Live data from Hacker News

Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

citizenlab.ca

51–60 of 314 posts

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#51

So, iiuc, this "zero-click" hack involved iMessage and payloads apparently injected via Apple's domains and the exfiltration of data through a tor-like network eventually reaching malicious servers. Is anyone aware of any (FOSS) software (presumably intrusion detectors or indicators of compromise) for mobile phones that might help flag or even prevent such attacks? TinyCheck [0] comes to mind, but it isn't truly mobi…

Most likely the malware is using SSL so packet sniffing from an external device isn't gonna work. And it's apple, so at best you might find a firewall among their tightly locked down app store. Don't worry, apple knows what's good for you far better than you ever could ::eye roll::

A lot of the teams inside Apple who create first-party apps like iMessage are understaffed compared to their competitors.

They should really hire more security folks. A lot of Apple's product security work seems to be outsourced to Google Project Zero.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#52
post #49

Earlier quoted context omitted.

Seems fairly hypocritical in a number of ways. From our own companies actions, like Blackwater, to our allies actions, like Saudi Arabia, to our own government's actions, like "Collateral Murder" or events in Yemen. Why punish Israel?

Israeli courts rejected the case to revoke NSOs export license which would then implicate the state itself. IANAL but I think the case can be made that the export of NSOs software is against US law and a violation of the Wassenaar Arrangement. See: 5D002.C.1 So in theory if Israel is allowing one of its companies to break US law then it would make sense to use that as a basis to stop aid to Israel which may be what O…

Israel is not a signatory of the Wassenaar Arrangement, and I'm not sure how that would work under the law mentioned. Either way, it would be rather targeted enforcement considering what the Hacking Team apparently did with Italy signing the agreement.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#53

America should stop giving aid to Israel as long as Israeli companies are going to assist in getting journalists arrested/murdered/dismembered.

Seems fairly hypocritical in a number of ways. From our own companies actions, like Blackwater, to our allies actions, like Saudi Arabia, to our own government's actions, like "Collateral Murder" or events in Yemen. Why punish Israel?

> Why punish Israel?

The whole "assist[ing] in getting journalists arrested/murdered/dismembered" thing still seems like pretty good justification to me. I'm not sure "but everyone else is doing it!" makes that acceptable. Requiring that we deal with every single one of those problems simultaneously else we shouldn't bother with any of them doesn't seem productive.

I'm also not sure I'd describe the refusal to actively fund that behaviour as punishment, but I suppose that's somewhat beside the point.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#54

America should stop giving aid to Israel as long as Israeli companies are going to assist in getting journalists arrested/murdered/dismembered.

Seems fairly hypocritical in a number of ways. From our own companies actions, like Blackwater, to our allies actions, like Saudi Arabia, to our own government's actions, like "Collateral Murder" or events in Yemen. Why punish Israel?

Everyone does it so I can too?

You have to start somewhere. But yes, let’s also cut off all the others you mentioned.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#55

So, iiuc, this "zero-click" hack involved iMessage and payloads apparently injected via Apple's domains and the exfiltration of data through a tor-like network eventually reaching malicious servers. Is anyone aware of any (FOSS) software (presumably intrusion detectors or indicators of compromise) for mobile phones that might help flag or even prevent such attacks? TinyCheck [0] comes to mind, but it isn't truly mobi…

Are these apps similar to Blockada?

https://blokada.org/

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#56
post #49

Earlier quoted context omitted.

Israeli courts rejected the case to revoke NSOs export license which would then implicate the state itself. IANAL but I think the case can be made that the export of NSOs software is against US law and a violation of the Wassenaar Arrangement. See: 5D002.C.1 So in theory if Israel is allowing one of its companies to break US law then it would make sense to use that as a basis to stop aid to Israel which may be what O…

Israel is not a signatory of the Wassenaar Arrangement, and I'm not sure how that would work under the law mentioned. Either way, it would be rather targeted enforcement considering what the Hacking Team apparently did with Italy signing the agreement.

I guess the question now is; under what jurisdiction does exploits based on WhatsApp and iOS source code lie?

If I reverse engineered and sold exploits of American missile systems while in Somalia would that mean everything is A-OK?

Idk. Again, not a lawyer.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#57

America should stop giving aid to Israel as long as Israeli companies are going to assist in getting journalists arrested/murdered/dismembered.

America didn't stop giving aid to Israel despite 53 years of military occupation and apartheid. You think this is going to be the thing that changes the status quo on Israel?

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#58

If journalists start sharing Google Voice numbers instead of their iphone #s then would they be resilient to this sort of attacks?

Depends. Perhaps it may not be zero-click, but it's definitely possible to hack someone's phone using a communication app by sending a malicious payload. For example, Jeff Bezos's iPhone was hacked using a WhatsApp exploit.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#59
post #46

America should stop giving aid to Israel as long as Israeli companies are going to assist in getting journalists arrested/murdered/dismembered.

WhatsApp "attempted" to get NSOs export license revoked and failed. How would you expect America to stop two of their allies from dealing with each other (with a potential courtship in the works)? Especially when America itself gets major weapons contracts to look the other way? This will just continue to get worse. More journalists and human rights activists will die because some delusional maniacs feelings were hur…

Everyone involved from NSO execs through to the Saudi's and Emirati's should be facing DOJ indictments no different to what Russian, North Korean and Chinese hackers face

This thin veneer of NSO being a legitimate company has been exposed

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#60

Earlier quoted context omitted.

Most likely the malware is using SSL so packet sniffing from an external device isn't gonna work. And it's apple, so at best you might find a firewall among their tightly locked down app store. Don't worry, apple knows what's good for you far better than you ever could ::eye roll::

A lot of the teams inside Apple who create first-party apps like iMessage are understaffed compared to their competitors. They should really hire more security folks. A lot of Apple's product security work seems to be outsourced to Google Project Zero.

Yet they somehow roll out some crazy new memoji or drawing feature every year

Their priorities are just in the wrong place

Post reply on HN