TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

NitroKey disappoints me

279 点作者 cunidev大约 2 年前

14 条评论

wepple大约 2 年前
Maybe NitroKey are surfacing something useful and potentially concerning, but they way they do it is so cheap that it completely turns me off their brand. It’s a bunch of negativity-hype with a “so buy our phone” tacked on.<p>If you handed a Nitrophone to any competent security researcher, I bet they’d find a ton of issues. Same with the NitroKey; that feature list is far too extensive to not have issues.
评论 #35709757 未加载
评论 #35708255 未加载
评论 #35708291 未加载
评论 #35707258 未加载
评论 #35708755 未加载
dang大约 2 年前
Related ongoing thread:<p><i>Smartphones with Qualcomm chip secretly send personal data to Qualcomm</i> - <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=35698547" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=35698547</a> - April 2023 (263 comments)
s1k3s大约 2 年前
I&#x27;ve criticized the original article for lack of information here: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=35698547#35703662" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=35698547#35703662</a><p>However, this blog post takes it too far:<p>&gt; It proceeds to not show the contents of this HTTP request because it would show that it&#x27;s not at all interesting. It does not contain any private data.<p>You don&#x27;t know that, nor do you take any steps to actually prove your claim. This blog post is just as bad as the original post for not providing any evidence to your claims.<p>To add to that: OP seems to summarize the HN comments section without even citing it.<p>I&#x27;m double disappointed :)
评论 #35707503 未加载
kotaKat大约 2 年前
Also to mention... A-GPS is <i>extremely</i> crucial to the underpinnings of the e911 system. Having rapid fixes means quicker positioning data being sent over the wire to the 911 center.
评论 #35709772 未加载
评论 #35716445 未加载
dchest大约 2 年前
The author didn&#x27;t address the list of things the devices allegedly sent when downloading A-GPS files, from the original article:<p>1. Unique ID<p>2. Chipset name<p>3. Chipset serial number<p>5. XTRA software version<p>6. Mobile country code<p>7. Mobile network code (allowing identification of country and wireless operator)<p>8. Type of operating system and version<p>9. Device make and model<p>10. Time since the last boot of the application processor and modem<p>11. List of the software on the device<p>12. IP address
评论 #35707224 未加载
评论 #35707187 未加载
评论 #35707348 未加载
WirelessGigabit大约 2 年前
Well, a device can get the time via GPS only.<p>If for whatever reason the system&#x27;s time is just SO wrong then there&#x27;s a change the HTTPS connection might fail because of certificate not valid yet &#x2F; expired.<p>For this I think it&#x27;s OK for it to be served over HTTP.
评论 #35708371 未加载
yellowapple大约 2 年前
Reminds me of your typical &quot;Windows support&quot; impersonator telling people to look at all the spooky errors and warnings in Event Viewer and &quot;all I need is for you to install this remote access tool and I can fix all your problems for you&quot;.
magicalhippo大约 2 年前
Was just looking at NitroKey after realizing my SoloKey v2[1] won&#x27;t come for yet another few months.<p>Given that they use similar firmware, the headline scared me a bit. However the article is about their marketing of an entirely different device, not their new Yubikey replacement.<p>The wait continues... not super-surprised though, crowd funding hardware is super-risky and I knew that.<p>[1]: <a href="https:&#x2F;&#x2F;solokeys.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;solokeys.com&#x2F;</a>
评论 #35707525 未加载
评论 #35710361 未加载
评论 #35710121 未加载
评论 #35708278 未加载
lifeisstillgood大约 2 年前
So, presumably if I bought one of their phones and turned it on, I would wait ten minutes to get a GPS fix instead of it using a almanac and working out the lat and long of three cell towers at certain signal strength?<p>Does anyone know if it&#x27;s possible to get at this info from user side ? Some API access? sounds fun
评论 #35714769 未加载
snvzz大约 2 年前
IP packets should not be sent or received behind our backs, and certainly firmware should not be bypassing the operating system to do this.<p>Whether it is useful for A-GPS does not matter. It must be done on top of the operating system or not done at all.
评论 #35707180 未加载
评论 #35707200 未加载
评论 #35707243 未加载
biomcgary大约 2 年前
Are A-GPS files tied to location or the same for everyone? Hopefully, the latter.
评论 #35707272 未加载
评论 #35707192 未加载
评论 #35707316 未加载
评论 #35707092 未加载
prince707大约 2 年前
&#x2F;e&#x2F;OS answered at &#x2F;e&#x2F;OS answered at <a href="https:&#x2F;&#x2F;community.e.foundation&#x2F;t&#x2F;qualcomm-chipsets-data-collection-linked-to-the-a-gps-service-in-e-os&#x2F;48982" rel="nofollow">https:&#x2F;&#x2F;community.e.foundation&#x2F;t&#x2F;qualcomm-chipsets-data-coll...</a>
dmbche大约 2 年前
Straight, concise, clear and to the point.<p>Thanks!
fredgrott大约 2 年前
Not to mention that AGPS is decades old by now. How many of you fell for the original article&#x27;s narrative?