Live data from Hacker News

A Saudi woman's iPhone revealed hacking around the world

reuters.com

101–110 of 184 posts

Re: A Saudi woman's iPhone revealed hacking around the world

#101
post #54
post #51

Why doesn’t Apple have a team doing what Citizens Lab does, instead of victims contacting a third party? Also, I wonder if Google Pixel is more secure?

Because Animoji was more important. Incase anyone was wondering, yes the amount they spent on that particular feature vastly eclipsed their spend on the kinds of teams that could have caught this.

I find it very hard to believe that the richest company in the world, didn’t have enough money to implement Animoji. And they had to eclipse the budget of security team. Could you provide a source for that?

Re: A Saudi woman's iPhone revealed hacking around the world

#102
post #88
post #28

Earlier quoted context omitted.

Which is why the only safe way to operate is assume anything that is susceptible to outside data is already compromised - and so run them in sandboxes.

The tech is the easy part: iOS/Android have the best security teams in the world, and an unlimited budget, and sandboxing is an old, proven tech. I guess that the politics here are the real barrier.

That's just a mitigation for tens of millions of lines of code written in C / C++.

Re: A Saudi woman's iPhone revealed hacking around the world

#103

How come the company that made Pegasus is being sanctioned, but the government that used Pegasus to abduct, kill, and then dismember a dissident - isn't?

Because that would set the precedent to sanction the government that rubber stamped the selling of Pegasus also.

Re: A Saudi woman's iPhone revealed hacking around the world

#104

Would compiling image parsers with ASLR and bounds checking prevent these zero-click hacks? I haven’t researched the exploits in detail but it seems to me Apple can develop better protection against such zero-click exploits. At the very least, iMessages shouldn’t preview images from unknown contacts.

I'm convinced that a bad image parser is apple's backdoor, but I only have my paranoia as proof.

What Apple stands to gain from a backdoor? It's clear what the cost of risk is, but what is the gain?

Re: A Saudi woman's iPhone revealed hacking around the world

#106

Earlier quoted context omitted.

Holy shit. My relatives have asked me in the past "could this [image|video|other supposedly innocuous file format] be a virus or hack my phone?". I've always told them not to worry. Can't do that anymore.

There's been buffer overflows/RCE exploits in all sorts of software that can parse images since, well, forever . I remember more than 20 years ago seeing a notice about the embedded Internet Explorer rendering engine in Microsoft Outlook Express having an RCE zero day which could be exploited by simply loading an image in the body of an email. Rich multimedia parsing display systems in messaging apps are a very tempt…

Why a messenger app needs a picture viewer?

Re: A Saudi woman's iPhone revealed hacking around the world

#107
post #9

Earlier quoted context omitted.

In the late 1990s there were a ton of hoaxes about image files supposedly being viruses. Most famously: https://en.wikipedia.org/wiki/Goodtimes_virus I remember telling lots of people at the time that this was impossible, because images weren't executable code, and viruses spread through running programs, not through viewing images. Unfortunately, this elegant, straightforward distinction didn't hold up over time. :-…

>because images weren't executable code I believe that is what the creators of this virus must be relying on. All I hope is that creating this image virus doesn't become common knowledge (cause that we will fundamentally reshape how we interact on social media).

> All I hope is that creating this image virus doesn't become common knowledge

All I hope is that devs start replacing parsers with ones written in a safe language.

Re: A Saudi woman's iPhone revealed hacking around the world

#108
post #60

Earlier quoted context omitted.

You're really cavalier about whether widespread hacks happen. See any of the text message attacks from the past decade.

Vulnerabilities on iOS are getting really scarce. People spend truckloads of money finding them and you need to pay twice that for the permission to burn said exploit. That stuff isn't burned on mass hacks on random phone users, it's way too valuable. BUT. There is a small sliver of time between the exploit being used on a high value target and Apple patching the hole. That's the spot where Joe Schmoe should be cauti…

You are probably right, but this attack only became visible because it had a bug. How many others are invisible currently? Well that's what I'm asking myself :)

Re: A Saudi woman's iPhone revealed hacking around the world

#109
post #7

Earlier quoted context omitted.

How does one know which category they are in?

Think about who would want to spy on you, what they'd want to know, and how much they'd be willing to spend to know it. If the most they could get out of you was a few thousand bucks from your bank account and maybe your email password, you're probably in the first category. On the other hand, if you have access to highly confidential information (think classified government info or you're literally working on the ne…

I don’t know. If I was going to bust a move on, say, Taiwan, it might be handy to have root access to as many computing devices as possible so that I could wreak havoc on my enemy’s communication and banking systems.

Re: A Saudi woman's iPhone revealed hacking around the world

#110
post #51

Why doesn’t Apple have a team doing what Citizens Lab does, instead of victims contacting a third party? Also, I wonder if Google Pixel is more secure?

A recent Pixel with GrapheneOS installed should be pretty secure.

https://en.wikipedia.org/wiki/GrapheneOS

Post reply on HN