> does the French government have a bad track record of abusing the capability of eavesdropping any phone communication?
I'd rather look into possible future scenarios, I don't know about past cases, but I don't really follow french politics. I know discussing politics is HN is not encouraged, so I'd just rather suggest to look up what's coming for France (and EU) if the current government fails and major powers switch. Sorry if you already know this.
> has this capability been useful for law enforcement?
In Hungary, Pegasus was used to eavesdrop on many citizens who were simply in an opposing position. Law enforcement is a good cover for data collection and of course can be effective, but we need transparency and safety to see if these tools are abused or not. There are no good answers I'm afraid.