Live data from Hacker News

Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

citizenlab.ca

21–30 of 314 posts

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#21
post #16

Earlier quoted context omitted.

This is why no amount of "but apple cares about privacy" will ever make me drop the "Trust but verify" I try to live by (money allowing), even if I believe they care more than most.

I look at the “Apple cares about privacy” as a qualified “more than them other OS &mobile firms”, not “enough that you should blindly trust us”. No one’s security is perfect

Including your own! A big part of opsec is putting systems in place that mitigate dangerous but unavoidable human behaviour.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#22

NSO Group will lose a lot of business when authoritarian countries wake up and realize they can simply force Apple to migrate user data into servers they own in exchange for market access.

>when authoritarian countries wake up and realize they can simply force Apple to migrate user data into servers they own in exchange for market access

China is the only authoritarian country with enough leverage over Apple to force them to do that sort of thing. There it's not just an enormous market, but also an utterly critical part of Apple's supply chains. Every other authoritarian country is small fry in comparison, and if they demanded such a thing Apple would tell them to get stuffed. Apple has not just commercial reasons, but political ones as well. While Trump is enamored with authoritarians, the incoming Biden Administration is not, nor is much of Congress or the general public. The EU would also like to at least pretend to care overall. Particularly right now at a time of scrutiny, Apple has every reason to not merely deny such a demand but to do so loudly and publicly.

And seriously, it's not like authoritarians are all stupid (unfortunately) and need to "wake up". They're all aware what China has demanded and gotten away with. If they thought they could too, they would. But they wouldn't, so they don't.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#23
post #10

Earlier quoted context omitted.

I think you misread. The exploit effects all ios’ before ios 14, not just ios 11

"In July 2020, KISMET was a zero-day against at least iOS 13.5.1 and could hack Apple’s then-latest iPhone 11."

Since this is a software exploit, not a hardware one, the model of phone hardly seems relevant. An iPhone 11 running iOS 14 should not be vulnerable to this. However an iPhone 8 running iOS 13.5.1 is presumably vulnerable. I suspect the parent post conflated iOS 11 (software) with iPhone 11 (hardware).

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#24

Apple needs to do a serious architecture of how its own apps work. Its clearly unacceptable that their own apps are not sandboxed to the same level as everything else. If its not possible to implement all of imessage with the public APIs then they need to find a way to expose those private APIs publicly in a safe way. imessage and facetime have been a constant source of exploits.

Apple has never devoted enough care, resources, or money to cybersecurity. It’s just a fact.

They’ve also never devoted enough care, resources, or money to network architecture and how important availability is (with fairness, they have improved in this area in the last couple of years due to the major iCloud outages they had).

Apple doesn’t hire mainstream IT people and cybersecurity people from the enterprise realms. There is a vast amount of talented people and knowledge they simply ignore because the Apple culture is too hip and cool for that.

Steve Jobs is primarily the blame for all the above. He treated the departments and any person that cared about enterprise like dirt. Steve Jobs always said Apple is a consumer company. This philosophy has obviously carried on.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#25
post #10

Earlier quoted context omitted.

"In July 2020, KISMET was a zero-day against at least iOS 13.5.1 and could hack Apple’s then-latest iPhone 11."

Since this is a software exploit, not a hardware one, the model of phone hardly seems relevant. An iPhone 11 running iOS 14 should not be vulnerable to this. However an iPhone 8 running iOS 13.5.1 is presumably vulnerable. I suspect the parent post conflated iOS 11 (software) with iPhone 11 (hardware).

That was my guess too, but I simply posted the claim from the article, since neither the parent (ironically) nor the GP appeared to have read it correctly.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#26
post #22

NSO Group will lose a lot of business when authoritarian countries wake up and realize they can simply force Apple to migrate user data into servers they own in exchange for market access.

> when authoritarian countries wake up and realize they can simply force Apple to migrate user data into servers they own in exchange for market access China is the only authoritarian country with enough leverage over Apple to force them to do that sort of thing. There it's not just an enormous market, but also an utterly critical part of Apple's supply chains. Every other authoritarian country is small fry in compar…

Orthogonal to your comment, but Apple could say no and walk away.

On the other hand, Google did so, and the cost to them is staggering and the reward negligible - they probably regret that decision intensely. It will become a business school case study in why companies shouldn't put ethics ahead of money.

The point being that we need a business environment where it makes business sense to stand up to authoritarian regimes.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#27

Apple needs to do a serious architecture of how its own apps work. Its clearly unacceptable that their own apps are not sandboxed to the same level as everything else. If its not possible to implement all of imessage with the public APIs then they need to find a way to expose those private APIs publicly in a safe way. imessage and facetime have been a constant source of exploits.

iMessage is not being attacked because it's not as sandboxed as other apps. It's being attacked because it's accessible with zero clicks.

For an attack like this you need to chain an iMessage exploit with an LPE, and the LPE can be launched from any other app.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#28

Apple needs to do a serious architecture of how its own apps work. Its clearly unacceptable that their own apps are not sandboxed to the same level as everything else. If its not possible to implement all of imessage with the public APIs then they need to find a way to expose those private APIs publicly in a safe way. imessage and facetime have been a constant source of exploits.

Apple has never devoted enough care, resources, or money to cybersecurity. It’s just a fact. They’ve also never devoted enough care, resources, or money to network architecture and how important availability is (with fairness, they have improved in this area in the last couple of years due to the major iCloud outages they had). Apple doesn’t hire mainstream IT people and cybersecurity people from the enterprise realm…

but which tech companies do devote enough care, resources and money to cybersecurity?

I always figured the industry never really rewarded those things over aspects (e.g. time to market).

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#30

Apple needs to do a serious architecture of how its own apps work. Its clearly unacceptable that their own apps are not sandboxed to the same level as everything else. If its not possible to implement all of imessage with the public APIs then they need to find a way to expose those private APIs publicly in a safe way. imessage and facetime have been a constant source of exploits.

Apple has never devoted enough care, resources, or money to cybersecurity. It’s just a fact. They’ve also never devoted enough care, resources, or money to network architecture and how important availability is (with fairness, they have improved in this area in the last couple of years due to the major iCloud outages they had). Apple doesn’t hire mainstream IT people and cybersecurity people from the enterprise realm…

They absolutely do hire cybersecurity folks from enterprise companies. Source: I know them.
Post reply on HN