Live data from Hacker News

Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

citizenlab.ca

1–10 of 314 posts

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#3
Journalists as messengers have always been targeted, and even killed, and it seems that Apple’s messaging system was the attack vector here.

While the article decries NSO being nefarious and selling to suspect “authoritarian” countries, high schools here in our democratic US have been buying hacking solutions to spy on students:

https://gizmodo.com/u-s-schools-are-buying-phone-hacking-tec...

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#6
post #4
post #2

Dupe: https://news.ycombinator.com/item?id=25489140

This is a dupe but seems to go into more technical detail. There’s no mention of iMessage in The Guardian’s coverage.

It's all sensational articles though. Show me the bug they used to exploit iMessage. That'd be far more interesting that this Cold War madness we read everyday.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#7
post #6
post #4

Earlier quoted context omitted.

This is a dupe but seems to go into more technical detail. There’s no mention of iMessage in The Guardian’s coverage.

It's all sensational articles though. Show me the bug they used to exploit iMessage. That'd be far more interesting that this Cold War madness we read everyday.

They may be under NDA from apple as the ios 11 is still widly used (I think)

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#8
post #6

Earlier quoted context omitted.

It's all sensational articles though. Show me the bug they used to exploit iMessage. That'd be far more interesting that this Cold War madness we read everyday.

They may be under NDA from apple as the ios 11 is still widly used (I think)

I think you misread. The exploit effects all ios’ before ios 14, not just ios 11

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#9
Apple needs to do a serious architecture of how its own apps work. Its clearly unacceptable that their own apps are not sandboxed to the same level as everything else. If its not possible to implement all of imessage with the public APIs then they need to find a way to expose those private APIs publicly in a safe way.

imessage and facetime have been a constant source of exploits.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#10

Earlier quoted context omitted.

They may be under NDA from apple as the ios 11 is still widly used (I think)

I think you misread. The exploit effects all ios’ before ios 14, not just ios 11

"In July 2020, KISMET was a zero-day against at least iOS 13.5.1 and could hack Apple’s then-latest iPhone 11."
Post reply on HN