Oh no, you're thinking, yet another cookie pop-up. Well, sorry, it's the law. We measure how many people read us, and ensure you see relevant ads, by storing cookies on your device. If you're cool with that, hit “Accept all Cookies”. For more info and to customise your settings, hit “Customise Settings”.

Review and manage your consent

Here's an overview of our use of cookies, similar technologies and how to manage them. You can also change your choices at any time, by hitting the “Your Consent Options” link on the site's footer.

Manage Cookie Preferences
  • These cookies are strictly necessary so that you can navigate the site as normal and use all features. Without these cookies we cannot provide you with the service that you expect.

  • These cookies are used to make advertising messages more relevant to you. They perform functions like preventing the same ad from continuously reappearing, ensuring that ads are properly displayed for advertisers, and in some cases selecting advertisements that are based on your interests.

  • These cookies collect information in aggregate form to help us understand how our websites are being used. They allow us to count visits and traffic sources so that we can measure and improve the performance of our sites. If people say no to these cookies, we do not know how many people have visited and we cannot monitor performance.

See also our Cookie policy and Privacy policy.

Backdoor snoops can access files on your Samsung phone via the cell network – claim

Android-replacement Replicant team discovers odd data API


Updated The developers of Replicant, a pure free-software version of Android, claim to have discovered a security hole in certain Samsung Galaxy phones and tablets – one so serious that it could potentially grant an attacker remote access to the device's file system.

Among the devices said to be vulnerable are the Nexus S, Galaxy S, Galaxy S 2, Galaxy Note, Galaxy Nexus, Galaxy Tab 2, Galaxy SIII, and Galaxy Note 2 – and there may be others.

The flaw lies in the software that enables communication between the Android OS and the device's radio modem, according to the Replicant project's Paul Kocialkowski.

"This program is shipped with the Samsung Galaxy devices and makes it possible for the modem to read, write and delete files on the phone's storage," Kocialkowski wrote in a guest post to a Free Software Foundation blog. "On several phone models, this program runs with sufficient rights to access and modify the user's personal data."

Like most smartphone vendors, Samsung ships its mobes with a preinstalled version of Android that's a mix of open source and proprietary software. Generally speaking, any code that directly interfaces with the hardware is proprietary – and that includes the modem.

In the case of Galaxy devices, Android's Radio Interface Layer (RIL) communicates with the modem using a Samsung-specific protocol. According to the Replicant website, that protocol includes support for a complete set of commands for performing read/write operations on the phone's internal file system.

That's troubling, Kocialkowski says, because the modem is powered by a separate microprocessor from the CPU that runs the rest of the phone's functions. And because this processor runs a proprietary operating system – like virtually all phone modems do – it's not readily apparent what it's capable of doing.

If the modem can be controlled remotely over the cell network – which Kocialkowski believes is not just possible but likely – then it can potentially be made to issue file system commands that leak, overwrite, corrupt, or otherwise compromise the handset's data.

"It is possible to build a device that isolates the modem from the rest of the phone, so it can't mess with the main processor or access other components such as the camera or the GPS," Kocialkowski says. "Very few devices offer such guarantees. In most devices, for all we know, the modem may have total control over the applications processor and the system, but that's nothing new."

The solution, Kocialkowski says, is to replace the device's stock Android firmware with a purely free-software OS, such as Replicant. In the course of building a version of Android that can run on existing phones without relying on any proprietary components, the Replicant project has had to write its own free replacement for Samsung's proprietary RIL.

"Our free replacement for that non-free program does not implement this back-door," Kocialkowski wrote. "If the modem asks to read or write files, Replicant does not cooperate with it."

He cautioned, however, that if the modem can potentially take full control of the device's main application processor, further remote exploits may still be possible, including ones that even an OS replacement like Replicant can't block. ®

Updated to add

It's a bit late, but Samsung did eventually respond to The Reg's request for comment on the matter with the following:

Samsung takes consumer privacy and security very seriously and we’d like to assure consumers that our products are safe to use. We are able to confirm that the matter reported by the Free Software Foundation is based on an incorrect understanding of the software feature that enables communication between the modem and the AP chipset.

Similar topics


Other stories you might like

  • Judge in UK rules Amazon Ring doorbell audio recordings breach data protection laws

    Relax, this isn't a binding precedent - but it puts down a marker

    A judge in England has ruled that an Amazon Ring doorbell's functions broke the Data Protection Act after a neighbour dispute, over claims of a gang of armed robbers trying to steal an Audi, ended up in court.

