Live data from Hacker News

Backdoor with root access found from OnePlus phones

twitter.com

101–110 of 113 posts

Re: Backdoor with root access found from OnePlus phones

#101
post #82

Earlier quoted context omitted.

Not sure specifically how you installed PA, but, generally, that would look something like: 1. Unlock bootloader 2. Install aftermarket recovery (CWM or TWRP) 3. Install new ROM (PA) Now that you've done 1 and 2 (usually the difficult parts), you really just need to repeat step 3 with a different ROM. Assuming you have TWRP installed, LineageOS has instructions for your specific situation (installing from recovery) a…

I just started messing with LineageOS on my Moto G4. Make sure you make a backup of the stock image so you can flash it back if something goes wrong with your cell network settings. I didn't and now I only have 3G and have been procrastinating flashing the stock everything and starting over.

For the OnePlus hardware the stock system images are all available for download from OnePlus themselves: http://downloads.oneplus.net/

Most OEMs should have some sort of downloads available. If that fails, you can generally find a thread on the xda forums that has links to download the stock ROM and other files (though then not directly from the OEM, so there's some element of trust/risk there).

(In your case, it looks like Motorola hosts the G4 images at: http://motorola-global-portal.custhelp.com/app/standalone/bo...)

Re: Backdoor with root access found from OnePlus phones

#102
post #60
post #46

Earlier quoted context omitted.

As a long time iPhone user that swings Android every few years to try the waters, I am consistently blown away at the level of garbage Android users are expected to deal with on a regular basis. Want to know how many times my iPhones have boot looped in the last nine years? Not once ever. My last Android (Nexus 6p) managed to do it several times in the 3-ish months I daily-drove it. Want to know how long you can expe…

> I am consistently blown away at the level of garbage Android users are expected to deal with on a regular basis. My girlfriend uses an iPhone; I am consistently blown away by the amount of garbage she's expected to deal with on a regular basis. When she changes to another app, our video chats go dark; there's no Termux or GNURoot equivalent (that I'm aware of); tapping doesn't move the cursor but instead selects wo…

> The sad fact is that the mobile phone ecosystem in general is full of garbage. Neither Android nor iOS is exempt. But at least with Android I have freedom.

As a Windows Phone user, this is why I'm dreading the day I need to replace my phone and pick a side. It seems like there's no winning in the mobile world.

Re: Backdoor with root access found from OnePlus phones

#104

Earlier quoted context omitted.

Encryption helps.

Does it? It seems useless when anyone with physical access can replace the bootloader. https://android.stackexchange.com/questions/38909/unlocked-b...

Well, this would require them to wipe your phone's data, so you would be alerted as soon as it happened since your phone would not have any of your old data once you logged in. If a malicious attacker is able to take your phone without you noticing and be able to replace it, the difference of a locked or unlock bootloader won't change the fact that you are going to put in your PIN on boot. Instead of replacing your OS with a malicious OS, they could simply replace your phone with a malicious copy of your phone and get your PIN on the first bootup. They still get your PIN and you still lose your data. The benefit of LineageOS is that it is open source and can be built yourself, so anyone can check the code for backdoors/vulnerabilities. This also means you get all updates as soon as you can build them.

Re: Backdoor with root access found from OnePlus phones

#105

Earlier quoted context omitted.

Does the iPhone 6s have a similar flaw? I'm still using one.

He was joking. The 6s and pretty much every new phone using a Secure Enclave to make brute forcing anything technically impossible.

I was not joking. There was a lockscreen bypass bug where you could access the photos/contacts. Also, I haven't kept up with jailbreaking, so I'm not sure if they can still be rooted. So, yeah, iphones have had several security flaws in almost all versions.

Re: Backdoor with root access found from OnePlus phones

#106
post #78
post #29

User builds on some Chinese phones are pretty sloppy. I needed to access an old Oppo phone the other day, where I couldn't remember the PIN. Luckily ADB was enabled, which suggests that their production software might have been a userdebug build. I couldn't enable root via ADB, since it was at least a production/user build, but the su binary was already on the phone, so I just su'ed and got a root prompt. From there…

My Chinese phone (iPhone 6s) had a similar flaw. Okay, that was tongue in cheek, but I don't see how adding the China qualifier adds anything new or interesting other than inject bias.

It is definitely a bit vague, but it can be reasonably assumed that it was meant as shorthand for "Obscure (or no) brand generic MTK phone sourced from China"

Re: Backdoor with root access found from OnePlus phones

#107
EngineerMode: so I fired this up on my OnePlus5 (and subsequently rooted my device). Fun times. Can anyone explain all the features in Engineer Mode? * DDR Aging Test: Some sort of DRAM physical memory test? * SUPL Tool: Tries to connect to supl.google.com:7276 ?? * Network set >> RAT Mode? .... other features test your screen, colors, backlight, NFC, Wifi, etc - would still be helpful if someone with a bit more background could give some color.

Re: Backdoor with root access found from OnePlus phones

#108

Earlier quoted context omitted.

Does it? It seems useless when anyone with physical access can replace the bootloader. https://android.stackexchange.com/questions/38909/unlocked-b...

Well, this would require them to wipe your phone's data, so you would be alerted as soon as it happened since your phone would not have any of your old data once you logged in. If a malicious attacker is able to take your phone without you noticing and be able to replace it, the difference of a locked or unlock bootloader won't change the fact that you are going to put in your PIN on boot. Instead of replacing your O…

LineageOS is a great OS. People should continue to use it for learning, fun, and getting things done.

Please elaborate though. How is an unlocked bootloader is more secure than than EngineerMode appearing on a phone [1]? Conclusion #6:

> Encryption is insecure with an unlocked bootloader or an open-access recovery.

If you have LineageOS with TWRP and an unlocked bootloader then it appears you have an insecure device.

[1] https://forum.xda-developers.com/android/software-hacking/tw...

Re: Backdoor with root access found from OnePlus phones

#109
post #7

I just checked and found it on my OnePlus Two. To other OP owners: make sure you look under "all" apps, not just "downloaded". After this finding , the data collection incident a month ago, and their last 1Gb+ OTA update that bootlooped my phone, I think I'm done with OnePlus products. I enjoyed the hardware but I can't tolerate this much malice/incompetence in software in something as critical to my daily life. I'm…

Yeah it's on my 1+X too. Trivial to gain root just from the info in that twitter thread

Re: Backdoor with root access found from OnePlus phones

#110
post #109
post #7

I just checked and found it on my OnePlus Two. To other OP owners: make sure you look under "all" apps, not just "downloaded". After this finding , the data collection incident a month ago, and their last 1Gb+ OTA update that bootlooped my phone, I think I'm done with OnePlus products. I enjoyed the hardware but I can't tolerate this much malice/incompetence in software in something as critical to my daily life. I'm…

Yeah it's on my 1+X too. Trivial to gain root just from the info in that twitter thread

Worth noting it has used 200mb data in three months
Post reply on HN