> However, if you install an application from an untrusted source, attackers can take advantage of that. I'm slightly confused: Do they mean any app or a compromised app?
A compromised app. The vulnerability requires local code execution, so either an app you install and run, or a malicious webpage that somehow breaks out of the browser sandbox, or... loading a specially constructed video file in a vulnerable version of VLC, or something. Basically you need to combine this with some other vulnerability or convince the user to just straight up run the code.
Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
71–80 of 236 posts
Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
#72Earlier quoted context omitted.
Wasn't this a case where members of the Project Zero team were individually commenting in a Chromium bug thread and not a Project Zero public facing blog post? Was there a Project Zero blog post before those comments went public that I missed?
It's not a "Chromium" bug, it's project-zero bug [1]. https://bugs.chromium.org/ is just a bug tracker site to host batch of projects by Google. While most of them are related to Chromium, there are also things like project-zero. [1] https://bugs.chromium.org/p/project-zero/issues/detail?id=19...
Because if this wasn't announced on their blog I'm going to have to say that this particular case would not be an apples to apples comparison.
Here was the Project Zero blog post on Apple's exploit, for comparison.
https://googleprojectzero.blogspot.com/2019/08/a-very-deep-d...
Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
#73Earlier quoted context omitted.
And your chance to share this complete control with every installed app. Phones should be like desktop computers. You install an app, you give it access to everything your account can touch on the computer.
Nobody would willingly run outdated, vulnerable software if there was an easy, direct, and supported way to root your phone. Sell phones locked for security or whatever, I couldn't care less, but give people the option to root when they want. So many iPhone users knowingly refuse to upgrade to newer versions of the operating system just so they can keep their jailbreak.
People do that all the time with desktop computers.
Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
#741. Over two years ago, this was apparently detected automatically by the syzkaller kernel fuzzer, and automatically reported on its public mailing list. [1]
2. Over a year and a half ago, it was apparently fixed in the upstream kernel. [2]
3. It was apparently never merged back to various "stable" kernels, leading to the recent CVE. [3]
So you might read that and think "Ok, probably a rare mistake"...
...but instead:
4. This is apparently a _super_ common sequence of events, with kernel vulnerabilities getting lost in the shuffle, or otherwise not backported to "stable" kernels for a variety of reasons like the patch no cleanly longer applies.
Dmitry Vyukov (original author of syzkaller fuzzer that found this 2 years ago) gave a very interesting talk on how frequently this happens a couple weeks ago at the Linux Maintainer's Summit, along with some discussion of how to change kernel dev processes to try to dramatically improve things:
slides: https://linuxplumbersconf.org/event/4/contributions/554/atta...
video: https://youtu.be/a2Nv-KJyqPk?t=5239
---
[1] https://twitter.com/dvyukov/status/1180195777680986113
[2] https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux...
[3] https://mobile.twitter.com/grsecurity/status/118005953923380...
Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
#75This is why we need the kernel to be re-written in Rust ASAP -- to make these flaws a thing of the past.
Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
#76Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
#77Earlier quoted context omitted.
Nobody would willingly run outdated, vulnerable software if there was an easy, direct, and supported way to root your phone. Sell phones locked for security or whatever, I couldn't care less, but give people the option to root when they want. So many iPhone users knowingly refuse to upgrade to newer versions of the operating system just so they can keep their jailbreak.
> Nobody would willingly run outdated, vulnerable software if there was an easy, direct, and supported way to root your phone. People do that all the time with desktop computers.
Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
#78Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
#79This is another great chance to root your phone and take complete control of what you should rightly own.
Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
#80After the recent disclosures about Apple vulnerabilities, I've seen a lot of (unwarranted, in my opinion) criticism from HN of Project Zero, specifically the accusation of non-Google bias. For those who hold this position, does this affect your stance?
This one gets a bug tracker entry.
When Project Zero posts a lengthy analysis with lots of scurious claims about the victims of the exploit, the window of exploitation, and narrative about the poor development practices that led to it, then call it even.
If it follows the traditional pattern, they'll write a post blaming some external party. No, seriously, when people point out all of the "Android" faults they've found invariably it is some variation of "but it isn't really Google's fault....".
Project Zero is brilliant, full of brilliant people, and is a remarkable effort, but when your paycheque is signed off by someone, it is human nature that you're really going to pussyfoot with them.