    Dr Mary Fairhurst took her neighbour Jon Woodard to court after alleging that his mass of CCTV cameras, including an Amazon Ring doorbell camera, amounted to harassment, a nuisance and a breach of the Data Protection Act (DPA) 2018*.

    The case was sparked by audio-visual technician Woodard installing yet another camera on a neighbour's wall after falsely claiming an "armed criminal gang" tried to steal his car – putting a communal car park and its access road under full surveillance.

    Continue reading
  • Electric car makers ready to jump into battery recycling amid stuttering supply chains

    It's better to get lithium from used batteries than from the ground, says Elon Musk

    Car makers are electrifying fleets at such a pace that battery makers can't keep up. So Tesla, GM, Ford and others are investing in battery recycling to cut costs and mitigate risks posed by an erratic international supply chain.

    Batteries are basically high-grade ore and a cheaper and more environmentally friendly way for materials to be extracted and reused, said Elon Musk, CEO of Tesla, during a shareholder meeting last week.

    "It pays to do recycling of batteries," Musk said, adding: "You can either get your lithium and your nickel and various constituents from rocks, or from batteries. It's much better to get them from batteries."

    Continue reading
  • Lenovo Neptune makes weather supercomputers cool again

    KMA will generate over one million forecast maps each day

    Sponsored It is only natural the world’s top supercomputing sites in climate and weather modeling should be leading the charge for more efficient, sustainable, and green datacenter practices. With the right approaches, these centers can show that power and performance do not need to be a game of trade-offs and that systems can achieve radical performance with highly efficient cooling.

    While power and cooling are concerns at the facility level, the leading provider of supercomputers in the TOP500, Lenovo, and the Korean Meteorological Administration (KMA) are proving what server-level liquid cooling can do for cutting-edge HPC efficiency.

    KMA, South Korea’s national weather service, provides weather forecasting and issues warnings of adverse weather conditions across the region. The administration also conducts research on climate change to enable the Korean government to enact policies. To do this work, KMA operates the National Center for Metrological Supercomputer (NCMS), the largest supercomputer in Korea supporting vital weather and climate forecasting.

    Continue reading
  • James Webb Space Telescope completes its voyage to French Guiana

    Only a million or so miles to go

    The multinational James Webb Space Telescope – named after a former NASA administrator – has arrived in French Guiana, home to Europe's Spaceport, with launch finally in sight.

    An international collaboration (including contributions from NASA, ESA and the Canadian Space Agency), the long-in-gestation and eye-wateringly overbudget observatory is due for launch atop an Ariane 5 rocket on 18 December, just squeaking into 2021, if all goes well.

    Aside from the 16-day, 5,800-mile trip at sea from California, it has been quite the journey for the space telescope, on which work began in 1996 ahead of a 2007 launch date. Back then the budget was around $500m. These days it's nearer $10bn after repeated delays and a redesign. To be fair, however, nothing quite like the James Webb Space Telescope (JWST) has ever been built before. Then again, that is still quite the overrun and delay.

    Continue reading
  • Is that a meteor crashing to Earth? No, it's Chromebook makers coming back to reality

    US market – where 70% Chromies are sold – nears saturation

    The march of the Chromebook looks to be over for now, at least in the United States, as consumers and students had their fill during the pandemic and are now buying far fewer machines.

    Shipment data collated by Gartner shows that in a global PC market which grew 1 per cent year-on-year in Q3 to 84.147 million units, Chromebook models actually declined 17 per cent.

    This is the first time since their market debut in 2011 that double-digit declines were recorded for the form factor, the analyst told us.

    Continue reading
  • For Dell, being edgy now means single-node HCI without virtual storage, and rugged laptops

    Is it really hyperconverged if it has vSphere but not VSAN? Big Mike says 'yes'

    Dell has made a play for the edge, with pretty much the same stuff it offers in most other places.

    The centrepiece of the hardware giant's edge compute push, revealed today at the Dell Technologies Summit, is a "VxRail satellite node" – a 1U server that runs a subset of VMware's hyperconverged stack. The nodes are 1U servers, lightly ruggedised, and Dell assumes you'll run vSphere on 'em so that your edge servers behave the same way as the data centre servers you entrust to Virtzilla.

    Readers may recall, however, that VMware generally recommends its HCI stack runs on multiple nodes, and that doing so is necessary for resilience of the VSAN virtual storage array – also just for resilience in general.

