Live data from Hacker News

Google Pixel pwned in 60 seconds

theregister.co.uk

31–40 of 41 posts

Re: Google Pixel pwned in 60 seconds

#31
post #17

Earlier quoted context omitted.

Yeah, it makes no sense to me for Google to throw away their Nexus brand and all the good will they built up behind it. If the Pixel (phone) was really made by Google, it might make a bit of sense to keep the Pixel branding in the sense that it's manufactured by Google vs Nexus where it's not. But the pixel phone is made by HTC, just like the Nexus phones. To add to the confusion, they already had the Chromebook Pixe…

Nexus kinda ran out of numbers, since they already used 7 for the tablet. Google experimented for a while with weird model numbers like 5X and 6P, but seems to have decided against continuing it. It's the version wars all over again. Who wants to be stuck at 5 and 6 when Apple is at 7, Samsung will soon return with an 8, and Microsoft already played the "we'll skip ahead to 10" card?

i was hoping they'd continue with the 'nexus 7 (2013)' and 'nexus 7 (2014)' trend. it was concise and easy to remember.

Re: Google Pixel pwned in 60 seconds

#32

...this had me concerned for a minute, then I read the article and realised that 'Pixel' now means a phone and not a Chromebook. Panic over!

Which also happens to run the same Android 7.1.

All the other ChromeOS models from Google are no longer on sale.

Re: Google Pixel pwned in 60 seconds

#33

Earlier quoted context omitted.

Yes if an user program like flash results in pwning the device, security model is broken. Ideally when a user level program is compromised it should not be able to impact OS in any condition if security architecture was adhered to as it was envisioned. But every single OS out there have chosen the easyway out. On hardware level CPU rings exist to protect kernel from rogue programs and each other but in reality all th…

Okay, apologies, I thought you were talking about the Pixel. After watching the video, it's unclear whether or not the exploit was in a user mode application or one with system permissions.

Apple Safari, Adobe Flash, Microsoft Edge they all are user mode applications. If they are not then problem is impossible to solve anyways.

Re: Google Pixel pwned in 60 seconds

#34
post #31
post #17

Earlier quoted context omitted.

Nexus kinda ran out of numbers, since they already used 7 for the tablet. Google experimented for a while with weird model numbers like 5X and 6P, but seems to have decided against continuing it. It's the version wars all over again. Who wants to be stuck at 5 and 6 when Apple is at 7, Samsung will soon return with an 8, and Microsoft already played the "we'll skip ahead to 10" card?

i was hoping they'd continue with the 'nexus 7 (2013)' and 'nexus 7 (2014)' trend. it was concise and easy to remember.

Gah, I dislike that. I even more dislike Apple's "late 2012" stuff. Please give me a specific name that refers to a specific hardware design. Things can get so confusing otherwise, especially when trying to buy something used.

Yes, I know that there are specific model numbers... in tiny print... but if people don't know them or use them it is no help.

Re: Google Pixel pwned in 60 seconds

#35
post #17

Earlier quoted context omitted.

Nexus kinda ran out of numbers, since they already used 7 for the tablet. Google experimented for a while with weird model numbers like 5X and 6P, but seems to have decided against continuing it. It's the version wars all over again. Who wants to be stuck at 5 and 6 when Apple is at 7, Samsung will soon return with an 8, and Microsoft already played the "we'll skip ahead to 10" card?

Where is SemVer for hardware models?

Since Google likes to release new phones every time there's a new major version of Android, they might as well match the phone model number with the Android version.

Re: Google Pixel pwned in 60 seconds

#36
breathless exclamations of relative ease of exploit execution is just subjective editorial flair, for those keeping track of the well-intended neophyte observations. The entire thing comes off subjective. In modern journalism courses don't they preach about avoiding that pitfall? Unless everyone in tech writing wants to be Hunter Thompson by breaking all the rules.

Re: Google Pixel pwned in 60 seconds

#37

As great it is that these exploits are being discovered by the right people, I always cringe at how douchey these competitions are and how journalists use it as an opportunity to undermine companies they don't like for whatever reason.

On the other hand if no one called out on the security holes of flash, and your data was sniffed by the wrong people.

A phone is an extension of you. Security is paramount.

Re: Google Pixel pwned in 60 seconds

#38

breathless exclamations of relative ease of exploit execution is just subjective editorial flair, for those keeping track of the well-intended neophyte observations. The entire thing comes off subjective. In modern journalism courses don't they preach about avoiding that pitfall? Unless everyone in tech writing wants to be Hunter Thompson by breaking all the rules.

Modern journal doesn't involve "courses".

Copying Hunter Thompson , initiating "gonzo" style, has been the rage for quite a while -- it's more fun than being honest and careful

Re: Google Pixel pwned in 60 seconds

#39

breathless exclamations of relative ease of exploit execution is just subjective editorial flair, for those keeping track of the well-intended neophyte observations. The entire thing comes off subjective. In modern journalism courses don't they preach about avoiding that pitfall? Unless everyone in tech writing wants to be Hunter Thompson by breaking all the rules.

I think it's more likely that many authors of on-line publications don't have journalism degrees or haven't taken courses. The web has made it easier for anyone to publish, which is great. People have been able to hone their writing skills and get feedback (through eyeballs and clicks) on how to increase their audience. However, that incentive alone doesn't necessarily align with quality.

As professional journalism has moved from print to on-line, they've been struggling to figure out how to sustain their businesses. The on-line incentives for eyeballs/clicks is now strong for them as well, and they've understandably hired people who have proven to attract online readers. Early on it was clearer to identify the "blog" section of an online publication, but that's become increasingly difficult.

Stray thought: Is there a resource out there to view the credibility of stories by byline?

Re: Google Pixel pwned in 60 seconds

#40

As great it is that these exploits are being discovered by the right people, I always cringe at how douchey these competitions are and how journalists use it as an opportunity to undermine companies they don't like for whatever reason.

they do provide an interesting and useful datapoint about the effort required to attack a given target.
Post reply on HN