Seems to me like this impacts not only Pixel devices but all Android devices? Patch was to AOSP: https://github.com/aosp-mirror/platform_frameworks_base/comm... I don't have a locked SIM handy, but can someone please test on their non-Pixel device and confirm?
Thing is, most phone manufacturers will customize the lockscreen quite a bit, so it's possible (but not necessary!) it affects others.
Accidental Google Pixel Lock Screen Bypass
221–230 of 475 posts
Re: Accidental Google Pixel Lock Screen Bypass
#222Earlier quoted context omitted.
I don't see how the timing is relevant here.
Let’s take it to the extreme. Suppose this becomes the last bug Google exhibits in the next fifty years. Forty nine years in the future Apple makes a major security faux pas. Do we need to remind everyone that Google made a bug fifty years ago, too?
Re: Accidental Google Pixel Lock Screen Bypass
#223Re: Accidental Google Pixel Lock Screen Bypass
#224Earlier quoted context omitted.
Everyone who reports a undisclosed bug should get a share of the bounty; this incentivizes them to stick to the embargo. If too many people are reporting the bug before you fix it then you have other problems. I also start to feel that at Google's scale bounties this serious should start doubling every month.
Do you mean each new person should get a new bounty, or all reporters should split the bounty? The latter does not really incentivize much, but the former incentivizes reporters to collude with other reporters (i.e. you find a bug, tell your 40 friends to report the same bug, you get a kickback from all your friends who also reported it. $$$$).
Re: Accidental Google Pixel Lock Screen Bypass
#225It's quite amazing how poorly designed Android really is. Every single part of that OS is poorly architected and have horrible APIs. What a shame.
Re: Accidental Google Pixel Lock Screen Bypass
#226Earlier quoted context omitted.
That's not really true at all - you can of course unlock your iPhone without entering PIN for every screen lock which should give you a clue that keys for disk encryption generally aren't purged when iPhone is locked. Some keys are, but not the ones that are the issue here. I've even seen conditions where iOS devices reboot and still retain keys.
If you unlock the screen using Face ID the OS gets the keys from the Secure Enclave which, depending on the model, does the face recognition itself or using the normal processor in some kind of secure way. Just like if you unlock the phone using the pin code, the OS gets the key from the Secure Enclave which makes sure it’s not easy to brute force. The PIN code is not the key itself of course. The only key that somet…
Re: Accidental Google Pixel Lock Screen Bypass
#227How come the security model is so basic? I even think they should dismiss modal by id instead of type. As this is a highly sensitive part, I think stacking lock screens on top of the unlocked menu leaves the door open for many bugs that could unlock your device. The unlocked menu should be locked at all times, and use a flag to monitor if it’s locked/unlocked, and only flip the flag when you unlock with biometrics or…
And you can only move down one tier of unlocking at a time. Unlocking SIM PIN moves you down one tier to phone PIN screen.
Re: Accidental Google Pixel Lock Screen Bypass
#228Re: Accidental Google Pixel Lock Screen Bypass
#229> The same issue was submitted to our program earlier this year, but we were not able to reproduce the vulnerability. When you submitted your report, we were able to identify and reproduce the issue and began developing a fix. > We typically do not reward duplicate reports; however, because your report resulted in us taking action to fix this issue, we are happy to reward you the full amount of $70,000 USD for this L…
Re: Accidental Google Pixel Lock Screen Bypass
#230My daughter wears earrings, so she never needs a SIM ejection tool. But I keep one on my keyring - amazing how handy it is. (I don't carry a PIN-locked SIM card!)