I wish closing things as "this is a duplicate" essentially required disclosure of the original (dupe) report. It may well be that it's a dupe, or it may be something that looks similar but not actually the same. And indeed as in this case it's only the follow up report that got the bug fixed. In this case it seems that contacts at google allowed them to escalate anyway and get it fixed. But so often and especially wi…
Accidental Google Pixel Lock Screen Bypass
71–80 of 475 posts
Re: Accidental Google Pixel Lock Screen Bypass
#72Re: Accidental Google Pixel Lock Screen Bypass
#73Given how much engineers make at Google after a long interview process to supposedly only get the best people, how significant the login system is to security, how "industry standard" the Google process is, it's not a bug that should have ever made it live. The bug fix show that the issue was clearly a case of a set of people not communicating well, code reviews being lax, and a general lack of understanding of how A…
Re: Accidental Google Pixel Lock Screen Bypass
#74Given the bug was already reported (and even more ignored) it seems like the $70,000 was really a “you made us do our jobs” fee.
It read like the payment came only when disclosure was imminent. Google basically extorted themselves into paying it to encourage pushing disclosure out a couple months.
*Edit: ̶H̶o̶w̶ ̶t̶o̶ ̶s̶t̶r̶i̶k̶e̶t̶h̶r̶o̶u̶g̶h̶?̶ - cheers
Re: Accidental Google Pixel Lock Screen Bypass
#75Earlier quoted context omitted.
It didn't work on a fresh reboot, so presumably, it functioned like you're describing. But, when he swapped the sim live, without the reboot, the phone was already running with the key in memory.
On iPhone, keys are evicted from memory when the device is locked. Apps running behind the Lock Screen can only write files to special file inboxes (this is why the camera lets you take pictures while locked but doesn’t display earlier pictures, for example) You’re telling me that android keeps keys in memory for its entire uptime?
There is a data protection class that is like what you're describing, but it is not used super-widely, the one most commonly used is exactly what is being described and makes data available after first unlock.
https://developer.apple.com/documentation/security/ksecattra...
Re: Accidental Google Pixel Lock Screen Bypass
#76Earlier quoted context omitted.
If you use a Pixel for high risk applications you are a bit at fault here
iOS has had many flaws this bad or worse, so what would you have people use? I agree current gen smartphones should not trusted for high risk uses but the reality is, they are. There are staggering numbers of people using their phones for banking, crypto trading, or to transmit sensitive information that could collapse markets or start wars. Also consider not all journalists or dissidents get a choice in what phone t…
Has iOS had a Lock Screen bypass in recent history?
Re: Accidental Google Pixel Lock Screen Bypass
#77I can't believe this is not a "drop everything and get it fixed ASAP" bug. This makes me think there's probably tons of other similar bugs out there being exploited right now even with disclosure.
Here's another example of a critical vulnerability in GCP that Google sat on for 9 months: https://github.com/irsl/gcp-dhcp-takeover-code-exec
Re: Accidental Google Pixel Lock Screen Bypass
#78Oh, the exceptional safety of object oriented programming!
Re: Accidental Google Pixel Lock Screen Bypass
#79Given how much engineers make at Google after a long interview process to supposedly only get the best people, how significant the login system is to security, how "industry standard" the Google process is, it's not a bug that should have ever made it live. The bug fix show that the issue was clearly a case of a set of people not communicating well, code reviews being lax, and a general lack of understanding of how A…
Re: Accidental Google Pixel Lock Screen Bypass
#80Earlier quoted context omitted.
If you use a Pixel for high risk applications you are a bit at fault here
What a weird argument. So if the law enforcement of your country uses this technique to unlock your phone without your permission(or you know, some criminal does that), that's your fault for using a Pixel phone? You should have known better than you know, buying a phone from one of the largest software houses on the planet? I smell a fair hint of victim blaming here.
Why is that a bad thing? You should absolutely blame and hold the victim responsible and accountable for their part.