Live data from Hacker News

Accidental Google Pixel Lock Screen Bypass

bugs.xdavidhu.me

391–400 of 475 posts

Re: Accidental Google Pixel Lock Screen Bypass

#391

>Two weeks after our call, I got a new message that confirmed the original info I had. They said that even though my report was a duplicate, it was only because of my report that they started working on the fix. Google engineers don't seem to care much or am I being too harsh here ?

If you are that makes two of us, my partner just asked me why I shouted "what the hell?!" when I read that.

Re: Accidental Google Pixel Lock Screen Bypass

#392
post #136

I wonder how many LEO agencies are now digging androids out of the evidence closet.

Sounds like this only affects phones that have been unlocked since the last restart, so unless they have kept them plugged it is unlikely that this attack would be successful.

Some discussion elsethread[0] suggests that that may only be the case for devices that are encrypted, as the passcode in that case would be part of the key for unlocking the contents.

If that's the case, it's possible that this attack may still work from a fresh boot for unencrypted devices.

[0] https://news.ycombinator.com/item?id=33550327

Re: Accidental Google Pixel Lock Screen Bypass

#394

Add to that the fact that the pixel 6 left audiophiles SOL for almost a year with no 3.5mm jack and broken USB-C DAC compatibility. Ontop of that Display Port Alt Mode is still disabled on every pixel for no good reason, despite many pixel owners reaching out to them, leaving us SOL for an alternative to samsung dex, or compaitibility with devices like the Nreal Air AR glasses. Google's hardware support IME is a shit…

Buy iPhone. I'm switching from iPhone to Pixel because iPhone bans some apps which are essential for me. Android is just so bad. The day Apple allow side loading, I'll switch back.

Re: Accidental Google Pixel Lock Screen Bypass

#395
post #314
post #64

Earlier quoted context omitted.

On iPhone, keys are evicted from memory when the device is locked. Apps running behind the Lock Screen can only write files to special file inboxes (this is why the camera lets you take pictures while locked but doesn’t display earlier pictures, for example) You’re telling me that android keeps keys in memory for its entire uptime?

Do you have any more details about how that works on iphone? It seems very hard to believe, given the complexity and diversity of background apps on iphones, some of which access huge data that would be impossible in system memory (e.g. offline GPS/navigation apps). For example, Google Photos can send the full photo library on the phone, even if large, to the cloud while the device is locked.

This should help: https://help.apple.com/pdf/security/en_US/apple-platform-sec...

Re: Accidental Google Pixel Lock Screen Bypass

#396

This is a great example of why you should use iOS. Most android devices do not receive security updates long enough to get this update. Since the author effectively tells you how to do it, all you need to do is find a pixel 4 or older and you’re golden.

Bugs happen in iOS too.

> all you need to do is find a pixel 4 or older and you’re golden

Its worse, it works on most Android phones without the latest security patch, not just Google phones.

Re: Accidental Google Pixel Lock Screen Bypass

#397
post #368
post #64

Earlier quoted context omitted.

On iPhone, keys are evicted from memory when the device is locked. Apps running behind the Lock Screen can only write files to special file inboxes (this is why the camera lets you take pictures while locked but doesn’t display earlier pictures, for example) You’re telling me that android keeps keys in memory for its entire uptime?

It has to, if you want to be able to unlock the device with a fingerprint

[deleted]

Re: Accidental Google Pixel Lock Screen Bypass

#398

Earlier quoted context omitted.

because if the number of screens is small and there are few tiers (only 2), passing an identifier around could be overkill sounds to me like it's an optimization for introducing more tiers than what there are

> the number of screens is small and there are few tiers (only 2) Making this kind of assumption, when there are no such guards in the system itself, is exactly what leads to security issues. If the system enforced two named singletons as security screens, so it was impossible to .dismiss() the wrong thing, then sure. But that's not how the system is, and assuming that "the number of screens is small" and "there are…

Since they are dismissing the Lock Screen _type_ (SIM, PUK, Pin) and not the instance, a logical example for where this might go wrong is if you have dual SIM. Then again, worst case you dismiss the incorrect SIM Lock Screen. That will not give you full unlock and also the ‘wrong’ SIM will still not work

Re: Accidental Google Pixel Lock Screen Bypass

#399
post #304

I was under the impression that decrypting storage actually requires the passcode of the phone, but this bug makes it look like the device is able to decrypt itself without any external input. Does anybody know more context about this? What's the point of encryption if the device can just essentially backdoor decrypt itself?

It was a fresh boot, and instead of the usual lock icon, the fingerprint icon was showing. It accepted my finger, which should not happen, since after a reboot, you must enter the lock screen PIN or password at least once to decrypt the device. i was surprised to read this part too. assuming that the author's version of the events are accurate here, my best guess is that the device had not fully powered down, and was…

Doesn’t seem like a full unlock, see the next paragraph: “After accepting my finger, it got stuck on a weird “Pixel is starting…” message, and stayed there until I rebooted it again.”

Re: Accidental Google Pixel Lock Screen Bypass

#400
Terrible response by Google to this.

Basically it seems like their bureaucracy is structured so that no one has an incentive to actually address this. Everyone at the company acted like they would rather this issue not even exist, rather that address a critical flaw that makes locking essentially not work on the Pixel.

This gives us a look under the cover of what's important at Google, and it seems like security is a clear subdivision of marketing in this case.

Post reply on HN