Security when buying a second hand PinePhone
#7
(12-08-2021, 08:19 AM)PineniP Wrote: Hi, everyone!

I want to buy this phone https://pine64.com/product/pinephone-bet...e-package/ from another person. They say it's like new and has only been tested.

Where could they hide malware in the phone?

Of course I'll reinstall the operating system and wipe the internal memory, but what types of firmware are there where someone could hide malware?

Is it possible to flash official firmware images from the Pine64 website or at least inspect the current firmware installed and compare a hash with other users? I'll inspect the phone for physical tampering, but if some firmware can be flashed with USB or other ways without desoldering or breaking some sort of seal, how would I know about it?

So basically: what types of firmware is there where malware could hide and how to detect whether the firmware(s) has been tampered with?


Thanks!
i have been playing with androids, finally found out that even fastboot is more or less controlled (by them). if i go on paranoid level, android could easily hide some nasty stuff. what i know about pinephone's booting process, it's almost impossible to put something unwanted there.

however, lte modem chip is an issue though, because it has its own firmware. lte modem could theoretically contain malware but modem resources are quite limited, and requires serious coder to put it there. you may or may not want to flash or reflash it. (mandatory disclaimer about possible BIO THERMO NUCLEAR IMPLOSION and bricking modem chip when flashing, it's flasher's fault).

if paranoid:
1: disable modem with dip switch
2: erase internal memory with random bytes e.g. dd if=/dev/urandom of=/dev/{targetdevice} bs=1M status=progress
3: install o.s. according to instructions.
4: enable modem with dip switch
5: reflash or flash modem chip
6: repeat 1-4, if more paranoid

stock firmware for modem chip:
https://github.com/Biktorgj/quectel_eg25_recovery

partially open source firmware for modem chip:
https://github.com/Biktorgj/pinephone_modem_sdk
  Reply


Messages In This Thread
RE: Security when buying a second hand PinePhone - by zetabeta - 12-08-2021, 07:46 PM

Possibly Related Threads…
Thread Author Replies Views Last Post
Star Selling my Pinephone Pro Explorer Edition zheyon 0 95 01-31-2025, 02:27 PM
Last Post: zheyon
  PinePhone earpiece too quiet Waffelo 3 409 01-01-2025, 09:41 PM
Last Post: Kevin Kofler
Question WhatsApp & Pinephone - What are the alternatives for collaborative comms? danimations 15 19,420 12-27-2024, 03:02 AM
Last Post: biketool
  eSIM on PinePhone just_a_q 9 5,646 12-25-2024, 04:16 AM
Last Post: zetabeta
  US Mobile, via T-Mobile, won't support Pinephone Pro - SOLVED, SIMPLY jovval 13 7,516 12-05-2024, 04:38 PM
Last Post: tllim
  Pinephone compatibility with Telstra, now that 3 G shutdown and 5 G available tracyanne 0 282 12-04-2024, 10:53 PM
Last Post: tracyanne
  Want to buy second hand PinePhone 3G version rudi.timmermans 0 453 11-01-2024, 09:58 AM
Last Post: rudi.timmermans
  Can use PlayStation on Pinephone? willharper 6 6,279 10-30-2024, 08:07 AM
Last Post: biketool
  Ordered PinePhone till today have no info or confirmation about order hennadiyt 1 639 10-05-2024, 02:20 PM
Last Post: KC9UDX
  How can I record video on a Pinephone? kk22 18 8,473 07-22-2024, 05:18 PM
Last Post: baptx

Forum Jump:


Users browsing this thread: 2 Guest(s)