Live data from Hacker News

Attacking Titan M with Only One Byte

blog.quarkslab.com

51–60 of 84 posts

Re: Attacking Titan M with Only One Byte

#51
post #19

Earlier quoted context omitted.

I guess there's someone who orders the marketing department to say "1 million", while telling the operational side "10k", because his bonus rides on it.

That's not how it works. Bug bounties work like this. Somebody sets up a bounty program and defines a framework for deciding how much to pay out. Security is complicated as hell and you cannot possibly devise a framework that accounts for all possible things so this framework is necessarily brittle. For example, you might reasonably decide that the highest payouts require very minimal attacker capabilities (fully rem…

I'm still surprised by the $10k payout given the disclosure timeline. For example they indicate that on 2022-05-04 there was a "conference call between Quarkslab engineers, Google Android Security Team members, and a Titan engineering team member." Since there were both Android security team members and a Titan engineer in the phone call there were clearly engineers in the loop who understood the technical details of the issue as well as the severity. The initial $10k payout was done on 2022-06-07, a month later.

One would imagine that this would have been escalated to some pretty senior security folks at Google before the payout was decided. That would mean that there would be some amount of discretion on Google's end as to the payout, since there would (presumably) be someone senior enough to look at this closely and authorize a higher amount even if there was some rubric that might seem to award a lower amount. Obviously this is ultimately what happened, as they eventually did increase the payout. It's a little strange to me though that this wasn't done sooner.

Re: Attacking Titan M with Only One Byte

#52
post #34
post #32

Earlier quoted context omitted.

Google bug bounty program is a sham. When I tried to report critical vulnerability in their authentication system, they told it's a 'feature' and threatened to sue if I disclose. Then fixed it in two and a half years, and wrote an article on how complicated bug they just found and how proud and secure they are with their pentesters.

Do you have a link?

It was looong time ago (2011). You could use app specific password to change master password and disable 2FA, with a script.

Funny thing. I had to discover this way myself when I lost my phone with Authenticator App. I took my mail client password and discovered that with some header magic I was able to hijack my own account. I couldn't believed it. So I created another account, protected with 2FA and did same thing. Got gaslighted by Google bug bounty team and decided it's not worth it.

Re: Attacking Titan M with Only One Byte

#53

Earlier quoted context omitted.

That's not how it works. Bug bounties work like this. Somebody sets up a bounty program and defines a framework for deciding how much to pay out. Security is complicated as hell and you cannot possibly devise a framework that accounts for all possible things so this framework is necessarily brittle. For example, you might reasonably decide that the highest payouts require very minimal attacker capabilities (fully rem…

I'm still surprised by the $10k payout given the disclosure timeline. For example they indicate that on 2022-05-04 there was a "conference call between Quarkslab engineers, Google Android Security Team members, and a Titan engineering team member." Since there were both Android security team members and a Titan engineer in the phone call there were clearly engineers in the loop who understood the technical details of…

> One would imagine that this would have been escalated to some pretty senior security folks at Google before the payout was decided.

Bug bounties are routine. "How much do you want to pay out" is way down the list of things that leadership is focused on for these things. "How do we mitigate this" and "how does the researcher get paid" are often questions owned by different people and teams. Directors aren't swooping in to make payout decisions.

Re: Attacking Titan M with Only One Byte

#54

This is an elegant attack that effectively compromises all Titan M chips. They were even able to dump all securely stored private cryptographic keys, which Google acknowledges in the disclosure timeline. Even still though, the award Google initially gave was only $10k USD(!). They finally bumped it to $75k USD after complaint and review, but Google's bug bounty program claims up to $1 Million USD. If fully compromisi…

For 2018 chip and for a company like Google, the decision to go with C despite their all knowledge oN C/C++ memory issues (hello Chrome) is a bit sad.

Re: Attacking Titan M with Only One Byte

#56
Sounds like an amateur hour at that Google team. While post authors are putting blame on the un-safeness of C, absence of user input validation, like that integer from a message, is a path to a very unhappy place independent of language. The rest of the exploited places of that Titan software seem to be similarly sloppy.

Re: Attacking Titan M with Only One Byte

#57

This is an elegant attack that effectively compromises all Titan M chips. They were even able to dump all securely stored private cryptographic keys, which Google acknowledges in the disclosure timeline. Even still though, the award Google initially gave was only $10k USD(!). They finally bumped it to $75k USD after complaint and review, but Google's bug bounty program claims up to $1 Million USD. If fully compromisi…

For 2018 chip and for a company like Google, the decision to go with C despite their all knowledge oN C/C++ memory issues (hello Chrome) is a bit sad.

I would imagine it wasn't a hard decision - they likely needed to build something in an environment where they are already paying 40-80k C++ developers, and I would guess something like 1-10k Rust developers, who are scattered around various teams and may not want to hop on a new team right now. Also it was released to the consumer market in 2018, so probably built in 2016-17. Rust and other memory-safe systems programming alternatives didn't have nearly the same uptake back then - so maybe 1-2k would be a safer bet. Not to mention, Rust didn't get tier-1 ARM support until 2021 - and even then, that's only when running on linux, which the Titan M chip is most likely not running.

Re: Attacking Titan M with Only One Byte

#58
post #32

This is an elegant attack that effectively compromises all Titan M chips. They were even able to dump all securely stored private cryptographic keys, which Google acknowledges in the disclosure timeline. Even still though, the award Google initially gave was only $10k USD(!). They finally bumped it to $75k USD after complaint and review, but Google's bug bounty program claims up to $1 Million USD. If fully compromisi…

Google bug bounty program is a sham. When I tried to report critical vulnerability in their authentication system, they told it's a 'feature' and threatened to sue if I disclose. Then fixed it in two and a half years, and wrote an article on how complicated bug they just found and how proud and secure they are with their pentesters.

On what grounds could they sue you if it was truly considered a "feature", and they used that exact terminology in their response?

Re: Attacking Titan M with Only One Byte

#59
post #25

Very cool. I wonder why companies still leave the UART pins accessible. Fine they're on the chip, but just remove the trace and slow down attack evolution is worth the cost of a board revision surely...

If THAT is your idea of security, i hope you do not work on any hardware whose security matters. First thing anyone would do is find the pins and connect to them. It buys you nothing, and if anything tells me that i should go look for them. Visible and labeled UART pins tell me that you've (hopefully) thought through the consequences of me having access to them. Hidden UART tells me that most likely nobody ever gave…

Do you have __any idea__ how difficult removing the chip and re-surface mounting it for an attack...

Removing the trace means an extra step which is the whole point. Ffs

Re: Attacking Titan M with Only One Byte

#60
post #26

Earlier quoted context omitted.

I think the $1M is probably reserved to something that would tank Google stock imo, but maybe I'm cynical

Nah, you're not cynical enough. My cynical take is there is nothing they would ever pay $1M for. "Up to" is a marketing term to get people to think that if they work hard enough, they might qualify for this mythical unicorn bounty, but at the end of the day they just get peanuts.

"You might win this car!"
Post reply on HN