Live data from Hacker News

Exploiting a Bug in Google's Glass

saurik.com

21–30 of 32 posts

Re: Exploiting a Bug in Google's Glass

#21

Earlier quoted context omitted.

It would be interesting if there was some way to pop the camera/microphone off so that Glass could still give you notifications, just not collect input. Would solve a few problems.

paper and sticky tape should sort the camera out nicely.

And look mighty attractive on your face.

Re: Exploiting a Bug in Google's Glass

#22
I'm not at all surprised that Glass can be rooted and such, but I wonder about the social implications. A while ago I (incorrectly, sort of) made a post saying that you wouldn't be able to tell when Glass is recording. Somebody replied and mentioned that it would have a red light visible when it is. I didn't bother replying because, despite precedent, I had no proof that Glass would be able to be rooted etc. My point is, with Glass already rooted, is anything stopping somebody from having Glass without a red light while recording?

Re: Exploiting a Bug in Google's Glass

#23
post #6
post #4

Earlier quoted context omitted.

I think the entire ensuing discussion and a small part of this followup article point to the fact that at the time at which he exploited the device, the kernel source was unavailable, as well as that flashing a new boot image is only useful if you can actually build a kernel to flash. Given that the kernel source was not made available until the next day, he could not have used oem unlock - even "if he wanted to."

To be fair, I'd say the goal of my article is to just make certain that everyone else can replicate what I did and learn from it; normally I'd co-release a post with the announcement, but I wanted to do the announcement sooner and wasn't expecting it to burn quite so much of my time. Additionally, my article documents the threat of this kind of security exploit on Glass, along with some issues with this specific devi…

Thank you for performing a valuable public service because we need to have the facts first before having a discussion about the implications. I read an article around the same time about the claim by Julian Assange that the internet is a threat to civilization, and thought your work tied in nicely as a cautionary warning about the path we are currently on. http://www.salon.com/2013/04/30/tk_5_partner_15/singleton/

Re: Exploiting a Bug in Google's Glass

#24
post #19

"At this point, I could have simply complained to Google in order to obtain the source code for the kernel. However, I expected that would take days (Google actually ended up posting the code within hours on Saturday, but that was under rather large public pressure), " FWIW: 1. It wouldn't have taken days, it would have taken roughly the same time no matter when it happened, or whether it was requested privately or p…

Hey, so speaking as someone who has tried and failed to get support from Google in the past, can you tell me the right way to complain to Google about such things? (Who to email, which webpage I submit the request at, or whatever the official process is) I'm asking here because what you said sounds great, but unfortunately Googling for "google gpl request" and the like didn't turn up anything.

Support or GPL source? For GPL or open source complaints, we actually watch a pretty large number of sources for this (gpl violations mailing lists, various open source mailing lists, G+ posts, twitter, etc). If you email legal@google, it will get to me, but they may take a little time. In fact, most normal support channels will get there, they just may take a few forwards to end up in my inbox.

I haven't heard that people have had difficulty getting source (because we try to be proactive about it), so I haven't set up an alternate method of contact specifically for it (and in most cases, i'd rather just fix whatever process is broken).

In the short term, the easiest way is to just email me at dannyb@

Longer term, maybe i'll create opensource-requests@ or something.

The only caveat i'll mention is that Motorola is run as a completely separate subsidiary, so I can't guarantee quick answers/solutions if you are having issues with Moto. Not that I can't help, but in practice, because the companies are run separately, it involves beating up people that don't work for me

Re: Exploiting a Bug in Google's Glass

#25

I'm not at all surprised that Glass can be rooted and such, but I wonder about the social implications. A while ago I (incorrectly, sort of) made a post saying that you wouldn't be able to tell when Glass is recording. Somebody replied and mentioned that it would have a red light visible when it is. I didn't bother replying because, despite precedent, I had no proof that Glass would be able to be rooted etc. My point…

It could be similar to how apple laptop camera lights work. Those light come on when the camera is recording and as far as I know it is impossible to stop them within the software. Hopefully glass does the same thing.

