Live data from Hacker News

Pixnapping Attack

pixnapping.com

41–50 of 75 posts

Re: Pixnapping Attack

#42
post #41

The best defence seems to be to configure your 2FA app to require biometrics. I'm not sure why they didn't mention this option.

think it's a fair point. but it still triggered this in me: "only way to prevent more of my data from being stolen is to give Android more of my data"

Re: Pixnapping Attack

#43
I'm no expert in security, but I'm guessing if you install an app on a Windows Desktop computer it can do more chaos faster and more discreetly than pixnapping can on Android.

If you use the same password on two websites, any one of the two websites can use it to log you it in the second website (if it doesn't have an extra layer of security).

On paper security is pretty weak yet in practice these attacks are not very common or easy to do.

Re: Pixnapping Attack

#44
post #21

You know it's serious because it's got a domain and a logo. Even security researchers gotta create engagement and develop their brand.

I'd say it's _not_ serious when they need to market it.

Re: Pixnapping Attack

#45

I'm no expert in security, but I'm guessing if you install an app on a Windows Desktop computer it can do more chaos faster and more discreetly than pixnapping can on Android. If you use the same password on two websites, any one of the two websites can use it to log you it in the second website (if it doesn't have an extra layer of security). On paper security is pretty weak yet in practice these attacks are not ver…

>but I'm guessing if you install an app on a Windows Desktop computer it can do more chaos faster and more discreetly than pixnapping can on Android.

On desktop, apps aren't sandboxed. On mobile, they are. Breaking out of the sandbox is a security breach.

On desktop, people don't install an app for every fast food chain. On mobile, they do.

Re: Pixnapping Attack

#46
post #37
post #17

Earlier quoted context omitted.

A patch for the original vulnerability is already public: https://android.googlesource.com/platform/frameworks/native/... and explicitly states in the commit message that it tries to defeat "pixel stealing by measuring how long it takes to perform a blur across windows." The researchers aren't releasing their code because they found a workaround to the patch. Then there's a bunch of "no GPU vendor has committed to pa…

If genuine, this finger pointing is an interesting approach to a security vulnerability. Last time I read such arguments was 20 years ago from a different firm in California and it was not to their advantage. P.S.: where did you see this discussion?

TFA: https://www.pixnapping.com

Re: Pixnapping Attack

#48
post #41

The best defence seems to be to configure your 2FA app to require biometrics. I'm not sure why they didn't mention this option.

Biometrics can't be changed if someone ever figures out how to duplicate them.

Re: Pixnapping Attack

#49
post #45

I'm no expert in security, but I'm guessing if you install an app on a Windows Desktop computer it can do more chaos faster and more discreetly than pixnapping can on Android. If you use the same password on two websites, any one of the two websites can use it to log you it in the second website (if it doesn't have an extra layer of security). On paper security is pretty weak yet in practice these attacks are not ver…

>but I'm guessing if you install an app on a Windows Desktop computer it can do more chaos faster and more discreetly than pixnapping can on Android. On desktop, apps aren't sandboxed. On mobile, they are. Breaking out of the sandbox is a security breach. On desktop, people don't install an app for every fast food chain. On mobile, they do.

inb4 "graphene solves this"
Post reply on HN