I appreciate that a solution is for people to update immediately. It really makes me wonder if my Android phones over the years have had 1-days exploited by the sheer incompetence of the ecosystem in updating phones. Not much confidence when you get an update with security patches from 2-3 months ago.
NSO group iPhone zero-click, zero-day exploit captured in the wild
131–140 of 886 posts
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#132[flagged]
1) What does this topic have to do with Android? 2) EU politicians don't know about Android updates because they don't understand how SW works and most probably have iOS anyway. The only time they hear about tech is when some Joe Schmoe insults them on Facebook so they send the courts after Facebook to doxx that person and get Facebook to moderate and ban "hate speech" on their platform. All in a day's work. Granted,…
That wasn’t a bad or mock-worthy question at all. TikTok’s app requests access to devices on the user’s local network. Why does it do that? Officially in order to connect to TVs/speakers, but what else could it decide to do with the access it’s granted?
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#133Here we go again... NSO Group has a long history of 0-click, 0-days against iMessage, and just a few months ago Kaspersky caught a different zero day iMessage exploit targeting their staff. If Apple repeatedly fails at securing their devices from an attack vector that has been demonstrated over, and over, and over... no wonder China is banning government officials from using their devices.
Please... Androids no better. At least Apple will have it patched within the year of discovery. Can't say the same for other Android vendors.
This eliminates this whole class of attack.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#134Earlier quoted context omitted.
Your comment does not make sense at all. You are confusing security (no exploits) with privacy (encryption). The iMessage system is really private (no third party not even Apple can read your messages) but traditionally full of security holes (messages once decrypted can harm the rest of your device).
You appear to be the one confused. I'm not confusing anything. The entire point of the exploits in question are to BREAK the privacy provided by messenger. Google doesn't provide any in the first place, and actively mines your data. Who needs an exploit when it's never encrypted in the first place? To further this: you realize NSO isn't selling these exploits to Russian kiddies to steal your bank info, right? These e…
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#135Earlier quoted context omitted.
This is the frustrating part: that is cool from a technical perspective but terrifying when you think about this stuff being used to target journalists, activists, etc. Maybe not everyone gets the bone saw but some will - and from the sounds of it it’s people standing up to abusive people: > Last week, while checking the device of an individual employed by a Washington DC-based civil society organization with interna…
What is frustrating is the NSO group continues to exist despite all the bad they do. How many people are they responsible for being on the receiving end of a bone saw?
Check out The Palestine Laboratory: How Israel Exports the Technology of Occupation Around the World
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#136Earlier quoted context omitted.
Isn't Messages E2E by default?
RCS is E2EE: https://support.google.com/messages/answer/10262381?hl=en Though it can fall back to SMS in case you don't have data, which isn't E2EE. I'm not sure what the UX flow is like in that case, whether it warns you and asks for permission to send over less secure channel.
I was under the impression that this is a 'proprietary' extension between Google devices, and that there was no RCS-standard-based E2EE:
> The RCS specification defines several types of messages. Our implementation of E2EE uses varying strategies for encrypting each type of message to maximize user privacy while still adhering to the RCS specification.
* https://www.gstatic.com/messages/papers/messages_e2ee.pdf
They use "vnd.google.rcs.encrypted" in the Content-Type header.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#137Earlier quoted context omitted.
>no wonder China is banning government officials from using their devices. Do you actually think security is the reason they are being banned? I think the reasons are far more political than technical.
Technology is political.
> And the whole reason for the hydrogen burning [by SLS' engines] was to keep the space shuttle contractors jobs. Once again it's not a technical reason but a pork barrel one.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#138Earlier quoted context omitted.
Please... Androids no better. At least Apple will have it patched within the year of discovery. Can't say the same for other Android vendors.
Android is moving away from C and towards more secure languages. From one of their recent blog posts, the majority of code written for android is now in memory safe languages.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#139Earlier quoted context omitted.
I would describe a one click rootkit as terrifying as opposed to wonderful.
If it makes you feel better the click was actually unnecessary theater.