Re: Exploiting a Bug in Google's Glass

#26

Very pleased to see such a detailed post. I'm also perturbed by how quickly I went from "Sweet, I can't wait to get glass and compile my own stuff," to "Wait, right, security holes in a 24/7 camera. Umm..." I mean, there have been studies that show you can identify passwords from audio recordings of known keyboard keys clicking. Then again, we did already have such as cellphones. (For quite some time I preferred iOS…

Not sure if you meant 'was' so hard to jailbreak there. I'm pretty sure jailbreaking the iPhone is the hardest it's ever been.

I meant 'was' because I'm currently testing a Nokia 920 and a Nexus 4. And yes, I'm planning on switching back to iOS as soon as it gets NFC or curved front-glass for easier swiping, as both phones have those two features and feel quite modern as a result. A new dashboard for icons wouldn't go amiss either. But I do miss my always-on encryption in sleep and lack of jailbreak, indeed...

Re: Exploiting a Bug in Google's Glass

#27
post #16

Very pleased to see such a detailed post. I'm also perturbed by how quickly I went from "Sweet, I can't wait to get glass and compile my own stuff," to "Wait, right, security holes in a 24/7 camera. Umm..." I mean, there have been studies that show you can identify passwords from audio recordings of known keyboard keys clicking. Then again, we did already have such as cellphones. (For quite some time I preferred iOS…

> from audio recordings of known keyboard keys clicking Neat. http://dl.acm.org/citation.cfm?id=1102169 "We present a novel attack taking as input a 10-minute sound recording of a user typing English text using a keyboard, and then recovering up to 96% of typed characters. There is no need for a labeled training recording. Moreover the recognizer bootstrapped this way can even recognize random text such as passwords.…

Thanks for sourcing my statement. I was worried for a minute that I'd misremembered it. (I'm also glad that's a word!)

Re: Exploiting a Bug in Google's Glass

#28
post #25

I'm not at all surprised that Glass can be rooted and such, but I wonder about the social implications. A while ago I (incorrectly, sort of) made a post saying that you wouldn't be able to tell when Glass is recording. Somebody replied and mentioned that it would have a red light visible when it is. I didn't bother replying because, despite precedent, I had no proof that Glass would be able to be rooted etc. My point…

It could be similar to how apple laptop camera lights work. Those light come on when the camera is recording and as far as I know it is impossible to stop them within the software. Hopefully glass does the same thing.

Glass does not have a light of any kind that comes on while it is recording. The closest you have is that the screen itself is visible from the front (due to how light refracts through a prism). I have heard that the older Glass units that were being demoed by Google employees did have such a light, but if that was true it was removed for the Explorer Edition units.

Re: Exploiting a Bug in Google's Glass

#29
The thing we seem to be missing is what was Dan Morrel getting at when he thought they didn't get root? Di he think they just ran adb against the glass and figured out how to talk to it directly via the same calls the mirror api uses? Is there some easier way to "hack" Glass into doing interesting stuff?

Re: Exploiting a Bug in Google's Glass

#30
post #28
post #25

Earlier quoted context omitted.

It could be similar to how apple laptop camera lights work. Those light come on when the camera is recording and as far as I know it is impossible to stop them within the software. Hopefully glass does the same thing.

Glass does not have a light of any kind that comes on while it is recording. The closest you have is that the screen itself is visible from the front (due to how light refracts through a prism). I have heard that the older Glass units that were being demoed by Google employees did have such a light, but if that was true it was removed for the Explorer Edition units.

Oh. Wow, I'm quite surprised they'd remove that, seems like it would make them a bit easier for people to accept if there's a clear sign of whether they're recording. I expect not doing so is going to mean they're treated like holding your phone up, and there's quite a few places that's really not going to fly.
Post reply on HN