Project

General

Profile

Actions

GalaxyS3I9300PrivacySecurityEvaluation » History » Revision 17

« Previous | Revision 17/37 (diff) | Next »
Wolfgang Wiedmeyer, 03/18/2017 03:22 PM
link to dedicated firmware page


GalaxyS3I9300PrivacySecurityEvaluation

Note that this information may or may not be exhaustive.
It also may or may not contain all known issues or good point about this device.

General freedom issues on the Galaxy S 3 (I9300):

  • The bootloader is proprietary and signed.
  • Some peripherals do require proprietary firmwares to work, some of which have to be loaded by the system. See also the "Missing without non-free firmwares" status in ReplicantStatus.
  • The bootrom is the first code that is executed, it's stored in a read-only memory: see freedom-privacy-security-issues for more details.
  • The hardware is proprietary, and we are not aware if any its schematics is available somewhere on the Internet.

Modem related:

The modem runs non-free software, which is loaded but not shipped by Replicant.
  • When using flight mode, The main CPU has to ask the modem to power itself off.
  • The modem is isolated:
    • It doesn't use shared memory with the CPU, instead it uses an "HSIC" bus.
    • We are not aware of it being able to access the GPS, but it wouldn't be surprising if it still could (by having a direct connection to it: since no schematics are publicly available we have easy no way to check).
    • It has no access to the other CPU peripherals.
  • Terminal profile

TODO:

  • Investigate its terminal profile
  • Investigate TrustZone and other potential issues with the bootloader.
  • Investigate device factory reset security in both Replicant and its recovery (Does it really wipe files?)
  • Investigate the flash layout, EMMC partitions, EMMC firmware

Updated by Wolfgang Wiedmeyer over 7 years ago · 17 revisions

Also available in: PDF HTML TXT