23 ms·
Kids find a security flaw in Linux Mint by mashing keys
- idiocrat 6y agoWell, the original definition of the word "hacking". Hacking on keyboard to exploit keypress timings, key combinations and key buffer overflows.
- radicalbyte 6y agoThe original definition of "hacking" was "hacking code together". Move fast and break things. There are a lot of us OG and TNG hackers here. It's kind of the SV spirit. "Cracker" is the term used commonly - as in "crack the nut"; i.e. gain access to systems / break copy protection etc. Then you have the phone guys, the phreakers, whistling for free calls.
- dagw 6y agoHacking (in the modern 'computer' sense) has been used since at least the late 50s and early 60s and used to mean experimenting with any technical machine or system. It wasn't until the 70s when it primarily became connected with programming.
- zwp 6y ago> original definition of "hacking" was "hacking code together" Hmm. Right spirit but not so much "hacking code together" going on at MIT's Tech Model Railroad Club in 1958. "a project undertaken or a product built not solely to fulfill some constructive goal but with some wild pleasure taken in mere involvement, was called a `hack'". (Steven Levy, "Hackers").
- masswerk 6y agoThe Tech Model Railroad Club (TMRC) Dictionary [1], June 1959, by Peter R. Samson defines (comments in italics by PRS, 2005): HACK: 1) something done without constructive end; 2) a project undertaken on bad self-advice; 3) an entropy booster; 4) to produce, or attempt to produce, a hack. I saw this as a term for an unconventional or unorthodox application of technology, typically deprecated for engineering reasons. There was no specific suggestion of malicious intent (or of benevolence, either). Indeed, the era of this dictionary saw some "good hacks:" using a room-sized computer to play music, for instance; or, some would say, writing the dictionary itself. HACKER: one who hacks, or makes them. A hacker avoids the standard solution. The hack is the basic concept; the hacker is defined in terms of it. ---- [1] "An Abridged Dictionary of the TMRC Language", 1959: http://www.gricer.com/tmrc/dictionary1959.html http://www.gricer.com/tmrc/dictionary1959.html
- s_gourichon 6y agoA well known reference, Eric Raymond's "jargon file" a.k.a. "hacker's dictionary" offers 9 definitions, much broader and seemingly older than keypress timings: http://catb.org/~esr/jargon/html/H/hack.html http://catb.org/~esr/jargon/html/H/hack.html ( see also http://catb.org/~esr/jargon/html/index.html http://catb.org/~esr/jargon/html/index.html and https://en.wikipedia.org/wiki/Jargon_File https://en.wikipedia.org/wiki/Jargon_File )
- scalableUnicon 6y agoRelated: https://news.ycombinator.com/item?id=25801693 https://news.ycombinator.com/item?id=25801693
- diegoperini 6y agoStep 1: Gather timings of key presses from a lot of kids. 2: Use ML to learn how to simulate it. 3: Sell it as a service, labeling it KaaS. 4: Profit, then go to jail because of a misunderstanding. But seriously, is there such a tool to automate this?
- fabianhjr 6y agoFuzzing ( https://en.m.wikipedia.org/wiki/Fuzzing https://en.m.wikipedia.org/wiki/Fuzzing )
- PartiallyTyped 6y agoThere's also model based testing and property based testing. QuickTest in Haskell and Erlang can generate test cases for your code.
- segfaultbuserr 6y agoPeople have been fuzzing user interfaces since the 80s. It was used for developing MacPaint and MacWrite in Apple's original Macintosh. Quote Wikipedia: > In 1983, Steve Capps at Apple developed "The Monkey", a tool that would generate random inputs for classic Mac OS applications, such as MacPaint [0]. The figurative "monkey" refers to the infinite monkey theorem which states that a monkey hitting keys at random on a typewriter keyboard for an infinite amount of time will eventually type out the entire works of Shakespeare. In the case of testing, the monkey would write the particular sequence of inputs that will trigger a crash. Read the story here: https://www.folklore.org/StoryView.py?story=Monkey_Lives.txt https://www.folklore.org/StoryView.py?story=Monkey_Lives.txt
- MrDresden 6y agoI frequently use the monkey bundled with the Android tool chain[0] to stress test my UIs. Have found numerous issues throughout the years by using it [0] https://developer.android.com/studio/test/monkey https://developer.android.com/studio/test/monkey
- 6y ago
- martin-adams 6y agoThis reminds me of when I was about 14. I had a Tamagotchi which I had for a record amount of time. My niece, about 2 at the time wanted to see it so let her hold it. Within 1/2 a second, she squeezed both buttons at the same time and crashed it. My daughter managed to buy 24 hours of football pass with NowTV by pressing the same button repeatedly on the remote within about 5 seconds. So a crash like this doesn't surprise me.