    Continue reading
  • Soaring cloud division turns things around for SAP after annus horribilis that was 2020

    Remember those car-crash results in Q3 a year ago? No repeat collision this time round

    A year after outlining horrific calendar Q3 financials that caused the share price to crash by €28bn, SAP had no nasty surprises up its sleeves this time.

    In fact the company raised its full-year outlook for the third time in 2021, such is the confidence with which SAP now views its cloud biz. It is estimating sales to grow by up to 19 per cent year-on-year, and operating profit to be between flat to a decline of 2 per cent, better than the earlier projection of a 4 per cent drop.

    The preliminary results for the latest quarter ended 30 September show turnover of €6.84bn, up 5 per cent on the corresponding quarter of 2020. Among the highlights, cloud revenue jumped by a fifth to €2.39bn and software licences and support fell 1 per cent to €3.52bn, so lots of customer have migrations to do.

    Continue reading
  • Microsoft .NET updates include C and C++ code in Blazor WebAssembly, release date for Visual Studio 2022

    Just don't mention WPF

    Microsoft has come up with its usual monthly splurge of .NET news, including the ability to compile native dependencies into Blazor WebAssembly, and a release date of 8 November for Visual Studio 2022.

    The .NET 6 wave – significant since it is a long-term support release – is close to release, with the launch expected at the online .NET Conf 2021 on 9-11 November. The date for Visual Studio 2022 is therefore no surprise. Not everything will be ready, though, in particular the cross-platform MAUI (Multi-platform App UI) framework, based on Xamarin technology, which is scheduled for an RC release in early 2022 and general availability in the second quarter of 2022. Preview 9 of MAUI is now out, with updated controls and graphics API (Microsoft.Maui.Graphics).

    At this point in the release cycle new features give way to bug fixes, but a key new feature has arrived in the Blazor framework for browser applications. Principal program manager Daniel Roth described native dependencies for Blazor WebAssembly (Wasm) apps, which means that "any portable native code can be used as a native dependency." This in turn means that C code, for example, can be called from C# code running in the browser. Both the C# and the C code will be compiled to Wasm so technically it may seem just a small step, but it is nicely wrapped to work in the same way as native code interop for C# on the server or desktop.

    Continue reading
  • Ex-camera biz Olympus investigating 'suspicious' network activity again a month after ransomware hit

    Plus: Extortionist gang threatens victims who talk to the press

    Olympus, the Japanese company once known for making cameras, is investigating "suspicious" activity on its networks again – a month after those same networks were ravaged by ransomware.

    In a statement issued last night the company said it had "mobilized a specialized response team including forensics experts" in response to a "cybersecurity incident" that was affecting its IT networks across North and South America.

    The attack began on 10 October. Affected systems are said to have been "suspended" and affected customers and suppliers informed, said Olympus.

    Continue reading
  • Microsoft slices Windows 11 update size by 40% (no, not by cutting hardware support)

    Show me the way to go home, I'm tired and I want to reverse this delta

    Microsoft is boasting of how it reckons to have reduced the size of Windows 11 updates. Surprisingly "cutting hardware support" didn't feature.

    The monthly cycle of fixes for Microsoft's wares has been the bane of many an administrator's life over the years. The operating system's decision to go for a lengthy lie-down at inopportune times while updates were being downloaded and applied have become something of a running joke, particularly with much of the world's move to remote working and occasionally iffy domestic internet connectivity.

    Microsoft began taking steps to address its package-size from the Windows 10 October 2018 Update (aka 1809) by using paired forward and reverse compression rather than the simple differential update of previous versions, which could get quite hefty and be painful to administer.

    Continue reading
  • Want to deploy a new Windows VM on Microsoft Azure? Today might not be your lucky day

    Users running non-Windows VMs or existing deployment not affected

    It is shaping up to be a Black Wednesday for providers of online services after Microsoft Azure Virtual Machines users suffered lingering near-global glitches that prevented them from spinning up new Windows-based systems.

    According to Microsoft's status page, the downtime happened "as early as" 05:12 UTC today and has yet to be fixed, with the company saying it is "Applying Mitigation", which we are sure is of some comfort to irritated users.

    The message states that a "subset of customers using Windows Virtual Machines may experience failure notifications when performing service management operations – such as start, create, update, delete."

    Continue reading

Biting the hand that feeds IT © 1998–2021