If this is true (and I generally believe this is is), and if basebands do indeed have backdoors for the government, why hasn't anyone found them? Why haven't we seen CVEs on this?
Can anyone point to a published baseband CVE that smells like a government plant, rather than a well-intentioned accident?
CVEs come out of Mitre, but lots of countries have equivalent systems or tracking codes. Further, large companies are pre-allocated blocks of CVEs to use.
But it’s irrelevant. The original position was that if govt are putting obvious remote access into devices, why has nobody ever seen and blogged or tweeted about it?
Now, can anyone definitively prove that they are back doors and not mistakes or exploits? No. But that's thanks to the age old "Never ascribe to malice that which is adequately explained by incompetence."
Is that talk recorded somewhere?
Title: "Over the Air, Under the Radar: Attacking and Securing the Pixel Modem" Summary/Slides: https://www.blackhat.com/us-23/briefings/schedule/#over-the-... YouTube (48 minute): https://www.youtube.com/watch?v=QrkB_enz2Pk
Talk at black hat =/= everyones devices are de facto vulnerable. For as tech savy as this forum is, its surprising how many people are not well read up on security.
The summary of vulnerability is this - if you use a cellular network, your baseband chip vulnerability is next to irrelevant. Your location can be triangulated from radio signals, and its likely that there are messaging contacts and calls that are logged that use the respective celluar services.
Now for pure data transmission from a secure messaging app. Most of the communication for privacy is done using end to end encryption apps like Telegram. While those can be compromised, those require a direct targeted attack on the device, you cant just remotely do this over the internet.
> Modern smartphones have a CPU chip, and a baseband chip which handles radio network communications (GSM/UMTS/LTE/etc.) This chip is connected to the CPU via DMA. Thus, unless an IOMMU is used, the baseband has full access to main memory, and can compromise it arbitrarily.
> It can be safely assumed that this baseband is highly insecure. It is closed source and probably not audited at all.
The problem is less that there are identified issues, and more that the variety of hardware and vulnerability of the implementation is suspicious.
To my knowledge the situation has changed nowadays and IOMMUs on smartphone SoCs are now common. Having said that I still don't rate the security of any smartphone and you should assume it will get compromised. There's a million reasons for this:
- Baseband is still radioactive and probably trivially compromised by any nation-state adversary so it's all down to the IOMMU.
- IOMMUs are hard to configure correctly and frequently misconfigured by drivers which don't use them correctly.
- Any host driver bugs in talking to the baseband might be exploitable.
- It's hard to verify an IOMMU is actually working correctly, so it's not like any of this is commonly audited.
- We're talking about SoCs here with the baseband usually integrated on the same chip, so there's always the risk of some undocumented channel between the baseband and the rest of the chip the vendor omitted to notice or tell anyone about.
The situation is at least better than it was but it's still 100% my assumption that no phone can be trusted in the face of an adversary who can put up a fake cellular network. There's simply far too much proprietary firmware, mysterious black boxes, etc. to be able to really trust these things.
Also I'm assuming here there's a desire to get access to the host processor and stored data, but you don't need to do that if you just want to get at the microphone or GPS or leak someone's location or so on. There's a million bad things someone could do getting access just to the baseband even if the IOMMU works right.
It's like what intelligent skeptics keep saying in the ongoing discussion of UFOs / UAPs and claims of extraterrestrial visits: With everyone having a camera in their pocket (or, more likely, in their hand) these days, shouldn't there be more compelling photographic evidence of extraordinary things at this point, if extraordinary things are really happening?
Edited to add: I guess I said it pretty well further down in that thread, "It does seem like some researcher or journalist should have blown the case open by now if this thing were systematically providing telemetry from everyone's "powered off" (but still plugged in) machines to an intelligence agency."
Or you can play the public hero and end up best buddies with Snowden and exiled from every Western country. The governments don't particularly like whistle blowers.
And if you found a backdoor, you probably wouldn't want to use it on every device all at once and reveal its existence. Somebody somewhere will log it. But if you carefully pick and choose your targets, just a few in a million (or several billion), it might not be detected for a long time.
White hack groups like Project Zero routinely find these exploits. That doesn't necessarily mean they're planted, it just means that it's definitely possible to hide them from common view, and it takes a lot of skill and dedication to uncover that, then also a strong enough corporate shield to protect you from any possible fallout.
Unlike taking pictures of UFOs, it's not just being in the right place at the right time. It takes a very high level of skill that the general population doesn't have.
Also check Mexico incidents of deactivated devices, Samsung, Oppo, Motorola and others have rootkits, too.
Also I could be thinking of something else entirely so, before repeating this, you'll probably want to google it.
why? because power.
what do do about it? get power. how to do that? dunno. If I told you then my own purported (and protracted) attempts would diminish. at least we don't get assasinated to death anymore..... ahahahaha (just our characters, andor career prospects, etc)
Basically rooting the phone but on a firmware level?
But is it still recording for later transmission? Perhaps!
This gives a trivial way to detect of the device is listening passively, at least on the workbench.
This microphones take 2.4 MHz clock and return PDM (pulse density modulation) signal. Does not seem very convinient for old-school analog electronic circuits, but it's pretty trivial to interface with any micro with pulse counter hardware.
And presumably the audio won't have any hum or interference from nearby radio transmitters, which is especially useful in cell phones.
[0] https://www.digikey.com/en/products/detail/cui-devices/CMM-4...
Civil liberties matter to everyone at some point.