NSO group iPhone zero-click, zero-day exploit captured in the wild
41–50 of 886 posts
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#42Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#43Earlier quoted context omitted.
Isn't Messages E2E by default?
iMessage or android messages? iMessage is E2E by default, unless one or more parties own multiple apple devices, in which case apple stores an encryption key on iCloud and maintains E2EE connections with every connected Apple device. This changes if you turn on Advanced data protection-- then iCloud no longer has the ability to decrypt messages. Somewhat unrelated but ADP is off by default as most customers do not wa…
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#44Here we go again... NSO Group has a long history of 0-click, 0-days against iMessage, and just a few months ago Kaspersky caught a different zero day iMessage exploit targeting their staff. If Apple repeatedly fails at securing their devices from an attack vector that has been demonstrated over, and over, and over... no wonder China is banning government officials from using their devices.
Do you actually think security is the reason they are being banned? I think the reasons are far more political than technical.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#45[flagged]
Huh?
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#46Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#47[flagged]
1) What does this topic have to do with Android? 2) EU politicians don't know about Android updates because they don't understand how SW works and most probably have iOS anyway. The only time they hear about tech is when some Joe Schmoe insults them on Facebook so they send the courts after Facebook to doxx that person and get Facebook to moderate and ban "hate speech" on their platform. All in a day's work. Granted,…
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#48Earlier quoted context omitted.
Some of the problems with iMessage have to do with the fact that it's integrated with the system SMS app. It seems that there are a large number of legacy requirements in the GSM spec that require the Messages app to be privileged in some way, especially with regards to automatic processing of data received. There have been plenty of iMessage or Messages related vulnerabilities. I do wish there was a way to turn off…
You can enable iOS’s “lockdown mode” which disabled automatic download attachment, JavaScript JIT and other rather hard to secure features.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#49[flagged]
I've never met a person who threw away a phone because of the lack of updates.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#50Earlier quoted context omitted.
At least they’re trying? Meanwhile Google has spent 2 decades refusing to release a messenger that encrypts by default because they think they should be able to mine all your personal conversations. I take that back, they announced encrypted messaging, then never released it, then probably fired the engineer who said it’d be a feature in allo (or whatever their last attempt was).
No that's not true. Google just fails miserably at anything social, but almost every chat attempt from them eas encrypted, and now they are pushing RCS, which is also E2EE.