Live data from Hacker News

Exploiting a Bug in Google's Glass

saurik.com

1–10 of 32 posts

Re: Exploiting a Bug in Google's Glass

#4
post #2

Summary: He did you not use oem unlock (but he could have if he wanted to), but rather exploited a race condition bug that let him gain root.

I think the entire ensuing discussion and a small part of this followup article point to the fact that at the time at which he exploited the device, the kernel source was unavailable, as well as that flashing a new boot image is only useful if you can actually build a kernel to flash.

Given that the kernel source was not made available until the next day, he could not have used oem unlock - even "if he wanted to."

Re: Exploiting a Bug in Google's Glass

#5
post #4
post #2

Summary: He did you not use oem unlock (but he could have if he wanted to), but rather exploited a race condition bug that let him gain root.

I think the entire ensuing discussion and a small part of this followup article point to the fact that at the time at which he exploited the device, the kernel source was unavailable, as well as that flashing a new boot image is only useful if you can actually build a kernel to flash. Given that the kernel source was not made available until the next day, he could not have used oem unlock - even "if he wanted to."

Why would you need the kernel source to fastboot unlock?

Re: Exploiting a Bug in Google's Glass

#6
post #4
post #2

Summary: He did you not use oem unlock (but he could have if he wanted to), but rather exploited a race condition bug that let him gain root.

I think the entire ensuing discussion and a small part of this followup article point to the fact that at the time at which he exploited the device, the kernel source was unavailable, as well as that flashing a new boot image is only useful if you can actually build a kernel to flash. Given that the kernel source was not made available until the next day, he could not have used oem unlock - even "if he wanted to."

To be fair, I'd say the goal of my article is to just make certain that everyone else can replicate what I did and learn from it; normally I'd co-release a post with the announcement, but I wanted to do the announcement sooner and wasn't expecting it to burn quite so much of my time.

Additionally, my article documents the threat of this kind of security exploit on Glass, along with some issues with this specific device that make exploits of any kind more dangerous (the lack of a PIN being key), as well as looking at some scary examples of Glass-specific malware opportunities.

Re: Exploiting a Bug in Google's Glass

#7
post #4

Earlier quoted context omitted.

I think the entire ensuing discussion and a small part of this followup article point to the fact that at the time at which he exploited the device, the kernel source was unavailable, as well as that flashing a new boot image is only useful if you can actually build a kernel to flash. Given that the kernel source was not made available until the next day, he could not have used oem unlock - even "if he wanted to."

Why would you need the kernel source to fastboot unlock?

I encourage you to read the article, as this is one of the things that I cover (including a quote from the developer of ClockwordMod regarding the practicality of using fastboot oem unlock for purposes of getting root on a device without anything to start with, such as kernel source in specific).

So, it is possible, it just isn't practical, especially when an exploit happened to be so easy to come by. Once you then have a security exploit, you can then start to ask "what does this let me do that an unlocked bootloader does not", and the ramifications on Glass are, at least to me, interesting.

Re: Exploiting a Bug in Google's Glass

#8

Relevant - 4 days ago there was a twitter pic posted and much discussion on HN [1]. [1] https://news.ycombinator.com/item?id=5614920

As someone who wasn't familiar with saurik or his work before this original picture posting (sorry!), I'd just like to say that it's really refreshing to see such a level-headed member of the community at work. Some of the responses (on HN and other places) to his original post seemed very dismissive (along the lines of the now-famous "Yes, Glass is hackable. Duh."), which could easily lead to some defensive bickering. But from what I saw, saurik responded calmly and thoroughly to many comments, in situations where I've seen less experienced/matured members of the community (no, I'm not going to name names) take a... different approach. I'm looking forward to reading his write-up more thoroughly when I get the chance.

Re: Exploiting a Bug in Google's Glass

#9
While the first part of this article couldn't decide whether it was directed toward technical or non-technical audience, second part about security implications of such an easy way to get root was definitely thought-provoking.

While I was super-eager to get Glass before, it really got me wondering if having camera and microphone in your glasses is such an great idea after all.

Re: Exploiting a Bug in Google's Glass

#10
post #9

While the first part of this article couldn't decide whether it was directed toward technical or non-technical audience, second part about security implications of such an easy way to get root was definitely thought-provoking. While I was super-eager to get Glass before, it really got me wondering if having camera and microphone in your glasses is such an great idea after all.

It would be interesting if there was some way to pop the camera/microphone off so that Glass could still give you notifications, just not collect input. Would solve a few problems.
Post reply on HN