Live data from Hacker News

Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

thenextweb.com

31–40 of 236 posts

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#31

This is another great chance to root your phone and take complete control of what you should rightly own.

And your chance to share this complete control with every installed app. Phones should be like desktop computers. You install an app, you give it access to everything your account can touch on the computer.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#32
post #18

> However, if you install an application from an untrusted source, attackers can take advantage of that. Attackers can also take advantage of the bug if they pair it with vulnerabilities in the Chrome browser to render content. So, you have to sideload an app or from some other source. Is it unreasonable to say don't do that? How common is it anyway? I work with IT folks and only a few ever seem to load outside the P…

I use some apps on F-Froid.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#33
post #29

Earlier quoted context omitted.

How many consumers across the world would actually be at risk from NSO having details of the exploit vs. all the other "bad guys" though? Isn't there a significant distinction that's being brushed under the rug here?

> How many consumers across the world would actually be at risk… We don't know, because we don't know who bought it and how widespread they deployed it.

Oh come on. We can never know with 100% certainty. But they already know the company is selling to authorities, not random people. Can't we make an educated guess here?

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#34

> However, if you install an application from an untrusted source, attackers can take advantage of that. I'm slightly confused: Do they mean any app or a compromised app?

A compromised app. The vulnerability requires local code execution, so either an app you install and run, or a malicious webpage that somehow breaks out of the browser sandbox, or... loading a specially constructed video file in a vulnerable version of VLC, or something. Basically you need to combine this with some other vulnerability or convince the user to just straight up run the code.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#35

> However, if you install an application from an untrusted source, attackers can take advantage of that. I'm slightly confused: Do they mean any app or a compromised app?

Yes, it's frustrating when people casually conflate using any alternative source of apps than official app stores with actual malicious application sources.

The reality is, you don't need to "trust" the source in general, you just need to trust that the source is not malicious. If the source is untrusted but you have faith it is not malicious then you can rely on Android's built in permissions system to protect you from it exceeding the bounds of what you would like it to do.

This may sound very pedantic, but the whole existence of an app ecosystem that isn't controlled by the hegemony of the 2 or 3 big app stores depends on this nuance.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#36
post #34

> However, if you install an application from an untrusted source, attackers can take advantage of that. I'm slightly confused: Do they mean any app or a compromised app?

A compromised app. The vulnerability requires local code execution, so either an app you install and run, or a malicious webpage that somehow breaks out of the browser sandbox, or... loading a specially constructed video file in a vulnerable version of VLC, or something. Basically you need to combine this with some other vulnerability or convince the user to just straight up run the code.

Thanks, the ambiguous wording from the article suggested to me that a vulnerability in the system code used for installing from an untrusted source may be used by the exploit.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#37

This is another great chance to root your phone and take complete control of what you should rightly own.

And your chance to share this complete control with every installed app. Phones should be like desktop computers. You install an app, you give it access to everything your account can touch on the computer.

Android has one of the best security models and sandboxing for apps. It's based around SELinux.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#38
post #29

Earlier quoted context omitted.

> How many consumers across the world would actually be at risk… We don't know, because we don't know who bought it and how widespread they deployed it.

Oh come on. We can never know with 100% certainty. But they already know the company is selling to authorities, not random people. Can't we make an educated guess here?

Sure, just model the relative probability that each hacking group will find a vulnerability. For a simple example, let's just say there are 5 organizations in the world that are equally good as NSO. So the odds that NSO were the first to find this one are 20%. In reality I think the odds would be quite a bit worse.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#39
post #13

Earlier quoted context omitted.

Well, one thing is it was apparently already publicly reported over 2 years ago by syzkaller: https://twitter.com/dvyukov/status/1180195777680986113

That was apparently fixed? > No longer occurring on linux-next, probably fixed by the following commit: > #syz fix: ANDROID: binder: remove waitqueue when thread exits. https://groups.google.com/forum/#!msg/syzkaller-bugs/QyXdgUh...

Not sure if it's that exact one, but according to https://bugs.chromium.org/p/project-zero/issues/detail?id=19... it was fixed in "Dec 2017 in the 4.14 LTS kernel, AOSP android 3.18 kernel, AOSP android 4.4 kernel, and AOSP android 4.9 kernel".

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#40
After the recent disclosures about Apple vulnerabilities, I've seen a lot of (unwarranted, in my opinion) criticism from HN of Project Zero, specifically the accusation of non-Google bias. For those who hold this position, does this affect your stance?
Post reply on HN