Earlier quoted context omitted.
> Historically the jump from overflow to RCE was much much shorter. Not really. I am about to read the article, but it sounds like return-oriented programming[1] chaining "gadgets" that are small bits of existing code that you can re-purpose into executing arbitrary code by manipulating the stack. Extremely common exploitation technique, even if not trivial. Who said an exploit or RCE was trivial to exploit? Edit: I…
Suffice it to say, this exploit was not simply chaining gadgets.
A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution
141–150 of 360 posts
Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution
#142It's a real shame that the people who came up with this exploit are working for NSO and not on solving P = NP or something. I'm sure if we got them and the ones working on crypto at NSA in a room together, we'd have it and clean unlimited energy in a week. I often feel sad thinking about how many brilliant engineers are dedicating their time to helping governments spy on people or other governments.
The thing is, it's usually much easier making money off these things then making money from solving impactful problems.
If you're a regular joe and you could spend your next 5 years with a 100% chance of making millions for finding exploits, or a 0.01% chance of solving P=NP, I think the irrational decision would be picking the latter.
Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution
#143Earlier quoted context omitted.
Now - that is a big change. Historically the jump from overflow to RCE was much much shorter. Still the iMessage attack surface is just massive and running in an unsafe language kind of crazy?
> Historically the jump from overflow to RCE was much much shorter. Not really. I am about to read the article, but it sounds like return-oriented programming[1] chaining "gadgets" that are small bits of existing code that you can re-purpose into executing arbitrary code by manipulating the stack. Extremely common exploitation technique, even if not trivial. Who said an exploit or RCE was trivial to exploit? Edit: I…
Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution
#144It's a real shame that the people who came up with this exploit are working for NSO and not on solving P = NP or something. I'm sure if we got them and the ones working on crypto at NSA in a room together, we'd have it and clean unlimited energy in a week. I often feel sad thinking about how many brilliant engineers are dedicating their time to helping governments spy on people or other governments.
Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution
#145Earlier quoted context omitted.
kinda like Werner von Braun, maybe. he just wanted to make rockets. whether they were for Nazi Germany or the US didn't matter, whether they were missiles or spacecraft didn't matter, he just wanted to build them.
Which we have a descriptive word for: unethical. The colorful word would be: disgusting
Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution
#146As other have commented, this is absolutely mind-bogglingly hard core. Kudos to the NSO group engineers who designed and built this (regardless of your allegiances and whether you like or dislike that they do this and whether it's objectively good or evil or somewhere in between, you have to admit that it's deeply technically impressive). Does anyone have a sense of who they sold this to and who used this particular…
Might as well praise German logistics circa 1940-1945.
Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution
#147Earlier quoted context omitted.
>There is, and has always been, a 7 figure market for high quality 0days. Hell, maybe its 8 figures these days. popular social media account handles go for 4 figures. people have wallets on their phones with 6+ figures in crypto OSINT'ing a billionaires' phone number, leveraging a 0-click, and you are looking at 8+ figure trade, personal, and national secrets.
This has already allegedly happened to Bezos (attacked by Saudi Arabia IIRC, which is an NSO customer). This was likely over his ownership of Washington Post and the reporting on the killing of Kashoggi. Yeah, billionaires and Trillion-dollar company CxOs have to step up their electronic security
The Saudi's wanted leverage, gotten via Bezo's affair, but the US cannot let (national security) leverage escape our borders - and leaked his affair.
Shit is just lulz to me.
Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution
#148Earlier quoted context omitted.
Feels weird that a private company can target individuals for a price. How was this legal? Isn’t it illegal to hack the phone of a private individual? Or do they simply say here’s the tool, here’s the manual, do what you want just don’t tell us?
Isreal classifies it as a weapon. In contrast to companies that make guns and bombs, spyware seems mild by comparison.
I'd rather be blown up.
Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution
#149Having iMessage disabled and no SIM card in the phone (use an external wifi vpn router with a sim) is a mitigation, and is one that I use.
Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution
#150Earlier quoted context omitted.
It's still pretty expensive! NSO charged a flat $500,000 fee for installing Pegasus. It charged government agencies $650,000 to spy on 10 iPhones; $650,000 for 10 Android users; $500,000 for five BlackBerry users; or $300,000 for five Symbian users.
Feels weird that a private company can target individuals for a price. How was this legal? Isn’t it illegal to hack the phone of a private individual? Or do they simply say here’s the tool, here’s the manual, do what you want just don’t tell us?
The collapse of that argument in the Facebook case is why Apple are now suing as well.