Live data from Hacker News

Accidental Google Pixel Lock Screen Bypass

bugs.xdavidhu.me

101–110 of 475 posts

Re: Accidental Google Pixel Lock Screen Bypass

#101

Every once in a blue moon when I pick up my locked iPhone (which auto-locks in just 30 seconds) and engage the home button just as the screen comes alive from the gyro sensing movement, it unlocks on its own. It just flashes the PIN dialog and slides right onto the home screen. I don't use Touch ID, and never stored my print with it even once to test the feature/hardware. It's been happening ever since iOS 11, with b…

[deleted]

Re: Accidental Google Pixel Lock Screen Bypass

#103
post #78

> When the SIM PUK was reset successfully, a .dismiss() function was called by the PUK resetting component on the “security screen stack”, causing the device to dismiss the current one and show the security screen that was “under” it in the stack Oh, the exceptional safety of object oriented programming!

There's nothing OOP-specific about this bug. The bug is in too-wide variable scoping, insufficient OO really.

Re: Accidental Google Pixel Lock Screen Bypass

#104
post #88
post #64

Earlier quoted context omitted.

On iPhone, keys are evicted from memory when the device is locked. Apps running behind the Lock Screen can only write files to special file inboxes (this is why the camera lets you take pictures while locked but doesn’t display earlier pictures, for example) You’re telling me that android keeps keys in memory for its entire uptime?

What do Windows/Mac/Linux do?

Key is in memory at all times after boot on all of those.

Full disk encryption is only useful on a laptop if the device is powered down fully.

Re: Accidental Google Pixel Lock Screen Bypass

#105

Glad he got rewarded. Feels like this could have played out differently, if it had hit his disclosure deadline we might have been reading about him going to prison, such is the febrile nature of the legal situation around vulnerabilities.

I tell companies 90 days. When they ignore me I go public at 90 days, consequences be damned.

No jail time for simply telling the truth about a discovery I made on my own time.

https://www.vice.com/en/article/3kxy4k/high-tech-japanese-ho...

Re: Accidental Google Pixel Lock Screen Bypass

#107
post #76
post #67

Earlier quoted context omitted.

iOS has had many flaws this bad or worse, so what would you have people use? I agree current gen smartphones should not trusted for high risk uses but the reality is, they are. There are staggering numbers of people using their phones for banking, crypto trading, or to transmit sensitive information that could collapse markets or start wars. Also consider not all journalists or dissidents get a choice in what phone t…

> iOS has had many flaws this bad or worse Has iOS had a Lock Screen bypass in recent history?

There have been MANY such attacks against the iPhone (and every other device), most of them against the biometrics mechanisms, which tend to be pretty weak as a matter of first principles. Add to that the persistent hints/rumors/claims of gray market unlock/rooting kits available to large entities. Phones just aren't that secure, though they're much more so than they were a decade ago. Security vs. physical access is an extremely hard nut to crack, it's only been in the last few years that we genuinely thought it was even possible.

Re: Accidental Google Pixel Lock Screen Bypass

#108
post #53

This is a great example of why you should use iOS. Most android devices do not receive security updates long enough to get this update. Since the author effectively tells you how to do it, all you need to do is find a pixel 4 or older and you’re golden.

Besides my opinion that iOS is just simply better built and more secure, the biggest difference for me comes down to the UI. Maybe my mind is just wired more for iOS, but subjectively I would say that it's by far the superior user interface. Snappy as hell too.

I've used both for about as much for quite some years, both OS phones are always with me.

I'd say iPhones used to be snappier maybe 5+ years ago, but nowadays I grab an Android phone if I want something to be done fast, say perform a web search. Two exceptions: 1) Android phones are stuttery disasters for some time after booting up. No big deal, since I rarely power my phones off. 2) iPhone is usually faster to snap a photo than Android.

For anything security related, like banking etc. I use iPhone.

Of course your mileage may vary.

Re: Accidental Google Pixel Lock Screen Bypass

#110

Earlier quoted context omitted.

What a weird argument. So if the law enforcement of your country uses this technique to unlock your phone without your permission(or you know, some criminal does that), that's your fault for using a Pixel phone? You should have known better than you know, buying a phone from one of the largest software houses on the planet? I smell a fair hint of victim blaming here.

> I smell a fair hint of victim blaming here. Why is that a bad thing? You should absolutely blame and hold the victim responsible and accountable for their part.

So let me rephrase my question - what part of the blame should be assigned to the victim here, if their "fault" was buying a phone made and marketed by one of the largest and most well known software developers on the planet?

Also, this is an interesting discussion in general. If someone forgets to lock their door and a thief gets in and robs them, do you think it's fair to "blame" the person who forgot to lock their door? Or do you think that maybe we should recognize that 100% of the blame should be on you know, the person doing the robbing?

Post reply on HN