Live data from Hacker News

Accidental Google Pixel Lock Screen Bypass

bugs.xdavidhu.me

221–230 of 475 posts

Re: Accidental Google Pixel Lock Screen Bypass

#221
post #180
post #5

Seems to me like this impacts not only Pixel devices but all Android devices? Patch was to AOSP: https://github.com/aosp-mirror/platform_frameworks_base/comm... I don't have a locked SIM handy, but can someone please test on their non-Pixel device and confirm?

Thing is, most phone manufacturers will customize the lockscreen quite a bit, so it's possible (but not necessary!) it affects others.

Yeah, agreed. I wonder if it affects LineageOS, which I run.

Re: Accidental Google Pixel Lock Screen Bypass

#222
post #125

Earlier quoted context omitted.

I don't see how the timing is relevant here.

Let’s take it to the extreme. Suppose this becomes the last bug Google exhibits in the next fifty years. Forty nine years in the future Apple makes a major security faux pas. Do we need to remind everyone that Google made a bug fifty years ago, too?

Or we can be realistic and agree that neither Apple nor Google are immune to future bugs.

Re: Accidental Google Pixel Lock Screen Bypass

#223
post #185
post #136

I wonder how many LEO agencies are now digging androids out of the evidence closet.

LEO already have access to locked phones via stuff like GrayKey. https://www.grayshift.com/graykey/

Android disabling USB data by default has been a thorn.

Re: Accidental Google Pixel Lock Screen Bypass

#224
post #133

Earlier quoted context omitted.

Everyone who reports a undisclosed bug should get a share of the bounty; this incentivizes them to stick to the embargo. If too many people are reporting the bug before you fix it then you have other problems. I also start to feel that at Google's scale bounties this serious should start doubling every month.

Do you mean each new person should get a new bounty, or all reporters should split the bounty? The latter does not really incentivize much, but the former incentivizes reporters to collude with other reporters (i.e. you find a bug, tell your 40 friends to report the same bug, you get a kickback from all your friends who also reported it. $$$$).

The latter does incentivize everyone who stumbles across the bug to not disclose it. At the same time, it's sad for the original researcher whose bounty gets smaller with every new person stumbling across it.

Re: Accidental Google Pixel Lock Screen Bypass

#226
post #114

Earlier quoted context omitted.

That's not really true at all - you can of course unlock your iPhone without entering PIN for every screen lock which should give you a clue that keys for disk encryption generally aren't purged when iPhone is locked. Some keys are, but not the ones that are the issue here. I've even seen conditions where iOS devices reboot and still retain keys.

If you unlock the screen using Face ID the OS gets the keys from the Secure Enclave which, depending on the model, does the face recognition itself or using the normal processor in some kind of secure way. Just like if you unlock the phone using the pin code, the OS gets the key from the Secure Enclave which makes sure it’s not easy to brute force. The PIN code is not the key itself of course. The only key that somet…

Yes, and that's how Pixels work as well. The condition in question here is of course when the secure enclave releases the keys and mounts the storage.

Re: Accidental Google Pixel Lock Screen Bypass

#227
post #7

How come the security model is so basic? I even think they should dismiss modal by id instead of type. As this is a highly sensitive part, I think stacking lock screens on top of the unlocked menu leaves the door open for many bugs that could unlock your device. The unlocked menu should be locked at all times, and use a flag to monitor if it’s locked/unlocked, and only flip the flag when you unlock with biometrics or…

I think an even better approach would be to have the concept of fixed tiers of locking combined with evicting the decryption key for any Lock Screen above the basic PIN.

And you can only move down one tier of unlocking at a time. Unlocking SIM PIN moves you down one tier to phone PIN screen.

Re: Accidental Google Pixel Lock Screen Bypass

#228
post #180

Earlier quoted context omitted.

Thing is, most phone manufacturers will customize the lockscreen quite a bit, so it's possible (but not necessary!) it affects others.

Yeah, agreed. I wonder if it affects LineageOS, which I run.

It does.

Re: Accidental Google Pixel Lock Screen Bypass

#229

> The same issue was submitted to our program earlier this year, but we were not able to reproduce the vulnerability. When you submitted your report, we were able to identify and reproduce the issue and began developing a fix. > We typically do not reward duplicate reports; however, because your report resulted in us taking action to fix this issue, we are happy to reward you the full amount of $70,000 USD for this L…

Ah, that's a nice hack to avoid having to pay your bounties! First report: "can't reproduce, sorry." Subsequent reports: "duplicate, sorry." Then fix on whatever schedule you feel isn't too blatant.

Re: Accidental Google Pixel Lock Screen Bypass

#230

My daughter wears earrings, so she never needs a SIM ejection tool. But I keep one on my keyring - amazing how handy it is. (I don't carry a PIN-locked SIM card!)

I also keep one on my keyring and I get poked in the finger/thigh by it all the time; it’s super annoying! Still keep it though since I regularly have to pop my SIM in and out..
Post reply on HN