Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

41–50 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#43
post #10
post #8

Earlier quoted context omitted.

Isn't Messages E2E by default?

iMessage or android messages? iMessage is E2E by default, unless one or more parties own multiple apple devices, in which case apple stores an encryption key on iCloud and maintains E2EE connections with every connected Apple device. This changes if you turn on Advanced data protection-- then iCloud no longer has the ability to decrypt messages. Somewhat unrelated but ADP is off by default as most customers do not wa…

That would be probably 100% of the iOS users that I know, including my entire family. Everyone's got an iPhone, iPad, Apple Watch, Macbook etc. It's such a nice ecosystem, so it's hard not to get hooked.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#44
post #23

Here we go again... NSO Group has a long history of 0-click, 0-days against iMessage, and just a few months ago Kaspersky caught a different zero day iMessage exploit targeting their staff. If Apple repeatedly fails at securing their devices from an attack vector that has been demonstrated over, and over, and over... no wonder China is banning government officials from using their devices.

>no wonder China is banning government officials from using their devices.

Do you actually think security is the reason they are being banned? I think the reasons are far more political than technical.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#47

[flagged]

1) What does this topic have to do with Android? 2) EU politicians don't know about Android updates because they don't understand how SW works and most probably have iOS anyway. The only time they hear about tech is when some Joe Schmoe insults them on Facebook so they send the courts after Facebook to doxx that person and get Facebook to moderate and ban "hate speech" on their platform. All in a day's work. Granted,…

That tech industry often lobbies for the wrong causes though.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#48
post #24

Earlier quoted context omitted.

Some of the problems with iMessage have to do with the fact that it's integrated with the system SMS app. It seems that there are a large number of legacy requirements in the GSM spec that require the Messages app to be privileged in some way, especially with regards to automatic processing of data received. There have been plenty of iMessage or Messages related vulnerabilities. I do wish there was a way to turn off…

You can enable iOS’s “lockdown mode” which disabled automatic download attachment, JavaScript JIT and other rather hard to secure features.

Doesn't Lockdown Mode fully block message attachments besides images? Not just automatic download.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#49

[flagged]

I've never met a person who threw away a phone because of the lack of updates.

I got a new phone last year because my old phone could not call emergency services. Even if it was still receiving updates it's not clear that this would be fixed though. Google seems to think that local regulations prevent them from fixing this users of certain of their phones on certain carriers.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#50
post #4

Earlier quoted context omitted.

At least they’re trying? Meanwhile Google has spent 2 decades refusing to release a messenger that encrypts by default because they think they should be able to mine all your personal conversations. I take that back, they announced encrypted messaging, then never released it, then probably fired the engineer who said it’d be a feature in allo (or whatever their last attempt was).

No that's not true. Google just fails miserably at anything social, but almost every chat attempt from them eas encrypted, and now they are pushing RCS, which is also E2EE.

Google started pushing for carriers to use RCS in 2015, and launched it's own app for it in 2019 after that failed to move quickly enough. They didn't start adding E2EE to it until 2020, and it wasn't the default until 2021.
Post reply on HN