Live data from Hacker News

Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

citizenlab.ca

281–290 of 314 posts

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#281

Earlier quoted context omitted.

> Hating on Israel specifically is a very cool and woke thing to do. Has been for decades. Well Israeli has been treating palestinians pretty badly so it's not like it isn't justified. At least critising Israel for genuine reasons isn't deemed anti-semitic in the latest international standard of the definition, oh wait!

Depending on when your justifiability timeline begins, Palestine is occupying the area illegally.

Sane people hold others culpable for what they do and not the sins of their fathers.

By that sane metric, Israel is by far the more complicit of the two entities, and everyone knows it. Even the biggest, baddest ally of Israel (America) has a population where the vast majority are opposed to supporting them any more because of what they've been doing right now.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#282

Earlier quoted context omitted.

> How come when we hear about this stuff it is always Israeli companies involved? Is ethics not taught in Israeli Computer Science curricula? Personal opinion, but I think the mandatory army service in Israel seems to teach that everything is 'defense' and Israel is always 'defending itself', no matter what, this sort of thinking then bleeds into the private sector as these guys leave the military and use the skills…

There is the idea that being the stronger side in a constant state of conflict with a neighbour for decades suits Israel economically, despite the human cost on both sides. Combined with national service, it creates a highly credible testing ground for public and private development of defence products, technologies and services, which are extremely valuable exports. A country of its size and only relative recent ind…

>There is the idea that being the stronger side in a constant state of conflict with a neighbour for decades suits Israel economically, despite the human cost on both sides.

In a way this also applies to America, with their 20-year-long wars in Afghanistan and Iraq.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#283

Earlier quoted context omitted.

> Hating on Israel specifically is a very cool and woke thing to do. Has been for decades. Well Israeli has been treating palestinians pretty badly so it's not like it isn't justified. At least critising Israel for genuine reasons isn't deemed anti-semitic in the latest international standard of the definition, oh wait!

Depending on when your justifiability timeline begins, Palestine is occupying the area illegally.

I don't care when or how Palestinians came to the area. Their treatment is immoral.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#284
post #46

Earlier quoted context omitted.

WhatsApp "attempted" to get NSOs export license revoked and failed. How would you expect America to stop two of their allies from dealing with each other (with a potential courtship in the works)? Especially when America itself gets major weapons contracts to look the other way? This will just continue to get worse. More journalists and human rights activists will die because some delusional maniacs feelings were hur…

>human rights activists will die Most Israelis I talked to (about this specific subject; including the ones, working for NSO Group) do not understand the concept of human rights. First two questions I get are "How gives these rights?" and "Where does the list written?" in this order with the same intonation. My guess it is result of some kind of indoctrination during high school and army service. P.S. I'm israeli

Utter crap. The overwhelming majority of NSO's hiring pool -- i.e. army tech "graduates" -- are firmly against them. Another chunk doesn't care and is swayed by their 2-4x salaries, luxurious company vacations, gifts, all things to "make it up for" what you do.

They're known to be "the bad guys". The tech courses we took in the army had plenty of emphasis on ethics, both the moral kind and conflict-of-interest kind.

Source: I'm an Israeli.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#285
post #233

Earlier quoted context omitted.

Its only for forensics because schools cannot afford the version that breaks into the phone for you, its expensive and not something that a school can get access to.

No. It’s because they’re totally different products, and cellebrite, a forensics company, doesn’t make a version that you are describing. They make forensics products, not monitoring tools. They have nothing to do with NSO.

This certainly sounds like something that breaks into a phone to me.

https://www.cellebrite.com/en/ufed/

They don’t have to have anything to do with NSO to have phone exploits that they use to gain access to the device without the owners permission.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#286
post #253

Earlier quoted context omitted.

>“Just reboot your phone, and you're good to go” Doesn’t really work like that. First of all, when would you reboot your phone? Once per day? Once per hour? Every five minutes? Regardless, these attacks are incredibly advanced, remember they require zero interaction from the user. Even if you rebooted constantly and the exploit lacked a persistence vector, they would still be able to exploit you whenever they want. T…

What about also removing your SIM card and disabling iMessage or otherwise firewalling all traffic to Apple?

Normally bugs in these types of attacks target daemons that are always connected even if not logged onto iMessage or even if you disable iMessage. Or at least this was the case with previously known bugs.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#287
post #253

Earlier quoted context omitted.

These attacks would be a lot less dangerous if they couldn't get on-disk persistence. Just reboot your phone, and you're good to go. Only creeps like NSO who spy on normal people need that degree of persistence. Everyone else can just hang out in ram on some always-on server. Vendors need to make it easier to verify the integrity of persistent firmware, in an offline fashion. It will dramatically increase the cost of…

>“Just reboot your phone, and you're good to go” Doesn’t really work like that. First of all, when would you reboot your phone? Once per day? Once per hour? Every five minutes? Regardless, these attacks are incredibly advanced, remember they require zero interaction from the user. Even if you rebooted constantly and the exploit lacked a persistence vector, they would still be able to exploit you whenever they want. T…

[deleted]

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#288

Earlier quoted context omitted.

These attacks would be a lot less dangerous if they couldn't get on-disk persistence. Just reboot your phone, and you're good to go. Only creeps like NSO who spy on normal people need that degree of persistence. Everyone else can just hang out in ram on some always-on server. Vendors need to make it easier to verify the integrity of persistent firmware, in an offline fashion. It will dramatically increase the cost of…

On-disk persistence (“untethered”) is actually fairly rare. Why do that when it leaves behind evidence and you can just remotely run the exploit again to hack the device?

[deleted]

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#289

Earlier quoted context omitted.

Android dominates the mobile OS market share though. Seems like targeting it would yield a higher ROI. Much like how malware writers target Windows, because it dominates the desktop OS market share.

Android is fragmented (though that is changing slowly), which means it's much harder to port and validate a single exploit chain to work on many Android phones.

OP asked specifically asked for Google Pixel 4a. If the market being fragmented is working in your favor, why not use it?

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#290
post #85

Earlier quoted context omitted.

Google has a very good internal security research team and there hasn't been a high impact/zero click RCE on androids that Google themselves maintain for a while. Considering the recent iOS exploits, you're likely to be a little bit safer on a Google phone and common sense at the moment - but I'm 100% sure that a player like NSO will have an exploit for your phone as well. Might have more luck with a dedicated "locke…

Apple's security architecture is leagues ahead of Android's. They have bespoke innovative protections at the hardware and hypervisor level, as well as an actual security CPU (as opposed to TrustZone on Androids, which is always swiss cheese in one way or another). This is largely possible because Apple are building their own silicon (none of the other silicon vendors are anywhere near as competent in this field). I s…

> Apple are building their own silicon (none of the other silicon vendors are anywhere near as competent in this field

Why is this useful when their software stack is having enough 0days on its own?

Disc: Googler but nowhere close to Android/Pixel.

Post reply on HN