- _puk 6y agoHah, just reminded me.. My daughter, whilst roaming in the US from the EU somehow managed to get unlimited data after her initial miserly roaming allowance was used up.. simply by switching airplane mode on and off repeatedly until data worked. I was stressing getting back home to a huge bill, but kept the "all chargeable services have been stopped" messages just in case. My final bill was £300+, zeroed. Phew!
- withinboredom 6y agoAlso reminds me of “impossible” bug reports, only to discover the way to reproduce them was just simply double clicking on links and buttons.
- berkes 6y agoWe had some race conditions that started appearing more often over time. Those race conditions could be triggered by rapidly firing events on a busy backend. After long research, we found correlation with marketing moving their target from only students to 'older people'. Apparently the latter 'doubleclick' on links and buttons in webforms far more often. At least for us they did.
- josefx 6y ago> Within 1/2 a second, she squeezed both buttons at the same time and crashed it. That was probably not a crash, on some that did a partial reset.
- gambiting 6y agoDoes anyone know why lockscreens in Linux have been such a joke? I remember trying Ubuntu couple years ago and when waking up my laptop it would show me my entire desktop with all the information displayed right there in the open for about 10-20 seconds before suddenly engaging the lockscreen. All you had to do was close the lid and open it again and you could just copy whatever was on the screen before the lock screen appeared. I guess it's because the lockscreen was a separate process that had to start up? Still, what an awful awful design.
- astrange 6y agoBad design in X11 which can't be fixed. https://news.ycombinator.com/item?id=25801693 https://news.ycombinator.com/item?id=25801693
- formerly_proven 6y agoX11 design flaws you say? https://github.com/swaywm/swaylock/issues/162 https://github.com/swaywm/swaylock/issues/162 https://github.com/swaywm/swaylock/issues/158 https://github.com/swaywm/swaylock/issues/158 https://github.com/swaywm/swaylock/issues/10 https://github.com/swaywm/swaylock/issues/10
- chrismorgan 6y agoI’m not familiar with the details of the design flaw and whether or not Wayland fixes it, but those links don’t contradict this being an X-specific design flaw. I get the impression that swaylock is a direct port of i3lock, and thus stands a fair chance of being written and architected in an X style, rather than taking advantage of any superior form that Wayland may support but X didn’t. Expressed otherwise: just because someone’s written one piece of bad software for Wayland doesn’t mean Wayland doesn’t allow you to write good software. (Whereas I get the impression from what I’m reading that X makes it impossible to write a good screen locker, if by that you require that it be crash-proof and use the usual platform toolkit for the UI.) (Remember in this that I’m saying I don’t know. I’d like to hear if Wayland does have a good answer to this, or from anyone with definite knowledge that it doesn’t.)
- stelf 6y agoTime to make a joke about Windows lock screens? Or perhaps not...
- snarfy 6y agohttps://i.imgur.com/rG0p0b2.gif https://i.imgur.com/rG0p0b2.gif
- codeulike 6y agoIt works in the movies
- herpderperator 6y agoIn middle school long ago, I was using one of the library search computers. They ran Windows XP and were locked down to the point where you couldn't open anything except the software that was running and you had no access to the desktop. One day I was rapidly mashing the "Search" button in the native book-searching software they were using - for no reason at all - and it suddenly opened an Explorer window out of nowhere showing everything in the filesystem. I could reproduce it easily with rapid-enough clicks. I still have no idea why that happened.
- Haemm0r 6y agoClassic thing was to write file:///C:\ (or something similar, I do not remember it anymore) on computers with only kiosk mode IE on them to access the local file system. :)
- mhh__ 6y agoAlso powershell was usually unbanned in my experience even if the policy disabled cmd
- michaelcampbell 6y agoIn the early web days, I had a public facing web site with a link that said "I can see what's on your computer", and the href was essentially what you posted. The number of emails I got from that was worth the vitriol contained in them, including threatened lawsuits.
