Google shoehorned Rust into Pixel 10 modem to make legacy code safer
Cellular modems are complex black boxes of legacy code, but Google is making them safer with Rust.
Signal weather
Rising
Momentum is building quickly, so this card is a good early entry point into the topic.
Modern smartphone operating systems have myriad systems in place to improve security, but none of that helps when attackers target the modem. Google's Project Zero team has shown it's possible to get remote code execution on Pixel phone modems over the Internet, which prompted Google to reevaluate how it secures this vital, low-level system. The solution wasn't to rewrite modem software but rather to shoehorn a safer Rust-based component into the Pixel 10 modem. Cellular modems are something of a black box. Your phone's baseband is its own operating system running legacy C and C++ code, which makes it an increasingly appealing attack surface. The core issue is that memory management in these systems is difficult and often leads to memory-unsafe firmware code on production devices. That can allow attackers to leverage serious vulnerabilities like buffer overflows and memory leaks to compromise devices. So that's not great—why are we still using this stuff? Part of the issue is just the inertia of embedded systems. Companies have been developing modem firmware based on 3GPP specifications for decades, so there's a lot of technical debt at this point. Modems also have to operate in real time to send and receive data effectively, and C/C++ code is fast. Read full article Comments
Stay on the signal
Follow Google shoehorned Rust into Pixel 10 modem to make legacy code safer
Follow this story beyond a single article: new follow-ups, adjacent sources, and the evolving storyline.
Story map
Understand this topic fast
A quick entry into the story: why it matters now, who is involved, and where to go next for context.
Why it matters now
Topic constellation
Open the live map for this story
See which entities, story threads, sources, and follow-up articles shape this story right now.
Click nodes to continue
Entity pages
Story timeline
Continue with this story
A short sequence of events and follow-up stories to understand the arc quickly.
How reliable this looks
Signal and trust for Ars Technica
This source works at a rapid pace: 100% of recent stories land in the hot window, and 0% carry visible search signal.
Reliability
92
Freshness
100
Sources in storyline
3
Related articles
More stories that share tags, source, or category context.
Google’s AI Mode can now help you find products in stock nearby
Although you can already track hotel prices at the city level, the new update lets you do so for a specific hotel that you're interested in.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
«Раздеть» за пару кликов. Apple и Google помогают нейросетям создавать порно без согласия
Доход сервисов для создания интимных изображений без согласия превысил 122 миллиона долларов.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
Chrome вас выдал. Оказывается, Google годами игнорирует простейший способ шпионить за пользователями
Думали, что в режиме «Инкогнито» вы невидимка? Александр Ханфф так не считает.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
Google now lets you explore the web side-by-side with AI Mode
Now, when you're using AI Mode on Chrome desktop, clicking a link will open the web page side-by-side with AI Mode.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
More from Ars Technica
Fresh reporting and follow-up coverage from the same newsroom.
US-sanctioned currency exchange says $15 million heist done by "unfriendly states"
Grinex says needed hacking resources "available exclusively to ... unfriendly states."
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
Man with @ihackedthegovernment Instagram account tells judge, “I made a mistake"
Probation for man who used stolen logins and posted private info on social media.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
Trump picks qualified, normal health leader to head CDC; experts still cautious
She's well qualified but will need to navigate RFK Jr.'s anti-vaccine agenda.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
$25,000 buys plenty of used EVs: Here are some options
Is $20,000–$25,000 a sweet spot for secondhand electric cars? We think so.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.