Live data from Hacker News

Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

citizenlab.ca

91–100 of 314 posts

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#91

Earlier quoted context omitted.

America didn't stop giving aid to Israel despite 53 years of military occupation and apartheid. You think this is going to be the thing that changes the status quo on Israel?

Sponsoring international terrorism used to be a real faux pas in the U.S. I guess those days are over.

I mean, regime replacement was totally our thing. We'd gladly put totalitarian in charge if a country talked socialism.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#92
post #87

America should stop giving aid to Israel as long as Israeli companies are going to assist in getting journalists arrested/murdered/dismembered.

not sure why the USA love Israel so much

The religious right has the whole 'second coming is happening in Israel' thing, so there is that.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#93

America should stop giving aid to Israel as long as Israeli companies are going to assist in getting journalists arrested/murdered/dismembered.

America didn't stop giving aid to Israel despite 53 years of military occupation and apartheid. You think this is going to be the thing that changes the status quo on Israel?

@dang can you please take a look at the above comment. This will trigger a flame war and is against hacker news policy

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#94
post #16

Earlier quoted context omitted.

This is why no amount of "but apple cares about privacy" will ever make me drop the "Trust but verify" I try to live by (money allowing), even if I believe they care more than most.

I look at the “Apple cares about privacy” as a qualified “more than them other OS &mobile firms”, not “enough that you should blindly trust us”. No one’s security is perfect

Apples security model seems to mostly be based on fixing issues fast and pushing them out to almost all users. That means the only people at risk are those worth burning a brand new exploit on. The average consumer is pretty safe.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#97
post #17

Earlier quoted context omitted.

It’s not just the lack of sandboxing — iMessage uses language-level serialization of object graphs. This design is never suitable for sending across privilege boundaries. Apple should replace the format with a reasonable wire format. If this requires updates to apps that integrate with iMessage or breaks interoperability with older iOS versions, so be it.

It’s not clear if this was involved in the exploits mentioned here.

It has been proven to be a weak point in their implementation with previous exploits, and it's likely to be the case here - it's a good guess at least.

Will be interesting to read a write-up.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#98
post #92
post #87

Earlier quoted context omitted.

not sure why the USA love Israel so much

The religious right has the whole 'second coming is happening in Israel' thing, so there is that.

The religious right can't even prevent Drag Queen Story Hour from happening, what makes you think they have this much power?

It's more likely that it is simply the influence of Israelis and Jews in America, who are powerful enough to determine US foreign policy (Jared Kushner, as far as I can tell, is not a "religious right" but a zionist Jew).

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#99
post #27

Apple needs to do a serious architecture of how its own apps work. Its clearly unacceptable that their own apps are not sandboxed to the same level as everything else. If its not possible to implement all of imessage with the public APIs then they need to find a way to expose those private APIs publicly in a safe way. imessage and facetime have been a constant source of exploits.

iMessage is not being attacked because it's not as sandboxed as other apps. It's being attacked because it's accessible with zero clicks. For an attack like this you need to chain an iMessage exploit with an LPE, and the LPE can be launched from any other app.

LPE. What is an LPE?

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#100
post #87

America should stop giving aid to Israel as long as Israeli companies are going to assist in getting journalists arrested/murdered/dismembered.

not sure why the USA love Israel so much

I think it's also because of their stance against Iran
Post reply on HN