Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Ok go turn off VoLTE.... unless your carrier did the following

  * “Google Pixel devices received software updates in 2021 that automatically enabled VoLTE and removed the toggle.”


Unneeded on pixel devices per the project zero announcement [0]:

> affected Pixel devices have already received a fix for CVE-2023-24033 in the March 2023 security update

[0] https://googleprojectzero.blogspot.com/2023/03/multiple-inte...


I am still running the February update on my Pixel 6. When I check for updates, I don't see one.


+1, no March update on pixel 6a yet


Chiming in to say the same thing.


+1 too.


But some Pixel phones haven't gotten the March 2023 security update yet, per the article.


[flagged]


Let me clarify: it's not that some Pixel owners just haven't installed the March update yet. It's that Google hasn't released it it for some Pixel models.


Is there any way to mitigate VoLTE on Pixel 6?

I see I can turn off Wi-Fi calling (which I did long ago because it never worked), but no toggle and no march update available.


I believe switching the "preferred network" back to 3G (in the SIM settings) does this. VoLTE is 4G/5G.


Google has not released the March update for Pixel 6, 6 Pro, and 6a.


Hang on - if I understand correctly, all of the following is true for Pixel 6, Pro, and 6a users??

- There's an exploit out there that lets attackers own my phone if they know my number

- A patch is not available for my phone yet

- It's not possible to work around the issue because a previous update removed the toggle

- Announcing this signals to every competent black hat worth their salt to begin looking for exploits on this chipset, knowing the reward is high and the method of pulling it off is implied to be simple

I really wish Google had delayed this blog post until after all of their currently supported flagship products were no longer affected...


> I really wish Google had delayed this blog post until after all of their currently supported flagship products were no longer affected

Aren't they legally required to disclose security vulnerabilities like this within a certain time limit?

Seems like the real anger should be directed at them removing the toggle to turn it off.


I don’t think they’re legally required to do so. However they have a very aggressive publication schedule and selectively making exceptions for Google and not for competitors would look terrible, and possibly expose them to lawsuits.


Some mobile careers no longer operate 3G so turn off VoLTE isn't an option for some people. Google must release patch before this.


Under what law?


This was patched in other models so that gives a head start for people who reverse-engineer such things.

As for Samsung, their March 2023 patch closes items that sound similar. [1]

[1] https://www.sammyfans.com/2023/03/06/samsung-march-2023-secu...


And then everyone here would attack Google for covering up their own vulnerabilities.

This is a sign of integrity.


[flagged]


That’s pretty funny. I just bought a pixel 6a with the intent of replacing my iPhone. About an hour of “how the hell do people put up with this shit” and it’s going. Then I wake up to this.


As a point of comparison a recently inherited a ton of Apple gear and I've been swearing at it in a similar fashion fairly regularly.


Oh I have exactly the same trouble. I’m in the middle of moving back to windows


Switching OS always takes time to adjust. I have the same feeling any time I try to use a Mac or iPhone.


Your brain definitely gets trained on one system and moving off hurts. Hell, I've had my work Macbook for 5 years and I still curse the keyboard shortcuts that are all wrong (and the even more shortcuts that it's missing).


> affected Pixel devices have already received a fix for CVE-2023-24033 in the March 2023 security update

That line is carefully deceptive (lawyerly, even). Pixel 6 series have not yet received the March 2023 update.


The patch was written but withheld due to bugs. So you are not patched yet.


Hi Matthew, could you provide a source? I thought the fix was already being rolled out (or about to get rolled out for the Pixel 6).


Yes I think it was a week late but is now being rolled out. People on Twitter are saying they don’t have it yet, which is the nature of individual experience.

https://9to5google.com/2023/03/06/march-google-pixel-update-...


Google Support said that the Pixel 6 series won't be updated until March 20. This seems horrific to me.


Today is March 23rd. There has been no pixel 6 update since March 5



That is only for CVE-2023-24033 thought, right? Not the other three that haven't been assigned CVE ID's?

> The four most severe of these eighteen vulnerabilities (CVE-2023-24033 and three other vulnerabilities that have yet to be assigned CVE-IDs) allowed for Internet-to-baseband remote code execution.


Ah, that would explain the multiple patches that came in last week on my 7 Pro. I thought it was strange.


LTE is data only, if you want to make a call you need to have VoLTE (voice over LTE). So it's pretty reasonable to prevent disabling this.

I wonder if you can disable LTE entirely and use an older standard.


Many carriers have already retired 3G, so there's nothing left to fall back on if you were to disable 4G/LTE.


2G is still common


2G is still there and isn't going anywhere.


Is it? Wikipedia says that AT&T, Sprint and Verizon have already killed it, with only T-Mobile still going until next year:

https://en.wikipedia.org/wiki/2G#Past_2G_networks

YMMV in other countries of course, but many networks worldwide have already phased it out or are going to soon.


You do realise that there are countries outside of the USA? Australia has no 2G networks and 3G is approaching EOL.


I bought a Motorola RAZR 3G for $0.50 while farting around inside a Cashies a while back

Turns out it was still locked to Telstra, they demanded *$100* to unlock the damn thing, even though they were turning off their 3G network anyway!