- jorvi 6y agoThis reminds me of the classic XP login screen bypass by opening the help dialog, then the print dialog, then searching for a file to open for printing, and then executing 'explorer.exe' (I might be misremembering, this is quite a while ago). I also remember figuring out how to share my USB key as a network drive to other users. Many fun middays were had blasting around in Halo or Soldier of Fortune II with like 10 friends, although less fun was had when our school's sysadmin found some lingering cache files that were owned by my id.
- 6y ago
- kuter 6y agoFor anyone interested there is something called fuzzing that uses usually code coverage based heuristics to generate data to find bugs. For example LLVM's lib fuzzer uses instrumentation to track code coverage and mutates data to find invalid behaviour. https://llvm.org/docs/LibFuzzer.html https://llvm.org/docs/LibFuzzer.html It uses a compiler pass to insert code to branch points functions calls etc. I think it uses genetic algorithms to increase coverage by changing the data. There are others that work in similar ways one of them is. https://github.com/google/AFL https://github.com/google/AFL
- Vinnl 6y agoSomewhat similar for web UIs: Quickstrom is a tool that lets you define a set of conditions that should hold (e.g. "there should always be an 'Add todo' button"), and then it'll simulate behaviour that might break that condition. See https://quickstrom.io/ https://quickstrom.io/ (I haven't used it myself yet, but it looks interesting.)
- cuillevel3 6y agoHere is an eight year old presentation on fuzzing X: https://media.ccc.de/v/30C3_-_5499_-_en_-_saal_1_-_201312291830_-_x_security_-_ilja_van_sprundel https://media.ccc.de/v/30C3_-_5499_-_en_-_saal_1_-_201312291...
- suyjuris 6y agoI have used AFL a few times casually in some personal projects, and it has always performed quite well for me. Of course, there are a lot of weird cornercases which would not occur on real-world (non-adversarial) inputs, but it also found some very real bugs. (For example, I once wrote a hash table implementation where the insertion and resizing procedures had slightly different views on wraparound, causing failures on very specific inputs. Another time, I wrote some code to buffer out-of-order messages, which would only occur due to a race condition. It was wrong. Both times I had thought carefully about the code, and the bugs would have been painful to discover otherwise.)
- passivate 6y agoWell, I guess the obvious question to ask is has anyone run this particular fuzzer on the code in question?
- greypowerOz 6y agowarning: cat-like typing detected
- dluan 6y agoSomething about this exchange was extremely pleasing and calming to read, maybe I'm irony poisoned from overly loud social media. But this was so nice to read through.
- berkes 6y agoA pleasant bugreport with no judgement or demands. And a quick response by the maintainer who shows thank, is focused on a clear outcome, and shows the progress transparently. I've seen too many bugreports where one, or both actors behave vastly different. This one here should be a reference for anyone involved in 'bugreports' in some way.
- blackrock 6y agoIs this the old monkey testing technique?
- smarx007 6y agoMargaret Hamilton's daughter Lauren still takes the first place for "kid fuzzing" the AGC IMO https://wehackthemoon.com/people/margaret-hamilton-her-daughters-simulation https://wehackthemoon.com/people/margaret-hamilton-her-daugh... But this is pretty impressive as well!
- carapace 6y agoHamilton who coined the phrase "software engineering". Great find!
- boomboomsubban 6y agoI'm surprised nobody had "ē" in their password to notice this earlier.
- 12312311241231 6y agoKeep in mind that screensavers aren't the only untested dumpster fire on Linux Desktops (or ~ distributions in general). The whole desktop architecture is out of date. I wouldn't be surprised if someone argued that screensavers aren't important because it's just your user data exposed, the root account is still safe!
- tauntz 6y agoMi kid got around the lock screen of my mac. Twice. It was 4-5 years ago when he was about 2. I had a 15+ character random password (a generated one including symbols etc) so the chances of him being lucky were rather slim. He was just mashing button on the lock screen for less than a minute when boom, I was suddenly signed in. The first time I thought it was a fluke. Then it happened again after a couple of months. After that I took my phone, sat him behind my computer and started to record him playing with the buttons but it never happened again and my hopes of getting a bug bounty from Apple vanished :(
- apexalpha 6y agoPerhaps it was related to this bug: https://www.wired.com/story/macos-high-sierra-hack-root/ https://www.wired.com/story/macos-high-sierra-hack-root/
- matsemann 6y agoProbably just hit enter when the password field was empty. For some reason that bypassed all security on OS X.
