From the top of the article: > We want to thank Citizen Lab for sharing a sample of the FORCEDENTRY exploit with us, and Apple’s Security Engineering and Architecture (SEAR) group for collaborating with us on the technical analysis. This reminded me that NSO went after Citizen Lab on multiple fronts. They even tried to use a spy to talk to JSR ( https://www.johnscottrailton.com ) and make him say controversial things…
A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution
181–190 of 360 posts
Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution
#182From the top of the article: > We want to thank Citizen Lab for sharing a sample of the FORCEDENTRY exploit with us, and Apple’s Security Engineering and Architecture (SEAR) group for collaborating with us on the technical analysis. This reminded me that NSO went after Citizen Lab on multiple fronts. They even tried to use a spy to talk to JSR ( https://www.johnscottrailton.com ) and make him say controversial things…
Darknet Diaries is so good. To anyone who hasn't listened, highly recommend. Jack hits a homerun each week and the story about JSR and NSO was buck wild
Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution
#183It's a real shame that the people who came up with this exploit are working for NSO and not on solving P = NP or something. I'm sure if we got them and the ones working on crypto at NSA in a room together, we'd have it and clean unlimited energy in a week. I often feel sad thinking about how many brilliant engineers are dedicating their time to helping governments spy on people or other governments.
I feel the opposite. All this stuff and even more hardcore crypto stuff is all relatively simple math. It's not even close to comparable to the things mathematicians do. Or even what physicist have achieved with LHC or fusion research.
Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution
#184TL;DR - the ending of the post is all you need: “JBIG2 doesn't have scripting capabilities, but when combined with a vulnerability, it does have the ability to emulate circuits of arbitrary logic gates operating on arbitrary memory. So why not just use that to build your own computer architecture and script that!? That's exactly what this exploit does. Using over 70,000 segment commands defining logical bit operation…
They must have spent tons of engineering effort to create this virtual computer to act as their foundation for further exploits. They don't deserve any sympathy of course, but it must really suck that their foundation disappears immediately with the fixed vulnerability.
Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution
#185Earlier quoted context omitted.
Darknet Diaries is so good. To anyone who hasn't listened, highly recommend. Jack hits a homerun each week and the story about JSR and NSO was buck wild
every other week release for the podcast, not weekly*
Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution
#186And still, in 2021, after so many exploits, realizing the futility of trying to fix these bugs and adding their "blast door" process, some Apple dev calls image parsing code where it doesn't belong. The people that are supposed to maintain the element of the OS that has been abused most by nation states do not know the internal APIs they are working with, even just to display looping GIFs. This negligence is killing…
Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution
#187Earlier quoted context omitted.
I feel the opposite. All this stuff and even more hardcore crypto stuff is all relatively simple math. It's not even close to comparable to the things mathematicians do. Or even what physicist have achieved with LHC or fusion research.
Surely cracking cryptographic algorithms is pretty hard math given people don't have that much success with it, even with a huge incentive (decrypting all communications worldwide)?
Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution
#188Earlier quoted context omitted.
There was this one: https://en.wikipedia.org/wiki/Operation_Aurora It seems that the level of access gained could have been used for a larger breach but fortunately the attackers had different motives.
Google banned Windows throughout the organisation in 2010 due to this (with some well fenced exceptions where Windows was unavoidable). 1. Google will do costly things to be secure. 2. At the time I did not hear of any other organisation following Google’s lead. 3. They did not reverse the ban later.
Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution
#189Earlier quoted context omitted.
It's still pretty expensive! NSO charged a flat $500,000 fee for installing Pegasus. It charged government agencies $650,000 to spy on 10 iPhones; $650,000 for 10 Android users; $500,000 for five BlackBerry users; or $300,000 for five Symbian users.
Feels weird that a private company can target individuals for a price. How was this legal? Isn’t it illegal to hack the phone of a private individual? Or do they simply say here’s the tool, here’s the manual, do what you want just don’t tell us?
It's only illegal if you get caught. And then find someone to prosecute you.
Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution
#190From the top of the article: > We want to thank Citizen Lab for sharing a sample of the FORCEDENTRY exploit with us, and Apple’s Security Engineering and Architecture (SEAR) group for collaborating with us on the technical analysis. This reminded me that NSO went after Citizen Lab on multiple fronts. They even tried to use a spy to talk to JSR ( https://www.johnscottrailton.com ) and make him say controversial things…
https://9to5mac.com/2021/12/15/pegasus-spyware-maker-nso-run... hopefully this company is on the way out...