Article count:16428 Read by:87919360

Hottest Technical Articles
Exclusive: A senior executive of NetEase Games was taken away for investigation due to corruption
OPPO is going global, and moving forward
It is reported that Xiaohongshu is testing to directly direct traffic to personal WeChat; Luckin Coffee is reported to enter the US and hit Starbucks with $2, but the official declined to comment; It is reported that JD Pay will be connected to Taobao and Tmall丨E-commerce Morning News
Yu Kai of Horizon Robotics stands at the historical crossroads of China's intelligent driving
Lei Jun: Don't be superstitious about BBA, domestic brands are rising in an all-round way; Big V angrily criticized Porsche 4S store recall "sexy operation": brainless and illegal; Renault returns to China and is building a research and development team
A single sentence from an overseas blogger caused an overseas product to become scrapped instantly. This is a painful lesson. Amazon, Walmart, etc. began to implement a no-return and refund policy. A "civil war" broke out between Temu's semi-hosted and fully-hosted services.
Tmall 3C home appliances double 11 explosion: brands and platforms rush to
Shareholders reveal the inside story of Huayun Data fraud: thousands of official seals were forged, and more than 3 billion yuan was defrauded; Musk was exposed to want 14 mothers and children to live in a secret family estate; Yang Yuanqing said that Lenovo had difficulty recruiting employees when it went overseas in the early days
The app is coming! Robin Li will give a keynote speech on November 12, and the poster reveals a huge amount of information
It is said that Zhong Shanshan asked the packaged water department to sign a "military order" and the entire department would be dismissed if the performance did not meet the standard; Ren Zhengfei said that it is still impossible to say that Huawei has survived; Bilibili reported that employees manipulated the lottery丨Leifeng Morning News
Account Entry

GeekPwn 2016 | Hacker demonstrates unlocking Huawei phone with nose tip

Latest update time:2021-09-03 22:40
    Reads:

Today, at the GeekPwn hacking competition held in Shanghai, hacker Nick from the US Shellphish team successfully hacked into a brand new Huawei P9 Lite phone.


On the stage, Nick called two girls as assistants. The attack was divided into two steps:


1. Let a girl input fingerprints step by step and pretend to be the owner of the phone;

2. He guided another girl step by step to download the attack tool from the predetermined address, and then lightly touched the phone with the tip of her nose, and the phone was instantly opened.


The whole process was extremely fast. Before the audience even understood what was happening, all the permissions of the phone had been obtained by the hacker.



This attack means that if a hacker has the opportunity to install his app on your phone, he can unlock the phone anytime and anywhere and check your little secrets.


According to GeekPwn founder Wang Qi's on-site introduction, this attack looks simple, but in fact it uses as many as eight vulnerabilities, which can be described as "black to the end."


However, for security reasons, the hacker did not intend to reveal the specific principles of his attack on the spot. However, the judges on the spot revealed that the basic attack path starts from the App, obtains root permissions, and then enters the core area of ​​fingerprint storage: TrustZone.


According to GeekPwn official news, any device using the HUAWEI TrustZone service will be affected by this attack, including the previous generation Huawei P8 Lite.


This is the world's first demonstration of breaking through the fingerprint unlocking of a mobile phone. Before this, many security researchers believed that our fingerprints and other secrets were safe with strong hardware encryption. However, hacker attacks tell us not to be so optimistic. Even if the security of the protection system is strong, we should not trust it unconditionally.



Since this attack requires the hacker to have physical contact with the unlocked phone, that is, the hacker must first ask you to help unlock the phone before continuing the attack. Obviously, such an attack condition is still relatively strict.


As for how to prevent Nick from unlocking your phone with his nose or any other part of his body, Leifeng.com's (public account: Leifeng.com) home channel suggests:


1. Don’t let your phone out of your sight;

2. Try not to make friends with hackers.


Follow-up:


After the vulnerabilities discovered during the on-site demonstration were breached, Huawei immediately conducted careful analysis and repair work on the vulnerabilities provided by the organizer to ensure that the security of Huawei's mobile phone system is further improved.


Huawei said:


Any smartphone has certain unknown security vulnerabilities, and the hacking demonstration can urge us to continuously discover product vulnerabilities, continuously test the reliability of the system, and continuously improve the system to keep the product in a relatively safe state and prevent user interests from being violated by malicious persons.


Security is no small matter. Huawei has always attached great importance to the system security of its products. Huawei phones undergo very strict software and hardware quality inspections before leaving the factory, and provide users with relatively comprehensive security protection applications after sales. For Huawei phones, which attach great importance to user security, the security geeks' hacking demonstration is undoubtedly an important opportunity to improve product security.



Click on a keyword to view related historical articles


WRC 2016 Special


Opening Ceremony Introduction

Vitaly Nedelskiy, Chairman of the Russian Robotics Association

Stanford professor Oussama Khatib

Zvi Shiller, President of the Israel Robotics Association

Qu Daokui, President of Siasun



CNCC 2016 Special Topics


Opening Ceremony Introduction

Academician Zhang Bei of Tsinghua University

Chen Chun from Zhejiang University

Sogou CEO Wang Xiaochuan



Hammer M1/M1L | Loongson 3A3000 | Samsung Note 7

DJI Mavic | Google Home

Domestic multi-line laser radar | Google Daydream VR helmet

Xiaomi 5s | Movidius | lightning | Prisma | Live

Xiaomi Robot Vacuum Cleaner | Yi M1 Micro Single Camera | Xiaomi Notebook

App ID | Huawei drone | Amazon Echo


Featured Posts


Latest articlesabout

Database "Suicide Squad" 
Exclusive: Yin Shiming takes over as President of Google Cloud China 
After more than 150 days in space, the US astronaut has become thin and has a cone-shaped face. NASA insists that she is safe and healthy; it is reported that the general manager of marketing of NetEase Games has resigned but has not lost contact; Yuanhang Automobile has reduced salaries and laid off employees, and delayed salary payments 
Exclusive: Google Cloud China's top executive Li Kongyuan may leave, former Microsoft executive Shen Bin is expected to take over 
Tiktok's daily transaction volume is growing very slowly, far behind Temu; Amazon employees exposed that they work overtime without compensation; Trump's tariff proposal may cause a surge in the prices of imported goods in the United States 
OpenAI's 7-year security veteran and Chinese executive officially announced his resignation and may return to China; Yan Shuicheng resigned as the president of Kunlun Wanwei Research Institute; ByteDance's self-developed video generation model is open for use丨AI Intelligence Bureau 
Seven Swordsmen 
A 39-year-old man died suddenly while working after working 41 hours of overtime in 8 days. The company involved: It is a labor dispatch company; NetEase Games executives were taken away for investigation due to corruption; ByteDance does not encourage employees to call each other "brother" or "sister" 
The competition pressure on Douyin products is getting bigger and bigger, and the original hot-selling routines are no longer effective; scalpers are frantically making money across borders, and Pop Mart has become the code for wealth; Chinese has become the highest-paid foreign language in Mexico丨Overseas Morning News 
ByteDance has launched internal testing of Doubao, officially entering the field of AI video generation; Trump's return may be beneficial to the development of AI; Taobao upgrades its AI product "Business Manager" to help Double Eleven丨AI Intelligence Bureau 

 
EEWorld WeChat Subscription

 
EEWorld WeChat Service Number

 
AutoDevelopers

About Us About Us Service Contact us Device Index Site Map Latest Updates Mobile Version

Site Related: TI Training

Room 1530, Zhongguancun MOOC Times Building,Block B, 18 Zhongguancun Street, Haidian District,Beijing, China Tel:(010)82350740 Postcode:100190

EEWORLD all rights reserved 京B2-20211791 京ICP备10001474号-1 电信业务审批[2006]字第258号函 京公网安备 11010802033920号 Copyright © 2005-2021 EEWORLD.com.cn, Inc. All rights reserved