Live data from Hacker News

A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

googleprojectzero.blogspot.com

61–70 of 360 posts

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#61

And NSO is the value option. Now imagine what nation states with an actual budget have at their disposal.

The problem with nation states is that they don't pay people. I don't think nation state can ever come up with something like this - it takes passion, genius and those qualities demand higher premiums than governments are ever willing to hand out.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#62

And NSO is the value option. Now imagine what nation states with an actual budget have at their disposal.

It came out in the recent trial that the FBI couldn't open Kyle Rittenhouse's iPhone, which was the latest generation at that time last year.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#63

It's a real shame that the people who came up with this exploit are working for NSO and not on solving P = NP or something. I'm sure if we got them and the ones working on crypto at NSA in a room together, we'd have it and clean unlimited energy in a week. I often feel sad thinking about how many brilliant engineers are dedicating their time to helping governments spy on people or other governments.

People of this caliber are avaliable here:

https://ctftime.org/

Here you have a list of decade of performance of experts/top competitors in:

security, reverse engineering, crypto, low lvl, malware analysis, OS internals, memory corruption

some of them even work at Google Project Zero :)

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#64
post #25

Earlier quoted context omitted.

Kind of ironic to use P = NP as an example of something to work on considering the biggest implications of proving P = NP :)

Forgive my ignorance, but what would they be - the complete implosion of all forms of known security, or something else? This is a bit beyond my ken :)

Among other things, mostly encryption. Most of our current methods depends on P != NP. So no need for 0 days if you can just read at encrypted data as if it wasn't.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#65
post #25

Earlier quoted context omitted.

Kind of ironic to use P = NP as an example of something to work on considering the biggest implications of proving P = NP :)

Forgive my ignorance, but what would they be - the complete implosion of all forms of known security, or something else? This is a bit beyond my ken :)

Well for one, the safety of encryption rests on certain problems being intractable. (In a theoretical sense; there are always implementation bugs that destroy security).

If P=NP, then those previously thought to be intractable problems, are actually tractable. And the foundation of a lot of security-related engineering collapses.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#66

And NSO is the value option. Now imagine what nation states with an actual budget have at their disposal.

It's still pretty expensive! NSO charged a flat $500,000 fee for installing Pegasus. It charged government agencies $650,000 to spy on 10 iPhones; $650,000 for 10 Android users; $500,000 for five BlackBerry users; or $300,000 for five Symbian users.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#67

> further demonstrating that the capabilities NSO provides rival those previously thought to be accessible to only a handful of nation states I mean the whole “nation state” or “nation state backed” hackers thing was always a liiiiitle (very) ambiguous right? Does the evidence really even move the goal post or mitigate the convenient scapegoating? Politicians and CEOs and certified IT professionals are all incentiviz…

I think it is worthwhile to distinguish the two, and I think generally speaking it's the use of bespoke 0days that separates nation state attackers from all others.

One can't really arrange the funding of computer scientists/mathematicians working full-time on the thankless job of finding vulnerabilities without nation-state kind of money, as opposed to employing known vulnerabilities which carry lesser chance of success and greater chance of blowback in their execution.

Aftercall NSO is itself an IDF unit 8200 outfit.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#68
Amazing apple let this slip past. Seems pretty obvious why this is bad design, easy to exploit, etc. so maybe it was intentional and already being used by us when the NSO group caught wind through “back channels” and hopped on the gravy train.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#69
> Based on our research and findings, we assess this to be one of the most technically sophisticated exploits we've ever seen, further demonstrating that the capabilities NSO provides rival those previously thought to be accessible to only a handful of nation states.

> Using over 70,000 segment commands defining logical bit operations, they define a small computer architecture with features such as registers and a full 64-bit adder and comparator which they use to search memory and perform arithmetic operations. It's not as fast as Javascript, but it's fundamentally computationally equivalent.

They create an emulated computer by decompressing an old image format inside a PDF file which has a .gif extension! That is top notch!

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#70
post #25

Earlier quoted context omitted.

Kind of ironic to use P = NP as an example of something to work on considering the biggest implications of proving P = NP :)

Forgive my ignorance, but what would they be - the complete implosion of all forms of known security, or something else? This is a bit beyond my ken :)

Yes. Just like in that movie Sneakers
Post reply on HN