Live data from Hacker News

A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

googleprojectzero.blogspot.com

211–220 of 360 posts

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#211

Earlier quoted context omitted.

This has already allegedly happened to Bezos (attacked by Saudi Arabia IIRC, which is an NSO customer). This was likely over his ownership of Washington Post and the reporting on the killing of Kashoggi. Yeah, billionaires and Trillion-dollar company CxOs have to step up their electronic security

Bezos willingly gave his personal Watsapp number to a Prince, just to "be in touch", and got hacked as a direct result. The Saudi's wanted leverage, gotten via Bezo's affair, but the US cannot let (national security) leverage escape our borders - and leaked his affair. Shit is just lulz to me.

Those conversations are important for a CEO like Bezos though. Let's not pretend MBS is not mega powerful. I would say those type of relationships for multi nationals is probably a bigger value/part of the ceo work than like micro managing teams.

But it's super stupid he had just one phone combining personal, business, more private business. At least from the reporting that's what it sounds like happened.

Even the dumb ass Jan 6th coordinators and Meadows used burner phones. IIRC standard practice for political 'execs'/important leg committee staff.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#212
post #3

This is mind boggling. NSO used a compression format's instructions to create logic gates and then from there "a small computer architecture with features such as registers and a full 64-bit adder and comparator which they use to search memory and perform arithmetic operations", all within a single pass of decompression. Combine this with a buffer overflow and you've got your sploit.

[deleted]

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#215

Earlier quoted context omitted.

kinda like Werner von Braun, maybe. he just wanted to make rockets. whether they were for Nazi Germany or the US didn't matter, whether they were missiles or spacecraft didn't matter, he just wanted to build them.

Which we have a descriptive word for: unethical. The colorful word would be: disgusting

There’s nothing unethical about a scientist working on weapon development for their country in the middle of a war. Imagine it’s 1935 and you lack the modern perspective. I mean you might not like it, but I don’t think there’s an ethical violation here.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#216
post #53

As other have commented, this is absolutely mind-bogglingly hard core. Kudos to the NSO group engineers who designed and built this (regardless of your allegiances and whether you like or dislike that they do this and whether it's objectively good or evil or somewhere in between, you have to admit that it's deeply technically impressive). Does anyone have a sense of who they sold this to and who used this particular…

I'm assuming NSO just buys these exploits and then packages them.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#217
post #36

TL;DR - the ending of the post is all you need: “JBIG2 doesn't have scripting capabilities, but when combined with a vulnerability, it does have the ability to emulate circuits of arbitrary logic gates operating on arbitrary memory. So why not just use that to build your own computer architecture and script that!? That's exactly what this exploit does. Using over 70,000 segment commands defining logical bit operation…

You should read the entire post.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#218
post #86
post #3

This is mind boggling. NSO used a compression format's instructions to create logic gates and then from there "a small computer architecture with features such as registers and a full 64-bit adder and comparator which they use to search memory and perform arithmetic operations", all within a single pass of decompression. Combine this with a buffer overflow and you've got your sploit.

It seems we're now at the point where anything Turing complete can be a vector. Wow...

Well, when combined with an integer overflow at least.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#219

There has been something called a Pegasus framework on my iphones since the 5s and now in my xr. I have seen other people question the same thing on apple dev site but just as i never got a response from apple about what it actually is, neither have they. There is also a Pegasus Arm64 too.

Perhaps you should’ve read my reply from when you asked this several months ago: https://news.ycombinator.com/item?id=28521664

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#220
post #62

And NSO is the value option. Now imagine what nation states with an actual budget have at their disposal.

It came out in the recent trial that the FBI couldn't open Kyle Rittenhouse's iPhone, which was the latest generation at that time last year.

Wait, but Kyle Rittenhouse was still alive and participated in the trial. They couldn't just make him open it himself?
Post reply on HN