- rand49an 6y agoYou used to be able to just open up recovery mode and reset the password anyway, passwords on OS X used to be a theatre. No idea about it now though.
- lights0123 6y agoStill works unless you have FireVault enabled for obvious reasons.
- thomasmg 6y agoMy kid (3 years old then) found an issue in the MacOS lock screen as well. It didn't result in a bypass, but a "Spinning Beach Ball of Death". I could then reproduce it and even filed an issue, but only I could reproduce (and one funny response was: "Why would you want a screen shot of the screen sleeping? It would just be black." - well tell that to my kid): https://discussions.apple.com/thread/7598463 https://discussions.apple.com/thread/7598463
- eth0up 6y agoPhyslock works comparatively well, but nothing can stop the omniscient stupidity of, eg ctrl-alt-del 10x (or similar) invoking reboot, which I've found no method of preventing. The general attitude encountered when seeking a solution to this madness is "if someone has physical access, you're pwned anyway", which is also supremely unimaginative and omnisciently stupid. This has gnawed at my cranial portions for years, and I now speak forth in due fury. https://linuxcommandlibrary.com/man/physlock https://linuxcommandlibrary.com/man/physlock
- Havoc 6y agoWho needs fancy fuzzing tools anyway?
- rblion 6y agoImagine if Jurassic Park was real and this happened...
- smooth__ 6y ago"It's a Linux system! I know this!" smashes keys Unlocks
- Qub3d 6y agoFor everyone linking the JWZ "I Told You So" post, the devs are aware of it and posted a response in the GitHub issue. I encourage everyone to read their side of the issue: https://github.com/linuxmint/cinnamon-screensaver/issues/354#issuecomment-762261555 https://github.com/linuxmint/cinnamon-screensaver/issues/354...
- sbierwagen 6y agoWhat context? Reading that issue, the content seems to be: 1: jwz says if you add accessibility features to a text box, make sure they don't have any bugs that can kill a process, since that will break screen lockers 2: Cinnamon adds a buggy accessibility feature to a text box that lets you crash the screen locker 3: Github user clefebvre says something along the lines of "why is jwz being so negative >:(" Well... you did exactly what he told you not to do. If you're going to add accessibility features to a text box, you need to not screw it up. If you screw it up, then it breaks the screen locker for every user in the world, including the 99% of people who will never use the accessibility features. If you make an obvious, stupid mistake, people will make fun of you. Complaining that people are making fun of you won't do much. Try, instead, to not make the obvious stupid mistake? From the issue: >With that said, I have on message for JWZ. Don't be that guy. It's too easy to just tell people no to cross the street. Work with us on building that safest path. Huh? What? He wrote xscreensaver 20 years ago. He's supposed to fix buggy code written by other people until he dies? Why is it his responsibility to fix your code? The distro extended his program, the extension broke. You can either ignore the problem, remove the extension, or fix the extension. None of these things sounds like xscreensaver's problem!
- Qub3d 6y ago> Why is it his responsibility to fix your code? The distro extended his program, the extension broke. cinnamon-screensaver (the repo this discussion is pertinent to) is written from scratch. The commenter's intent here is to suggest that JWZ has valid criticisms, but he has voiced them before and his latest blog post doesn't add anything to the discussion. This blog post, which links to the issue, creates additional overhead for the project to deal with. Just like this HN link does. I think its fair for us to give them a voice in the matter if we're showing the discussion to everyone. It would be nice to assume people read the entire discussion but clearly, that is not a reality.
- mhh__ 6y agoUnless there's something unbelievably wacky going on, this is why people use formal verification. If you can describe your program as a state machine, you can ask an SMT solver to find any transitions that break stuff. Unfortunately it's a lot harder to do for software than hardware because of the plasticity people expect from the former, but works it was it's really nice.
- cuillevel3 6y agoRight .... Start kiosk mode fullscreen app as a lock screen -> if app exits -> show desktop
- mhh__ 6y agoThe inputs cause the transitions, but it depends on if you can encode the states granularly enough to be invalid.
- Darmody 6y agoIf you leave a Virtual Box window open with Windows (I'm not sure about other OS) it'll bypass the lockscreen on Ubuntu, at least partially.
- Leherenn 6y agoAnother tangentially linked anecdote. We had build artefacts stored on a Samba shared drive, that were write protected, since some people regularly used to move them instead of copying them. Then one day, the latest build was gone again. We asked around to see whether someone had purposefully removed the build, but no. Turns out someone on Windows 10 had tried to cut and paste the file, but his computer had crashed before pasting. Apparently the permissions were only checked on paste, but the file was unlinked on cut?
- mercora 6y agoi don't think these permissions are enforced client side... I also think write and delete are separate permissions on windows and i am pretty sure i never lost a file on accidentally doing only the first halt of a cut and paste aka move... so i conclude this "someone" either had nothing to do with the incident or removed it by accident...
- Leherenn 6y agoI was surprised as well, but we could reproduce it. Delete would not work, "normal" cut and paste would throw an error when pasting, but cut and switch off power -> file was gone.
- passivate 6y agoSounds like something funky was going on, server side. For file operations, I don't believe the OS does anything to the file/folder for Cut and Copy operations, it simply notes the handle. Its only when you paste the file is when the operation happens. You can try this yourself, cut/copy a large file and see if your mem usage spikes and/or perform cut on any folder which you don't have delete rights for.
- joshspankit 6y agoMy own anecdote: My daughter was 1ish at the time, and I sat her down while I grabbed something from the fridge. Windows 98, locked. When I came back the screensaver was on, the password dialog was still up, but the desktop was fully functional in front of it. I could navigate, open applications, and everything else. Still no idea how she did it, but that’s not the first or last time she surprised me :)
- z29LiTp5qUC30n 6y agoThe best part is the moved to physlock, specifically the version which you can bypass by hitting enter 3 times...
- amid34d 6y agohllo
- amid34d 6y agopoophbdam
- mightybyte 6y agoYears ago I taught a high school typing class in a K-12 school. The school didn't have the funds to get a commercial typing program so I wrote my own typing program. It evolved over time with features to help me track the students' progress etc. One day we had a school open house where all the parents could come to school. We had a bunch of different activities set up in different classrooms and I ended up getting assigned to the 3rd grade classroom to set up my typing program so anyone coming through could test their typing speed. It was a DOS program and I didn't want people using anything other than my typing program, so I modified it so you couldn't quit the typing program. Over the course of the day the 3rd graders were hanging out in their homeroom not really doing anything productive. Of course the computer was a novel attraction and they were just smashing keys and exploring my program's UI. Eventually at one point I noticed that they had somehow crashed my program with a segfault in what had otherwise become a pretty stable piece of software. To this day I have absolutely no idea what the bug was.
- BruiseLee 6y agoAre you sure it was a segfault? DOS did not have any memory protection, so segfault would be impossible. Or maybe you used some protected mode DOS extender?
- tachyonbeam 6y agoWhat happens if you try to read from a null pointer in DOS?
- mensetmanusman 6y agoHilarious, esp. if you have kids. I see similar behavior with smartphones. 3 y.o. figure it out better than my parents because it seems their mindset is ‘do all the things’ to see what the i/o structure is. Their brain is built that way when they are so young.
- 0xTJ 6y agoNot really the same, but I had fun back in high school. Finding the Novell messaging utility that let me send a message to (IIRC) anyone in the school board currently logged in, though not anonymously. Using some a couple lines of VBScript to change a couple registry entries (computers didn't persist storage anyways) you could also give your local admin privileges, to install stuff. That one got me in a touch of trouble, and I lost my account for a couple weeks while they "looked at my files", because I stored it on my network drive folder.
- causalmodels 6y agoThe first computer I ever bricked was a my father's work laptop running Windows 95. I was a toddler and wanted to press the buttons. Good to see the kids are still at it!
- GlitchMr 6y agoI find interesting that GNOME Screensaver's security depends on it to not crash. Meanwhile, in KDE the lock screen is managed by KDE Session Management Server which ensures that lock screen cannot be bypassed by simply crashing its process. The way it works is follows: ksmserver draws a black rectangle over everything and spawns kscreenlocker. If kscreenlocker crashes, the black rectangle is still here, and ksmserver will spawn kscreenlocker again but this time with software rendering (just in case it crashed due to graphics driver issue). If kscreenlocker crashes four times then KDE Session Management Server gives up, stops respawning kscreenlocker and simply draws the following text on the screen. The screen locker is broken and unlocking is not possible anymore. In order to unlock switch to a virtual terminal (e.g. Ctrl+Alt+F2), log in and execute the command: loginctl unlock-session %1 Afterwards switch back to the running session (Ctrl+Alt+F%2). If ksmserver itself crashes then the entire session closes. I'm not sure why GNOME screensaver cannot do something like this. Lock screen crashing seems like something inevitable (especially considering buggy graphic card drivers and so on), and it makes sense to prepare for it so that crashes won't bypass the screen locker.
- dr_cypher 6y agojwz has a lot to say about complex graphical toolkits/desktop environments and their complex locking mechanisms. It's an interesting series of posts. If you are not running xscreensaver on Linux, then it is safe to assume that your screen does not lock. Once is happenstance. Twice is coincidence. Three times is enemy action. Four times is Official GNOME Policy. https://www.jwz.org/xscreensaver/toolkits.html https://www.jwz.org/xscreensaver/toolkits.html
- GlitchMr 6y agoI would recommend not linking to jwz's website. Use web archive or something if you have to. jwz dislikes Hacker News and intentionally shows an NSFW image when Referer header shows Hacker News.
- smnrchrds 6y agoCan he at least update the text? HN was full of entrepreneurs and wantrepreneurs years ago. It is mostly big- and mid tech employees now, tech bureaucrats if you will.
- plumeria 6y agoSo, is this an instance of the infinite monkey theorem?
- WhompingWindows 6y agoIs there an automated process security researchers use like this? Just mashes random buttons for hours until it finds vulnerabilities?
- viro 6y agoThe concept of fuzzing is similar...ish
- scotty79 6y agoI once had cat walk over my keybord and do hard reset on windows 95 in about 1 second. No dialogs or confirmations. Just black screen and computer rebooting.
- etxm 6y agoI worked at a finance co pa y in the early 00s. The QA team had a test they called “the elbow test” where they did exactly this. Just kind of put their elbow randomly on the keyboard to see if stuff would break.
- inetknght 6y agoA piece of GNOME easily crashes and causes security issues? Color me surprised! /s
- lostgame 6y agoHuh. Am I alone in that I consistently test for a massive ton of random key or screen presses? Either manually or through automation?
- viro 6y agoAs an infosec person with no CVE's stories like this make me feel like a complete failure. ¯\_(ツ)_/¯
- technothrasher 6y agoI remember finding a very similar issue with XDM on a Sun 3/60 back in about 1992. Just mash the keyboard while in the 'password' field and it would eventually drop a root shell. Oops!
- chromatin 6y agoMeatspace fuzzing
- fmakunbound 6y agoThere is no hope for us in this field, is there.
- atomize 6y agoThey learn so young these days! Never ceases to amaze me. They are totally set up for this industry. Would hire 10/10.
- nrvn 6y agoI enjoy to see my kid breaking software, POS terminals and causing ATMs to throw error windows. Nothing critical, just funny how random screen touching and keyboard mashing drives “serious” software crazy. Fool-proof and child-proof software is yet to come. Hire QA kids.
- Jerry2 6y agoThat reminded me of the Linux GRUB2 bug where you could press Backspace key 28 times and bypass all security. [1] >The source of the vulnerability is nothing but an integer underflow fault that was introduced with single commit in Grub version 1.98 (December 2009) – b391bdb2f2c5ccf29da66cecdbfb7566656a704d – affecting the grub_password_get() function. [1] https://thehackernews.com/2015/12/hack-linux-grub-password.html https://thehackernews.com/2015/12/hack-linux-grub-password.h...
- uoaei 6y agoLinux Mint, and whatever it's built on, has been disappointing to me. The most worrying thing I've experienced is that, when waking up from sleep, the unlocked screen will sometimes flash before showing the lockscreen. That is a huge no-no and really betrays the fallibility of whatever security measures are employed.
- johnwayne117 6y agoand they say, "monkey testing" is underrated
- exabrial 6y agoMy cat previously unlocked OSX Leopard with a similar attack.