Live data from Hacker News

Accidental Google Pixel Lock Screen Bypass

bugs.xdavidhu.me

371–380 of 475 posts

Re: Accidental Google Pixel Lock Screen Bypass

#371
post #131

Earlier quoted context omitted.

So you'd go out and refactor a major security sensitive component (which dates to time before your career most likely) in a span of a single month for an emergency security patch deadline? That doesn't inspire a lot of confidence in your risk assesment and decision making. I'd do what Google did: rollout a patch that addresses the immediate danger and then backlog proper refactors over time.

I don't think that is as much of an issue as the ridiculous process he had to go through. Think about that first security researcher. You literally found a Screen Unlock bypass (should be Priority #1, right?) - and Google just went and put fixing it on the backburner. If they will put something like that on the backburner, what else are they ignoring? It isn't confidence-inspiring. Edit: Also, knowing Google, what ar…

Could have been sold for up to 300k or more on the black market.

Re: Accidental Google Pixel Lock Screen Bypass

#372

I went to buy a phone maybe two months ago. Before I had my current Google Pixel 6, I used a OnePlus 3T for six years, and even then I only stopped because I sat in a hot tub with it on. At the T-Mobile store, I announced to the salesman that I would be back to buy a Pixel 6 when they had it in stock, and a man pulled me aside and privately asked me why I wanted to buy a Pixel. He explained to me that he was actually…

Modern carriers are migrating to VoLTE, and LineageOS is unable to implement this outside of a few devices, meaning that many phones have been dropped from the latest release.

As [w]cdma is shut down in preference for 5g and LTE, Pixels (model 3 and above) will be more desirable for users who wish to run Android without Google on modern cellular networks.

I am one such user.

Supposedly, two different implementations of VoLTE exist in AOSP, neither of wich are used outside Pixels (if I understood previous discussions correctly).

Re: Accidental Google Pixel Lock Screen Bypass

#374

I went to buy a phone maybe two months ago. Before I had my current Google Pixel 6, I used a OnePlus 3T for six years, and even then I only stopped because I sat in a hot tub with it on. At the T-Mobile store, I announced to the salesman that I would be back to buy a Pixel 6 when they had it in stock, and a man pulled me aside and privately asked me why I wanted to buy a Pixel. He explained to me that he was actually…

I'm... not sure that I would take a random person* in a T-Mobile store at their word when they claimed that they were "actually working in the hardware division at Google."

I recognize that I should've been more clear but the person who pulled me aside was a random customer waiting in line who pulled me aside when I told the T-Mobile guy that I was planning on getting a Pixel, which they didn't have in stock. I did ask a fair number of questions about what it was that he did to determine that it wasn't someone older who was just messing with me. Granted, this was some number of months ago, but if I recall correctly he was trying to figure out why people wanted Pixels because on his team, people would use iPhones because their family members used iPhones, or because it was easier from an enterprise security standpoint with BYOD. I'm not sure if I remember specifics beyond that.

It's kind of a post-hoc realization that I should've used his admission to me as a reason to second guess a purchase on a device which I've come to discover: has a stock messenger application that fails to sync message receipt times, that gets very hot to the touch, drops cell phone tower connections until rebooted. And, as the article we're replying to points out, had a lock screen bypass bug that wasn't fixed for months.

Re: Accidental Google Pixel Lock Screen Bypass

#375

Earlier quoted context omitted.

Why? Seems pretty intuitive to me in a time where everything is encrypted.

If the phone is setup for automatic updates it'll restart within a month (most of the phones I've had do monthly security patches) and you'll be in a fresh boot state. You can't turn off the updates without first unlocking the phone giving you a rather limited window to attempt to exploit the device.

Will it reboot if it's not on network?

Re: Accidental Google Pixel Lock Screen Bypass

#376
post #172
post #156

Earlier quoted context omitted.

Fooling a biometric sensor is precisely a lock screen bypass, that's what the biometrics are for. By that logic the linked bug was "fooling the SIM security layer" and not a "lock screen bypass". Don't play that game, it's bad logic and bad security practice.

But it’s a fundamentally different type of security bug: these biometrics bypasses require knowing something about the user (lift a fingerprint, picture of a face, etc). I see this as a different class: I can grab an unknown person’s Pixel they left in a coffee shop and get into it.

Cellebrite sits on a pile of unlock exploits for Apple devices and sells unlocking services to law enforcement, or presumably anyone with money.

https://cellebrite.com/en/cas-sales-inquiry/

Zerodium brokers sales of iOS FCP Zero Click for $2m. I expect they sell to people like Cellebrite who can make a profit selling expensive unlocks and keeping the vuln secret.

https://www.zerodium.com/program.html

All phones are security shit shows. It is just a game of how well known this months exploits are and how much someone has to gain by targeting you.

Re: Accidental Google Pixel Lock Screen Bypass

#377

> The same issue was submitted to our program earlier this year, but we were not able to reproduce the vulnerability. When you submitted your report, we were able to identify and reproduce the issue and began developing a fix. > We typically do not reward duplicate reports; however, because your report resulted in us taking action to fix this issue, we are happy to reward you the full amount of $70,000 USD for this L…

Ah, that's a nice hack to avoid having to pay your bounties! First report: "can't reproduce, sorry." Subsequent reports: "duplicate, sorry." Then fix on whatever schedule you feel isn't too blatant.

And they stiffed him $30K

Re: Accidental Google Pixel Lock Screen Bypass

#378

Earlier quoted context omitted.

> "Due to this, they decided to make an exception" Sounds like they weren't going to at first, though, because it appeared to be a duplicate, but this was the better bug report that prompted an action. (To be fair: my hat's off to Google for even having one, and it's still shocking to me that AWS doesn't have one at all.)

AWS has a bug bounty it's just hosted by the fine black hat community instead of amazon

took me a moment to catch! nice!

Re: Accidental Google Pixel Lock Screen Bypass

#379
post #245

So basically google wanted to give this guy nothing. Then he set a hard deadline for disclosure and google managed to buy him for 70k so they could stick with their own deadline.

I agree that it appears to have been the disclosure threat that resulted in the bounty, but I don't agree (if I'm reading you correctly) that the OP acted unethically. It sounds credible to me that he was just doing everything he could to get the bug fixed.
Post reply on HN