Live data from Hacker News

A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

googleprojectzero.blogspot.com

251–260 of 360 posts

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#251

There has been something called a Pegasus framework on my iphones since the 5s and now in my xr. I have seen other people question the same thing on apple dev site but just as i never got a response from apple about what it actually is, neither have they. There is also a Pegasus Arm64 too.

Perhaps you should’ve read my reply from when you asked this several months ago: https://news.ycombinator.com/item?id=28521664

Seems most users don't know about https://hnreplies.com/

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#252

Earlier quoted context omitted.

Stop weird machines! http://langsec.org/occupy/

In this particular case: If you are Wrangling Untrusted File Formats, you should be doing so Safely, using WUFFS. You can't make this mistake in WUFFS. Your WUFFS image decoder might decode the image incorrectly, maybe Rudolph has a green or blue nose, maybe he's upside down or just a sea of noise, but it can't have a buffer overflow even if you screwed up really badly. For example, any equivalent of the repeated add…

https://github.com/google/wuffs

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#253
If this is the level of sophistication just going after an iPhone by a private company, it’s laughable to think our critical infrastructure isn’t able to be completely turned off on demand.

An invisible nuke that destroys access to clean water overnight across the nation, that’s the future!

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#254
post #74

Earlier quoted context omitted.

It also demonstrates how much more work there is after “buffer overflow” until you get to RCE.

Now - that is a big change. Historically the jump from overflow to RCE was much much shorter. Still the iMessage attack surface is just massive and running in an unsafe language kind of crazy?

> running in an unsafe language kind of crazy?

It sounds like their first step in remediation was to move the GIF copy operation into the BlastDoor sandbox, which is written in Swift.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#255
post #116

Earlier quoted context omitted.

https://9to5mac.com/2021/12/15/pegasus-spyware-maker-nso-run... hopefully this company is on the way out...

I'd assume they're using the Erik Prince/Constellis business model, taking some time off and getting the band back together under a different name to do the same work.

I think when you are providing such a valuable service, there is almost zero chance they just stop.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#256

Earlier quoted context omitted.

Dear sir, the entire NSA staff are currently plugging away on that pesky P=NP problem, including datacenter janitors.

I have suspected for awhile now that the bitcoin blockchain is actually an attempt to break SHA-256. Bitcoin is built around incentives, and it has created an incentive for people all over the world to basically brute force this algorithm and maintain a recursive set of low entropy outputs. Which would make the btc blockchain an incredibly expensive and valuable data set, for someone armed with the right mathematical…

Part of Security is knowing your adversaries power. I think you might be on the right track. You can’t put a price on the security of an algorithm. However, Satoshi gave us a very good metric for calculating it.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#257

Earlier quoted context omitted.

"I found a 3rd party library that uses eval, so we just send it code we want to run and...boom. We're in." "I found a popular chat app that after install leaves a tool with full sudo privileages behind for us to take advantage of located clickityclickity... here. We're in." Sometimes, it can be even more pedestrian sounding. Hackers don't always have to be clever if other people are absolutely dumbasses before their…

To be clear, what this exploits is nothing like what you've mentioned. The article does a very good job of describing the relevant parts of the image format. They built a VM inside of an images single pass decompression route. I'd highly recommend reading the article. This is just one of the exploits in a very large chain. To quote some of the nations top security researchers: > Based on our research and findings, we…

Yeah. Even I know about eval. I'm just happy Google and Apple actually care about security unlike the 2000s companies and can rival the smartest hackers to keep my phone safe!

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#258
post #144

It's a real shame that the people who came up with this exploit are working for NSO and not on solving P = NP or something. I'm sure if we got them and the ones working on crypto at NSA in a room together, we'd have it and clean unlimited energy in a week. I often feel sad thinking about how many brilliant engineers are dedicating their time to helping governments spy on people or other governments.

I feel the same way about all the smart engineers solving problems for Facebook, Twitter, etc...

Those engineering problems are trivial compared to many real problems. Turning out all those engineers to work on say cancer wouldn't necessarily result in any new breakthroughs . Case in point: all the brilliant software engineers who thought they could solve Covid (https://www.protocol.com/Newsletters/pipeline/very-venture-c...) only to find themselves out of their depth. The software engineering approach doesn't translate to all things and can even be harmful in some fields (cough Theranos). Physicists are another group that tend to have this conceit -i.e if they weren't so busy solving physics problems they would solve the economy and world peace

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#259

> further demonstrating that the capabilities NSO provides rival those previously thought to be accessible to only a handful of nation states I mean the whole “nation state” or “nation state backed” hackers thing was always a liiiiitle (very) ambiguous right? Does the evidence really even move the goal post or mitigate the convenient scapegoating? Politicians and CEOs and certified IT professionals are all incentiviz…

All security is only how many zeros of money is it built to protect agaist.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#260
post #52

From the top of the article: > We want to thank Citizen Lab for sharing a sample of the FORCEDENTRY exploit with us, and Apple’s Security Engineering and Architecture (SEAR) group for collaborating with us on the technical analysis. This reminded me that NSO went after Citizen Lab on multiple fronts. They even tried to use a spy to talk to JSR ( https://www.johnscottrailton.com ) and make him say controversial things…

Darknet Diaries is so good. To anyone who hasn't listened, highly recommend. Jack hits a homerun each week and the story about JSR and NSO was buck wild

I wish they would write articles too.. I don't have the patience to listen to podcasts :) But I've been told it's really good.
Post reply on HN