Live data from Hacker News

A Saudi woman's iPhone revealed hacking around the world

reuters.com

21–30 of 184 posts

Re: A Saudi woman's iPhone revealed hacking around the world

#21
post #18
post #15

Earlier quoted context omitted.

Construction has essentially created the problem of potholes. Can they fix it?

Good analogy. Question here is: can they fix potholes faster than new ones show up? Seems answer is no for tech. And construction, these days.

I think the answer is probably an astounding yes for both, if you think of the trend of vulnerabilities/units of software generated.

The move to a large majority of software being run in a sandboxed environment has drastically reduced this sort of thing.

Re: A Saudi woman's iPhone revealed hacking around the world

#22
>Fearful that her iPhone had been hacked as well, al-Hathloul contacted the Canadian privacy rights group Citizen Lab and asked them to probe her device for evidence

I wonder if she had a preexisting relationship w the group or how she was connected with them.

Presumably her work included a network of journalist protection orgs. But had she had a device “probed” like this before?

It’s such an important point of contact I wonder about the details of this.

Re: A Saudi woman's iPhone revealed hacking around the world

#24
post #15
post #13

Tech has essentially created this problem. Can’t tech fix it?

Construction has essentially created the problem of potholes. Can they fix it?

"The invention of the ship was also the invention of the shipwreck" ― Paul Virilio

Re: A Saudi woman's iPhone revealed hacking around the world

#25
post #17
post #9

Earlier quoted context omitted.

In the late 1990s there were a ton of hoaxes about image files supposedly being viruses. Most famously: https://en.wikipedia.org/wiki/Goodtimes_virus I remember telling lots of people at the time that this was impossible, because images weren't executable code, and viruses spread through running programs, not through viewing images. Unfortunately, this elegant, straightforward distinction didn't hold up over time. :-…

> Unfortunately, this elegant, straightforward distinction didn't hold up over time. :-( I think it was more that it was never true, rather than not holding up in time. ;) The earliest I can find is a vulnerability in Netscape 3.0 (1996), not found until four years later: https://www.openwall.com/articles/JPEG-COM-Marker-Vulnerabil...

You just need a buffer overflow in a file format parser.

Thus the distinction has never existed. There has never been such thing as a “safe” format.

Re: A Saudi woman's iPhone revealed hacking around the world

#26

Earlier quoted context omitted.

Holy shit. My relatives have asked me in the past "could this [image|video|other supposedly innocuous file format] be a virus or hack my phone?". I've always told them not to worry. Can't do that anymore.

The problem with cpu's is they dont know what instructions are supposed to run in order. Pipeline cache goes a little way towards getting the instructions in order, but ultimately a cpu does not know what instructions it has to run in order for a group of instructions to not be malicious. Think of a cpu like an old human telephone exchange where the operator is plugging in different cables to different sockets and ho…

We've gone from 'every OS and device is easily exploitable' to mass market devices/OS pairings where drive-by exploits cost a million dollars.

Re: A Saudi woman's iPhone revealed hacking around the world

#27
post #9

Earlier quoted context omitted.

Holy shit. My relatives have asked me in the past "could this [image|video|other supposedly innocuous file format] be a virus or hack my phone?". I've always told them not to worry. Can't do that anymore.

In the late 1990s there were a ton of hoaxes about image files supposedly being viruses. Most famously: https://en.wikipedia.org/wiki/Goodtimes_virus I remember telling lots of people at the time that this was impossible, because images weren't executable code, and viruses spread through running programs, not through viewing images. Unfortunately, this elegant, straightforward distinction didn't hold up over time. :-…

>because images weren't executable code

I believe that is what the creators of this virus must be relying on. All I hope is that creating this image virus doesn't become common knowledge (cause that we will fundamentally reshape how we interact on social media).

Re: A Saudi woman's iPhone revealed hacking around the world

#28
post #19

Earlier quoted context omitted.

Holy shit. My relatives have asked me in the past "could this [image|video|other supposedly innocuous file format] be a virus or hack my phone?". I've always told them not to worry. Can't do that anymore.

https://en.wikipedia.org/wiki/Windows_Metafile_vulnerability Long story short: Windows library routines for handling an obscure, obsolete image format had a parser flaw. Simply rendering an appropriately crafted image via the standard Windows APIs -- whether in a web browser, file explorer, file preview, word processor, anywhere -- resulted in kernel-level arbitrary code execution. Now, we've gotten a bit smarter abo…

Which is why the only safe way to operate is assume anything that is susceptible to outside data is already compromised - and so run them in sandboxes.

Re: A Saudi woman's iPhone revealed hacking around the world

#29
Loujain is a University of British Columbia graduate and was a political prisoner:

https://www.google.com/search?client=firefox-b-1-d&q=loujain...

https://en.wikipedia.org/wiki/Loujain_al-Hathloul

Let's not forget that the present Saudi regime (MBS) is responsible for luring political opponents/journalists, killing them, and dismembering them with bone saws.

https://en.wikipedia.org/wiki/Assassination_of_Jamal_Khashog...

Re: A Saudi woman's iPhone revealed hacking around the world

#30
post #3

Earlier quoted context omitted.

Here's the writeup: https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i... edit, previous discussion: https://news.ycombinator.com/item?id=29568625

Holy shit. My relatives have asked me in the past "could this [image|video|other supposedly innocuous file format] be a virus or hack my phone?". I've always told them not to worry. Can't do that anymore.

There's been buffer overflows/RCE exploits in all sorts of software that can parse images since, well, forever. I remember more than 20 years ago seeing a notice about the embedded Internet Explorer rendering engine in Microsoft Outlook Express having an RCE zero day which could be exploited by simply loading an image in the body of an email.

Rich multimedia parsing display systems in messaging apps are a very tempting attack surface for entities such as NSO.

Post reply on HN