Attacking Android Binder
androidoffsec.withgoogle.com
androidoffsec.withgoogle.com
(It still has something to do with the early implementations since I recognize some of the #define names..)
https://www.osnews.com/story/13674/introduction-to-openbinde...
I don't think I'll ever be able to trust modern devices until we finally abandon memory-unsafe languages. It's such low hanging fruit at this point I don't understand anymore why OS developers keep investing their time in other parts of the threat model of operating systems if memory usage vulnerabilities keep arising that completely destroy the existence of any security layer in the system.
Was Google's plan to replace Android with Fuchsia? Is there any plan to get rid of these vulnerabilities (specially use-after-free) at scale on Android like the Chrome project has attempted with the MiraclePtr project?
One of the oddities of BigCo and diffusion of responsibility / abdication of intent is, I'm not sure there's one single person who could accurately answer this.
I hate coming out and saying it because I'm a xoogler, and I'm worried people will think I'm breaking new territory by saying this, but it's known outside Google at this point: no. Never say never, but, it's as close to no as you can get.
Given:
- Nest Hubs were/are the only shipping Fuchsia product and are de facto deprecated for Pixel tablet
- Assistant is de facto deprecated for Gemini (Assistant was responsible for Nest Hub's UI, which hasn't seen even minor updates in years)
- what I see occurring on Google's Blind re: multiple Chrome OS engineers confirming they were told to chill out and wait for reprioritization, and a handful expressing it is dead and they're expecting to be transferred to Android desktop work
- Flutter and Fuchsia have both been reported to have firings, whereas Android has had none reported.
- Hiroshi Lockheimer left recently, so now the hardware head owns Android/Chrome OS/Fuchsia.
This all plays along well with what Sundar spends his time on and drags on, and on, and on: about efficiency and focus, meaning, please cull 5-10% of your workers yearly and you're not getting new headcount soon if ever. Because profit margins because Wall Street.
Thus, it looks like a hard decision by a genius leader to turn Assistant, Chrome OS, and Fuchsia into ghost towns staffed by a skeleton crew and reallocate headcount to keeping Android untouched/growing.
I'd be very surprised if Fuchsia ever shipped on anything new Google sells other than things clearly too resource-constrained for Android (speakers and non-ARM chips, i.e nest hubs)
On the other side, I'd say the short sighted thing was not being brave enough to keep going. I worked on Android, and _much_ prefer the Flutter stack*, to the point you could say that's part of the reason I left. I believe it's a revolution in dev efficiency.
That being said, Flutter doesnt need Fuchsia, and Fuchsia didn't need to replace the kernel on the hubs, and when it did, there were contemporaneous issues with the hubs being janky that just would have killed absolutely any practical argument for Fuchsia they would be having 6 layers above me.
* By Flutter stack, I just mean, flutter. a significant feature of my last 3 years there was being the dude on Android randomly writing flutter - I was doing high stakes UI prototyping and thought it was friggin awesome that it A) worked on web, so I could easily share things with designers without needing an android build B) used skia on web, so if it worked there, it was clear it could work on Android C) eventually when my stuff was cross-org regularly, a Flutter demo objectively set a floor for performance on any platform it might deploy it
Fuchsia is neat, but the politics of the whole thing and the absolute idiocy of rewrites for rewrites sake... Makes me not feel so terrible about their reduced headcount.
I surmise either A) Hiroshi wanted a fresh OS without the political risk of committing to it in a well-known way and/or
B) I don't grok how free-wheeling Google could be prior to my arrival (late 2016), combined with general bureaucratic inertia of there not really being an incentive to eliminate things*
* that probably sounds funny, but IIRC most of the major public cancellations are when a big project gets shuffled under a VP who could give 2 craps, or rebrandings that people got too upset about
Home Hub launched with a perfectly good HTML-based UI that ran great, and shipped to millions of devices. And then they immediately set about rewriting the whole thing in Flutter and then they had to pretend that Flutter existed for the thing, which it didn't and so that had to get written, too.
I think the idea was that Fuchsia might replace Linux (so Android, ChromeOS, and various other OS things at Google would have a dependency on Fuchsia, instead of having a dependency on Linux)
But that seems unlikely now.
I think Fuchsia is pretty much dead, unless someone outside of Google starts using Fuchsia for something (e.g. Facebook almost used Fuchsia a few years ago)
There is no automatic memory safety from a language like Rust here. It's not so simple.
Now, perhaps some part of the system could be defined in a memory safe language. That might be good. But not this part.
Insecurity is freedom.
What a great motivation. Oh wait, then you write your literal operating system and all services in Java of all languages.
I find Android's architecture so frustrating, all the wrong design decisions