Live data from Hacker News

The battle for the world’s most powerful cyberweapon

nytimes.com

21–30 of 87 posts

Re: The battle for the world’s most powerful cyberweapon

#21

Why is the FBI paying to get Pegasus? Doesn't the US have NSA to do this kind of hacks or find no click zero days in Android/iPhone and share the zero days with the FBI? Or why hasn't someone try to trick NSO to hack a monitored phone and find out the zero day? I am having these questions because every time I hear about NSO there is this question in my head "What is so special about NSO?". I see 2017, 2018, etc. how…

I don’t think it’s a single or even a fixed collection of zero days, it’s an arms race that requires constant updates to the vulnerability catalog in order to be able to exploit the latest fully patched phones.

Re: The battle for the world’s most powerful cyberweapon

#22

How is it that we can't have an OS that stops such things? I'm of the opinion that the NSA must have a long running covert program to discourage the adoption of secure operating systems. Multilevel Secure Operating Systems have existed since the 1980s, yet most people haven't even heard of them.

For the same reason we can't have pick-proof locks. Total security is physically impossible. You have to defend every access surface with equal flawlessness. Attackers can all coordinate on a single point of failure. By nature of this equation, any time you make a part more secure, attackers will simply focus their efforts on the next weakest link and go at it again.

Immunity can't prevent disease from entering your body either; They can only make it harder and actively respond to intrusion.

Re: The battle for the world’s most powerful cyberweapon

#23
post #11

Why is the FBI paying to get Pegasus? Doesn't the US have NSA to do this kind of hacks or find no click zero days in Android/iPhone and share the zero days with the FBI? Or why hasn't someone try to trick NSO to hack a monitored phone and find out the zero day? I am having these questions because every time I hear about NSO there is this question in my head "What is so special about NSO?". I see 2017, 2018, etc. how…

Paying is the key. NSA doing it for FBI would generate no profit for anyone. Given various loopholes exploiting arrangements between allied security services, I'd not be surprised if NSA were a source of 0days for NSO.

> NSA were a source of 0days for NSO

Not directly, NSA requests tech companies to slow down 0day research so they and others can exploid them.

Re: The battle for the world’s most powerful cyberweapon

#24

Why is the FBI paying to get Pegasus? Doesn't the US have NSA to do this kind of hacks or find no click zero days in Android/iPhone and share the zero days with the FBI? Or why hasn't someone try to trick NSO to hack a monitored phone and find out the zero day? I am having these questions because every time I hear about NSO there is this question in my head "What is so special about NSO?". I see 2017, 2018, etc. how…

Because NSO is on a different level completely. Google engineers who analyzed NSA hacks found it to be "terrifying". See https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...

Re: The battle for the world’s most powerful cyberweapon

#25

How is it that we can't have an OS that stops such things? I'm of the opinion that the NSA must have a long running covert program to discourage the adoption of secure operating systems. Multilevel Secure Operating Systems have existed since the 1980s, yet most people haven't even heard of them.

There's insufficient motivation for OS creators. It's possible to compile C code with various hardening options and pay a few percent overhead for it, but it remains almost entirely in the realm of academia...

Except for the Xbox. Someone hacking an Xbox would lose _Microsoft_ money through piracy, which hurts their bottom line!

As a result, the Xbox runs a type 1 hypervisor with various compiler hardening options like Control Flow Integrity enabled, and are generally some of the most locked down consumer devices sold today.

What's Apple's motivation beyond bad press? iMessage was parsing media sent to it with a pdf parser. Sure, some activists in repressive regimes will get spied on and executed, but it's just so much effort to invest dev effort on rewrites for security when you could find new ways to send cute animated gifs to each other.

Re: The battle for the world’s most powerful cyberweapon

#26

The most powerful cyberweapon is making sure every human understands an inkling of number theory

So everyone's invented their own cryptography. Great! I'll just buffer-overflow the TCP stack and let myself in; then I can read all their messages after they've decrypted them. Rock, meet paper.

So we have evolved best practice in secure commumication using the most rigorous scientific review methods available to math. We just need to help each other understand how we're modelling this stuff.

