Live data from Hacker News

Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

thenextweb.com

21–30 of 236 posts

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#21
post #9
post #2

> The researchers speculate the bug is being used by NSO, an Isreal-based group known to sell tools to authorities to exploit iOS and Android. > Due to evidence of in the wild exploit, we are now de-restricting this bug 7 days after reporting to Android. Why is this a good idea?

Because the "bad guys" already know about the vulnerability, so there's no benefit from keeping it secret but a duty to the consumers to inform them as well - especially since the kernel patch already exists.

If the "bad guys" were one team it would make sense, but there's a whole world of guys who can turn "bad" when the opportunity is given. And it is given, when a new vuln is unmasked.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#23
post #18

> However, if you install an application from an untrusted source, attackers can take advantage of that. Attackers can also take advantage of the bug if they pair it with vulnerabilities in the Chrome browser to render content. So, you have to sideload an app or from some other source. Is it unreasonable to say don't do that? How common is it anyway? I work with IT folks and only a few ever seem to load outside the P…

There are lots of sites out there that host APKs of apps (older versions, etc.)... I'd wager they have more than a few users.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#25
post #11

Earlier quoted context omitted.

It's being actively exploited, which changes the calculus.

"Actively exploited" by... law enforcement? Do all consumers really need to freak out about this the same way they would if hackers had access? Doesn't that detail change the calculus here?

Not all law enforcements are working for the good of their people, probably.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#26
post #18

> However, if you install an application from an untrusted source, attackers can take advantage of that. Attackers can also take advantage of the bug if they pair it with vulnerabilities in the Chrome browser to render content. So, you have to sideload an app or from some other source. Is it unreasonable to say don't do that? How common is it anyway? I work with IT folks and only a few ever seem to load outside the P…

Some of us are just trying to remove ourselves from Google's teat because we don't want to be sucking from Apple's teat instead, but it's getting increasingly harder to do so.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#27
post #18

> However, if you install an application from an untrusted source, attackers can take advantage of that. Attackers can also take advantage of the bug if they pair it with vulnerabilities in the Chrome browser to render content. So, you have to sideload an app or from some other source. Is it unreasonable to say don't do that? How common is it anyway? I work with IT folks and only a few ever seem to load outside the P…

I believe the article is translating that badly from the bug report. An app installed through the Play store is also an "untrusted app code execution" - Play deploys some scanning tools on submitted apps during the review, but do you trust them to catch it always? There's also things like Amazon devices with Amazon app store, ...

Similarly, Chrome is only mentioned because it's notable that it can be effective from inside its isolation if combined with a browser exploit. That likely applies to all browsers, but the article recommends to switch browsers.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#28

Earlier quoted context omitted.

"Actively exploited" by... law enforcement? Do all consumers really need to freak out about this the same way they would if hackers had access? Doesn't that detail change the calculus here?

Not all law enforcements are working for the good of their people, probably.

That still doesn't counter my point.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#29
post #9

Earlier quoted context omitted.

Because the "bad guys" already know about the vulnerability, so there's no benefit from keeping it secret but a duty to the consumers to inform them as well - especially since the kernel patch already exists.

How many consumers across the world would actually be at risk from NSO having details of the exploit vs. all the other "bad guys" though? Isn't there a significant distinction that's being brushed under the rug here?

> How many consumers across the world would actually be at risk…

We don't know, because we don't know who bought it and how widespread they deployed it.

Post reply on HN