Live data from Hacker News

Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

thenextweb.com

81–90 of 236 posts

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#81

“It’s advisable that you don’t install apps from non-trustworthy sources, ” Unpopular opinion but this is why I prefer walled garden apple for my family then alternative.

I don't understand people who want to remove choice. Don't want the ability to install apps from untrustworthy sources? Don't enable the option that gives you that ability.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#82

This is another great chance to root your phone and take complete control of what you should rightly own.

And your chance to share this complete control with every installed app. Phones should be like desktop computers. You install an app, you give it access to everything your account can touch on the computer.

I always wonder if the people who go around spreading this FUD have ever used a rooted phone. Privilege elevation is a specific, clear, and targeted procedure. It's not automatic, apps don't just get access to the entire system right away bu default, and nobody who rooted their phone just answers "yes, give root to this app" for any old purpose.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#83

“It’s advisable that you don’t install apps from non-trustworthy sources, ” Unpopular opinion but this is why I prefer walled garden apple for my family then alternative.

The actual bug talks about "untrusted app code execution". As in, code in any app, regardless of where it was installed from. So you're relying on review by the walled garden as protection.

And of course, "untrusted sources" is not the same as "all side-loading". I use sources to sideload from that I trust more than the average app developer.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#84
post #65

Earlier quoted context omitted.

From the article “However, on Aug. 15, a Google researcher discovered a flaw with the installer, which can let a separate app on your phone hijack what the software actually downloads.” So a separate app can hijack what another app does. That means the sandbox is broken.

their installer downloaded the game into shared storage. They should at least have known that access to shared storage is not sandboxed and should have been verifying what they are about to install instead of trusting no other app would maliciously place an apk where their installer did expect it to be... ideally they would never have used shared storage at all... that said, the sandboxing and permission system worke…

So you have to trust the app not to do anything stupid or malicious? Isn’t the whole point of an operating systems permission system so you don’t have to trust the developer? All apps having access to shared storage without explicit permission is no better than computer operating systems.

If an app can trash your user data the permission system is useless.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#86
post #37

Earlier quoted context omitted.

And your chance to share this complete control with every installed app. Phones should be like desktop computers. You install an app, you give it access to everything your account can touch on the computer.

Android has one of the best security models and sandboxing for apps. It's based around SELinux.

> Android has one of the best security models and sandboxing for apps. It's based around SELinux.

You mean a security model that misses the fact that the kernel cannot be updated and relies on a "sanboxing" solution that doesn't bother limiting kernel attack surface. No, I don't think they even had a security model in mind, a threat model or anything beyond random ad hoc ideas. And if they did some thinking, they would not have chosen SELinux either, as it's not a decent solution to anything, it's more like a solution to "we must to do something, this is something, we must do this".

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#87
post #29

Earlier quoted context omitted.

> How many consumers across the world would actually be at risk… We don't know, because we don't know who bought it and how widespread they deployed it.

Oh come on. We can never know with 100% certainty. But they already know the company is selling to authorities, not random people. Can't we make an educated guess here?

It's very hard to tell because we've observed NSOs using comparable vulnerabilities both very sparingly against select individual targets, and also observed exploits used in a mass fashion against whole populations such as the recent uncovering of exploits targeting Uyghur communities.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#88
post #18

> However, if you install an application from an untrusted source, attackers can take advantage of that. Attackers can also take advantage of the bug if they pair it with vulnerabilities in the Chrome browser to render content. So, you have to sideload an app or from some other source. Is it unreasonable to say don't do that? How common is it anyway? I work with IT folks and only a few ever seem to load outside the P…

I've been using LineageOS on my phones for a couple of years now, recently reinstalled and made the decision to not install the Play Store... and am totally happy with it! I get most of my stuff from F-Droid and some software vendors provide APKs straight from their websites and whatever is Play Store exclusive, I simply don't use. It was going really well, at least until recently, when here in Germany they started i…

Use YALP [1] or Aurora [2] (both are on FDroid) to get the APK's for your banking apps. These apps This is what I do for the Swedish electronic ID app, it has worked for years and hopefully will continue to do so.

[1] https://f-droid.org/en/package/com.github.yeriomin.yalpstore...

[2] https://f-droid.org/en/packages/com.aurora.store/

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#89

After the recent disclosures about Apple vulnerabilities, I've seen a lot of (unwarranted, in my opinion) criticism from HN of Project Zero, specifically the accusation of non-Google bias. For those who hold this position, does this affect your stance?

So far this further supports the argument that they are special casing and going into a lot more detail when it comes to non Android or Chrome bugs.

Will there be a large analysis how frequently this was exploited and so forth? How about a public Google blog post around this?

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#90

Earlier quoted context omitted.

I've been using LineageOS on my phones for a couple of years now, recently reinstalled and made the decision to not install the Play Store... and am totally happy with it! I get most of my stuff from F-Droid and some software vendors provide APKs straight from their websites and whatever is Play Store exclusive, I simply don't use. It was going really well, at least until recently, when here in Germany they started i…

Use YALP [1] or Aurora [2] (both are on FDroid) to get the APK's for your banking apps. These apps This is what I do for the Swedish electronic ID app, it has worked for years and hopefully will continue to do so. [1] https://f-droid.org/en/package/com.github.yeriomin.yalpstore... [2] https://f-droid.org/en/packages/com.aurora.store/

Tried 'em both, IIRC Yalp didn't work, Aurora seemed fine.

Since it was a banking app, I got the APK of many different sites/programs and compared the hashes, and one of the programs had definitely tampered with the APK, but I can't remember which.

Since I left Aurora on my phone, they seemed to have passed on untouched APKs, but don't take my word for it.

EDIT: Also, this voids me of any "warranties" my bank would offer me, so I'm really not going down that path. Really, the only correct thing would be for the bank to offer the APK on their site, but I'd probably have to wait until the government forces this to happen (if ever).

Post reply on HN