Connect with us

Technology

Pixel 9 series’ modem is ‘armored’ against baseband vulnerabilities

Published

on

Pixel 9 series' modem is 'armored' against baseband vulnerabilities

Google launched the Pixel 9 series with some improvements compared to previous generations. While the new features and design stand out above everything else, there are also improvements at the security level. Google has revealed how it has enhanced security against modem or baseband attacks in the Pixel 9 series.

The importance of preventing modem-related vulnerabilities

Our smartphones have become an extension of ourselves. Protecting these devices from potential attacks is crucial as they store a significant amount of personal data. Google has worked hard to solve or mitigate vulnerabilities that may be present in Android. Although the most visible efforts are at the OS level, there are components, such as basebands, that require special treatment.

The baseband is part of the set of hardware and software that manages mobile signals on your device. The device’s baseband and modem work together to fulfill the tasks of sending/receiving and processing signals, respectively. When talking about vulnerabilities, many focus mainly on the OS or on apps. However, baseband firmware is a sensitive component whose nature makes it prone to certain types of external attacks, like phishing campaigns using false base stations.

Google had security issues with Exynos modems

Google has already had to deal with baseband vulnerabilities in Tensor chips. The company’s hardware inherited these vulnerabilities from the Exynos modems it relies on. Between late 2022 and early 2023, Google found and disclosed a modem vulnerability that “remotely compromises a phone at the baseband level with no user interaction.” At the time, the Mountain View giant advised users to disable VoLTE and Wi-Fi calling while they worked on a fix.

Advertisement

Additionally, baseband security is the responsibility of each Android brand. “Mature software hardening techniques that are commonplace in the Android operating system, for example, are often absent from cellular firmwares of many popular smartphones,” Google says in a blog post. Anyway, Android includes system-level protections for attacks arising from potential baseband vulnerabilities.

This is how Google “shielded” the Pixel 9 series’ modem against baseband vulnerabilities

The Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, and Pixel 9 Pro Fold use a new Exynos 5400 modem and baseband set. The modem is not only more efficient but also more secure. Google has built in multiple layers of security at the hardware level, on top of Android’s native security layers. First, “Bounds Sanitizer” prevents malicious code from running or memory corruption from data overflow techniques.

“Integer Overflow Sanitizer” is another of the security measures implemented by Google. The system ensures that calculations during data processing are accurate to prevent attackers from “confusing” the baseband with false values that cause unexpected behavior. “Stack Canaries” is a system that guarantees the correct flow of code execution. If any block of code tries to “circumvent” the correct order, the modem will receive an alert.

“Control Flow Integrity (CFI)” acts similarly to “Stack Canaries,” but focuses on the “paths” along which code is executed rather than the execution order. If the system detects code that attempts to deviate from set execution paths, it will reset the modem. Finally, “Auto-Initialize Stack Variables” prevents the leakage or manipulation of confidential data caused by code initialization errors.

Advertisement

Source link

Continue Reading
Advertisement
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Servers computers

9U Wall-Mount Server Rack Cabinet – RK920WALM | StarTech.com

Published

on

9U Wall-Mount Server Rack Cabinet - RK920WALM | StarTech.com



This 9U server or network rack cabinet lets you mount your EIA-310 compliant equipment to the wall, in a secure enclosure. The enclosure features adjustable mounting depth from 2 to 19 in. to provide a robust storage solution for your rack-mount equipment.

To provide secure stability for your heaviest equipment, this rack offers 4-post mounting, supporting a higher weight capacity per U than 2-post racks and supporting a total load capacity of up to 200 lb. (90 kg).

