Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

These days almost everyone is behind a NAT, which effectively defeats all the scanners trying to exploit Internet-listening services (and XP comes with an unfortunately large number of them in a default install.)


Except for almost all people using smartphones ;)


All modern smartphones came out after XP SP2 so the industry knew the problems with exposed ports - I don’t believe any shipping smartphone in the US today comes with any processes with open listening ports by default (even carrier bundleware) - please correct me if I’m wrong.

That said - because of the sheer number of phones in existence, on IPv4 you’re guaranteed to be running behind a giant NAT operated by your network carrier - and on IPv6 the address space is too big to port-scan (at least) but while it’s no help if attackers know your address - I understand there’s still a mix of carrier-based and handset-based network lockdown going on.


Sure, industry learned that exposing ports is dangerous. But they apparently didn't understand the deeper risk of trusting the network.

Cellular baseband is poorly secured, and it's privileged over userland. And its firmware is a closed-source blob, so it's ~impossible to fully assess the risks.

And so it's arguable that adversaries can pwn smartphones through baseband.

That's the analogy to Windows XP machines. Windows Firewall was just a stopgap. What helped most was going from dial-up modems, which are no more secure than network interfaces, to modem/routers with NAT firewalls.

So smartphones ought to have discrete cellular modem/routers. And that's an easy option for the PinePhone, given the kill switch.


Many mobile devices (especially those connected to a MVNO) are on one big giant subnet with "L2" style connectivity to each other.

This is how Charlie Miller and Chris Valasek were able to remotely compromise vehicles with a vulnerable infotainment system via a pwned femtocell.

"To find vulnerable vehicles you just need to scan on port 6667 from a Sprint device on the IP addresses 21.0.0.0/8 and 25.0.0.0/8."[0]

[0] http://illmatics.com/Remote%20Car%20Hacking.pdf, pdf page 46.


OK, so they used a femtocell (miniature cell tower) that had been exploited to allow console access. In particular, a Sprint Airave. Basically that gave them direct access to Sprint's WAN. And this is mind-blowing:

> It turns out that any Sprint device anywhere in the country can communicate [as in telnet] with any other Sprint device anywhere in the country.

So remote devices do have network connectivity to cellular baseband. At least on Sprint.

Do other cellular networks work like that?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: