5 ms·
Four things of note: 1. I've not seen anyone explain whether this could be exploited by anyone with access to phone lines (i.e. Twilio users) or not and if it
by ddod 4y ago
Four things of note:
1. I've not seen anyone explain whether this could be exploited by anyone with access to phone lines (i.e. Twilio users) or not and if it would be trivial to try the vuln with every phone number you could find in any DB. If those things are the case, it seems like the chances would be very high that this would be or has already been exploited and affecting every unpatched phone.
2. It seems like Project Zero mistakenly thought that Google devices were already patched when they made their announcement ("affected Pixel devices have received a fix"). Whoops! Thanks for giving attackers a heads up.
3. When contacting Google support (specifically Fi) multiple CS reps told me repeatedly this was all fake news and that Project Zero was unaffiliated with Google. They assured me there was no problem, and if there was a vulnerability, it would be communicated on the Fi website (which has no service status or security pages and has never published any outages or vulnerabilities in the past).
4. The delayed March update for Pixel 6 phones doesn't even show up when you open the software update panel (which shows a checking animation that I assume does nothing). You have to manually check again. Who knows when the folks who are unaware of this vulnerability will actually be prompted to install the patch.
Google have guaranteed at least one person and their family to never purchase another Google product or service.
- flangola7 4y agoI will still purchase Pixels because they isolate the modem.
- pa7ch 4y agoDo you have more information on this? I was not aware pixel phones have any additional protection against modem exploits.
- silisili 4y agoIf that were true, how could they be affected by a bug that allows full device compromise via the baseband?
- flangola7 4y agoThey're not affected, or at least less affected. The baseband doesn't have direct memory access like on other phones.
- JCharante 4y ago> When contacting Google support (specifically Fi) multiple CS reps told me repeatedly this was all fake news and that Project Zero was unaffiliated with Google. I hate CS reps. I used to work as one but I never lied. If I didn’t know something and I couldn’t find it in my knowledge base I contacted the on-site staff to relay the caller’s question/concern.
- behnamoh 4y ago> Google have guaranteed at least one person and their family to never purchase another Google product or service. They did that when they waited more than a month to patch the phone call bug in Pixel 6 series. What if someone has an emergency? Nope, Google thought that can wait.
- saagarjha 4y ago> Tests conducted by Project Zero confirm that those four vulnerabilities allow an attacker to remotely compromise a phone at the baseband level with no user interaction, and require only that the attacker know the victim's phone number.
- ddod 4y agoI read that as well, and either it's unclear or I lack the technical understandings to apply that to my question. What does "at the baseband level" mean in terms of remote attack vector? Do they need to be physically nearby with an antenna or could they be across the world connecting through VOIP? And why do they need to know a phone number? If it's that they need a nearby antenna + knowledge of a phone number, it sounds like this vulnerability might not be a big deal, and it would be great if they communicated that clearly. Alternatively, if the vulnerability is accessible from any remote phone connection, knowledge of a phone number wouldn't matter because attackers would spam the attack against millions of numbers.
- saagarjha 4y agoIn effect, it means if they can call you, they can exploit you. The description given was what an attacker needs to hack you in particular, which means they need your phone number to determine which device to target. If they want to spam a million users they could do that too, although these kinds of things are typically not done this way because that is very noisy and reduces the effective life of the vulnerability.
- ddod 4y ago> If they want to spam a million users they could do that too, although these kinds of things are typically not done this way That seems like a convenient assertion not based on evidence. Without trying to sound confrontational, it appears as if you are a current employee of Google, which might have colored your comment and should probably have been disclosed.
- 4y ago
- JeremyNT 4y ago> It seems like Project Zero mistakenly thought that Google devices were already patched when they made their announcement ("affected Pixel devices have received a fix"). Whoops! Thanks for giving attackers a heads up. Do you have a source for the fact that Pixel devices don't yet have a fix? The post we're commenting on is actually just blogspam, with its only real source being the initial project zero disclosure [0], which still asserts this to be the case... [0] https://googleprojectzero.blogspot.com/2023/03/multiple-internet-to-baseband-remote-rce.html https://googleprojectzero.blogspot.com/2023/03/multiple-inte...
- ddod 4y agoThe blog post was published on the 16th.[0] Pixel 6 and 6a started the update rollout on the 20th.[1] The March security update was scheduled for earlier but was delayed for 6/a for some reason, and it seems like the Project Zero team didn't check on the actual status of the rollout. [0] https://googleprojectzero.blogspot.com/2023/03/multiple-internet-to-baseband-remote-rce.html https://googleprojectzero.blogspot.com/2023/03/multiple-inte... [1] https://9to5google.com/2023/03/20/pixel-6-march-2023-update/ https://9to5google.com/2023/03/20/pixel-6-march-2023-update/