Earlier quoted context omitted.
Apple has never devoted enough care, resources, or money to cybersecurity. It’s just a fact. They’ve also never devoted enough care, resources, or money to network architecture and how important availability is (with fairness, they have improved in this area in the last couple of years due to the major iCloud outages they had). Apple doesn’t hire mainstream IT people and cybersecurity people from the enterprise realm…
They absolutely do hire cybersecurity folks from enterprise companies. Source: I know them.
Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit
31–40 of 314 posts
Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit
#32Apple needs to do a serious architecture of how its own apps work. Its clearly unacceptable that their own apps are not sandboxed to the same level as everything else. If its not possible to implement all of imessage with the public APIs then they need to find a way to expose those private APIs publicly in a safe way. imessage and facetime have been a constant source of exploits.
Apple has never devoted enough care, resources, or money to cybersecurity. It’s just a fact. They’ve also never devoted enough care, resources, or money to network architecture and how important availability is (with fairness, they have improved in this area in the last couple of years due to the major iCloud outages they had). Apple doesn’t hire mainstream IT people and cybersecurity people from the enterprise realm…
Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit
#33Apple needs to do a serious architecture of how its own apps work. Its clearly unacceptable that their own apps are not sandboxed to the same level as everything else. If its not possible to implement all of imessage with the public APIs then they need to find a way to expose those private APIs publicly in a safe way. imessage and facetime have been a constant source of exploits.
It’s not just the lack of sandboxing — iMessage uses language-level serialization of object graphs. This design is never suitable for sending across privilege boundaries. Apple should replace the format with a reasonable wire format. If this requires updates to apps that integrate with iMessage or breaks interoperability with older iOS versions, so be it.
Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit
#34Earlier quoted context omitted.
> when authoritarian countries wake up and realize they can simply force Apple to migrate user data into servers they own in exchange for market access China is the only authoritarian country with enough leverage over Apple to force them to do that sort of thing. There it's not just an enormous market, but also an utterly critical part of Apple's supply chains. Every other authoritarian country is small fry in compar…
Orthogonal to your comment, but Apple could say no and walk away. On the other hand, Google did so, and the cost to them is staggering and the reward negligible - they probably regret that decision intensely. It will become a business school case study in why companies shouldn't put ethics ahead of money. The point being that we need a business environment where it makes business sense to stand up to authoritarian re…
Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit
#35Earlier quoted context omitted.
> when authoritarian countries wake up and realize they can simply force Apple to migrate user data into servers they own in exchange for market access China is the only authoritarian country with enough leverage over Apple to force them to do that sort of thing. There it's not just an enormous market, but also an utterly critical part of Apple's supply chains. Every other authoritarian country is small fry in compar…
Orthogonal to your comment, but Apple could say no and walk away. On the other hand, Google did so, and the cost to them is staggering and the reward negligible - they probably regret that decision intensely. It will become a business school case study in why companies shouldn't put ethics ahead of money. The point being that we need a business environment where it makes business sense to stand up to authoritarian re…
>On the other hand, Google did so, and the cost to them is staggering and the reward negligible - they probably regret that decision intensely.
Wait, what? Who did Google do that to that wasn't China? Because the only one I remember is China, and I explicitly acknowledged in my comment that they have the leverage to carve their own rules. Arguably even more-so with Apple than Google, that's one place where Apple's hardware and vertical integration strategy is a definite weakness vs other players rather than a strength. It's certainly not as if Apple has no negotiating chips vs China, but it's clear who likely has the strongest hand.
But for Google, was there really a "staggering" cost, or any real cost, over refusing the likes of Saudi Arabia or the UAE? I'd love to read up on that if you could point me to what you're thinking of.
Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit
#36Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit
#37Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit
#38When engineers make companies that sell tools like this, it makes all the talk you see about ethical AI and privacy look like bikeshedding.
Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit
#39Earlier quoted context omitted.
Orthogonal to your comment, but Apple could say no and walk away. On the other hand, Google did so, and the cost to them is staggering and the reward negligible - they probably regret that decision intensely. It will become a business school case study in why companies shouldn't put ethics ahead of money. The point being that we need a business environment where it makes business sense to stand up to authoritarian re…
> Orthogonal to your comment, but Apple could say no and walk away. > On the other hand, Google did so, and the cost to them is staggering and the reward negligible - they probably regret that decision intensely. Wait, what? Who did Google do that to that wasn't China? Because the only one I remember is China, and I explicitly acknowledged in my comment that they have the leverage to carve their own rules. Arguably e…
Although the book was published in 2011. I do remember it being a good read at the time, and probably still is!
Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit
#40America should stop giving aid to Israel as long as Israeli companies are going to assist in getting journalists arrested/murdered/dismembered.