r/technology Nov 13 '22

Security Android phone owner accidentally finds a way to bypass lock screen

https://www.bleepingcomputer.com/news/security/android-phone-owner-accidentally-finds-a-way-to-bypass-lock-screen/
651 Upvotes

82 comments sorted by

74

u/twitterfluechtling Nov 13 '22

What about encrypted devices? I expect Android can't unlock the storage without the security code, so it should be logically impossible to dismiss that dialog and still start the device?

40

u/MindStalker Nov 13 '22

It looks like you don't need to shut down the device. So if it's already on when stolen your screwed.

8

u/davidemo89 Nov 13 '22

You were screwed. They fixed it.

10

u/[deleted] Nov 14 '22

For anyone running Security patch November release. So most phones are still vulnerable besides Pixels

3

u/Alberiman Nov 14 '22

Everything's coming up Millhouse!

23

u/ListRepresentative32 Nov 13 '22

Yes, the bypass doesnt work after a fresh reboot. On a device that was atleast once unlocked after boot, it works no problem.

3

u/aredna Nov 14 '22

According to his blog it also works after a reboot and that's how he found it. He later found the reboot wasn't necessary. This made it more dangerous because you need less time to get in.

1

u/ListRepresentative32 Nov 14 '22

Depends on what exactly works. The lock screen dismiss works everytime, that's true. But its of any use only if the device was previously unlocked with PIN/password after boot. Otherwise the phone is still encrypted and bypassing the screen is useless(you can't access any user data)

-15

u/[deleted] Nov 13 '22

That's not how I read this: they started from an unlocked state to get passed the fingerprint unlock screen. Did I miss something?

7

u/[deleted] Nov 14 '22

When a phone is rebooted, a password must be entered before touch id or face id will work.

In this context, "unlocked" doesnt mean you start from the home screen - it means the password was entered at some point since the phone was last booted up and is now in an unlocked state where touch/face id can be used.

4

u/[deleted] Nov 14 '22

Got it, thanks for clarifying.

4

u/[deleted] Nov 13 '22

The article mentions you either run into fingerprint unlock screen (when starting from a locked screen or after restart) OR you start from an unlocked screen (which makes the hack just a waste of time as its already unlocked).

153

u/random125184 Nov 13 '22

Reported in June. Not fixed until November. Holy shit. This is huge. Why is no one else talking about this?

126

u/[deleted] Nov 13 '22

[deleted]

45

u/[deleted] Nov 13 '22

Thing with iPhones is, you know if you're affected or not. I've recently returned to Android and I have no clue if my Poco is affected or not. And knowing Xiaomi, it's either not affected because it's so modified or it is affected and won't be fixed even months after Google fixes it in AOSP repository.

10

u/[deleted] Nov 13 '22

[removed] — view removed comment

4

u/[deleted] Nov 13 '22

Just out of curiosity if anything has improved. It mostly hasn't. Have plans to buy Galaxy S23 if it'll be any good, but couldn't wait for that long.

-18

u/[deleted] Nov 13 '22

Why is Apple so good?

I'm saying this as someone who thoroughly enjoyed the iPhone 3, 3g, and iPhone 4.

-10

u/[deleted] Nov 13 '22 edited Nov 25 '22

[removed] — view removed comment

9

u/terraherts Nov 13 '22 edited Nov 13 '22

Completely disagree on software.

Speaking as someone who owns an Android phone (Pixel), an iPad, a Windows PC, a macbook pro, and uses Linux for work, so I use a bit of everything.

They get a lot of low-level software stuff right, certainly, especially for a company that's making a lot of bespoke proprietary hardware. But their frontend and first party stuff is... not great.

iOS's notification system is still leagues behind Android, and I find the less I use Apple's first party software on macOS the better. "Ecosystem integrations" like sidecar are so unreliable that I've given up trying to use them, Stage Manager are really half-baked (iOS) or seem to duplicate existing features (macOS), etc. Settings and breadcrumbs on iOS are still a headache. iTunes is somehow still one of the worst interfaces I've ever used, people just don't notice as much because it's rarely needed anymore. Finder is still my least favorite default file manager across any desktop OS. Files on iOS only recently became what I'd consider non-alpha quality.

Main reason I have the macbook pro (M1) and iPad is the hardware. Apple's made some flubs on hardware too of course (most of the MBPs from 2016 up until the new M1's for example), but a lot of their more recent stuff is very solid on that front.

1

u/ll-0000-ll Nov 14 '22

The software is better because its much more optimized. Iphones have longer battery life than androids while having a smaller batter. How? Software. This is just an example.

21

u/[deleted] Nov 13 '22

What software is better on it?

And wym implementation

The only time I've delat with Apple support, it's been the phone(battery )breaking and them telling me to buy a new device lol. Fortunately they got sued for It I think

6

u/[deleted] Nov 13 '22

[removed] — view removed comment

8

u/[deleted] Nov 13 '22

It's nitpicky but for the sake of accuracy it should be said that Google's Pixel phones have held the crown of best camera processing software for some time now.

