4 ms·
> ... but only if the perpetrator has physical access to the device, enters the user's password ... Clickbait title. If you have physical access and password o
by progbits 2y ago
> ... but only if the perpetrator has physical access to the device, enters the user's password ...
Clickbait title. If you have physical access and password of course you can do whatever. That is the point of the password.
- croes 2y agoWhere is the clickbait? The software is there but inactive. That's exactly the case.
- TheDong 2y agoDid you know linux is delivered with a secret but inactive remote shell for hackers to attack your box? It can be enabled with: socat file:`tty`,raw,echo=0 TCP-L:1022 Or: awk 'BEGIN {s = "/inet/tcp/0/0.0.0.0/1022"; while(42) { do{ printf "shell>" |& s; s |& getline c; if(c){ while ((c |& getline) > 0) print $0 |& s; close(c); } } while(c != "exit") close(s); }}' /dev/null Better uninstall awk or else you're "vulnerable to spyware", from the wording of the article. The article is clearly playing this up far more than it should be. The title is very clearly angling at "this is malicious, it's bad", when it sounds totally benign if it's just like the socat thing above, where you need to already be on the other side of the airtight door to use it https://devblogs.microsoft.com/oldnewthing/20221004-00/?p=107246 https://devblogs.microsoft.com/oldnewthing/20221004-00/?p=10...
- sureglymop 2y agoOr even better... While booting, using either grub or systemd-boot, enter a uefi shell and change the kernel parameters to include 'init=/bin/bash rw'. Boot like that and you'll get a rw root shell. The point is.. a system someone has physics access to is never secure. One thing that helps a little bit is using LUKS full disk encryption.
- bitwize 2y agoApple has made significant progress in terms of developing evil-maid-resistant systems. "No system is secure when you have physical access" is one of those canards that was true ten or so years ago, but was not an iron law even then and has been falsified by recent developments. Kinda like "there's no such thing as unbreakable DRM" in an era when the Xbox DRM is indeed, for all intents and purposes, unbreakable.
- strcat 2y ago> Apple has made significant progress in terms of developing evil-maid-resistant systems. Definitely, but a couple of the high end forensic data extraction companies have largely kept up with them. It's no longer something which can be done by someone who doesn't have access to expensive commercial exploit tools or government-developed tools. Most of the forensic companies can't keep up anymore but the demand is there for a couple options which do and they're not unsuccessful. Cellebrite Premium is widely available and used by law enforcement and governments around the world. https://grapheneos.social/@GrapheneOS/112826067364945164 https://grapheneos.social/@GrapheneOS/112826067364945164 is their leaked documentation on their capabilities from July 2024. Recent iPhones and Pixels are successfully preventing brute force attacks via Cellebrite Premium for Before First Unlock devices via their secure elements. They aren't successfully prevented the OS being exploited either Before First Unlock or After First Unlock. Pixels being able to run a more hardened OS is a major advantage in this regard. iOS lockdown mode and USB restricted mode exist, but don't appear to defend against Cellebrite Premium. Lockdown mode mainly reduces browser and Apple service attack surface.
- arianvanp 2y agoWon't work if you're using UKIs. The kernel command line is fixed, signed and measured into TPM2 and your disk won't unlock
- m4rtink 2y agoHardly anynone uses that currently & it has a lot of unsolved issues.
- jansommer 2y agoWhat are some of the unsolved issues? Just curious
- realxrobau 2y agoWhen the motherboard fails, everything is gone. There is no way around this. You either accept that your data is irretrievably tied to your motherboard, or accept that your data can be viewed/modified by someone who can replace your motherboard.
- LorenDB 2y agoNo? All you need to do is install to a standard LUKS partition with a good password. Then your data is secure but not irretrievably tied to your motherboard. Granted, that's not UKI, but it's a functional solution.
- jansommer 2y agoYes, TPM is just one way to access your disk. The only reason to use it is in my opinion to not have to enter a super long password on every boot. An extra key if your mobo fails is the way to go. Or if you can't boot after an update, and you don't sign your recovery OS with the same key.
- paulmd 2y ago> The point is.. a system someone has physics access to is never secure. this is an article of faith among certain tech circles but it's not actually true. The entire point of the xbox security model is defending against an attacker who has unlimited physical access to the console, and it was not breached during the lifetime of the xbox one nor does xbox series S/X appear to be any different. like literally the title of the presentation is "Guarding Against Physical Attacks". And they succeeded, despite an intense amount of effort from the modding community. https://www.youtube.com/watch?t=1130&v=U7VwtOrwceo&feature=youtu.be https://www.youtube.com/watch?t=1130&v=U7VwtOrwceo&feature=y...
