Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

101–110 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#101
post #10
post #8

Earlier quoted context omitted.

Isn't Messages E2E by default?

iMessage or android messages? iMessage is E2E by default, unless one or more parties own multiple apple devices, in which case apple stores an encryption key on iCloud and maintains E2EE connections with every connected Apple device. This changes if you turn on Advanced data protection-- then iCloud no longer has the ability to decrypt messages. Somewhat unrelated but ADP is off by default as most customers do not wa…

iMessage is E2E even without ADP, even with groups and multiple devices. The details are complex, but they are publicly documented here[1]:

The issue (I think) you are referring to is that if you enable iCloud backup[2] or iCloud for Messages[3] (both of which move effectively move the storage of the messages to the cloud, either as part of the device backup or as the canonical representation that devices sync from respectively) then the messages decoded on device will be stored in blobs that iCloud has the keys to unless you enable Advanced Data Protection.

[1]: https://support.apple.com/guide/security/how-imessage-sends-...

[2]: https://support.apple.com/en-us/HT211228

[3]: https://support.apple.com/guide/icloud/what-you-can-do-with-...

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#102
post #35
post #10

Earlier quoted context omitted.

iMessage or android messages? iMessage is E2E by default, unless one or more parties own multiple apple devices, in which case apple stores an encryption key on iCloud and maintains E2EE connections with every connected Apple device. This changes if you turn on Advanced data protection-- then iCloud no longer has the ability to decrypt messages. Somewhat unrelated but ADP is off by default as most customers do not wa…

Android Messages, the competitor to iMessage. The parent claimed that Google resists encrypting anything so they can mine your data. I was merely trying to ask for accuracy. I don't know the technical aspects of every Google messaging app but as the other responses in the thread confirm, Messages is end to end encrypted by default for non-SMS messages.

I just checked and Google does have a Messages app, different from the Messages app on my phone, probably by Samsung, which deals with SMSes. According to Play it has 1B+ downloads so it's probably preinstalled.

Anyway, the competitor of iMessage and Messages is WhatsApp. Nobody is sending me SMSes except banks so even iPhone users use WhatsApp to send messages to friends and to groups in my country. If somebody would insist using only iMessage they would be out of the loop. And about Messages, well, I don't have that app, I receive no SMSes, I still communicate with everybody so I guess that nobody uses Messages too.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#103
post #23

Here we go again... NSO Group has a long history of 0-click, 0-days against iMessage, and just a few months ago Kaspersky caught a different zero day iMessage exploit targeting their staff. If Apple repeatedly fails at securing their devices from an attack vector that has been demonstrated over, and over, and over... no wonder China is banning government officials from using their devices.

China not worried about 0-clicks on Apple. They are worried about US-Apple collusion with iOS software.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#104
post #52

Earlier quoted context omitted.

[flagged]

The US could demand NSO on a platter if they realty wanted to, but they don't. Israel intelligence often aids the US alphabet boys and the NSA on various offensive operations and intelligence gathering, which is why NSO is allowed to keep doing business by both parties.

[deleted]

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#105
post #38
post #23

Here we go again... NSO Group has a long history of 0-click, 0-days against iMessage, and just a few months ago Kaspersky caught a different zero day iMessage exploit targeting their staff. If Apple repeatedly fails at securing their devices from an attack vector that has been demonstrated over, and over, and over... no wonder China is banning government officials from using their devices.

Please... Androids no better. At least Apple will have it patched within the year of discovery. Can't say the same for other Android vendors.

Interesting how your response makes it seem like the person you're responding to mentioned android at all.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#106

Wow this sounds like stagefright was way back when. So for those keeping score, is Android now ahead of iOS in this aspect of security?

Maybe, but probably not.

They have regular security releases that often patch critical vulnerabilities such as https://source.android.com/docs/security/bulletin/2023-08-01

The bigger issue with Android IMO is you might not get the patches right away depending on your device and it’s age.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#107

Wow this sounds like stagefright was way back when. So for those keeping score, is Android now ahead of iOS in this aspect of security?

While there's a big difference between a CVE and a CVE, Android has had 939 CVEs in 2023 alone [0]. I wouldn't necessarily hold my breath on this one.

[0] https://www.cvedetails.com/vulnerability-list/vendor_id-1224...

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#108
post #95

Earlier quoted context omitted.

I would describe a one click rootkit as terrifying as opposed to wonderful.

If it makes you feel better the click was actually unnecessary theater.

Yeah, the whole way that the jailbreaks installed was scary enough for me to never want to go near them.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#109
post #70

Again a buffer overflow in image decoding, that sounds similar to the one from 2021 [1]. That one was wild, building a CPU out of primitives offered by an arcane image compression format embedded in pdf, to be able to do enough arithmetic to further escalate to arbitrary code execution! [1]: https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...

And a much older bug with TIF rendering in iOS 4 used by jailbreakme.com back in the day. It was wonderful pressing a button in Safari and suddenly seeing my iPod touch reboot with Cydia installed.

This is the frustrating part: that is cool from a technical perspective but terrifying when you think about this stuff being used to target journalists, activists, etc. Maybe not everyone gets the bone saw but some will - and from the sounds of it it’s people standing up to abusive people:

> Last week, while checking the device of an individual employed by a Washington DC-based civil society organization with international offices, Citizen Lab found an actively exploited zero-click vulnerability being used to deliver NSO Group’s Pegasus mercenary spyware.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#110

Earlier quoted context omitted.

And a much older bug with TIF rendering in iOS 4 used by jailbreakme.com back in the day. It was wonderful pressing a button in Safari and suddenly seeing my iPod touch reboot with Cydia installed.

I would describe a one click rootkit as terrifying as opposed to wonderful.

[deleted]
Post reply on HN