Live data from Hacker News

Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

citizenlab.ca

71–80 of 314 posts

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#71
It was awesome when Facebook deleted NSO group employees personal profiles. And then they whined about it. The silver lining of Facebook owning WhatsApp.

I hope more organizations do this.

https://arstechnica.com/information-technology/2019/10/faceb...

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#72
> We were unable to retrieve these binaries from flash memory, as we did not have access to a jailbreak for iPhone 11 running iOS 13.5.1.

It’s ironic that the exploit is able to plant arbitrary code on an up-to-date device and yet the owner of the phone can’t introspect their phone to see it themselves because they don’t know how to bypass the protections :/

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#73
post #46

Earlier quoted context omitted.

WhatsApp "attempted" to get NSOs export license revoked and failed. How would you expect America to stop two of their allies from dealing with each other (with a potential courtship in the works)? Especially when America itself gets major weapons contracts to look the other way? This will just continue to get worse. More journalists and human rights activists will die because some delusional maniacs feelings were hur…

Everyone involved from NSO execs through to the Saudi's and Emirati's should be facing DOJ indictments no different to what Russian, North Korean and Chinese hackers face This thin veneer of NSO being a legitimate company has been exposed

Exposed? We knew NSO was selling exploits to authoritarian governments for years. Pegasus is nothing new.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#74

Earlier quoted context omitted.

A lot of the teams inside Apple who create first-party apps like iMessage are understaffed compared to their competitors. They should really hire more security folks. A lot of Apple's product security work seems to be outsourced to Google Project Zero.

Yet they somehow roll out some crazy new memoji or drawing feature every year Their priorities are just in the wrong place

Of course, the people writing the Memoji code and the people doing security work on the app are frequently different people…

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#75
post #69

Earlier quoted context omitted.

Whether the actions are technically illegal doesn't really matter unless we are already punishing anyone that breaks those laws. In your hypothetical, we would be punishing Somalia when Italy did the exact same thing unpunished.

I forgot to add on my hypothetical that the Somalian government was protecting me. In which case it would be valid for people to be calling for sanctions let alone revocation of state aid. Iirc, hacking team dissolved or greatly downsized after their leak. I do not recall any cases against them for their export license to be revoked. I'm sure if the Italian courts rejected the case baselessly then there would be cons…

>The difference with Italy is that it does not receive state aid from the Americans. I'm sure if they were then people would be calling for cuts in a similar situation.

This isn't true. On top of the general disaster aid, including $10 million for COVID, we have seven US military bases in the country which accounts for millions a year in aid.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#76

Earlier quoted context omitted.

>You have to start somewhere Then start with yourself. I'm not condoning Israel's actions but punishing them for what we still do is tyranny.

We can start with ourselves by not sending military aid to Israel.

Which doesn't necessarily prevent any journalist deaths, while we send many Yemeni journalists one step closer to starvation.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#77
post #61

More generally, is there a known correlation between kernel panics and exploits, especially on macOS? > Almisshal’s device shows what appears to be an unusual number of kernel panics (phone crashes) between January and July 2020. While some of the panics may be benign, they may also indicate earlier attempts to exploit vulnerabilities against his device.

Failing exploits tend to cause kernels to panic.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#79

As someone that isn't a developer, I wonder how many zero days come from people inside the software team. To simply have knowledge of a difficult bug that hasn't been resolved would seem to be valuable commodity in a closed source system.

Is it not something as simple as a try catch unresolved or ignoring an injection attack?

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#80

When engineers make companies that sell tools like this, it makes all the talk you see about ethical AI and privacy look like bikeshedding.

Ethical AI are rules of engagement for honest brokers. Having honestly intentioned people not have hidden badness in their products is still important even if other dishonest people do bad things.
Post reply on HN