So basically google wanted to give this guy nothing. Then he set a hard deadline for disclosure and google managed to buy him for 70k so they could stick with their own deadline.
Or more charitably, by the terms of the program he wasn't eligable for anything, but they gave him seventy thousand dollars out of goodwill and the spirit of the program.
Accidental Google Pixel Lock Screen Bypass
281–290 of 475 posts
Re: Accidental Google Pixel Lock Screen Bypass
#282So, did someone else get the full $100k for reporting the vuln already or was that BS?
Re: Accidental Google Pixel Lock Screen Bypass
#283This is going to be one if the uncounted casualties of a downturn in tech and layoffs. When the organization is in turmoil, and the tenured folks have left out the backdoor, security flaws are going to remain open for a lot longer
Re: Accidental Google Pixel Lock Screen Bypass
#284My daughter wears earrings, so she never needs a SIM ejection tool. But I keep one on my keyring - amazing how handy it is. (I don't carry a PIN-locked SIM card!)
Re: Accidental Google Pixel Lock Screen Bypass
#285Can we expect a fix for Pixels outside of the official service window? So 4 or older?
No. "No security updates after X" means no security updates after X. Of course you can install an up-to-date OS, e.g. LineageOS works on the Pixel 4.
https://support.google.com/nexus/answer/4457705?hl=en#zippy=...
Re: Accidental Google Pixel Lock Screen Bypass
#286Re: Accidental Google Pixel Lock Screen Bypass
#287Earlier quoted context omitted.
Who knows how many bugs live in iOS as well. Security through obscurity (iOS is closed source) isn't usually considered that great a strategy. Besides the whole "can't install user software" issue.
The number of long-running bugs which have been found in popular open source projects suggests that “many eyes make all bugs shallow” should be remembered as an amusing bit of 90s trivia like Swatch Internet Time. What seems to matter more is how many auditors are actually digging in and how aggressively secure coding practices are applied. It certainly doesn’t seem like there’s a big difference between the two in te…
“many eyes make all bugs shallow” should have always been seen as horse shit. It has the same level of evidence as other linuxy "truisms" like "worse is better" and "everything as text or a file is best"
Heartbleed and shellshock sat right in public eye for quite some time, but it turns out nobody was watching.
Re: Accidental Google Pixel Lock Screen Bypass
#288Re: Accidental Google Pixel Lock Screen Bypass
#289What is up with the Pixel specific bugs lately? One would think Google did more QA on their own products than on stock Android but the opposite seems to be the case.
Re: Accidental Google Pixel Lock Screen Bypass
#290Every once in a blue moon when I pick up my locked iPhone (which auto-locks in just 30 seconds) and engage the home button just as the screen comes alive from the gyro sensing movement, it unlocks on its own. It just flashes the PIN dialog and slides right onto the home screen. I don't use Touch ID, and never stored my print with it even once to test the feature/hardware. It's been happening ever since iOS 11, with b…
Unless of course you can do this long after it locks…