To learn more visit StarTech.com

source

Continue Reading

Technology

159 employees leave WordPress founder’s company after extortion lawsuit

Published

on

159 employees leave WordPress founder's company after extortion lawsuit

The feud between WP Engine and Matt Mullenweg, WordPress co-founder and Automattic CEO, recently came to a head when the web hosting service sued the latter, accusing him of “abuse of power, extortion and greed.” In a new blog post, Mullenweg said his opponent’s attacks on him and his company have been effective enough so that “a good chunk of [his] Automattic colleagues disagreed with [him and his] actions.” As a response, he created a “buy-out package” that offered employees $30,000 or six months of salary, whichever is higher, if they resign. A total of 159 people, or 8.4 percent of the company, took the offer.

Most of the employees who left came from the company’s Ecosystem / WordPress business, while the rest came from the division working on apps like Tumblr and Cloudup. As TechCrunch notes, Mullenweg gave the event a positive spin and exclaimed that “the other 91.6 percent gave up $126 million of potential severance to stay!”

Mullenweg called WP Engine a “cancer to WordPress” and accused the company of violating WordPress’ trademarks. He said they offered WP Engine the option to “pay a direct licensing fee, or make in-kind contributions to the open source project,” but the company refused. WP Engine argued that its use of the WordPress trademark was legal. In response, the WordPress Foundation changed its trademark policy page to say that the “WP” abbreviation is indeed not covered by the WordPress trademark, but to please not use it “in a way that confuses people.” It named WP Engine outright and even said that the company has “never once even donated to the WordPress Foundation, despite making billions of revenue on top of WordPress.” The WordPress co-founder also banned WP Engine from accessing some of WordPress’ plug-ins and themes, which broke a lot of the websites it’s hosting.

WP Engine accused Mullenweg of demanding eight percent of the company’s monthly revenue as royalty and of libel, slander, as well as of violations of the Computer Fraud and Abuse Act and IRS fraud. In a statement, Automattic’s lawyer Neal Katyal said he stayed up all night reading the complaint and found the whole thing “meritless.” He added that he’s looking “forward to the federal court’s consideration of [the] lawsuit.”

Advertisement

Update October 4, 2024, 1:57PM ET: We updated the post to attribute the quote at the end to Automattic’s lawyer.

Source link

Continue Reading

Technology

This new cloud storage service offers cross-platform integration and enhanced privacy for digital media management

Published

on

This new cloud storage service offers cross-platform integration and enhanced privacy for digital media management

Mylio has announced its new platform for personal, family, or business cloud storage needs.

Mylio SecureCloud is available with a base subscription starting at $11.98 per month for 2TB of storage, which the company hopes will make it an accessible option for a wide range of users, from individuals to small businesses.

Source link

Continue Reading

Servers computers

D-Link Server Racks & Storage Enclosures

Published

on

D-Link Server Racks & Storage Enclosures



An enterprise customer ensures high performance on an information-sharing network. It is very important to design an effective network infrastructure keeping in view ROI, Reliability, Current Technology Trends, and Green in nature. Also, the network should support progressive expansion.

Watch our expert Mr. Jaffar Tungekar share some tips on designing and the importance of a network infrastructure.

To know more click on the link below:
https://its.dlink.co.in/category.php?cat=Network%20Enclosures&ref=4 .

source

Continue Reading

Technology

NYT Crossword: answers for Sunday, October 6

Published

on

NYT Crossword: answers for Monday, September 23


The New York Times crossword puzzle can be tough! If you’re stuck, we’re here to help with a list of today’s clues and answers.

Source link

Continue Reading

Servers computers

The New SMB Must-Have: Intel's Modular Server

Published

on

The New SMB Must-Have: Intel's Modular Server



As the SMB blade movement gains steam, you’re seeing names like IBM, HP, and Dell all jockeying for a piece of the emerging business. But sometimes it makes the most sense to go with a channel-only solution that plays to your unique, local touch strengths, especially if that channel-only play happens to have technical and value advantages not found anywhere else. When you have an SMB customer ready to consolidate present and future servers into the most compact, management-friendly form possible, check out the new Intel Modular Server. .

source

Continue Reading

Trending

Copyright © 2024 WordupNews.com