Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Are you telling me the baseband on an iPhone doesn't have access to the system RAM?


Yes. The baseband on an iPhone is effectively just a USB peripheral. Did you think Apple spent tens of millions of dollars designing a custom secure enclave processor running a separate operating system unrelated to iOS and just said "fuck it, give the whole system to the baseband vendor"?


That's very good to know. Thanks!

What's the status for Android devices?

Is it true, as DCKing says, that the baseband radio doesn't have access in "common chipsets used in Android phones"?


90+% are having cellular modem inside SoC, all the cheap ones do for sure.


From https://www.apple.com/business/site/docs/iOS_Security_Guide....

"To protect the device from vulnerabilities in network processor firmware, network interfaces including Wi-Fi and baseband have limited access to application processor memory. When USB or SDIO is used to interface with the network processor, the network processor can’t initiate Direct Memory Access (DMA) transactions to the application processor. When PCIe is used, each network processor is on its own isolated PCIe bus. An IOMMU on each PCIe bus limits the network processor’s DMA access to pages of memory containing its network packets or control structures."


For the curious: quoted section appears on page 41 of the linked PDF.


It's still a common meme that on modern phones the baseband has full access to whatever it wants. The available evidence (which admittedly is very scant) and common sense suggests that this is not true, not in iPhones or common chipsets used in Android phones.

It may have been true on older phones with simpler system architectures but you're really going to need some new evidence to show the meme still holds true.


available evidence (which admittedly is very scant)

How do you figure? When Apple or Google say 'baseband is constrained from accessing OS memory in the following ways', these aren't unverifiable claims. People would be doing demos at conferences showing malicious basebands thieving your private catpictures.


Absence of evidence is only weak evidence of absence.


There are literally open source projects that talk to the baseband over HSIC on iPhones. This isn't a huge mystery.


> you're really going to need some new evidence to show the meme still holds true.

Uhh no, that’s not how security assurances work.


Only if you ignore the other part of my comment that circumstantial evidence of this more sensible system architecture does exist [1].

[1]: https://news.ycombinator.com/item?id=10907317


Mh, from GSM official docs SIM cards are small OSes with yes a limited power, but not that limited, they can officially set various kind of phone options, use speakerphone etc.

Of course that does not automatically means that those systems do exists like fictional echelon project but potentially power is there and know tech also...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: