And NSO is the value option. Now imagine what nation states with an actual budget have at their disposal.
A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution
61–70 of 360 posts
Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution
#62And NSO is the value option. Now imagine what nation states with an actual budget have at their disposal.
Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution
#63It's a real shame that the people who came up with this exploit are working for NSO and not on solving P = NP or something. I'm sure if we got them and the ones working on crypto at NSA in a room together, we'd have it and clean unlimited energy in a week. I often feel sad thinking about how many brilliant engineers are dedicating their time to helping governments spy on people or other governments.
Here you have a list of decade of performance of experts/top competitors in:
security, reverse engineering, crypto, low lvl, malware analysis, OS internals, memory corruption
some of them even work at Google Project Zero :)
Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution
#64Earlier quoted context omitted.
Kind of ironic to use P = NP as an example of something to work on considering the biggest implications of proving P = NP :)
Forgive my ignorance, but what would they be - the complete implosion of all forms of known security, or something else? This is a bit beyond my ken :)
Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution
#65Earlier quoted context omitted.
Kind of ironic to use P = NP as an example of something to work on considering the biggest implications of proving P = NP :)
Forgive my ignorance, but what would they be - the complete implosion of all forms of known security, or something else? This is a bit beyond my ken :)
If P=NP, then those previously thought to be intractable problems, are actually tractable. And the foundation of a lot of security-related engineering collapses.
Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution
#66And NSO is the value option. Now imagine what nation states with an actual budget have at their disposal.
Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution
#67> further demonstrating that the capabilities NSO provides rival those previously thought to be accessible to only a handful of nation states I mean the whole “nation state” or “nation state backed” hackers thing was always a liiiiitle (very) ambiguous right? Does the evidence really even move the goal post or mitigate the convenient scapegoating? Politicians and CEOs and certified IT professionals are all incentiviz…
One can't really arrange the funding of computer scientists/mathematicians working full-time on the thankless job of finding vulnerabilities without nation-state kind of money, as opposed to employing known vulnerabilities which carry lesser chance of success and greater chance of blowback in their execution.
Aftercall NSO is itself an IDF unit 8200 outfit.
Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution
#68Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution
#69> Using over 70,000 segment commands defining logical bit operations, they define a small computer architecture with features such as registers and a full 64-bit adder and comparator which they use to search memory and perform arithmetic operations. It's not as fast as Javascript, but it's fundamentally computationally equivalent.
They create an emulated computer by decompressing an old image format inside a PDF file which has a .gif extension! That is top notch!
Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution
#70Earlier quoted context omitted.
Kind of ironic to use P = NP as an example of something to work on considering the biggest implications of proving P = NP :)
Forgive my ignorance, but what would they be - the complete implosion of all forms of known security, or something else? This is a bit beyond my ken :)