Live data from Hacker News

A 0-click exploit chain for the Pixel 10

projectzero.google

251–255 of 255 posts

Re: A 0-click exploit chain for the Pixel 10

#251

Earlier quoted context omitted.

Sure, in an ideal world different from this one. You should be able to do anything on any device and never worry about security. Unfortunately, since we don't live in that world, we need to not open links, emails, text messages, etc, if they are sketchy. A better solution may someday exist, but as of yet has not been found.

"Don't click on links" is not a solution, and it's not something people actually do, it's just something they think they do. Corporate Security will tell you that it's ok to click links to the payroll system or hr or vanta or the 'secure email service' or jira or github or to docusign or the microsoft office document that a partner company sent you or an amazon delivery notification, but not ok to click links in the…

[flagged]

Re: A 0-click exploit chain for the Pixel 10

#252

Earlier quoted context omitted.

"Don't click on links" is not a solution, and it's not something people actually do, it's just something they think they do. Corporate Security will tell you that it's ok to click links to the payroll system or hr or vanta or the 'secure email service' or jira or github or to docusign or the microsoft office document that a partner company sent you or an amazon delivery notification, but not ok to click links in the…

> "Don't click on [sketchy] links" is not a solution, and it's not something people actually do, it's just something they think they do. And yet, there is currently no better solution I'm aware of, so that is what they must do. "Just let anybody click and open anything" is not a solution, either.

It's not a solution, it's the problem statement.

Re: A 0-click exploit chain for the Pixel 10

#253

Earlier quoted context omitted.

> "Don't click on [sketchy] links" is not a solution, and it's not something people actually do, it's just something they think they do. And yet, there is currently no better solution I'm aware of, so that is what they must do. "Just let anybody click and open anything" is not a solution, either.

It's not a solution, it's the problem statement.

If the solution you're suggesting is not a solution, then the solution I suggested (which is a solution) seems to be the best one we have at the moment.

Re: A 0-click exploit chain for the Pixel 10

#254

Earlier quoted context omitted.

It's not a solution, it's the problem statement.

If the solution you're suggesting is not a solution, then the solution I suggested (which is a solution) seems to be the best one we have at the moment.

> It's not a solution

It seems we're in violent agreement: neither of us think that "just let anybody click and open anything" is a solution.

That leaves us with the robust solution cited earlier: "Don't click on sketchy links".

Re: A 0-click exploit chain for the Pixel 10

#255

Earlier quoted context omitted.

If the solution you're suggesting is not a solution, then the solution I suggested (which is a solution) seems to be the best one we have at the moment.

> It's not a solution It seems we're in violent agreement: neither of us think that "just let anybody click and open anything" is a solution. That leaves us with the robust solution cited earlier: "Don't click on sketchy links" .

[deleted]
Post reply on HN