Live data from Hacker News

Google Pixel pwned in 60 seconds

theregister.co.uk

1–10 of 41 posts

Re: Google Pixel pwned in 60 seconds

#4

How do these competitions declare a winner? Snippets like "it only took 4 seconds" suggest they use the total exploit running time as the only criteria?

they go into a randomized lottery which decides who gets to run their exploit first. They then have a set time to exploit the device (commonly 2 minutes), and if they can't do it the next team in gets to go.

Generally once a target has been compromised, no other teams are allowed to use the same vulnerabilities. this prevents a team from sharing an exploit/vuln to others who run it again. The downside is that if you've been working on an exploit chain for 6 months but a team runs a similar bug ahead of you, your work is worthless.

Re: Google Pixel pwned in 60 seconds

#7
So they spend weeks developing the exploits and when they present it the headline is that it took 4 or 60 seconds? They even used the phrase "breached Adobe Flash with a flick of the finger" as if anyone could hack it with a finger gesture.

Re: Google Pixel pwned in 60 seconds

#9
It looks like these exploits require either shell access or installing an app that contains the exploit code.

Apart from the Flash vulnerability, did any of the exploits use Chrome to gain all permissions on the Pixel? That would be scary, because the user would just have to be served Javascript containing malicious code or visit an affected website.

Why isn't Linux or the BSDs usually included in these pawn competitions?

Post reply on HN