Live data from Hacker News

A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

googleprojectzero.blogspot.com

141–150 of 360 posts

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#141
post #139

Earlier quoted context omitted.

> Historically the jump from overflow to RCE was much much shorter. Not really. I am about to read the article, but it sounds like return-oriented programming[1] chaining "gadgets" that are small bits of existing code that you can re-purpose into executing arbitrary code by manipulating the stack. Extremely common exploitation technique, even if not trivial. Who said an exploit or RCE was trivial to exploit? Edit: I…

Suffice it to say, this exploit was not simply chaining gadgets.

Right, my bad. I now read the article, the technique is intriguing, but I can't say much more for lack of details!

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#142

It's a real shame that the people who came up with this exploit are working for NSO and not on solving P = NP or something. I'm sure if we got them and the ones working on crypto at NSA in a room together, we'd have it and clean unlimited energy in a week. I often feel sad thinking about how many brilliant engineers are dedicating their time to helping governments spy on people or other governments.

I think you could also say the same about gambling, porn and other questionable industries.

The thing is, it's usually much easier making money off these things then making money from solving impactful problems.

If you're a regular joe and you could spend your next 5 years with a 100% chance of making millions for finding exploits, or a 0.01% chance of solving P=NP, I think the irrational decision would be picking the latter.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#143

Earlier quoted context omitted.

Now - that is a big change. Historically the jump from overflow to RCE was much much shorter. Still the iMessage attack surface is just massive and running in an unsafe language kind of crazy?

> Historically the jump from overflow to RCE was much much shorter. Not really. I am about to read the article, but it sounds like return-oriented programming[1] chaining "gadgets" that are small bits of existing code that you can re-purpose into executing arbitrary code by manipulating the stack. Extremely common exploitation technique, even if not trivial. Who said an exploit or RCE was trivial to exploit? Edit: I…

ROP chains are similar in spirit but typically created by hand and thus not all that long (several dozen steps, at most). Creating a 70,000 step program via a Turing tarpit is very interesting.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#144

It's a real shame that the people who came up with this exploit are working for NSO and not on solving P = NP or something. I'm sure if we got them and the ones working on crypto at NSA in a room together, we'd have it and clean unlimited energy in a week. I often feel sad thinking about how many brilliant engineers are dedicating their time to helping governments spy on people or other governments.

I feel the same way about all the smart engineers solving problems for Facebook, Twitter, etc...

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#145

Earlier quoted context omitted.

kinda like Werner von Braun, maybe. he just wanted to make rockets. whether they were for Nazi Germany or the US didn't matter, whether they were missiles or spacecraft didn't matter, he just wanted to build them.

Which we have a descriptive word for: unethical. The colorful word would be: disgusting

"When the rockets go up, who cares where they come down? That's not my department, says Werner von Braun." ~ Tom Lehrer

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#146
post #53

As other have commented, this is absolutely mind-bogglingly hard core. Kudos to the NSO group engineers who designed and built this (regardless of your allegiances and whether you like or dislike that they do this and whether it's objectively good or evil or somewhere in between, you have to admit that it's deeply technically impressive). Does anyone have a sense of who they sold this to and who used this particular…

> regardless of your allegiances and whether you like or dislike that they do this and whether it's objectively good or evil or somewhere in between, you have to admit that it's deeply technically impressiv

Might as well praise German logistics circa 1940-1945.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#147

Earlier quoted context omitted.

>There is, and has always been, a 7 figure market for high quality 0days. Hell, maybe its 8 figures these days. popular social media account handles go for 4 figures. people have wallets on their phones with 6+ figures in crypto OSINT'ing a billionaires' phone number, leveraging a 0-click, and you are looking at 8+ figure trade, personal, and national secrets.

This has already allegedly happened to Bezos (attacked by Saudi Arabia IIRC, which is an NSO customer). This was likely over his ownership of Washington Post and the reporting on the killing of Kashoggi. Yeah, billionaires and Trillion-dollar company CxOs have to step up their electronic security

Bezos willingly gave his personal Watsapp number to a Prince, just to "be in touch", and got hacked as a direct result.

The Saudi's wanted leverage, gotten via Bezo's affair, but the US cannot let (national security) leverage escape our borders - and leaked his affair.

Shit is just lulz to me.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#148

Earlier quoted context omitted.

Feels weird that a private company can target individuals for a price. How was this legal? Isn’t it illegal to hack the phone of a private individual? Or do they simply say here’s the tool, here’s the manual, do what you want just don’t tell us?

Isreal classifies it as a weapon. In contrast to companies that make guns and bombs, spyware seems mild by comparison.

Depends whether the spyware ends up with you being cut to pieces with a hacksaw while a Saudi prince watches over a teleconference link, I guess.

I'd rather be blown up.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#149
> Recently, however, it has been documented that NSO is offering their clients zero-click exploitation technology, where even very technically savvy targets who might not click a phishing link are completely unaware they are being targeted. In the zero-click scenario no user interaction is required. Meaning, the attacker doesn't need to send phishing messages; the exploit just works silently in the background. Short of not using a device, there is no way to prevent exploitation by a zero-click exploit; it's a weapon against which there is no defense.

Having iMessage disabled and no SIM card in the phone (use an external wifi vpn router with a sim) is a mitigation, and is one that I use.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#150
post #66

Earlier quoted context omitted.

It's still pretty expensive! NSO charged a flat $500,000 fee for installing Pegasus. It charged government agencies $650,000 to spy on 10 iPhones; $650,000 for 10 Android users; $500,000 for five BlackBerry users; or $300,000 for five Symbian users.

Feels weird that a private company can target individuals for a price. How was this legal? Isn’t it illegal to hack the phone of a private individual? Or do they simply say here’s the tool, here’s the manual, do what you want just don’t tell us?

NSO have been trying to argue that they're shielded from responsibility for their actions by being a de facto extension of the state that they've sold to and therefore enjoy sovereign immunity.

The collapse of that argument in the Facebook case is why Apple are now suing as well.

Post reply on HN