Why doesn’t Apple have a team doing what Citizens Lab does, instead of victims contacting a third party? Also, I wonder if Google Pixel is more secure?
Because Animoji was more important. Incase anyone was wondering, yes the amount they spent on that particular feature vastly eclipsed their spend on the kinds of teams that could have caught this.
A Saudi woman's iPhone revealed hacking around the world
101–110 of 184 posts
Re: A Saudi woman's iPhone revealed hacking around the world
#102Earlier quoted context omitted.
Which is why the only safe way to operate is assume anything that is susceptible to outside data is already compromised - and so run them in sandboxes.
The tech is the easy part: iOS/Android have the best security teams in the world, and an unlimited budget, and sandboxing is an old, proven tech. I guess that the politics here are the real barrier.
Re: A Saudi woman's iPhone revealed hacking around the world
#103How come the company that made Pegasus is being sanctioned, but the government that used Pegasus to abduct, kill, and then dismember a dissident - isn't?
Re: A Saudi woman's iPhone revealed hacking around the world
#104Would compiling image parsers with ASLR and bounds checking prevent these zero-click hacks? I haven’t researched the exploits in detail but it seems to me Apple can develop better protection against such zero-click exploits. At the very least, iMessages shouldn’t preview images from unknown contacts.
I'm convinced that a bad image parser is apple's backdoor, but I only have my paranoia as proof.
Re: A Saudi woman's iPhone revealed hacking around the world
#105Isn't the walled garden and locked down OS/hardware supposed to prevent these things?
Re: A Saudi woman's iPhone revealed hacking around the world
#106Earlier quoted context omitted.
Holy shit. My relatives have asked me in the past "could this [image|video|other supposedly innocuous file format] be a virus or hack my phone?". I've always told them not to worry. Can't do that anymore.
There's been buffer overflows/RCE exploits in all sorts of software that can parse images since, well, forever . I remember more than 20 years ago seeing a notice about the embedded Internet Explorer rendering engine in Microsoft Outlook Express having an RCE zero day which could be exploited by simply loading an image in the body of an email. Rich multimedia parsing display systems in messaging apps are a very tempt…
Re: A Saudi woman's iPhone revealed hacking around the world
#107Earlier quoted context omitted.
In the late 1990s there were a ton of hoaxes about image files supposedly being viruses. Most famously: https://en.wikipedia.org/wiki/Goodtimes_virus I remember telling lots of people at the time that this was impossible, because images weren't executable code, and viruses spread through running programs, not through viewing images. Unfortunately, this elegant, straightforward distinction didn't hold up over time. :-…
>because images weren't executable code I believe that is what the creators of this virus must be relying on. All I hope is that creating this image virus doesn't become common knowledge (cause that we will fundamentally reshape how we interact on social media).
All I hope is that devs start replacing parsers with ones written in a safe language.
Re: A Saudi woman's iPhone revealed hacking around the world
#108Earlier quoted context omitted.
You're really cavalier about whether widespread hacks happen. See any of the text message attacks from the past decade.
Vulnerabilities on iOS are getting really scarce. People spend truckloads of money finding them and you need to pay twice that for the permission to burn said exploit. That stuff isn't burned on mass hacks on random phone users, it's way too valuable. BUT. There is a small sliver of time between the exploit being used on a high value target and Apple patching the hole. That's the spot where Joe Schmoe should be cauti…
Re: A Saudi woman's iPhone revealed hacking around the world
#109Earlier quoted context omitted.
How does one know which category they are in?
Think about who would want to spy on you, what they'd want to know, and how much they'd be willing to spend to know it. If the most they could get out of you was a few thousand bucks from your bank account and maybe your email password, you're probably in the first category. On the other hand, if you have access to highly confidential information (think classified government info or you're literally working on the ne…
Re: A Saudi woman's iPhone revealed hacking around the world
#110Why doesn’t Apple have a team doing what Citizens Lab does, instead of victims contacting a third party? Also, I wonder if Google Pixel is more secure?