Live data from Hacker News

A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

googleprojectzero.blogspot.com

11–20 of 360 posts

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#11
post #3

This is mind boggling. NSO used a compression format's instructions to create logic gates and then from there "a small computer architecture with features such as registers and a full 64-bit adder and comparator which they use to search memory and perform arithmetic operations", all within a single pass of decompression. Combine this with a buffer overflow and you've got your sploit.

That reads like some handwavy explanation of a hack in a movie scene...

"Now I just have to embed a 64-bit computer architecture into my compression algorithm and... boom. We're in."

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#12
post #10

Earlier quoted context omitted.

Project Zero is a team of security analysts employed by Google tasked with finding zero-day vulnerabilities. https://en.wikipedia.org/wiki/Project_Zero?wprov=sfti1 Don’t think of these folks as “google” employees. Think of them as “really good hackers with corporate sponsorship”. They look for flaws in everything - windows, apple, Linux, and google software. You should read some earlier blog posts, they’re really hig…

how does Google benefit from this?

Google makes money when people use the Internet. By making it safer to use the Internet, more people will use it and Google will make more money.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#13
post #10

Earlier quoted context omitted.

Project Zero is a team of security analysts employed by Google tasked with finding zero-day vulnerabilities. https://en.wikipedia.org/wiki/Project_Zero?wprov=sfti1 Don’t think of these folks as “google” employees. Think of them as “really good hackers with corporate sponsorship”. They look for flaws in everything - windows, apple, Linux, and google software. You should read some earlier blog posts, they’re really hig…

how does Google benefit from this?

We’re talking about them right now

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#14
post #10

Earlier quoted context omitted.

Project Zero is a team of security analysts employed by Google tasked with finding zero-day vulnerabilities. https://en.wikipedia.org/wiki/Project_Zero?wprov=sfti1 Don’t think of these folks as “google” employees. Think of them as “really good hackers with corporate sponsorship”. They look for flaws in everything - windows, apple, Linux, and google software. You should read some earlier blog posts, they’re really hig…

how does Google benefit from this?

They are very often on the receiving end of state level shenanigans. Finding bugs in software they use, helps them stay secure. Not to mention the goodwill earned.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#16
post #10

Earlier quoted context omitted.

Project Zero is a team of security analysts employed by Google tasked with finding zero-day vulnerabilities. https://en.wikipedia.org/wiki/Project_Zero?wprov=sfti1 Don’t think of these folks as “google” employees. Think of them as “really good hackers with corporate sponsorship”. They look for flaws in everything - windows, apple, Linux, and google software. You should read some earlier blog posts, they’re really hig…

how does Google benefit from this?

Among others, what jumps to me: more stability on the network and terminals (better for their business), goodwill, attracting talent.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#17
post #3

This is mind boggling. NSO used a compression format's instructions to create logic gates and then from there "a small computer architecture with features such as registers and a full 64-bit adder and comparator which they use to search memory and perform arithmetic operations", all within a single pass of decompression. Combine this with a buffer overflow and you've got your sploit.

Its amazing how they took a buffer overflow and ran with it to create a whole turing complete machine. Its mind boggling how complex these exploits can be, no wonder they sell for millions

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#18

Am I reading this right? Google engineers are fixing apple software?

> Google engineers are fixing apple software?

In this case, this was already fixed by Apple's engineers. And like the article says, Citizen Lab (people who captured the exploit in the wild) and Apple have shared the exploit with Project Zero who analyzed it as well and wrote up that blog post.

Project Zero people have found numerous bugs in Apple's software in the past. They look at all kinds of software that's written by all vendors.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#19
post #10

Earlier quoted context omitted.

Project Zero is a team of security analysts employed by Google tasked with finding zero-day vulnerabilities. https://en.wikipedia.org/wiki/Project_Zero?wprov=sfti1 Don’t think of these folks as “google” employees. Think of them as “really good hackers with corporate sponsorship”. They look for flaws in everything - windows, apple, Linux, and google software. You should read some earlier blog posts, they’re really hig…

how does Google benefit from this?

A large percentage of the planet has personal sensitive data stored by Google. If that data leaks, even due to a bug in another company's product through which Google has no fault, Google suffers. Google greatly benefits by having a secure Internet.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#20
It's a real shame that the people who came up with this exploit are working for NSO and not on solving P = NP or something. I'm sure if we got them and the ones working on crypto at NSA in a room together, we'd have it and clean unlimited energy in a week.

I often feel sad thinking about how many brilliant engineers are dedicating their time to helping governments spy on people or other governments.

Post reply on HN