Google Pixel pwned in 60 seconds
theregister.co.uk
theregister.co.uk
For example Flash, even when sandboxed, continues to be an extremely easy and lucrative attack vector (relatively speaking). Four seconds puts the exploit in drive-by territory.
A sixty second web exploit is not so useful for "cyber" criminals. But if you can "compromise all aspects of the phone including contacts, photos, messages, and phone calls" in 60 seconds, this is probably worth it.
A phone is an extension of you. Security is paramount.
Apart from the Flash vulnerability, did any of the exploits use Chrome to gain all permissions on the Pixel? That would be scary, because the user would just have to be served Javascript containing malicious code or visit an affected website.
Why isn't Linux or the BSDs usually included in these pawn competitions?
I think that there are not many companies willing to pay to find vulnerabilities in Linux and BSD.
http://arstechnica.com/security/2016/09/linux-kernel-securit...
Given its use across the industry, and being written in C, GNU/Linux has become the target they used to joke about Windows since its existence.
For the BSDs, I imagine only OpenBSD would be an hard nut to crack given their focus on security. Then again, it isn't an OS that has much desktop visibility like the systems that are part of this competition.
Generally once a target has been compromised, no other teams are allowed to use the same vulnerabilities. this prevents a team from sharing an exploit/vuln to others who run it again. The downside is that if you've been working on an exploit chain for 6 months but a team runs a similar bug ahead of you, your work is worthless.
Google experimented for a while with weird model numbers like 5X and 6P, but seems to have decided against continuing it. It's the version wars all over again. Who wants to be stuck at 5 and 6 when Apple is at 7, Samsung will soon return with an 8, and Microsoft already played the "we'll skip ahead to 10" card?
Yes, I know that there are specific model numbers... in tiny print... but if people don't know them or use them it is no help.
All the other ChromeOS models from Google are no longer on sale.
A complete redesign is required but it won't happen unless it causes major catastrophy and losses.
On hardware level CPU rings exist to protect kernel from rogue programs and each other but in reality all that protection is either completely or partially circumvented.
I read a paper on this a year back. I will try to find the link and post it here.
Copying Hunter Thompson , initiating "gonzo" style, has been the rage for quite a while -- it's more fun than being honest and careful
As professional journalism has moved from print to on-line, they've been struggling to figure out how to sustain their businesses. The on-line incentives for eyeballs/clicks is now strong for them as well, and they've understandably hired people who have proven to attract online readers. Early on it was clearer to identify the "blog" section of an online publication, but that's become increasingly difficult.
Stray thought: Is there a resource out there to view the credibility of stories by byline?
not 100% sure why, but I figure Mozilla don't pay out significant bounties and compromise of the browser is relatively easy compared to other targets given there's no real sandbox.