HN2new | past | comments | ask | show | jobs | submitlogin

While certainly a step in the right direction, the lack of an open baseband remains a huge problem, even with TextSecure. Any smartphone has a whole separate OS running, with access to the system bus and memory, that we generally have zero visibility into. There could be exploitable bugs, there could be actual backdoors, and we just have no idea. If you truly want to secure data, you need to use an airgapped system with hardware that is much more open.


Indeed. Samsung baseband was found to have a backdoor to read files in the phone.

https://www.fsf.org/blogs/community/replicant-developers-fin...


That should be a solvable problem, aren't there tons of operating systems professors and electrical engineers around in Europe that could in principle develop an open baseband chip and operating system? Germany and France should have an interest that their communication can't be trivially backdoored by the NSA.


Main issue is there really no specifications available on many things. Also it's will be nearly impossible to pass certification so no real manufacturer would use it.

If you want more details you may check OsmocomBB site and IRC.

> Germany and France should have an interest that their communication can't be trivially backdoored by the NSA.

Nobody saying that governments don't have trusted hardware with only their own backdoors. In almost every country manufacturer have to provide source code and specs in order to pass certification so gov does have everything needed.

Though it's not help anybody else as it's will never be open.


Manual baseband isolation via mobile hotspot and nexus 7, does the trick for now


Until the AMSS in the hotspot is compromised and used to attack your Android device via wifi.

This applies to mobile hotspots built around Qualcomm baseband/application processors, in other cases you would have to exploit the main CPU first.


Well, at least that requires two exploits/backdoors, instead of one.


Modern basebands are sandboxed, from what I understand. Partly because phones kept getting unlocked through exploiting baseband bugs and that messes with carrier subsidies.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: