Comment by ajross
7 months ago
This really needs to be the link. The article is phrased as if this was a zero day exploiting some kind of 2FA bug, but the actual meat is that it's a novel and really interesting new kind of attack vector (albeit not a particularly practical one) that no one had thought about before.
I would not say "no one had thought about before".
Side channel attack is not a novel idea, just not used to find Android bugs like this.
> Side channel attack is not a novel idea
Yes, but "side channel attack" isn't much of a description, is it? You can't just declare "I make a side channel attack!"[1], you need to invent one.
In this case it turns out that the hardware rendering of the zoom animation in the blur effect of stacked activities on the screen left crumbs that can be detected in the alien context. I certainly didn't know that. Did you know that? I don't think anyone knew that! It's "novel".
[1] Shades of Michael Scott declaring bankruptcy.