Live data from Hacker News

Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

thenextweb.com

51–60 of 236 posts

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#51

This is another great chance to root your phone and take complete control of what you should rightly own.

And your chance to share this complete control with every installed app. Phones should be like desktop computers. You install an app, you give it access to everything your account can touch on the computer.

Nobody would willingly run outdated, vulnerable software if there was an easy, direct, and supported way to root your phone. Sell phones locked for security or whatever, I couldn't care less, but give people the option to root when they want.

So many iPhone users knowingly refuse to upgrade to newer versions of the operating system just so they can keep their jailbreak.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#52
post #18

> However, if you install an application from an untrusted source, attackers can take advantage of that. Attackers can also take advantage of the bug if they pair it with vulnerabilities in the Chrome browser to render content. So, you have to sideload an app or from some other source. Is it unreasonable to say don't do that? How common is it anyway? I work with IT folks and only a few ever seem to load outside the P…

In places without proper internet access it's common for phone stores to host their own fdroid repos on the local network to set people up with apps.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#53
post #21
post #9

Earlier quoted context omitted.

Because the "bad guys" already know about the vulnerability, so there's no benefit from keeping it secret but a duty to the consumers to inform them as well - especially since the kernel patch already exists.

If the "bad guys" were one team it would make sense, but there's a whole world of guys who can turn "bad" when the opportunity is given. And it is given, when a new vuln is unmasked.

The precautions a cautious user will want to take when armed with this information don’t really change or become more burdensome whether there’s one group of attackers or many, so I don’t see how that changes the calculus at all.

It’s also probably not a terribly great assumption that no one else has independently discovered this vulnerability that’s already been independently discovered twice. Caution suggests we should assume this is in the wild and act accordingly.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#54

After the recent disclosures about Apple vulnerabilities, I've seen a lot of (unwarranted, in my opinion) criticism from HN of Project Zero, specifically the accusation of non-Google bias. For those who hold this position, does this affect your stance?

I've not seen that criticism myself. But to me what Project Zero is doing re: Apple vulnerabilities is great. I own Apple products and it's only going to improve/harden them

However, I do think some of the motive is to take a bit of shine off Apple - meaning it's partly a marketing campaign.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#55
post #18

> However, if you install an application from an untrusted source, attackers can take advantage of that. Attackers can also take advantage of the bug if they pair it with vulnerabilities in the Chrome browser to render content. So, you have to sideload an app or from some other source. Is it unreasonable to say don't do that? How common is it anyway? I work with IT folks and only a few ever seem to load outside the P…

I don't get why you're being downvoted, because that's an excellent question: I do that all the time: I'm using F-Droid more often than the Play Store. Actually, I haven't ever used the Play Store on my second smartphone (it requires a Google Account and I don't want to link it to a Google identity) — I've tens of apps on it.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#56
post #35

Earlier quoted context omitted.

Yes, it's frustrating when people casually conflate using any alternative source of apps than official app stores with actual malicious application sources. The reality is, you don't need to "trust" the source in general, you just need to trust that the source is not malicious. If the source is untrusted but you have faith it is not malicious then you can rely on Android's built in permissions system to protect you f…

Android’s built in permission system didn’t work too well with the Fortnite installer https://www.pcmag.com/news/363357/google-irks-epic-games-by-...

Kudos to Epic for using their power to attempt to break Google's Play Store hegemony, facepalms for unfortunately proving one of Google's (both legit and pretended) concerns on safety and security regarding acquiring apps from outside of the Play Store.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#57

Earlier quoted context omitted.

Wasn't this a case where members of the Project Zero team were individually commenting in a Chromium bug thread and not a Project Zero public facing blog post? Was there a Project Zero blog post before those comments went public that I missed?

It's not a "Chromium" bug, it's project-zero bug [1]. https://bugs.chromium.org/ is just a bug tracker site to host batch of projects by Google. While most of them are related to Chromium, there are also things like project-zero. [1] https://bugs.chromium.org/p/project-zero/issues/detail?id=19...

They CNAME the site and give P0 a dedicated domain if they wanted to alleviate this confusion.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#58
post #49

Earlier quoted context omitted.

Android’s built in permission system didn’t work too well with the Fortnite installer https://www.pcmag.com/news/363357/google-irks-epic-games-by-...

this has nothing to do with androids permission system at all... epic made the decision to distribute Fortnite themselves while bypassing the Play Store in order to save on the 30% cut google would otherwise get from game sales. This worked by installing an app manually that did download the game and installs or updates it afterwards. This installer had a serious flaw allowing malicious apps to install other software…

From the article

“However, on Aug. 15, a Google researcher discovered a flaw with the installer, which can let a separate app on your phone hijack what the software actually downloads.”

So a separate app can hijack what another app does. That means the sandbox is broken.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#59

Earlier quoted context omitted.

Android’s built in permission system didn’t work too well with the Fortnite installer https://www.pcmag.com/news/363357/google-irks-epic-games-by-...

Kudos to Epic for using their power to attempt to break Google's Play Store hegemony, facepalms for unfortunately proving one of Google's (both legit and pretended) concerns on safety and security regarding acquiring apps from outside of the Play Store.

Hasn’t the entire argument been that Android’s permission system would have prevented this even if the app was installed outside of the store?

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#60
post #48

Earlier quoted context omitted.

SHOULD desktop apps be like this? :D

Absolutely not. It's an outdated concept from the days where all the software you run was either preinstalled or you created it yourself and the only security consideration was stopping you from messing up another users setup on the shared computer.

My desktop environment doesn't associate data with particular programs. Data is ideally in standard file formats and multiple programs can interact with it. I can see that tying data to a particular program may improve security, but it would also be extremely inconvenient.
Post reply on HN