Exploiting a Bug in Google's Glass
saurik.com
Exploiting a Bug in Google's Glass
1–10 of 32 posts
Re: Exploiting a Bug in Google's Glass
#2Re: Exploiting a Bug in Google's Glass
#3Re: Exploiting a Bug in Google's Glass
#4Summary: He did you not use oem unlock (but he could have if he wanted to), but rather exploited a race condition bug that let him gain root.
Given that the kernel source was not made available until the next day, he could not have used oem unlock - even "if he wanted to."
Re: Exploiting a Bug in Google's Glass
#5Summary: He did you not use oem unlock (but he could have if he wanted to), but rather exploited a race condition bug that let him gain root.
I think the entire ensuing discussion and a small part of this followup article point to the fact that at the time at which he exploited the device, the kernel source was unavailable, as well as that flashing a new boot image is only useful if you can actually build a kernel to flash. Given that the kernel source was not made available until the next day, he could not have used oem unlock - even "if he wanted to."
Re: Exploiting a Bug in Google's Glass
#6Summary: He did you not use oem unlock (but he could have if he wanted to), but rather exploited a race condition bug that let him gain root.
I think the entire ensuing discussion and a small part of this followup article point to the fact that at the time at which he exploited the device, the kernel source was unavailable, as well as that flashing a new boot image is only useful if you can actually build a kernel to flash. Given that the kernel source was not made available until the next day, he could not have used oem unlock - even "if he wanted to."
Additionally, my article documents the threat of this kind of security exploit on Glass, along with some issues with this specific device that make exploits of any kind more dangerous (the lack of a PIN being key), as well as looking at some scary examples of Glass-specific malware opportunities.
Re: Exploiting a Bug in Google's Glass
#7Earlier quoted context omitted.
I think the entire ensuing discussion and a small part of this followup article point to the fact that at the time at which he exploited the device, the kernel source was unavailable, as well as that flashing a new boot image is only useful if you can actually build a kernel to flash. Given that the kernel source was not made available until the next day, he could not have used oem unlock - even "if he wanted to."
Why would you need the kernel source to fastboot unlock?
So, it is possible, it just isn't practical, especially when an exploit happened to be so easy to come by. Once you then have a security exploit, you can then start to ask "what does this let me do that an unlocked bootloader does not", and the ramifications on Glass are, at least to me, interesting.
Re: Exploiting a Bug in Google's Glass
#8Relevant - 4 days ago there was a twitter pic posted and much discussion on HN [1]. [1] https://news.ycombinator.com/item?id=5614920
Re: Exploiting a Bug in Google's Glass
#9While I was super-eager to get Glass before, it really got me wondering if having camera and microphone in your glasses is such an great idea after all.
Re: Exploiting a Bug in Google's Glass
#10While the first part of this article couldn't decide whether it was directed toward technical or non-technical audience, second part about security implications of such an easy way to get root was definitely thought-provoking. While I was super-eager to get Glass before, it really got me wondering if having camera and microphone in your glasses is such an great idea after all.