Post #797640
2023-04-25 08:20 UTC
Replies (22)
-
@nitrokey@social.nitrokey.com 2023-04-27 11:42
The article has been corrected to state that the responsible software is not executed as firmware but in the operating system. Also requests to android.clients.google.com originate from microG. We are going to publish Wireshark logs in the coming days.
-
@sven222@soc.hardwarepunk.de 2023-04-25 09:09
@nitrokey@social.nitrokey.com Oh je, schade, dass nicht noch kurz ein Test mit einem Fairphone gemacht wurde, aber das ist ein absolutes Desaster.
-
@lejapproach@social.anoxinon.de 2023-04-25 09:41
@nitrokey@social.nitrokey.com #SailfishOS does have an option called Exclusive Mode, which as far as I can see disables the use of A-GPS.
-
@seachaint@hackers.town 2023-04-25 09:50
@nitrokey@social.nitrokey.com Image description: Eminently skippable. A stock photo of a hand holding a generic phone, onto which a red screen with a warning-sign captioned "Qualcomm" has been edited. A laptop is visible behind it.
-
@cammel@chaos.social 2023-04-25 11:41
Ui, auch fairphone ... Aber wehe das hätte China gebracht. Gibt es jetzt auch Verkaufsverbot für Qualcom und US Phones wegen Spionageverdacht? *mecker* @leyrer@chaos.social
-
@elias@go.arkadi.one 2023-04-25 13:39
@nitrokey@social.nitrokey.com Interesting. I searched those URLs on my pihole and they aren't present on my network which is good I guess. I thought my wife had a Qualcomm chip in her phone. Let's all keep an eye on this.
-
@cbpread@mastodon.social 2023-04-25 16:37
@nitrokey@social.nitrokey.com Makes me wonder what else Qualcomm is up to.
-
@sovereign_stack@mastodon.social 2023-04-25 17:18
@nitrokey@social.nitrokey.com Here a list of the data Qualcomm may collect from your phone according to their privacy policy: - Unique ID - Chipset name - Chipset serial number - XTRA software version - Mobile country code - Mobile network code (allowing identification of country and wireless operator) - Type of operating system and version - Device make and model - Time since the last boot of the application processor and modem - List of the software on the device - IP address
-
@ilumium@eupolicy.social 2023-04-25 18:08
Hey @Fairphone@social.weho.st, as a #Fairphone user impacted by this apparent breach of EU law, I wonder: Do you intend to demand from #Qualcomm to provide a #firmware update that brings your devices into compliance? Update: there is quite some criticism of @nitrokey@social.nitrokey.com & qualified people saying their claims are wrong & #Samsung is not actually transmitting any personal data with the A-GPS data requests (beyond technically required IP address): https://blog.brixit.nl/nitrokey-dissapoints-me
-
@Fr333k@infosec.exchange 2023-04-25 18:31
@nitrokey@social.nitrokey.com what is in the pcap, just a GET? Or more?
-
@wolf480pl@mstdn.io 2023-04-25 19:27
@nitrokey@social.nitrokey.com have you actually seen a list of installed applications in the sniffed traffic?
-
@kkarhan@mstdn.social 2023-04-25 20:04
@nitrokey@social.nitrokey.com Funfuckingtastic... So they literally integrated some #Malware if not #Govware into their #SoC's... So I guess #Qualcomm will be on my "#WontBuy" #sanctions list...
-
@waterbear@scicomm.xyz 2023-04-25 20:11
@nitrokey@social.nitrokey.com what's worse, the DNS for izatcloud.net resolved to an IP in China...
-
@waterbear@scicomm.xyz 2023-04-25 20:18
@nitrokey@social.nitrokey.com is it expected that all Qualcomm Snapdragon chips phone home in this manner?
-
@bart@mastodon.fam-ribbers.com 2023-04-25 20:49
@nitrokey@social.nitrokey.com Sorry but this is just unnecessary fearmongering. https://blog.brixit.nl/nitrokey-dissapoints-me/
-
@atoponce@fosstodon.org 2023-04-25 21:12
@nitrokey@social.nitrokey.com Looks like it might be overly sensationalized to sell Nitrophones. What are your thoughts on these counterpoints? https://reddit.com/r/privacy/comments/12yii9u/german_security_company_nitrokey_proves_that/jhojlr7/ https://blog.brixit.nl/nitrokey-dissapoints-me/
-
@tux@anonsys.net 2023-04-26 07:37
@nitrokey@social.nitrokey.com Wie schätzt ihr denn die Antwort von @GrapheneOS@grapheneos.social ein? 👉 German security company Nitrokey proves that Qualcomm chips have a backdoor and are phoning home - r/privacy Wäre super, wenn auf meine Frage eine Antwort kommen würde. 😉
-
@satmd@brettvormkopf.de 2023-04-26 18:14
@nitrokey@social.nitrokey.com This either bad research or willingly or unwillingly bad representation of facts. It may hurt your reputation if it stands uncorrected and I think that you already got feedback to this through other channels, but I want to add it here for fediverse readers: This is about PSDS data which the chip wants to have for speeding up GPS location. PSDS is useful information, but it needs to be fetched from somewhere. This fetching is done through HTTP and in this case involves sending device information to the remote party. More information than required. Nitrokey implemented safeguards/workarounds for this, but they’re not the only party doing this. Also this isn’t strictly a pure software problem, but involves the firmware too. And while it is correct and important to publish these facts, Nitrokey aren’t the first ones to speak about this problem in public.
-
@blake@fosstodon.org 2023-04-27 00:01
@nitrokey@social.nitrokey.com I appreciate that you published a method you used to find the issue, so anyone can test for themselves to see if it's true.
-
@PawelK@noagendasocial.com 2023-04-27 05:05
@nitrokey@social.nitrokey.com Bullshit story!
-
@crystal@hachyderm.io 2023-04-27 13:03
@nitrokey@social.nitrokey.com why should I trust anything you say when your blog post shows a clear lack of understanding about how Android and location services in general work?
-
@islamicaudiobooks@mastodon.social 2023-04-27 23:47
@nitrokey@social.nitrokey.com The Qualcomm Register article corrects 2 things: - Requests do not originate in Qualcomm firmware (corrected now) - They're publicly disclosed The rest of it appears to be a lot of interpretation/analysis about why what it does is not really a big deal, it's anonymized info and people with high threat models should simply not use phones. #Qualcomm seems to confirm the rest of the claims in the Nitrokey article including the uploading of personal data but trivialises it!