Re: The battle for the world’s most powerful cyberweapon

#27

How is it that we can't have an OS that stops such things? I'm of the opinion that the NSA must have a long running covert program to discourage the adoption of secure operating systems. Multilevel Secure Operating Systems have existed since the 1980s, yet most people haven't even heard of them.

There's insufficient motivation for OS creators. It's possible to compile C code with various hardening options and pay a few percent overhead for it, but it remains almost entirely in the realm of academia... Except for the Xbox. Someone hacking an Xbox would lose _Microsoft_ money through piracy, which hurts their bottom line! As a result, the Xbox runs a type 1 hypervisor with various compiler hardening options li…

Which hardening options are Apple ignoring? I would have thought the standard types of ones (debian's default) would also be set on macos/ios, eg https://help.apple.com/xcode/mac/current/#/devf87a2ac8f

From what I can tell all NSO's rigmarole of making a virtual machine in the PDF parser is to work around the existing mitigations.

I guess they could also turn on asan etc in production but that's more than a few percent slowdown.

Re: The battle for the world’s most powerful cyberweapon

#28

Earlier quoted context omitted.

So everyone's invented their own cryptography. Great! I'll just buffer-overflow the TCP stack and let myself in; then I can read all their messages after they've decrypted them. Rock, meet paper.

So we have evolved best practice in secure commumication using the most rigorous scientific review methods available to math. We just need to help each other understand how we're modelling this stuff.

All cryptography is based on the assumption that the inverse of some operation is hard to compute, because nobody's found an easy way to do it (yet).

RSA is based on the assumptions that factoring prime numbers and finding discrete logarithms are both hard. ECC is based on the assumption that the subtraction analogue of that weird additiony thingy is hard. Afaik, neither of these things has been proven.

Re: The battle for the world’s most powerful cyberweapon

#29

Why is the FBI paying to get Pegasus? Doesn't the US have NSA to do this kind of hacks or find no click zero days in Android/iPhone and share the zero days with the FBI? Or why hasn't someone try to trick NSO to hack a monitored phone and find out the zero day? I am having these questions because every time I hear about NSO there is this question in my head "What is so special about NSO?". I see 2017, 2018, etc. how…

The NSA does have an organization devoted to developing these sorts of attacks that make the NSO group look like a bunch of kindergarteners as evidenced by the Snowden leaks. The CIA also, independently of the NSA, has an organization that develops these sorts of attacks that make the NSO group also look like a bunch of kindergarteners as evidenced by the Vault 7 leaks. Almost without a doubt, the FBI, DHS, US Navy, US Army, and US Air Force all also have their own independent organizations that each make the NSO group looks like a bunch of kindergarteners given that developing a capability that makes NSO look like kindergarteners only costs on the order of ~$100M (i.e. less than a single jet fighter). There is absolutely nothing special about the NSO other than that they got caught and brought under the limelight.

The most likely reasons the FBI paid for access to Pegasus are: 1. It is another tool that frankly does not cost very much if you are the FBI. 2. The part of the FBI that bought it likely does not have authorization or possibly even knowledge of the other tools and contracted with NSO to gain those capabilities at the cost of just some money. This is like how a developer team in large stodgy old mega corporation might not be able to get IT to setup their servers so they just get a budget that they spend on AWS to do an end-run around their own IT organization.

The zero days are likely occasionally being discovered and fixed, but buying a zero-click zero day for Android/iPhone on the black market only costs on the order of $1-2M at retail. If you have your own competent team you can reasonably expect to find a zero-click zero day with only a few person-months of effort which, even at US wages, is only a few 100k per zero day. At those prices, you could keep a dozen or so stockpiled for less than the cost of starting a McDonalds franchise, so they likely did maintain a dozen or so at any one time, so if one was discovered they could just switch over to a different one and write off the old one as a cost of doing business.

They absolutely do have competition. One high profile example is Hacking Team. In terms of overall competition, I do not have any hard information, but given the size of the vulnerability markets there are probably at least a couple dozen to a few hundred organizations similar in scope to the NSO group. We do not hear about them because they mostly sell to governments.

Post reply on HN