Live data from Hacker News

Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

citizenlab.ca

271–280 of 314 posts

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#271

How come when we hear about this stuff it is always Israeli companies involved? Is ethics not taught in Israeli Computer Science curricula? Those who wrote this exploit are clearly "brilliant" and at least some of them are bound to be reading Hacker News. Is other countries' spyware firms just better at hiding their malware than Israel's is?

Israel has mandatory military service and part of it's military is an elite hacking group known as Unit 8200[0]. Members of this unit who leave the military have founded a huge number of information security and antivirus companies based in Israel (mostly in Tel Aviv)[1].

----

[0] https://en.wikipedia.org/wiki/Unit_8200

[1] https://en.wikipedia.org/wiki/Unit_8200#Companies_founded_by...

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#272

How come when we hear about this stuff it is always Israeli companies involved? Is ethics not taught in Israeli Computer Science curricula? Those who wrote this exploit are clearly "brilliant" and at least some of them are bound to be reading Hacker News. Is other countries' spyware firms just better at hiding their malware than Israel's is?

> Is ethics not taught in Israeli Computer Science curricula? ...Is ethis taught in any CS curriculum? It sure wasn't in mine (but to be fair, that was in Switzerland).

THERAC-25 was the topic of a lengthy ethics discussion during my computer engineering undergrad

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#273

"The phones were compromised using an exploit chain that we call KISMET, which appears to involve an invisible zero-click exploit in iMessage" Why aren't there a hardware switch on the phones that renders the OS read-only during normal use?

How would this work, and how would it help?

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#274

How come when we hear about this stuff it is always Israeli companies involved? Is ethics not taught in Israeli Computer Science curricula? Those who wrote this exploit are clearly "brilliant" and at least some of them are bound to be reading Hacker News. Is other countries' spyware firms just better at hiding their malware than Israel's is?

> Is ethics not taught in Israeli Computer Science curricula? ...Is ethis taught in any CS curriculum? It sure wasn't in mine (but to be fair, that was in Switzerland).

It's no longer commonly taught, I think it was 10 years ago. It may have something to do with degree accreditation bodies but I'm not sure.

Knowing Ethics doesn't really mean much, given ethicists aren't more ethical than normal people [0].

As an aside, another consideration is this isn't some private corporation, it's every government, you've got to consider the number of people before someone like Snowden popped their faces out.

[0] https://qz.com/1582149/ethicists-are-no-more-ethical-than-th...

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#275
post #43

Earlier quoted context omitted.

Can you explain a bit? Are you saying they send messages as Swift objects/structures directly? Instead of a serialization like JSON/CBOR/Proto/Proprietary/etc?

I don’t expect anything as old and critical as iMessage is written on Swift. Chances are it’s all Objective C underneath.

I hear that parts of the app have been rewritten in Swift: https://twitter.com/5aelo/status/1340995243320205313

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#276
post #228

> We were unable to retrieve these binaries from flash memory, as we did not have access to a jailbreak for iPhone 11 running iOS 13.5.1. It’s ironic that the exploit is able to plant arbitrary code on an up-to-date device and yet the owner of the phone can’t introspect their phone to see it themselves because they don’t know how to bypass the protections :/

They should’ve sent the phones to Apple to investigate.

Perhaps they did?

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#277
post #228

> We were unable to retrieve these binaries from flash memory, as we did not have access to a jailbreak for iPhone 11 running iOS 13.5.1. It’s ironic that the exploit is able to plant arbitrary code on an up-to-date device and yet the owner of the phone can’t introspect their phone to see it themselves because they don’t know how to bypass the protections :/

They should’ve sent the phones to Apple to investigate.

Why would Apple investigate? This costs thousands of dollars and Apple isn’t a forensics service provider.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#278
post #85

Earlier quoted context omitted.

Google has a very good internal security research team and there hasn't been a high impact/zero click RCE on androids that Google themselves maintain for a while. Considering the recent iOS exploits, you're likely to be a little bit safer on a Google phone and common sense at the moment - but I'm 100% sure that a player like NSO will have an exploit for your phone as well. Might have more luck with a dedicated "locke…

Apple's security architecture is leagues ahead of Android's. They have bespoke innovative protections at the hardware and hypervisor level, as well as an actual security CPU (as opposed to TrustZone on Androids, which is always swiss cheese in one way or another). This is largely possible because Apple are building their own silicon (none of the other silicon vendors are anywhere near as competent in this field). I s…

In the UK, through Section 49 of RIPA, if you refused to provide your password to police you will get arrested for 2 years just on that. If they claim it could be national security related, you get 5 years.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#279
post #175

Earlier quoted context omitted.

And yet the Iran deal is gone and not coming back, and recently the US has pushed Arab states to normalize relations with Israel.

Both due to Trump, not AIPAC. Biden is likely to restore the Iran deal, at least in form. US pushing mideast peace is longstanding American policy.

You don't think Trump was influenced by powerful zionists including AIPAC and his son-in-law? Why else would he care?

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#280

Earlier quoted context omitted.

People regularly do say that, and they are generally the same ones using Iran's support of Palestine to justify our actions against Iran. I don't get your point.

The problem with ISIS is their beheadings, slaughter of innocents, destabilization of countries, piracy, and persecuting minorities. Not their support of Islam. The problem with Iran is their development of nuclear weapons, their ballistic missile program which now extends in range to cover the Europe, their support in weapons, money and training of various paramilitary groups such as the Houthis, Hezbollah, Hamas an…

Now ask yourself, how much of that list is the US or Israel also guilty of an equivalent crime? Supporting Palestine is one of the few things that seperates them.
Post reply on HN