Unfortunately all the resources on hacking them has long since succumbed to linkrot, plus getting it hooked up over USB to an XP VM to try and unlock it that way seemed risky


In Germany you move farther out of cities, you are stuck with 2G

[0] https://www.nperf.com/en/map/DE/-/187895.Telekom/signal/?ll=...


Germany and internet connection, I can't comprehend how one of the richest countries in the world, in such a small land mass can have such bad connectivity.

It's really baffling going here from Sweden where I'm starting to get 5G signal outside of core city areas, get 4G almost across the whole country with speeds of 50-100+Mbps, into the city centre of Berlin and there I fallback to 3G networks every 3rd/4th block walking.

Friends living there having terrible experiences with Telekom, almost no fiber available, etc.

Germany should enact something like this policy from here: https://pts.se/sv/bransch/internet/bredbandsstrategin/


> Germany and internet connection, I can't comprehend how one of the richest countries in the world, in such a small land mass can have such bad connectivity.

A combination of toxic financial mindset (back in the early '00s, finance minister Hans Eichel wanted a "balanced" budget and auctioned off the frequency licenses for dozens of billions of euros, saddling the carriers with the debt instead of the government), thoroughly incompetent politicians (Merkel's "Das Internet ist für uns alle Neuland" is just the tip of the iceberg), NIMBYs (sadly, projects for tower construction routinely end up in death threats, and since 5G conspiracies also in actual terrorist attacks), and a populace that to a large degree just doesn't give enough of a fuck.


Merkel is probably the worst German politician since...you know that guy.

Japan has a nuclear accident, caused by a tsunami and partly due to known issues in the power plant. Merkel: "Oh no, let's close down all our nuclear power plants right away."

Merkel: "Oh, we need more energy now when we closed all our nuclear power plants. No problem, my buddy Putin has agreed to build a gas pipeline and provide us will all energy we need."

Putin has been rattling his weapons on the border or Ukraine since 2014. Merkel: "No problem, I called my buddy Putin and he said he will not attack. And by the way, no need for us to invest in our defense. We can continue to have Europe's weakest army per capita as Putin said he would not attack."

Migrant crisis in 2015. Merkel: "Everyone is welcome! Smugglers, just send them here, we will show our solidarity. Oh, we do not have enough schools, daycare, hospitals to take care of them all? Oh, many are lost teenagers and children without parents who took the chance now when we said everyone was welcome? Well, I guess they can earn their living selling drugs and sex."


I agree Merkel was bad, but not that bad - Kohl was inarguably worse.

> Japan has a nuclear accident, caused by a tsunami and partly due to known issues in the power plant. Merkel: "Oh no, let's close down all our nuclear power plants right away."

The entire country was calling for the dismantling of the NPPs, and no one sans the FDP and the Nazis cares much about them any more, not even their operators.. As for the gas pipeline, thank former Chancellor Schröder for that one.

> Putin has been rattling his weapons on the border or Ukraine since 2014. Merkel: "No problem, I called my buddy Putin and he said he will not attack. And by the way, no need for us to invest in our defense. We can continue to have Europe's weakest army per capita as Putin said he would not attack."

A valid point, but one shared across the political spectrum except the Greens - everyone else from left to right and the entire leadership of the German industry was blinded by the prospect of cheap energy. It is unfair IMO to single out Merkel there.

> Migrant crisis in 2015. Merkel: "Everyone is welcome! Smugglers, just send them here, we will show our solidarity. Oh, we do not have enough schools, daycare, hospitals to take care of them all? Oh, many are lost teenagers and children without parents who took the chance now when we said everyone was welcome? Well, I guess they can earn their living selling drugs and sex."

The first part is a blank reproduction of common Nazi conspiracy myths - the "pull factor" has been thoroughly disproven by now, even with the EU being a deadly fortress at its borders, still thousands of people attempt to cross the Mediterranean each year. The latter is one of the worst interpretations you can give - I'd put that one rather on bland disinterest and fear of the far-right, not an intention to push people off to selling drugs.


haha, all but one 2G network in the USA is gone, so I suspect they are not from the USA, actually.


At least in the US the 2G networks have already gone. It made news for long-lived devices like cars and ebook readers that had 2G modems built-in.

Nissan Leafs used AT&T and it was shut down at the end of 2016.

https://www.greencarreports.com/news/1102612_nissan-leaf-con...


It's around for a little more than a year more on T-Mobile: https://www.t-mobile.com/support/coverage/t-mobile-network-e...

Some areas were never built out with 2G but for the footprint that was always there they have not turned it off since it doesn't impact their spectrum very much. AT&T had poor spectrum planning so had to kill it off sooner to refarm the spectrum.


I'm not sure why you're being downvoted.

I was on an EDGE connection in Mexico just last month.


Because 2G has already been sunset or has date set for sunset by most carriers around the world.


The Swedish regulator PTS intends to re-assign frequencies in the 900 MHz-, 2.1 GHz- and 2.6 GHz bands during 2023. This will most definitely sunset 2G and 3G in Sweden. With 1800 MHz already being re-assigned in 2017.


I thought 2G was still being supported for emergency services in the USA?


No you can’t. 3G SIMs were flagged a while back and the account holders were notified of the retirement. At one point they started blacklisting SIMs that connected to 3G because customers didn’t upgrade.

Careful if you put your SIM in a 3G only phone it may get blacklisted and you’ll need a new one.

Source: work at a carrier.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: