Live data from Hacker News

Hackers used zerodays to infect Windows, iOS, and Android users

arstechnica.com

61–70 of 156 posts

Re: Hackers used zerodays to infect Windows, iOS, and Android users

#61
post #14

Earlier quoted context omitted.

The author uses quotes as actual quotes instead of as scare quotes. I'm not a fan of "scare" quotes so I'd be very pleased if other journalists did the same even if it takes some getting used to.

I use "(!)" when I mean sarcasm: > Expert (!) hackers used... I hope then it's clear they are not experts really and when I say "experts" it's clear that I'm just quoting.

I would not understand that you were using that to indicate sarcasm—I would think you were emphasizing the fact that they're experts. I also don't think that usage is in any style guide, so you're not going to see journalists doing it.

On the other hand, using quotation marks to indicate sarcasm or irony is normal use and is in style guides.

You just have to rely on context to differentiate. The headline of the linked article is pretty ambiguous and like GP I read them as sarcasm. I think it was a poor choice to include them at all in this case—they don't add anything to the headline.

Re: Hackers used zerodays to infect Windows, iOS, and Android users

#62
post #11

How long until we realize that JIT was a mistake and that we should offer orders of magnitude slower JS in browsers that is actually safe (or start building webpages without JS at all again, which will probably never happen) lest we give every website the ability to take over our device? I'd pay real money for a browser with a slow, safe JS interpreter.

why do you assume an interpreter is any safer than JIT? kinda like saying arrays are better than matrices.

A JIT will write to memory and then turn the executable bit on.

https://en.wikipedia.org/wiki/W%5EX

Re: Hackers used zerodays to infect Windows, iOS, and Android users

#63
post #40

Been playing with tools like angr lately and learning more about binary analysis. It seems to me that "automatic exploit generation" is improving quite a bit where the infrastructure for analysis is a little tricky to set up, but then you can direct that infrastructure to analyze the code for you. The bad guys and good guys are in a race to find new exploits faster (they always have been) but I've been pretty amazed…

>I might just go back to pen and paper at this point. Maybe you kid, but... I've been using a physical calendar on the wall this year. I also replaced my Apple Watch with a Casio F-91W some time ago. You know what's really great? My calendar or watch never gets hacked and it's never unavailable because some overnight software update broke it! Sure, the F-91W technically runs software, but it has no connectivity. That…

I suppose this year is different but what about when you're outside and you want to check your calendar? Do you copy everything to a pocket calendar and risk them going out of sync?

Re: Hackers used zerodays to infect Windows, iOS, and Android users

#64

Earlier quoted context omitted.

I use "(!)" when I mean sarcasm: > Expert (!) hackers used... I hope then it's clear they are not experts really and when I say "experts" it's clear that I'm just quoting.

I would not understand that you were using that to indicate sarcasm—I would think you were emphasizing the fact that they're experts. I also don't think that usage is in any style guide, so you're not going to see journalists doing it. On the other hand, using quotation marks to indicate sarcasm or irony is normal use and is in style guides. You just have to rely on context to differentiate. The headline of the linke…

I don't know why started using it but it's in wiktionary so everyone should (!) understand it: https://en.wiktionary.org/wiki/(!)

I don't know why started using it but it's in wiktionary so "everyone should" understand it: https://en.wiktionary.org/wiki/(!)

I guess, as you also mentioned, without enough context around it, both are hard to understand.

Re: Hackers used zerodays to infect Windows, iOS, and Android users

#65
post #13

>The importance of keeping apps and OSes up to date and avoiding suspicious websites still stands. Unfortunately, neither of those things would have helped the victims hacked by this unknown group. Disabling Javascript would have helped. You can even use tools like uMatrix to set exceptions per site so you're not exposing yourself to every single site on the internet by default. Though you won't see online news sites…

> Disabling Javascript would have helped Thank you for saying that. I'm one of first in 2005/2006 advocating JS rendering in the browser. JS in the browser has really gotten out of hand. I no longer advocate to do everything on the client/browser side. A web site should just work without JS.

Normal websites should absolutely, but actual webapps don't necessarily need to. Modern JS allows for very capable audio, video and 3d web applications inside the browser. The alternative if it wasn't for JS would be to build desktop apps, which would introduce a completely new set of problems and potential security risks.

Re: Hackers used zerodays to infect Windows, iOS, and Android users

#66
post #57
post #45

I said this once and I'll say it again: To counter such threats we need a healthy heterogeneous ecosystem. According to the article, the attack would have been prevented by using Firefox, (because it relied on a Chrome CVE). It also did not work on Linux and presumably not on Apple's ARM CPUs. But unfortunately we don't get exponential security. Normally, one would expect that n variables (Browser, OS, CPU architectu…

Diversity is a sign of health in an ecosystem. But, increasing diversity directly isn't really viable. Question is, why is diversity low? In my opinion, Web, OSes and CPUs suffer from being overly complicated, closed-source ridden, non-modular systems-within-systems. Basicly, the opposite of what the Unix philosophy advocates.

Diversity is low because of the massive amounts of capital Google has. Both in terms of money and power.

Re: Hackers used zerodays to infect Windows, iOS, and Android users

#67

Earlier quoted context omitted.

why do you assume an interpreter is any safer than JIT? kinda like saying arrays are better than matrices.

A JIT will write to memory and then turn the executable bit on. https://en.wikipedia.org/wiki/W%5EX

you are implying this is the underlying cause for code execution exploit, it is not.

Re: Hackers used zerodays to infect Windows, iOS, and Android users

#68

Probably a stupid question to ask, and I realise the bigger picture here is that there are sophisticated groups searching for complicated exploits all the time, but are these specific exploits addressed already in the latest software updates for the affected platforms? Wasn’t clear to me from the article, although I may just have missed it being the idiot that I am.

Usually, security researchers communicate exploits to the companies that build platforms before publishing so they get a chance to plug the holes. Of course it happens that those companies just don't react but with such a high-profile zoo of exploits, their security guys would be scrambling.

Re: Hackers used zerodays to infect Windows, iOS, and Android users

#69
post #40

Earlier quoted context omitted.

>I might just go back to pen and paper at this point. Maybe you kid, but... I've been using a physical calendar on the wall this year. I also replaced my Apple Watch with a Casio F-91W some time ago. You know what's really great? My calendar or watch never gets hacked and it's never unavailable because some overnight software update broke it! Sure, the F-91W technically runs software, but it has no connectivity. That…

I suppose this year is different but what about when you're outside and you want to check your calendar? Do you copy everything to a pocket calendar and risk them going out of sync?

So far that hasn't really come up. How often do you need to check your calendar outside? Maybe I don't need to very much because I work from home.

Here's some possible scenarios though:

* If I need to remember when something is going to happen, such as "I'm leaving my house to meet a friend at 4 PM", I can just commit to memory what time it was suppose to be.

* If there's a lot of stuff happening, then I'd make a note on my phone. If the times of events change while I'm out, it doesn't really matter if my calendar at home is out of sync. I'm just going to cross the day off when I get back.

* If I find out a later date will change ("the user group has been moved to Thursdays"), then I'll leave myself a reminder on my phone. Most of the things on my calendar are actually little post-it notes, so I can move things around. I only write things in ink when they will never change, like national holidays that are already scheduled/set in stone.

So far, I haven't really run into any pain points. The drawbacks of paper calendars just aren't enough to overcome the drawbacks of electronic calendars.

Re: Hackers used zerodays to infect Windows, iOS, and Android users

#70
post #45

I said this once and I'll say it again: To counter such threats we need a healthy heterogeneous ecosystem. According to the article, the attack would have been prevented by using Firefox, (because it relied on a Chrome CVE). It also did not work on Linux and presumably not on Apple's ARM CPUs. But unfortunately we don't get exponential security. Normally, one would expect that n variables (Browser, OS, CPU architectu…

Exactly how biodiversity protects us from diseases.

But this is reversed for a watering hole bug against an organization. They only needed to get into one stack one member of the org uses and stay. Their reason for releasing multiple chains of attack at once instead of whenever their current attack is patched is unclear unless they want to get into multiple organizations where some avoid a diversity of exploitable software.
Post reply on HN