Latest security loophole
#1
Hi,

How to disable the IMU sensors on pine64 community edition? Anyone knows?
#2
Were you in the Matrix channel yesterday, by chance? Tongue

I don't believe this is possible with the hardware killswitches - unless killing all five disables additional hardware, ala the Librem 5?

If the IMU sensors are exposed to and supported by the kernel, would something akin to rfkill be applicable? If not, I posit that software will have to be written to achieve this.
#3
(07-26-2020, 09:08 AM)jed Wrote: Were you in the Matrix channel yesterday, by chance? Tongue

I don't believe this is possible with the hardware killswitches - unless killing all five disables additional hardware, ala the Librem 5?

If the IMU sensors are exposed to and supported by the kernel, would something akin to rfkill be applicable? If not, I posit that software will have to be written to achieve this.


The hardware killswitches do not disable to IMU.

I am on the channel.
#4
Fingerprinting can be done via IMU / motion based biometrics. The hardware switches preclude transfer of the data, so even if the device is compromised, you have to turn the communications back on before there's any loss of information to an attacker.

The degree of separation between the compromise and the protections means the hardware switches still do their job. Cameras can be used as data transfer, beyond just data harvesting, meaning an exploit of the camera creates the opportunity for future exploitation of the device, based on data triggers or streams via light or QR codes, etc. Microphones can accomplish input and output. GPS radios can be used for i/o, as can power ports, and screens can be used for output.

Is there an exploit of the specific hardware the pinephone uses for IMU? Wireless IMU chips can obviously be recruited into an I/O setup, but passive measurement hardware would only be able to passively collect data, which can be dealt with in sanitizing a device before resuming communications.


Possibly Related Threads…
Thread Author Replies Views Last Post
  Security when buying a second hand PinePhone PineniP 6 5,103 12-08-2021, 07:46 PM
Last Post: zetabeta
Sad LTE data does not work on T-Mobile US with latest postmarketOS 21.06 SP3 PacificSinewave 1 1,712 11-07-2021, 10:15 AM
Last Post: beta-user
  Just reflashed to latest mobian, it never asked for disk encryption? JuniperFury 3 2,824 10-18-2021, 10:24 AM
Last Post: JuniperFury
  PinePhone Security TurpentineOS 9 12,311 10-11-2021, 01:34 PM
Last Post: TurpentineOS
Lightbulb [12.11.20 Update] Latest PinePhone CE Manjaro - Device Arrival & Initial Tests Thread kern707 11 13,847 12-25-2020, 10:23 PM
Last Post: crevdunekin
  Latest PinePhone CE Manjaro - Charging issues: hardware or software? kern707 5 5,581 11-20-2020, 12:09 AM
Last Post: bcnaz
Big Grin Is the latest PinePhone CE that is shipping now a semi-stable device ? kern707 21 20,710 11-09-2020, 07:51 AM
Last Post: firefox-58
  Security Based OS ? NobodyNew1 4 5,537 09-15-2020, 07:15 AM
Last Post: User 18618
  Installing latest version of crust davegermiquet 0 2,064 06-24-2020, 01:14 AM
Last Post: davegermiquet

Forum Jump:


Users browsing this thread: 1 Guest(s)