Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Hardware Bug. Show all posts

Why Andy Rubin’s Essential Phone Failed Despite Fixing Android’s Biggest Problems

 

Andy Rubin spent ten years creating Android before launching Essential Products, which was based on the idea that Android phones had too many compromises, such as bloatware, software skins, slow updates, and accessories that became obsolete when new hardware was released. Essential launched the PH-1 in August 2017, which had near-stock Android, premium materials, fast updates, and a display that extended to the edges. 

Rubin had co-founded Android Inc. with Rich Miner, Nick Sears, and Chris White in 2003, and Google bought the company in 2005 for $50 million. Rubin continued to lead Android’s development for the next eight years. The PH-1 was meant to overcome some of the shortcomings of the open-source platform. It had Android 7.1.1 and was expected to receive two major Android upgrades and three years of monthly security updates. 

Essential delivered on Android 9 and Android 10, the same day as Google’s Pixel phones. The hardware was also supposed to overcome Android’s challenges. The phone had a titanium frame and a ceramic back, and it was among the first smartphones to have a notch. It had magnetic pins on the back, which were supposed to allow accessories to snap onto the phone instead of using a USB-C port. Essential announced a 360 camera and an audio adapter, but the ecosystem was never realized.

The launch of the PH-1 did not go well for Essential. The company announced that the phone would be available for purchase within 30 days, but the first units were not shipped until August 25 th , nearly two months after launch. The camera was also heavily criticized, and the $699 price was permanently reduced to $499 only two months after its launch. The only US carrier that sold the Essential PH-1 was Sprint. Essential’s sales were also underwhelming despite the star power of Andy Rubin.

A $300 million funding round in 2017 valued Essential at around $1.2 billion, but Bloomberg revealed that Essential had only sold 150,000 phones by May 2018. In October 2018, The New York Times revealed that Google had investigated a sexual harassment complaint against Rubin and found the allegations credible. Google approved a $90 million exit package for Rubin, but he denied the allegations. 

The report received a negative reaction from many Google employees, and Rubin’s reputation became a liability for Essential. Essential also announced Project Gem, a tall and thin smartphone that was designed to be used with one hand. The phone never reached the market, and Essential filed for bankruptcy on February 12 th , 2020, after realizing that there was no viable way to bring the phone to the market. The PH-1 was a lesson that high-end materials, limited software, and fast updates were not enough for a struggling smartphone brand to survive. 

The phone’s troubled launch, limited accessories, poor camera, and lack of network support hindered its chances, and Essential was unable to turn it around. The company realized that its ideas were not scalable enough to sustain a smartphone manufacturer, and it filed for bankruptcy later in 2020.

Security Bug Detected in Apple M1 Processor Chipsets

 

MIT researchers have unearthed an “unpatchable” hardware bug in Apple's M1 processor chipsets that could allow hackers to breach its last line of security defenses. 

The security loophole is rooted in a hardware-level security mechanism employed in Apple M1 chips called pointer authentication codes, or PAC. This mechanism restricts a hacker to inject malicious code into a device’s memory and it also shields against buffer overflow exploits, which is a form of assault that forces memory to leak into other locations of the chip and acts as the last line of defense.

Employing assault to identify vulnerability 

MIT researchers demonstrated a novel hardware assault dubbed PACMAN that combines memory corruption and speculative execution to bypass the security feature. The assault depicted that pointer authentication can be breached without leaving a trace, and as it employs a hardware mechanism that cannot be patched with software features. 

The attack works by “guessing” a pointer authentication code (PAC), a cryptographic signature that confirms that an app hasn’t been maliciously altered. This is done using speculative execution — a methodology employed by modern computer processors to enhance performance by speculatively guessing various lines of computation — to leak PAC verification results, while a hardware side-channel reveals whether or not the guess was correct.

According to the researchers, there are many possible values of a PAC, but with a device that reveals whether a guess is correct or false, one can try them all until they hit the right one. 

“The idea behind pointer authentication is that if all else has failed, you still can rely on it to prevent attackers from gaining control of your system. We’ve shown that pointer authentication as a last line of defense isn’t as absolute as we once thought it was,” explained MIT CSAIL Ph.D. student Joseph Ravichandran and co-lead author of the paper. 

“When pointer authentication was introduced, a whole category of bugs suddenly became a lot harder to use for attacks. With PACMAN making these bugs more serious, the overall attack surface could be a lot larger”. 

Multiple chipsets are in danger 

Apple uses PAC on all its M1 chips, including the M1, M1 Pro, and M1 Max. In the coming months, other chip designers, including Samsung along with Qualcomm, are expected to launch new chips supporting PAC. 

If this exploit is not mitigated, it will impact the majority of mobile devices, and likely even desktop devices in the coming years, researchers warned. 

Prevention tips 

To mitigate the risks, modification of the software is required so PAC verification results are never done under speculation, meaning a hacker couldn’t go incognito while attempting to breach. 

The second technique is to guard against PACMAN in the same way Spectre vulnerabilities are being mitigated. And finally, patching memory corruption bugs would ensure this last line of defense isn’t required.