Live data from Hacker News

The battle for the world’s most powerful cyberweapon

nytimes.com

51–60 of 87 posts

Re: The battle for the world’s most powerful cyberweapon

#51
post #29

Why is the FBI paying to get Pegasus? Doesn't the US have NSA to do this kind of hacks or find no click zero days in Android/iPhone and share the zero days with the FBI? Or why hasn't someone try to trick NSO to hack a monitored phone and find out the zero day? I am having these questions because every time I hear about NSO there is this question in my head "What is so special about NSO?". I see 2017, 2018, etc. how…

The NSA does have an organization devoted to developing these sorts of attacks that make the NSO group look like a bunch of kindergarteners as evidenced by the Snowden leaks. The CIA also, independently of the NSA, has an organization that develops these sorts of attacks that make the NSO group also look like a bunch of kindergarteners as evidenced by the Vault 7 leaks. Almost without a doubt, the FBI, DHS, US Navy,…

The FBI comment in this article is interesting in they give an offhand excuse that it could be for evaluating foreign software and threats. holds water. But so to does them buying it to use it

Re: The battle for the world’s most powerful cyberweapon

#52
post #27

Earlier quoted context omitted.

There's insufficient motivation for OS creators. It's possible to compile C code with various hardening options and pay a few percent overhead for it, but it remains almost entirely in the realm of academia... Except for the Xbox. Someone hacking an Xbox would lose _Microsoft_ money through piracy, which hurts their bottom line! As a result, the Xbox runs a type 1 hypervisor with various compiler hardening options li…

Which hardening options are Apple ignoring? I would have thought the standard types of ones (debian's default) would also be set on macos/ios, eg https://help.apple.com/xcode/mac/current/#/devf87a2ac8f From what I can tell all NSO's rigmarole of making a virtual machine in the PDF parser is to work around the existing mitigations. I guess they could also turn on asan etc in production but that's more than a few perce…

I don‘t know anything about the benefits of these options but if the tradeoff is only a slowdown of the device this should be an option given to the user. Maybe even payed for („hardened version“ at buy time) or through a subscription.

Re: The battle for the world’s most powerful cyberweapon

#54
post #23
post #11

Earlier quoted context omitted.

Paying is the key. NSA doing it for FBI would generate no profit for anyone. Given various loopholes exploiting arrangements between allied security services, I'd not be surprised if NSA were a source of 0days for NSO.

> NSA were a source of 0days for NSO Not directly, NSA requests tech companies to slow down 0day research so they and others can exploid them.

how are you aware of that?

Re: The battle for the world’s most powerful cyberweapon

#55

Just imagine if we had a key escrow or other backdoor like FBI asked for. If governments were made up of 99.9% very honest people, hundreds of untrustworthy individuals would still have enormous power ready to be abused.

We already have a form of key escrow in the form of public PKI infra/root CAs, etc.

Re: The battle for the world’s most powerful cyberweapon

#56

How is it that we can't have an OS that stops such things? I'm of the opinion that the NSA must have a long running covert program to discourage the adoption of secure operating systems. Multilevel Secure Operating Systems have existed since the 1980s, yet most people haven't even heard of them.

I wonder if governments quietly talk the companies behind the mainstream consumer OSes (Windows, Android, iOS and macOS) and components (I'm thinking about the device drivers) into not to try too hard to make them invulnerable to attacks. They can do all sort of subtle and not too subtle things to companies that cost them more money than they can lose because of zero days and zero clicks. After all nearly everybody has a phone that NSO could spy into and we didn't go back to Nokia 3310.

Re: The battle for the world’s most powerful cyberweapon

#57
post #24

Earlier quoted context omitted.

Because NSO is on a different level completely. Google engineers who analyzed NSA hacks found it to be "terrifying". See https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...

They say it's terrifying but this doesn't seem like an incredible advancement on any previous "weird machine" exploits. It's just nobody else has this problem to need to write a compiler like this.

Indeed. It’s a fairly logical step in exploit development, and (while a significant amount of impressive work) not a particularly novel idea.

Re: The battle for the world’s most powerful cyberweapon

#58
post #27

Earlier quoted context omitted.

There's insufficient motivation for OS creators. It's possible to compile C code with various hardening options and pay a few percent overhead for it, but it remains almost entirely in the realm of academia... Except for the Xbox. Someone hacking an Xbox would lose _Microsoft_ money through piracy, which hurts their bottom line! As a result, the Xbox runs a type 1 hypervisor with various compiler hardening options li…

Which hardening options are Apple ignoring? I would have thought the standard types of ones (debian's default) would also be set on macos/ios, eg https://help.apple.com/xcode/mac/current/#/devf87a2ac8f From what I can tell all NSO's rigmarole of making a virtual machine in the PDF parser is to work around the existing mitigations. I guess they could also turn on asan etc in production but that's more than a few perce…

Address Sanitizer is not meant to be used as security hardening.

Re: The battle for the world’s most powerful cyberweapon

#59
post #29

Why is the FBI paying to get Pegasus? Doesn't the US have NSA to do this kind of hacks or find no click zero days in Android/iPhone and share the zero days with the FBI? Or why hasn't someone try to trick NSO to hack a monitored phone and find out the zero day? I am having these questions because every time I hear about NSO there is this question in my head "What is so special about NSO?". I see 2017, 2018, etc. how…

The NSA does have an organization devoted to developing these sorts of attacks that make the NSO group look like a bunch of kindergarteners as evidenced by the Snowden leaks. The CIA also, independently of the NSA, has an organization that develops these sorts of attacks that make the NSO group also look like a bunch of kindergarteners as evidenced by the Vault 7 leaks. Almost without a doubt, the FBI, DHS, US Navy,…

> The CIA also, independently of the NSA, has an organization that develops these sorts of attacks that make the NSO group also look like a bunch of kindergarteners as evidenced by the Vault 7 leaks.

Have you actually looked at the Vault 7 leaks? There’s nothing there far beyond the capabilities of a NSO-type actor. NSO is at the level of a nation state, but so are all the nation states. It’s easy to think that funneling infinite money at something will just make you that much better at something, but this isn’t true at all. Otherwise Apple and Google and Microsoft would just be unimaginably distanced from every other smaller company, and I’m sure you agree that they are not ;)

Re: The battle for the world’s most powerful cyberweapon

#60
post #29

Why is the FBI paying to get Pegasus? Doesn't the US have NSA to do this kind of hacks or find no click zero days in Android/iPhone and share the zero days with the FBI? Or why hasn't someone try to trick NSO to hack a monitored phone and find out the zero day? I am having these questions because every time I hear about NSO there is this question in my head "What is so special about NSO?". I see 2017, 2018, etc. how…

The NSA does have an organization devoted to developing these sorts of attacks that make the NSO group look like a bunch of kindergarteners as evidenced by the Snowden leaks. The CIA also, independently of the NSA, has an organization that develops these sorts of attacks that make the NSO group also look like a bunch of kindergarteners as evidenced by the Vault 7 leaks. Almost without a doubt, the FBI, DHS, US Navy,…

wow, the word kindergarten is repeated four times, that doesn't communicate an abundance of confidence...
Post reply on HN