Live data from Hacker News

Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

thenextweb.com

71–80 of 236 posts

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#71
post #34

> However, if you install an application from an untrusted source, attackers can take advantage of that. I'm slightly confused: Do they mean any app or a compromised app?

A compromised app. The vulnerability requires local code execution, so either an app you install and run, or a malicious webpage that somehow breaks out of the browser sandbox, or... loading a specially constructed video file in a vulnerable version of VLC, or something. Basically you need to combine this with some other vulnerability or convince the user to just straight up run the code.

What wasn't clear was that is there a known browser sandboxing vulnerability at this point that can be used to get root or the idea is that if someone has one they could use this one to get root. Can I use Chrome in my Android phone now or cannot?

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#72

Earlier quoted context omitted.

Wasn't this a case where members of the Project Zero team were individually commenting in a Chromium bug thread and not a Project Zero public facing blog post? Was there a Project Zero blog post before those comments went public that I missed?

It's not a "Chromium" bug, it's project-zero bug [1]. https://bugs.chromium.org/ is just a bug tracker site to host batch of projects by Google. While most of them are related to Chromium, there are also things like project-zero. [1] https://bugs.chromium.org/p/project-zero/issues/detail?id=19...

So where was the Project Zero blog post on the matter?

Because if this wasn't announced on their blog I'm going to have to say that this particular case would not be an apples to apples comparison.

Here was the Project Zero blog post on Apple's exploit, for comparison.

https://googleprojectzero.blogspot.com/2019/08/a-very-deep-d...

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#73
post #51

Earlier quoted context omitted.

And your chance to share this complete control with every installed app. Phones should be like desktop computers. You install an app, you give it access to everything your account can touch on the computer.

Nobody would willingly run outdated, vulnerable software if there was an easy, direct, and supported way to root your phone. Sell phones locked for security or whatever, I couldn't care less, but give people the option to root when they want. So many iPhone users knowingly refuse to upgrade to newer versions of the operating system just so they can keep their jailbreak.

> Nobody would willingly run outdated, vulnerable software if there was an easy, direct, and supported way to root your phone.

People do that all the time with desktop computers.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#74
To me, the biggest part of this story is:

1. Over two years ago, this was apparently detected automatically by the syzkaller kernel fuzzer, and automatically reported on its public mailing list. [1]

2. Over a year and a half ago, it was apparently fixed in the upstream kernel. [2]

3. It was apparently never merged back to various "stable" kernels, leading to the recent CVE. [3]

So you might read that and think "Ok, probably a rare mistake"...

...but instead:

4. This is apparently a _super_ common sequence of events, with kernel vulnerabilities getting lost in the shuffle, or otherwise not backported to "stable" kernels for a variety of reasons like the patch no cleanly longer applies.

Dmitry Vyukov (original author of syzkaller fuzzer that found this 2 years ago) gave a very interesting talk on how frequently this happens a couple weeks ago at the Linux Maintainer's Summit, along with some discussion of how to change kernel dev processes to try to dramatically improve things:

slides: https://linuxplumbersconf.org/event/4/contributions/554/atta...

video: https://youtu.be/a2Nv-KJyqPk?t=5239

---

[1] https://twitter.com/dvyukov/status/1180195777680986113

[2] https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux...

[3] https://mobile.twitter.com/grsecurity/status/118005953923380...

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#76
Mobile phones, especially Android ones are very vulnerable as they rarely get updates, or if they get updates at all. And these devices are used for second factor security. And sometimes they are the only thing needed to get access to your entire life.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#77
post #51

Earlier quoted context omitted.

Nobody would willingly run outdated, vulnerable software if there was an easy, direct, and supported way to root your phone. Sell phones locked for security or whatever, I couldn't care less, but give people the option to root when they want. So many iPhone users knowingly refuse to upgrade to newer versions of the operating system just so they can keep their jailbreak.

> Nobody would willingly run outdated, vulnerable software if there was an easy, direct, and supported way to root your phone. People do that all the time with desktop computers.

As much as a certain outspoken group want you to think, there are lots of other reasons besides security to do something.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#79

This is another great chance to root your phone and take complete control of what you should rightly own.

In Android land you can buy a phone where the bootloader can be unlocked and directly flash a pre-rooted ROM rather than relying on people exploiting security vulnerabilities like this.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#80

After the recent disclosures about Apple vulnerabilities, I've seen a lot of (unwarranted, in my opinion) criticism from HN of Project Zero, specifically the accusation of non-Google bias. For those who hold this position, does this affect your stance?

Their release pattern with the Apple fault could effectively be called a PR campaign, including a lot of editorial narrative about bad software development processes, etc.

This one gets a bug tracker entry.

When Project Zero posts a lengthy analysis with lots of scurious claims about the victims of the exploit, the window of exploitation, and narrative about the poor development practices that led to it, then call it even.

If it follows the traditional pattern, they'll write a post blaming some external party. No, seriously, when people point out all of the "Android" faults they've found invariably it is some variation of "but it isn't really Google's fault....".

Project Zero is brilliant, full of brilliant people, and is a remarkable effort, but when your paycheque is signed off by someone, it is human nature that you're really going to pussyfoot with them.

Post reply on HN