TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

The hackers keeping you safe online

27 pointsby megahzover 2 years ago

1 comment

Veservover 2 years ago
Am I being kept safe by Google? What evidence is there of that?<p>There appear to be 635 vulnerabilities publicly disclosed by 3rd parties in Android this year with 43 being critical and 139 being high or critical [1]. 224 in Chrome [2], though none being labeled high severity, though that is mostly due to the fact that things such as disclosed remote zero-click heap corruptions leave the final bit of actually getting full code execution as a trivial exercise to the reader.<p>There was a cool attack demonstrated a few weeks ago completely defeating the Google Titan M security chip [3], their custom-designed secure vault used to store your most sensitive secrets. It could be hacked through software alone to exfiltrate all of its secrets. Given its purpose their security process should have resulted it being designed by their best security experts and been their most secure consumer product. Beaten by three people with a year and a half.<p>I mean seriously, their flagship, in-house Android phones are advertised as only conforming to the absolute lowest levels of security [4][5]. Seriously, go read that [6] on page 9 they describe the arduous certification process where the auditor googles “Android” and sees that there are no unpatched vulnerabilities. This is their primary advertised third party audit of whole system Android security.<p>So, a company which produces products with loads of vulnerabilities, has their most secure products defeated by moderately resourced attackers, and only certifies their products with third parties to the absolute lowest levels of security is keeping me safe from hackers? Pull the other one.<p>[1] <a href="https:&#x2F;&#x2F;www.cvedetails.com&#x2F;vulnerability-list&#x2F;vendor_id-1224&#x2F;product_id-19997&#x2F;year-2022&#x2F;Google-Android.html" rel="nofollow">https:&#x2F;&#x2F;www.cvedetails.com&#x2F;vulnerability-list&#x2F;vendor_id-1224...</a><p>[2] <a href="https:&#x2F;&#x2F;www.cvedetails.com&#x2F;vulnerability-list&#x2F;vendor_id-1224&#x2F;product_id-15031&#x2F;year-2022&#x2F;Google-Chrome.html" rel="nofollow">https:&#x2F;&#x2F;www.cvedetails.com&#x2F;vulnerability-list&#x2F;vendor_id-1224...</a><p>[3] <a href="https:&#x2F;&#x2F;blog.quarkslab.com&#x2F;attacking-titan-m-with-only-one-byte.html" rel="nofollow">https:&#x2F;&#x2F;blog.quarkslab.com&#x2F;attacking-titan-m-with-only-one-b...</a><p>[4] <a href="https:&#x2F;&#x2F;support.google.com&#x2F;pixelphone&#x2F;answer&#x2F;11062200?hl=en#zippy=" rel="nofollow">https:&#x2F;&#x2F;support.google.com&#x2F;pixelphone&#x2F;answer&#x2F;11062200?hl=en#...</a><p>[5] <a href="https:&#x2F;&#x2F;www.niap-ccevs.org&#x2F;Product&#x2F;Compliant.cfm?PID=11239" rel="nofollow">https:&#x2F;&#x2F;www.niap-ccevs.org&#x2F;Product&#x2F;Compliant.cfm?PID=11239</a><p>[6] <a href="https:&#x2F;&#x2F;www.niap-ccevs.org&#x2F;MMO&#x2F;Product&#x2F;st_vid11239-vr.pdf" rel="nofollow">https:&#x2F;&#x2F;www.niap-ccevs.org&#x2F;MMO&#x2F;Product&#x2F;st_vid11239-vr.pdf</a>
评论 #33124535 未加载
评论 #33128825 未加载