- strcat 2y agoIf you do get ADB access, a filesystem write vulnerability or exploit the device to get code execution then this app is irrelevant since you already have more access. A real attack vector has not been presented, which is why Google determined that it wasn't valid security vulnerability. That's their standard operating procedure. That doesn't mean they won't fix a bug or remove attack surface. They removed Showcase from Android 15, which is visible in the Android 15 Beta. However, you do need more than physical access with a Pixel to enable this and set it up. They have full verified boot with a specific per-device key (which is how key rotation gradually happens) and anti-rollback fuses to prevent downgrade attacks to old vulnerable versions. The OS images are completely verified with anti-rollback via the secure element which has authenticated encryption between it and the main SoC. The data partition for the OS has every block encrypted, although it's not authenticated encryption yet. The firmware is quite locked down and reset attack mitigation for firmware boot modes was added in April based on a vulnerability report from us in January. RAM isn't fully encrypted yet but it's quite difficult to tamper with modern RAM or even dump it without controlling the OS / SoC firmware unless there's debugging functionality left enabled in production. Fully encrypted RAM is the main thing they're missing aside from a more hardened OS. Cellebrite can successfully exploit up-to-date Android and iOS devices with physical access as part of their Cellebrite Premium product, but it's increasingly not easy for them. They often fall behind with updates, but they consistently catch up again. Leaked July 2024 documentation showing the current capabilities is available here: https://grapheneos.social/@GrapheneOS/112826067364945164 https://grapheneos.social/@GrapheneOS/112826067364945164 For GrapheneOS, our aim is defending the device long enough for our auto-reboot timer after locking to activate combined with zero-on-free and firmware reset attack mitigation. They haven't been very successful at exploiting GrapheneOS but did develop exploits for older versions from 2022 and earlier. Physical access is not an entirely lost cause, the goals just need to be well defined. Defending the device for 18 hours since it was locked (our default auto-reboot timer) is our goal. Users can set auto-reboot as low as 10 minutes but then they'd be missing notifications.
- jamesjamesdupre 2y agoLinux is an ecosystem that includes Android. Pixel is an Andoid phone by Google that is supposed to be hardened against local attacks, showing when an unhardened OS is booted, etc. No one cares that you can run a firewall on an insecure OS configuration, but they care if your shipped appliance does it.
- jraph 2y agoThis is beside the point. The point is that many OSes include tools that you can use to do remote maintenance as long as you have the password and physical access. There's nothing to write home about. There being inactive software somewhere to do maintenance that can be used if you have physical access and the password is as best interesting (curiosity), at worst not newsworthy, and in any case not concerning. Now, phones sold pre-filled with junk / invasive software all over the place is gross.
- jamesjamesdupre 2y agoNo it is not besides the point. They are not supposed to ship a setup where physical access escalates to permanent spying with no warnings because they are promising things about devices not about an ecosystem's overall functionality to build any possible configuration. Many people feel Google and Apple have ulterior motives, but that is an academic argument unless they abandon this motive, at that point they need to always ship rooted insecure boot phones for our ease of use.
- throwaway290 2y agoFunny how you people keep making it as if bins included openly in normal Linux distributions are as bad as some weird unaudited internal tool by Verison of all things, additionally hidden from the user. I would have higher expectations of a Pixel tbh
- jamesjamesdupre 2y agoIt seems to me like a lot of it is hatred for the messengers.. But I think Palantir is a perfect organization to resentfully report a telco conspiracy to create a law enforcement back door as long as they didn't get a piece of it.
- croes 2y agoI thought we talk about the title and not the article. You could claim the article is fear mongering but the title not clickbait.
- deleted 2y ago[deleted]
- 1vuio0pswjnm7 2y ago"Users cannot uninstall Showcase.apk themselves." Linux is just a kernel. There is no requirement to install/keep gawk. One can use a faster awk that has no TCP networking. Most GNU/Linux distributions do not have socat pre-installed. Linux, being only a kernel, allows the computer owner to choose what programs they want in a userland. By contrast, this "smartphone" from an advertising company comes with software pre-installed. And not easily removed. This is why "smartphones" suck as general purpose computers.
- jdietrich 2y ago"Secret" is the clickbait, as it implies that there's some kind of subterfuge going on. The app isn't intentionally hidden as far as I can tell, so "preinstalled" would be far less sensational. Any operating system distro is going to come with a bunch of stuff that you're not necessarily going to use; obviously it's less than ideal if distributions are being shipped with old junk that nobody uses, but it's hardly the crime of the century.
- croes 2y agoIt's hidden from the normal user, isn't it?
- arghwhat 2y ago> If you have physical access and password of course you can do whatever. Well, you should be able to do whatever given that it's your device. Devices unfortunately also try to protect themselves against their owners nowadays...
- LoganDark 2y agoYep. Verified boot is designed to erase your ability to use banking apps, streaming apps, etc. if you touch any of the code running on the system. Because it's "insecure" to change anything from the default. (read: "insecure" to reduce the amount of remote control that big tech has over your phone) When I buy a phone, I don't want to use something owned by someone else. I want to own it myself. Mobile Linux is absolute garbage though, even worse than desktop Linux, which is why I can't realistically use either.
- throwaway290 2y agoIt's not clickbait. Imagine if your Linux shipped with TeamViewer like app hidden somewhere. You would have to ask some serious questions. especially if you are a security related IT business
- sva_ 2y agoLike... SSH?
- throwaway290 2y ago> Like... SSH? Except SSH is a protocol, and this is some shady piece of internal enterprise tool... probs written by one unpaid intern and never security audited once in its lifetime... otherwise yeah no difference at all, nailed it ;)