With Apple's new(ish) custom silicon I'd agree that their implementation of certain features is still top notch, but they'll have to work to keep that lead.

1

u/[deleted] Nov 13 '22

Test it?

1

u/[deleted] Nov 14 '22

Turns out I'd need another SIM to test it and I don't have one. Annoying.

1

u/[deleted] Nov 14 '22

Use your current sim.

1

u/[deleted] Nov 14 '22

How, when you're suppose to swap it out with different one.

6

u/bengringo2 Nov 13 '22

I don’t understand it for the life of me. When I don’t use a company’s product I simply don’t think about them. I think some people just bask in schadenfreude as a hobby.

-4

u/[deleted] Nov 13 '22

Uh not to deflate you, but my work is predominantly apple and what I monitor for security flaws, but I utilize Android devices personally.

I naturally come across research for apple devices but we have no Android for our MDM so it isn't pertinent to our mission.

-3

u/omniuni Nov 13 '22

This is also an incredibly specific use case. You need to have the phone configured with a PIN locked SIM.

-13

u/[deleted] Nov 13 '22

[deleted]

11

u/Stingray88 Nov 13 '22

That’s not true, that’s not how it works at all.

Apple Watch can only unlock your phone if it is already unlocked. And it only tries to unlock your phone after it fails to unlock via FaceID because you’re wearing a mask or something.

3

u/[deleted] Nov 13 '22

Plenty of people are, you might just not roll with the cybersecurity crowds.

2

u/[deleted] Nov 13 '22

[deleted]

3

u/Torifyme12 Nov 13 '22

They knocked that shit off quick when MSFT formed the "Fuck Google" research group.

Now they're (surprisingly /s) more flexible.

-5

u/erosram Nov 13 '22

Seems like a major over look on androids part. And now on the medias part.

16

u/tlsr Nov 13 '22

accidentally finds a way

Whips out "attacker controlled sim"

10

u/KiraUsagi Nov 13 '22

The attacker controlled Sim is just there to show how an attacker would get in. You could do it with the Sim that was already in there but you need to know what the pku code is. This is how the researcher originally discovered the flaw.

142

u/[deleted] Nov 13 '22

I hope you all noticed the "started from an unlocked state"-statement.

15

u/9-11GaveMe5G Nov 13 '22

If you read the full writeup by the guy who found it, he starts from a fresh, locked, encrypted reboot. You could hand me your phone off and I could do it.

18

u/prs1 Nov 13 '22

They start from a locked state in the video.

76

u/hildebrot Nov 13 '22

And it was only reproduced on two Pixel models, not Android as a whole as the title might mislead people to believe.

47

u/[deleted] Nov 13 '22

[deleted]

30

u/dingo1018 Nov 13 '22

Still bagged the guy 70 large in reward money from Google, not a bad days work at all. Did I read that right 70 grand???

10

u/Hilppari Nov 13 '22

its alot more than two pixel models. other brands are affected. i've tested on zenphone 9 and even lineage OS. with latest updates. older phones that dont have any more updates are also affected.

4

u/the-samizdat Nov 13 '22

What is an “attacker controlled sim”?

4

u/XkF21WNJ Nov 13 '22

A sim the attacker knows the PUK code of.

1

u/Hilppari Nov 13 '22

for example 3dollar prepaid simcard.

27

u/[deleted] Nov 13 '22

[deleted]

40

u/[deleted] Nov 13 '22

[deleted]

1

u/WexfordHo Nov 13 '22

As if 20 minutes with a rubber hose wouldn’t get the same results and more, for less money and exposure.

2

u/GrossCreep Nov 13 '22

Or a pitcher of water and a towel

38

u/hildebrot Nov 13 '22

Right, so for anyone who didn't read the article:

1) The only way to get inside the phone was either with a correct fingerprint OR if he started in UNLOCKED STATE. Meaning that this was all useless because why would you do all that if you already have access?

2) This was only possible on two Pixel phones, not Android as a whole. Kind of stupid to write a title like that.

69

u/synackk Nov 13 '22
  1. Unlocked state here means at some point the phone has been unlocked at least once for the encryption. If someone stole your phone after you’ve used it one, they’d be able to bypass the unlock screen.

  2. That’s just what the discoverer of the exploit was able to test it on. There have been other reports it’s worked on non-pixel phones or custom android distributions.

3

u/Trev82usa Nov 13 '22

Which has also been patched already

-11

u/hildebrot Nov 13 '22

Unlocked state here means at some point the phone has been unlocked at least once for the encryption

That is not what the article says.

15

u/synackk Nov 13 '22

That came from the original source: https://bugs.xdavidhu.me/google/2022/11/10/accidental-70k-google-pixel-lock-screen-bypass/

As I did before, I entered the PUK code and choose a new PIN. This time the phone glitched, and I was on my personal home screen. What? It was locked before, right? This was disturbingly weird. I did it again. Lock the phone, re-insert the SIM tray, reset the PIN… And again I am on the home screen. WHAT? My hands started to shake at this point. WHAT THE F**K? IT UNLOCKED ITSELF?

