I wish closing things as "this is a duplicate" essentially required disclosure of the original (dupe) report. It may well be that it's a dupe, or it may be something that looks similar but not actually the same. And indeed as in this case it's only the follow up report that got the bug fixed. In this case it seems that contacts at google allowed them to escalate anyway and get it fixed. But so often and especially wi…
Accidental Google Pixel Lock Screen Bypass
61–70 of 475 posts
Re: Accidental Google Pixel Lock Screen Bypass
#62Bottomline: have buddies at Google if you want anything ever get fixed.
Re: Accidental Google Pixel Lock Screen Bypass
#63Earlier quoted context omitted.
> This was a serious feature deficit viz a viz the relevant iPhone at the time. IIRC, the iPhone uses not just a photo from the selfie cam, but adds infrared to construct a sort-of-3d-ish depth map of your face as well - that is what defeats a simple attempt at unlocking with photos. Now, the really interesting thing to research is if a silicone molded face mask could be used to fool the iPhone into unlocking. Photos…
Won’t work - https://9to5mac.com/2019/12/16/3d-mask/amp/ Muscle movement is also now necessary so it’s pretty difficult to circumvent
Re: Accidental Google Pixel Lock Screen Bypass
#64I was under the impression that decrypting storage actually requires the passcode of the phone, but this bug makes it look like the device is able to decrypt itself without any external input. Does anybody know more context about this? What's the point of encryption if the device can just essentially backdoor decrypt itself?
It didn't work on a fresh reboot, so presumably, it functioned like you're describing. But, when he swapped the sim live, without the reboot, the phone was already running with the key in memory.
You’re telling me that android keeps keys in memory for its entire uptime?
Re: Accidental Google Pixel Lock Screen Bypass
#65Re: Accidental Google Pixel Lock Screen Bypass
#66Earlier quoted context omitted.
The security researchers only mistake was letting Google fart around for so long. You give them 90 days, then you go public. That is the policy Google Project Zero holds other companies to, so it is only fair to hold Google to the same standard. People using their device for high risk applications need to be informed in a timely manner, and Google needs to pay a reputational price for their negligence.
If you use a Pixel for high risk applications you are a bit at fault here
I smell a fair hint of victim blaming here.
Re: Accidental Google Pixel Lock Screen Bypass
#67Earlier quoted context omitted.
The security researchers only mistake was letting Google fart around for so long. You give them 90 days, then you go public. That is the policy Google Project Zero holds other companies to, so it is only fair to hold Google to the same standard. People using their device for high risk applications need to be informed in a timely manner, and Google needs to pay a reputational price for their negligence.
If you use a Pixel for high risk applications you are a bit at fault here
I agree current gen smartphones should not trusted for high risk uses but the reality is, they are. There are staggering numbers of people using their phones for banking, crypto trading, or to transmit sensitive information that could collapse markets or start wars.
Also consider not all journalists or dissidents get a choice in what phone they can afford.
Security issues like this can be life or death, and security researchers must sometimes -force- companies to treat them as such.
Re: Accidental Google Pixel Lock Screen Bypass
#68Earlier quoted context omitted.
except apple takes bug fixes and security 100x more than google does. I remember the Android nightmares of Camera1 Camera2 CameraX APIs, then bluetooth all buggy implementation with years passing by and no decent solution in place. I don't remember a single big bug by iOS
From what I have heard, they may fix thing quickly but their bug bounty program is not liked and they skimp on paying higher payouts. Much more lukrative to sell your exploit on the black market.
Re: Accidental Google Pixel Lock Screen Bypass
#69Given how much engineers make at Google after a long interview process to supposedly only get the best people, how significant the login system is to security, how "industry standard" the Google process is, it's not a bug that should have ever made it live. The bug fix show that the issue was clearly a case of a set of people not communicating well, code reviews being lax, and a general lack of understanding of how A…
Re: Accidental Google Pixel Lock Screen Bypass
#70This is a great example of why you should use iOS. Most android devices do not receive security updates long enough to get this update. Since the author effectively tells you how to do it, all you need to do is find a pixel 4 or older and you’re golden.
Who knows how many bugs live in iOS as well. Security through obscurity (iOS is closed source) isn't usually considered that great a strategy. Besides the whole "can't install user software" issue.
What seems to matter more is how many auditors are actually digging in and how aggressively secure coding practices are applied. It certainly doesn’t seem like there’s a big difference between the two in terms of security but Android has more people using old software because their manufacturer didn’t want to ship an update.