America should stop giving aid to Israel as long as Israeli companies are going to assist in getting journalists arrested/murdered/dismembered.
We saw the news this year when a Saudi prince directly authorized the murder and dismemberment of an American/Saudi journalist inside it's own embassy. And literally nothing happened. I'm not holding my breath on America ever making the right decisions with respect to foreign policy.
Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit
131–140 of 314 posts
Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit
#132America should stop giving aid to Israel as long as Israeli companies are going to assist in getting journalists arrested/murdered/dismembered.
I suspect the reason that does not happen is because NSO does the US's dirty work for it, otherwise the US would have stopped it already. After all, the US directly supports those same governments NSO works with. It's probably not too upset its dependents are getting support from a different actor.
Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit
#133How come when we hear about this stuff it is always Israeli companies involved? Is ethics not taught in Israeli Computer Science curricula? Those who wrote this exploit are clearly "brilliant" and at least some of them are bound to be reading Hacker News. Is other countries' spyware firms just better at hiding their malware than Israel's is?
It’s called selection bias. It’s fun and always acceptable to hate on Israel. It’s also more memorable due to the sensationalization of it. A few years ago bluecoat systems was caught providing deep packet inspection gear to the Syrian government. But that wasn’t Israel so no biggie and you either never heard about it or didn’t pay much attention because it wasn’t Israel. American and European companies do this all t…
Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit
#134How come when we hear about this stuff it is always Israeli companies involved? Is ethics not taught in Israeli Computer Science curricula? Those who wrote this exploit are clearly "brilliant" and at least some of them are bound to be reading Hacker News. Is other countries' spyware firms just better at hiding their malware than Israel's is?
Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit
#135As someone that isn't a developer, I wonder how many zero days come from people inside the software team. To simply have knowledge of a difficult bug that hasn't been resolved would seem to be valuable commodity in a closed source system.
If one were sufficiently motivated and planned ahead, you could almost consider it as a future "insurance policy" of sorts.
Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit
#136As someone that isn't a developer, I wonder how many zero days come from people inside the software team. To simply have knowledge of a difficult bug that hasn't been resolved would seem to be valuable commodity in a closed source system.
This is why internal bug bounties should pay cash. Most orgs don't even have one.
Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit
#137So, iiuc, this "zero-click" hack involved iMessage and payloads apparently injected via Apple's domains and the exfiltration of data through a tor-like network eventually reaching malicious servers. Is anyone aware of any (FOSS) software (presumably intrusion detectors or indicators of compromise) for mobile phones that might help flag or even prevent such attacks? TinyCheck [0] comes to mind, but it isn't truly mobi…
Assuming such applications existed, how would you install them on the "suspect" iPhone?
Assuming you were able to install such applications, you'd still not have any access to or control over the baseband (which I strongly suspect has plenty of issues of its own).
Assuming the malicious software avoided using Wi-Fi and used only the the cellular data connection for command and control, exfiltration, etc., it'd be damn near impossible to monitor the ("plain-text") data being sent and received (assuming such software would make use of private certificates -- or asymmetric encryption, in general -- to avoid being MITM'd itself, which seems like a reasonable assumption).
--
EDIT: This got me thinking, "what would be the most secure way to keep and use a mobile phone?" (assuming one could not simply avoid doing so).
My first thought is to use a mobile phone with the baseband radio(s) (verifiably) disabled/removed (if that is even possible?) or -- even better -- a Wi-Fi only device (similar in function as the old iPod Touch, for example) on which one used only SIP applications for calling (ideally via an "internal PBX" shared by all of one's correspondents) along with one's preferred E2E-encrypted messaging applications (e.g., Matrix, Signal, WhatsApp, etc.), all of which are used (importantly!) exclusively over an always-on VPN connection.
In instances where Wi-Fi was unavailable and/or one had no other options, a "mobile hotspot" or another ("real") mobile phone acting as one could potentially be used.
I'm interested in hearing thoughts on this idea (including any reasons why this is a bad idea that didn't occur to me during my two minute thought experiment), any other similar ideas that others have had, or any actual practices that are actually being used.
Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit
#138Earlier quoted context omitted.
We saw the news this year when a Saudi prince directly authorized the murder and dismemberment of an American/Saudi journalist inside it's own embassy. And literally nothing happened. I'm not holding my breath on America ever making the right decisions with respect to foreign policy.
Khashoggi wasn't American. And imo, he was an idiot - never sought asylum, constantly criticized the Saudi regime, and in the end got diced because he decided it would be spiffy to go to the embassy of the very regime he attacked to get a marriage document or something. That was hubris at play, thinking that he was highly placed enough to not be killed.
I also don't think his nationality should matter, but you're right that he was only a US resident.
Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit
#139How come when we hear about this stuff it is always Israeli companies involved? Is ethics not taught in Israeli Computer Science curricula? Those who wrote this exploit are clearly "brilliant" and at least some of them are bound to be reading Hacker News. Is other countries' spyware firms just better at hiding their malware than Israel's is?
Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit
#140America should stop giving aid to Israel as long as Israeli companies are going to assist in getting journalists arrested/murdered/dismembered.
WhatsApp "attempted" to get NSOs export license revoked and failed. How would you expect America to stop two of their allies from dealing with each other (with a potential courtship in the works)? Especially when America itself gets major weapons contracts to look the other way? This will just continue to get worse. More journalists and human rights activists will die because some delusional maniacs feelings were hur…
Most Israelis I talked to (about this specific subject; including the ones, working for NSO Group) do not understand the concept of human rights. First two questions I get are "How gives these rights?" and "Where does the list written?" in this order with the same intonation. My guess it is result of some kind of indoctrination during high school and army service.
P.S. I'm israeli