Live data from Hacker News

Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

citizenlab.ca

181–190 of 314 posts

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#181
post #178

Earlier quoted context omitted.

If Facebook was sincere, they could have held their ground. The Israeli government would then have to decide whether it was willing to ban a platform so widely used in their country or to simply fine them. Instead, FB decided to comply. Just a bunch of dead brown people — who cares?

The Israeli government has absolutely no say in how any of this plays out, that is the entire point of an independent judiciary. The lawsuit and sanctions are decided by the courts based on existing laws and precedent, and for them Facebook's size or position in the Israeli market does not (and should not) hold any weight whatsoever. The most the legislative can do is amend the relevant laws to make what Facebook tri…

Facebook could choose to leave the Israeli market so it would not be bound by Israeli law.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#182
post #46

Earlier quoted context omitted.

WhatsApp "attempted" to get NSOs export license revoked and failed. How would you expect America to stop two of their allies from dealing with each other (with a potential courtship in the works)? Especially when America itself gets major weapons contracts to look the other way? This will just continue to get worse. More journalists and human rights activists will die because some delusional maniacs feelings were hur…

>human rights activists will die Most Israelis I talked to (about this specific subject; including the ones, working for NSO Group) do not understand the concept of human rights. First two questions I get are "How gives these rights?" and "Where does the list written?" in this order with the same intonation. My guess it is result of some kind of indoctrination during high school and army service. P.S. I'm israeli

That's absolutely bullshit, many tech literate people here are against the weapon industry, which NSO is part of. Enough of them don't give a shit, which is why NSO can hire people from the intelligence arm of the army for ridiculous salaries.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#183
post #171

Earlier quoted context omitted.

It would be interesting to have a dedicated bug fixer whose only job was hunting bugs. No meetings, no scrum, no design docs, etc.

Kind of like a red team.

Which Apple has, of course.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#184

Earlier quoted context omitted.

I doubt those days are over, we'll continue punishing Iran for supporting Palestine.

Saying “Iran is punished for supporting Palestine” is like saying “ISIS was punished for supporting traditional Islamic values”.

People regularly do say that, and they are generally the same ones using Iran's support of Palestine to justify our actions against Iran. I don't get your point.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#185
"Journalists"? More like Islamist propagandists on the payroll of the Qatari regime and the Iranian intelligence seeking to spread instability and fan discontent among Shia minorities in the Gulf Arab countries. Not that the Gulf monarchies are angels but it's funny seeing people in the Western countries naively cover up for Islamist radicals (like Khashoggi) who like to posture all liberal and democratic until their Muslim brotherhood friends win the elections and institute an Islamist theocracy. Truly, Lenin was right when he said (apocryphally) that "our enemies will sell us the rope which we will hang them with".

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#186

As someone that isn't a developer, I wonder how many zero days come from people inside the software team. To simply have knowledge of a difficult bug that hasn't been resolved would seem to be valuable commodity in a closed source system.

This isn't a thing, mostly because it's a giant legal risk.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#187
post #85
post #78

Is an iPhone safer or a Pixel 4a w/ 5G safer? I seem to hear a lot about iOS 0days and not so much about pixel 0days.

Google has a very good internal security research team and there hasn't been a high impact/zero click RCE on androids that Google themselves maintain for a while. Considering the recent iOS exploits, you're likely to be a little bit safer on a Google phone and common sense at the moment - but I'm 100% sure that a player like NSO will have an exploit for your phone as well. Might have more luck with a dedicated "locke…

Apple's security architecture is leagues ahead of Android's. They have bespoke innovative protections at the hardware and hypervisor level, as well as an actual security CPU (as opposed to TrustZone on Androids, which is always swiss cheese in one way or another). This is largely possible because Apple are building their own silicon (none of the other silicon vendors are anywhere near as competent in this field).

I say this as an Android user. Apple only gets hit with all these exploit chains because they are immensely valuable single target. All the Android phones are worse, it's just that hacking Android doesn't pay nearly as much (and that market is much more fragmented).

Additionally, Google's public bug bounty project for Android is dysfunctional and run by contractors without the slightest clue how to handle the reports.

On the other hand, since Android is a more open ecosystem, you can make simpler architectural guarantees than you can on iOS. For example, on a rooted Android you can set a long boot-time-only passphrase for full disk encryption which guarantees data security at rest, which you can't on iOS or non rooted Android (they force you to use your regular unlock passphrase, which isn't practical to make long, and in Apple's case isn't used for FDE, though Android is moving in that direction too). But none of that will save you from NSO runtime 0days, just from police seizing your phone and getting data out if you turn it off.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#188

How come when we hear about this stuff it is always Israeli companies involved? Is ethics not taught in Israeli Computer Science curricula? Those who wrote this exploit are clearly "brilliant" and at least some of them are bound to be reading Hacker News. Is other countries' spyware firms just better at hiding their malware than Israel's is?

> Is ethics not taught in Israeli Computer Science curricula?

...Is ethis taught in any CS curriculum?

It sure wasn't in mine (but to be fair, that was in Switzerland).

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#189

Apple needs to do a serious architecture of how its own apps work. Its clearly unacceptable that their own apps are not sandboxed to the same level as everything else. If its not possible to implement all of imessage with the public APIs then they need to find a way to expose those private APIs publicly in a safe way. imessage and facetime have been a constant source of exploits.

Apple has never devoted enough care, resources, or money to cybersecurity. It’s just a fact. They’ve also never devoted enough care, resources, or money to network architecture and how important availability is (with fairness, they have improved in this area in the last couple of years due to the major iCloud outages they had). Apple doesn’t hire mainstream IT people and cybersecurity people from the enterprise realm…

Some of my most competent security friends work or used to work for Apple.

They are, indeed, not "IT people and cybersecurity people from the enterprise realms", because those would be wholly unqualified to work on iOS security. The people actually working on iOS security are hackers and embedded security experts. As they should be. The enterprise cybersecurity world has approximately nothing to do with something like security of a mobile device (e.g. the people in that field wouldn't know the slightest thing about cutting edge exploit mitigations or hardware assisted countermeasures like pointer authentication, memory protection and IOMMUs, etc).

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#190

Earlier quoted context omitted.

Apple has never devoted enough care, resources, or money to cybersecurity. It’s just a fact. They’ve also never devoted enough care, resources, or money to network architecture and how important availability is (with fairness, they have improved in this area in the last couple of years due to the major iCloud outages they had). Apple doesn’t hire mainstream IT people and cybersecurity people from the enterprise realm…

but which tech companies do devote enough care, resources and money to cybersecurity? I always figured the industry never really rewarded those things over aspects (e.g. time to market).

"Cybersecurity" is a meaningless buzzword, but I can give you more specific statement.

Which tech companies devote enough care and have competent personnel working on embedded consumer device security?

Answer: Apple and Microsoft (Xbox group).

(Google is nowhere close because they don't design their own silicon, and the OEMs they rely on are incompetent in this field, so their efforts can only go so far, no amount of hiring competent sec folks will fix that problem).

Post reply on HN