TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Sh1mmer – An exploit capable of unenrolling enterprise-managed Chromebooks

223 pointsby XionXIVover 2 years ago

11 comments

e12eover 2 years ago
Seems the site is struggling - archive cache:<p><a href="https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20230130125805&#x2F;https:&#x2F;&#x2F;sh1mmer.me&#x2F;" rel="nofollow">https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20230130125805&#x2F;https:&#x2F;&#x2F;sh1mmer.m...</a><p>Github:<p><a href="https:&#x2F;&#x2F;github.com&#x2F;CoolElectronics&#x2F;sh1mmer">https:&#x2F;&#x2F;github.com&#x2F;CoolElectronics&#x2F;sh1mmer</a>
评论 #34579507 未加载
DharmaPoliceover 2 years ago
I wouldn&#x27;t have a career in IT if I hadn&#x27;t spent many hours at ages 11 to 15 trying to get round my schools network security. My logon was frequently disabled for misuse and I was even suspended for a couple of days once but I learnt more that way than in any class I&#x27;ve ever taken.
评论 #34579931 未加载
评论 #34580712 未加载
评论 #34579970 未加载
评论 #34586111 未加载
评论 #34586210 未加载
评论 #34584556 未加载
评论 #34580900 未加载
mindondrugsover 2 years ago
Is there a source for `bored kids`? I dont see any evidence of kids creating this exploit?
评论 #34579416 未加载
评论 #34581753 未加载
评论 #34584103 未加载
评论 #34579594 未加载
评论 #34581409 未加载
评论 #34579909 未加载
gibspauldingover 2 years ago
I thought this was fairly doable for some time. Surprised it hasn&#x27;t been an issue before.<p>I used to do tech support for a school district with some ~5000 Chromebooks in circulation and we did all of our repairs in house. This meant I spent the first few weeks of COVID bringing home boxes of damaged devices and spare parts and getting them back into working order. Occasionally I would have to do a board swap for a bad power jack or something which meant you would have to overwrite the serial number on the new board to match the old one so that it would join Google admin as one of our devices. If I remember right the process would have worked the other way around too, to change the serial number to one we didn&#x27;t control.
lol768over 2 years ago
This is hilarious, and quite impressive given the presumed age of the kids that&#x27;d be interested in doing this. I&#x27;m sure some K-12 tech staff are stressing over the exploit right now.
评论 #34579927 未加载
bell-cotover 2 years ago
Anyone else suddenly imagining that you hear Pink Floyd lyrics?
XionXIVover 2 years ago
The silliest thing about it is probably this. Google seemed to have just kind of forgotten to add code that would verify the rootfs on shims, even though they had everything they needed to do it already set up.<p><a href="https:&#x2F;&#x2F;chromium-review.googlesource.com&#x2F;c&#x2F;chromiumos&#x2F;platform&#x2F;initramfs&#x2F;+&#x2F;4180190&#x2F;3&#x2F;factory_shim&#x2F;bootstrap.sh" rel="nofollow">https:&#x2F;&#x2F;chromium-review.googlesource.com&#x2F;c&#x2F;chromiumos&#x2F;platfo...</a>
评论 #34584152 未加载
offlinehackerover 2 years ago
I like the attitude these kinds have. No one should have control over my laptop, but me. Being locked in corporate silos is way too normal these days.
评论 #34586706 未加载
Overtonwindowover 2 years ago
I hope I don&#x27;t sound like a Luddite, but I don&#x27;t think kids should have chrome books, or any type of laptops in school...
评论 #34579273 未加载
评论 #34579299 未加载
评论 #34579231 未加载
评论 #34579298 未加载
评论 #34579285 未加载
评论 #34579312 未加载
评论 #34579444 未加载
评论 #34579323 未加载
评论 #34579213 未加载
评论 #34580322 未加载
评论 #34579512 未加载
评论 #34579310 未加载
评论 #34579860 未加载
评论 #34579237 未加载
评论 #34579338 未加载
评论 #34579516 未加载
XionXIVover 2 years ago
And it just takes two minutes.
bertilover 2 years ago
I stand with everyone on Hacker News in admiration for young’uns sticking it to the man and learning about command-line secret power.<p>_However_, I’m a little more ambivalent knowing that most of them do that to look at naked ladies, presumably. Maybe create pictures of naked ladies (again: very impressed by Generative AI, with the caveat that it’s widely used for pr0n)<p>That doesn’t feel ideal for the emotional maturation of middle-schooler. In my time ::shakes fists at cloud::, hacking the school network meant you risk exposing yourself to people with strong opinions about plot points in Buffy The Vampire Slayer. Nowadays, it also means risking ending on a psyops from Russian secret service, whatever Andrew Tate is (and please, don’t tell me: that’s one shred of innocence I want to keep) or, inexplicable, worse. I remember ridiculing music producers who were saying that if you didn’t pay for CDs, you would end up empowering “pedonazis”. That felt ridiculous at the time. It feels less so now, both not paying for music and enabling actual pedophiles and actual nazis by sticking blindly to open-web principles.<p>I am very happy that the kids stick it to the man. I feel like we grey manes need to put our heads together and think about how we talk to them about emotional maturation, bad people, and safely exploring. It will sound ridiculous coming from the generation that cared about Facebook, but I feel like we can’t just stand in the bleachers and clap every time the JV red team scores a point.
评论 #34580485 未加载
评论 #34580760 未加载
评论 #34580373 未加载
评论 #34582182 未加载
评论 #34584141 未加载