Live data from Hacker News

Accidental Google Pixel Lock Screen Bypass

bugs.xdavidhu.me

121–130 of 475 posts

Re: Accidental Google Pixel Lock Screen Bypass

#122

I dislike Google like the next guy. And this is problem of monumental proportions. But if you came here to piss on Android and praise Apple's security, let me remind you of this: https://www.howtogeek.com/334611/huge-macos-bug-allows-root-...

Surely you can find something more recent than five years.

Re: Accidental Google Pixel Lock Screen Bypass

#123
post #11

I can't believe this is not a "drop everything and get it fixed ASAP" bug. This makes me think there's probably tons of other similar bugs out there being exploited right now even with disclosure.

This was kind of my experience with reporting a bug to Google as well. Some years ago I managed to upload a SWF file to "google.com" which allowed me to do an XSS and access anyone's gmail, contacts, etc. I reported it and they just initially never responded and I had to constantly follow up. It was seemingly a simple bug to fix but it took them a couple months and they eventually only paid $500. Being able to exfiltrate data out of someone's gmail account always seemed high priority to me but I guess not lol.

Re: Accidental Google Pixel Lock Screen Bypass

#124
post #104
post #88

Earlier quoted context omitted.

What do Windows/Mac/Linux do?

Key is in memory at all times after boot on all of those. Full disk encryption is only useful on a laptop if the device is powered down fully.

That sounds like a security issue. Why are disk encryption keys not evicted in sleep mode? Seems like no apps should be running in sleep mode?

Re: Accidental Google Pixel Lock Screen Bypass

#125

I dislike Google like the next guy. And this is problem of monumental proportions. But if you came here to piss on Android and praise Apple's security, let me remind you of this: https://www.howtogeek.com/334611/huge-macos-bug-allows-root-...

Surely you can find something more recent than five years.

I don't see how the timing is relevant here.

Re: Accidental Google Pixel Lock Screen Bypass

#126

I dislike Google like the next guy. And this is problem of monumental proportions. But if you came here to piss on Android and praise Apple's security, let me remind you of this: https://www.howtogeek.com/334611/huge-macos-bug-allows-root-...

Surely you can find something more recent than five years.

Like Apple not patching macOS security holes on older versions: https://arstechnica.com/gadgets/2021/11/psa-apple-isnt-actua... ?

(This happened again with Ventura).

Re: Accidental Google Pixel Lock Screen Bypass

#127
post #21

I wish closing things as "this is a duplicate" essentially required disclosure of the original (dupe) report. It may well be that it's a dupe, or it may be something that looks similar but not actually the same. And indeed as in this case it's only the follow up report that got the bug fixed. In this case it seems that contacts at google allowed them to escalate anyway and get it fixed. But so often and especially wi…

Yeah for purposes of the reward it should only be allowed to be considered a dupe if it duplicates a disclosed bug.

I suppose the risk is people could 'game' the system.

Person A finds the issue, reports it.

Then Person A secretly tells Person B about it (with no apparent connection), and Person B reports the same issues a few weeks later, but with apparent different code/description to look ever so slightly different.

Re: Accidental Google Pixel Lock Screen Bypass

#129

Earlier quoted context omitted.

> I smell a fair hint of victim blaming here. Why is that a bad thing? You should absolutely blame and hold the victim responsible and accountable for their part.

So let me rephrase my question - what part of the blame should be assigned to the victim here, if their "fault" was buying a phone made and marketed by one of the largest and most well known software developers on the planet? Also, this is an interesting discussion in general. If someone forgets to lock their door and a thief gets in and robs them, do you think it's fair to "blame" the person who forgot to lock their…

> If someone forgets to lock their door and a thief gets in and robs them, do you think it's fair to "blame" the person who forgot to lock their door?

No, but let's say they've bought from a manufacturer who is not most well known for their lock mechanisms, wouldn't it be the user's responsibility to find a better alternative? You're to be held accountable for your part.

You're making the assumption that the average person thinks Google employs the “most well known software developers on the planet” – that's your subjective take, not anything close to common knowledge

Re: Accidental Google Pixel Lock Screen Bypass

#130

Appalling handling on Google’s end here. The duplicate issue part I can understand, but why should it take two reports of a critical vulnerability to take action? Surely when the first one comes through it’s something you jump on, fix and push out ASAP, not give delay to the point where a second user can come along, find the bug, and report it. The refactor that’s mentioned towards the end of the article is great, bu…

Just trying to rationalize, but if the "external researcher" was hired by Google to find security issues, google might have a requirement to fix the bug at its own pace.

I would personally be highly suspicious of a security flaw being a duplicate though. It's can be a very convenient excuse not to pay the bounty.

Post reply on HN