Live data from Hacker News

A Saudi woman's iPhone revealed hacking around the world

reuters.com

121–130 of 184 posts

Re: A Saudi woman's iPhone revealed hacking around the world

#121
post #19

Earlier quoted context omitted.

Holy shit. My relatives have asked me in the past "could this [image|video|other supposedly innocuous file format] be a virus or hack my phone?". I've always told them not to worry. Can't do that anymore.

https://en.wikipedia.org/wiki/Windows_Metafile_vulnerability Long story short: Windows library routines for handling an obscure, obsolete image format had a parser flaw. Simply rendering an appropriately crafted image via the standard Windows APIs -- whether in a web browser, file explorer, file preview, word processor, anywhere -- resulted in kernel-level arbitrary code execution. Now, we've gotten a bit smarter abo…

> There could be a parser bug somewhere in your web browser for example that allows a properly crafted input to hijack the browser process.

Bit of a caveat: Chromium and Firefox are probably some of the most hardened software programs in the world (for other browsers, all bets are off).

Chromium distributes its logic over multiple processes per tab, so that even if you eg find a zero-day in V8, you still can't use it to get arbitrary file access without a sandbox escape. Last I checked, Firefox was getting there. Also, Firefox compiles some parsing and image processing libraries to WebAssembly for another layer of sandboxing (and to protect against ROP exploits), and increasingly uses Rust for sensitive tasks.

That's not to say they're safe, but I don't think they're the biggest source of exploits.

Re: A Saudi woman's iPhone revealed hacking around the world

#122
post #19

Earlier quoted context omitted.

https://en.wikipedia.org/wiki/Windows_Metafile_vulnerability Long story short: Windows library routines for handling an obscure, obsolete image format had a parser flaw. Simply rendering an appropriately crafted image via the standard Windows APIs -- whether in a web browser, file explorer, file preview, word processor, anywhere -- resulted in kernel-level arbitrary code execution. Now, we've gotten a bit smarter abo…

I wish OSs would just can support for legacy stuff nobody uses and make it an explicit install for the 1% of people who need it.

Each feature has a different 1% who use it

Re: A Saudi woman's iPhone revealed hacking around the world

#123

Earlier quoted context omitted.

Vulnerabilities on iOS are getting really scarce. People spend truckloads of money finding them and you need to pay twice that for the permission to burn said exploit. That stuff isn't burned on mass hacks on random phone users, it's way too valuable. BUT. There is a small sliver of time between the exploit being used on a high value target and Apple patching the hole. That's the spot where Joe Schmoe should be cauti…

You are probably right, but this attack only became visible because it had a bug. How many others are invisible currently? Well that's what I'm asking myself :)

A lot, but they're still only used for high-value targets. They're way too valuable to waste on some random person who happens to click a link.

Re: A Saudi woman's iPhone revealed hacking around the world

#124
post #2

"The image files tricked the iPhone into giving access to its entire memory, bypassing security and allowing the installation of spyware that would steal a user's messages." Seems like there is a lot behind this summary of the hack. How does an image file trick the iPhone into all that?

hi

Re: A Saudi woman's iPhone revealed hacking around the world

#125
post #7

Earlier quoted context omitted.

How does one know which category they are in?

Think about who would want to spy on you, what they'd want to know, and how much they'd be willing to spend to know it. If the most they could get out of you was a few thousand bucks from your bank account and maybe your email password, you're probably in the first category. On the other hand, if you have access to highly confidential information (think classified government info or you're literally working on the ne…

The problem is, everyone is in the second category over a long enough time frame. Hong Kongers probably thought the same, but suddenly there were crackdowns, and state actors probably would have loved to have unrestricted access to peoples phones to see if citizens were exercising their “free speech” correctly.

Think about Ukraine today, the Russian government would probably love to have a way to compromise millions of Ukrainian citizens’ phones.

These people all use iPhones.

Re: A Saudi woman's iPhone revealed hacking around the world

#126

Earlier quoted context omitted.

I'm convinced that a bad image parser is apple's backdoor, but I only have my paranoia as proof.

What Apple stands to gain from a backdoor? It's clear what the cost of risk is, but what is the gain?

Just spitballing, but market access to China and the like?

Re: A Saudi woman's iPhone revealed hacking around the world

#127
post #13

Tech has essentially created this problem. Can’t tech fix it?

As long as people aren't put in jail for faulty software, it will never be fixed. Remember Diginotar? Who knows how many lives were affected in Iran...

Surgeons aren't put in jail for faulty surgery. Wanting this for software is a bit draconian.

Re: A Saudi woman's iPhone revealed hacking around the world

#128
post #125

Earlier quoted context omitted.

Think about who would want to spy on you, what they'd want to know, and how much they'd be willing to spend to know it. If the most they could get out of you was a few thousand bucks from your bank account and maybe your email password, you're probably in the first category. On the other hand, if you have access to highly confidential information (think classified government info or you're literally working on the ne…

The problem is, everyone is in the second category over a long enough time frame. Hong Kongers probably thought the same, but suddenly there were crackdowns, and state actors probably would have loved to have unrestricted access to peoples phones to see if citizens were exercising their “free speech” correctly. Think about Ukraine today, the Russian government would probably love to have a way to compromise millions…

> These people all use iPhones.

A quick research tells me that pretty much all stats show Android use to be around 80% in Ukraine. Or did you mean Hong Kong? For the latter I see a 50/50 divide.

Just curious about that sentence. I don't think the stats take anything away from your general argument.

Re: A Saudi woman's iPhone revealed hacking around the world

#129

Earlier quoted context omitted.

I always remember a quote from a sci fi I read about the "multi planet Internet" there. It was layer upon layer upon layer of protocols and software. Because it wasn't possible to remove old layers (because some satellites or wormholes or whatever would stop working.) So, it was super easy to hack...and sending spam. Well you will get killed for that though.

Would be interested in the name of he book ?

It sounds like Vernor Vinge’s A Fire Upon The Deep (& sequels), well worth finding.

Re: A Saudi woman's iPhone revealed hacking around the world

#130
post #7

Earlier quoted context omitted.

How does one know which category they are in?

Think about who would want to spy on you, what they'd want to know, and how much they'd be willing to spend to know it. If the most they could get out of you was a few thousand bucks from your bank account and maybe your email password, you're probably in the first category. On the other hand, if you have access to highly confidential information (think classified government info or you're literally working on the ne…

Who might be my enemy in the future? Well, maybe anyone who thinks I have something worth to them. Let's say a social media account with a double letter username. Or anything I don't think has any worth now but can be turned into a handsome buck tomorrow. People have been doxed and SWATed over less.
Post reply on HN