TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

The hackers keeping you safe online

27 点作者 megahz超过 2 年前

1 comment

Veserv超过 2 年前
Am I being kept safe by Google? What evidence is there of that?<p>There appear to be 635 vulnerabilities publicly disclosed by 3rd parties in Android this year with 43 being critical and 139 being high or critical [1]. 224 in Chrome [2], though none being labeled high severity, though that is mostly due to the fact that things such as disclosed remote zero-click heap corruptions leave the final bit of actually getting full code execution as a trivial exercise to the reader.<p>There was a cool attack demonstrated a few weeks ago completely defeating the Google Titan M security chip [3], their custom-designed secure vault used to store your most sensitive secrets. It could be hacked through software alone to exfiltrate all of its secrets. Given its purpose their security process should have resulted it being designed by their best security experts and been their most secure consumer product. Beaten by three people with a year and a half.<p>I mean seriously, their flagship, in-house Android phones are advertised as only conforming to the absolute lowest levels of security [4][5]. Seriously, go read that [6] on page 9 they describe the arduous certification process where the auditor googles “Android” and sees that there are no unpatched vulnerabilities. This is their primary advertised third party audit of whole system Android security.<p>So, a company which produces products with loads of vulnerabilities, has their most secure products defeated by moderately resourced attackers, and only certifies their products with third parties to the absolute lowest levels of security is keeping me safe from hackers? Pull the other one.<p>[1] <a href="https:&#x2F;&#x2F;www.cvedetails.com&#x2F;vulnerability-list&#x2F;vendor_id-1224&#x2F;product_id-19997&#x2F;year-2022&#x2F;Google-Android.html" rel="nofollow">https:&#x2F;&#x2F;www.cvedetails.com&#x2F;vulnerability-list&#x2F;vendor_id-1224...</a><p>[2] <a href="https:&#x2F;&#x2F;www.cvedetails.com&#x2F;vulnerability-list&#x2F;vendor_id-1224&#x2F;product_id-15031&#x2F;year-2022&#x2F;Google-Chrome.html" rel="nofollow">https:&#x2F;&#x2F;www.cvedetails.com&#x2F;vulnerability-list&#x2F;vendor_id-1224...</a><p>[3] <a href="https:&#x2F;&#x2F;blog.quarkslab.com&#x2F;attacking-titan-m-with-only-one-byte.html" rel="nofollow">https:&#x2F;&#x2F;blog.quarkslab.com&#x2F;attacking-titan-m-with-only-one-b...</a><p>[4] <a href="https:&#x2F;&#x2F;support.google.com&#x2F;pixelphone&#x2F;answer&#x2F;11062200?hl=en#zippy=" rel="nofollow">https:&#x2F;&#x2F;support.google.com&#x2F;pixelphone&#x2F;answer&#x2F;11062200?hl=en#...</a><p>[5] <a href="https:&#x2F;&#x2F;www.niap-ccevs.org&#x2F;Product&#x2F;Compliant.cfm?PID=11239" rel="nofollow">https:&#x2F;&#x2F;www.niap-ccevs.org&#x2F;Product&#x2F;Compliant.cfm?PID=11239</a><p>[6] <a href="https:&#x2F;&#x2F;www.niap-ccevs.org&#x2F;MMO&#x2F;Product&#x2F;st_vid11239-vr.pdf" rel="nofollow">https:&#x2F;&#x2F;www.niap-ccevs.org&#x2F;MMO&#x2F;Product&#x2F;st_vid11239-vr.pdf</a>
评论 #33124535 未加载
评论 #33128825 未加载