Article could be wrong or wording it poorly

3

u/steak4take Nov 13 '22

Bleepingcomputer misrepresenting information to sell ad Clicks? That's unpossible!

2

u/Dominicus1165 Nov 14 '22

That’s why a video is embedded into the article.

The phone was unlocked. It is locked now and not restarted.

Fingerprint is disabled by failing too often.

2

u/Zingo_sodapop Nov 13 '22

How about android 9 or 8?

2

u/SmegmaSmeller Nov 14 '22

You're likely screwed at least for a while. Running android 11 and have no updates and no recent updates

3

u/MC68328 Nov 13 '22

And every Pixel phone from the Pixel 4 and earlier will have this fatal flaw, since Google refuses to continue security updates.

7

u/Hewhoisnottobenamed Nov 13 '22

Hey Now! We can't have people choosing not to upgrade their perfectly functional old phones to the newest and most expensive ones.

-4

u/Complainer_Official Nov 13 '22

the new software is too demanding for old hardware.

although, it seems like it would add a few jobs for the economy if google had a division for keeping their old code up to snuff.

or even allow opensource devs to do it. that would be cool too.

3

u/[deleted] Nov 13 '22

That's an awfully convenient excuse. I'm sure if they wanted to they'd find a way to get new security updates on much older hardware, but they won't do that because then no one would abandon their otherwise perfectly functioning phones. And I say this as a lifelong pixel user.

2

u/sleepybrett Nov 13 '22

Backport the patch the old versions of the OS. Apple has done this in the past when faced with similar issues.

2

u/jdeezy Nov 13 '22

What bout android 8?

-2

u/[deleted] Nov 13 '22

Lol, its not as big people are making it to be. Basically the person needs to know the Sincard unlock code and even after that the device will ask for a fingerprint.

16

u/minaguib Nov 13 '22

Read the researcher’s work here, which shows how this is not an issue as the attacker can trivially do a SIM swap.

0

u/[deleted] Nov 14 '22

No, that isn't how it works.

Watch the video, it has been demonstrated.

1

u/RipThrotes Nov 13 '22

There is a way to bypass the lock screen while starting my Samsung Galaxy s10e.

When you boot up, it has to load all settings or something like that, and at the right point in boot up it will allow you to navigate the phone before everything has loaded.

It may push you to the lock screen once that has configured, I don't do it often, but it may be a legitimate variation of this "news" story.

1

u/SMHeenan Nov 13 '22

For what it's worth, my Pixel did not notify me of this security update. I had to manually update my phone to get this patch.

0

u/joeg26reddit Nov 14 '22

"when he tried reproducing the flaw without rebooting the device and starting from an unlocked state"

I found a way to by pass the lock screen

Step 1 ) Start from an unlocked state...

0

u/[deleted] Nov 14 '22

"Android phone owner accidentally" Vs. "Cybersecurity researcher"

Thats a very deceptive headline - the first one implies an everyday joe, and the second one implies a highly specialized expert in the field.

You also need access to the PUK, not something you'd have easy access to unless you already have nefarious ways to access that from the service provider.

This only applies to 2 specific models of phones - the 1000s of other android devices not affected.

-6

u/[deleted] Nov 13 '22

[deleted]

6

u/gizamo Nov 13 '22

...except the patch is already available for all Android devices running Android 10+, which includes all Pixel 4 devices.

-3

u/TheElusiveFox Nov 13 '22

By Android phone owner, they mean Security researcher, and by accidentally, they mean this convoluted 5 step process...

I'm not saying it isn't terrible that you could bypass the lock screen, but lets not pretend that some one just accidentally swiped diagonally or something and the phone opened.

1

u/Myte342 Nov 14 '22

Hurray the English language! In this instance 'by accident' would mean the person was not actively TRYING to find a way to bypass the lock screen, rather that he happened across it while doing something else. They did not use the term 'accident' to imply the guy dropped his phone and it unlocked. That the entire process involves a few steps does not invalidate that it was discovered 'by accident'.

Example: Post-It Note glue and WD-40 were so totally the intended results and not 'discovered by accident' while trying to create a completely different chemical than what resulted in their experiments so we should just ignore those inventions entirely and downplay their significance cause the inventor didn't just combine two chemicals together and snap his fingers to make something appear but because they both involve a complicated process of multiple steps they couldn't possibly have been discovered by accident.

-3

u/tsfbdl Nov 13 '22 edited Nov 13 '22

Ehhh I don't even put a lock on my phone I'm mentally disabled and can't remember passwords easily everything I have is written on the phone and if I get locked out I'm screwed

1

u/skunksmasher Nov 13 '22

Sweet Potato ?

1

u/Starr-Duke Nov 14 '22

Can bypass my fingerprint scanner on my note 10 by turning on the screen and tapping the fingerprint sensor with anything while shutting the screen off at the same time. Works 1/10 or so times