Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

131–140 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#131

I appreciate that a solution is for people to update immediately. It really makes me wonder if my Android phones over the years have had 1-days exploited by the sheer incompetence of the ecosystem in updating phones. Not much confidence when you get an update with security patches from 2-3 months ago.

These exploits are highly targeted, they aren't just flying around hitting random devices.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#132

[flagged]

1) What does this topic have to do with Android? 2) EU politicians don't know about Android updates because they don't understand how SW works and most probably have iOS anyway. The only time they hear about tech is when some Joe Schmoe insults them on Facebook so they send the courts after Facebook to doxx that person and get Facebook to moderate and ban "hate speech" on their platform. All in a day's work. Granted,…

> Mr. CEO, can TikTok access my WiFi?

That wasn’t a bad or mock-worthy question at all. TikTok’s app requests access to devices on the user’s local network. Why does it do that? Officially in order to connect to TVs/speakers, but what else could it decide to do with the access it’s granted?

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#133
post #38
post #23

Here we go again... NSO Group has a long history of 0-click, 0-days against iMessage, and just a few months ago Kaspersky caught a different zero day iMessage exploit targeting their staff. If Apple repeatedly fails at securing their devices from an attack vector that has been demonstrated over, and over, and over... no wonder China is banning government officials from using their devices.

Please... Androids no better. At least Apple will have it patched within the year of discovery. Can't say the same for other Android vendors.

On Android you can disable automatic link preview and downloading of MMS messages. You can also swap out the application that handles text messages entirely.

This eliminates this whole class of attack.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#134
post #83
post #36

Earlier quoted context omitted.

Your comment does not make sense at all. You are confusing security (no exploits) with privacy (encryption). The iMessage system is really private (no third party not even Apple can read your messages) but traditionally full of security holes (messages once decrypted can harm the rest of your device).

You appear to be the one confused. I'm not confusing anything. The entire point of the exploits in question are to BREAK the privacy provided by messenger. Google doesn't provide any in the first place, and actively mines your data. Who needs an exploit when it's never encrypted in the first place? To further this: you realize NSO isn't selling these exploits to Russian kiddies to steal your bank info, right? These e…

It not being e2e-enxrypted doesn't mean that the Mexican army can read my messages.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#135
post #122
post #109

Earlier quoted context omitted.

This is the frustrating part: that is cool from a technical perspective but terrifying when you think about this stuff being used to target journalists, activists, etc. Maybe not everyone gets the bone saw but some will - and from the sounds of it it’s people standing up to abusive people: > Last week, while checking the device of an individual employed by a Washington DC-based civil society organization with interna…

What is frustrating is the NSO group continues to exist despite all the bad they do. How many people are they responsible for being on the receiving end of a bone saw?

It continues to exist because state governments have an interest for it to exist

Check out The Palestine Laboratory: How Israel Exports the Technology of Occupation Around the World

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#136
post #8

Earlier quoted context omitted.

Isn't Messages E2E by default?

RCS is E2EE: https://support.google.com/messages/answer/10262381?hl=en Though it can fall back to SMS in case you don't have data, which isn't E2EE. I'm not sure what the UX flow is like in that case, whether it warns you and asks for permission to send over less secure channel.

> RCS is E2EE: https://support.google.com/messages/answer/10262381?hl=en

I was under the impression that this is a 'proprietary' extension between Google devices, and that there was no RCS-standard-based E2EE:

> The RCS specification defines several types of messages. Our implementation of E2EE uses varying strategies for encrypting each type of message to maximize user privacy while still adhering to the RCS specification.

* https://www.gstatic.com/messages/papers/messages_e2ee.pdf

They use "vnd.google.rcs.encrypted" in the Content-Type header.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#137

Earlier quoted context omitted.

>no wonder China is banning government officials from using their devices. Do you actually think security is the reason they are being banned? I think the reasons are far more political than technical.

Technology is political.

To foster your point, I quote a comment from another post on HN now

> And the whole reason for the hydrogen burning [by SLS' engines] was to keep the space shuttle contractors jobs. Once again it's not a technical reason but a pork barrel one.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#138
post #38

Earlier quoted context omitted.

Please... Androids no better. At least Apple will have it patched within the year of discovery. Can't say the same for other Android vendors.

Android is moving away from C and towards more secure languages. From one of their recent blog posts, the majority of code written for android is now in memory safe languages.

Google at large is slowly banning use of non memory safe languages. Android in particular is doing well at adopting Rust.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#139
post #95

Earlier quoted context omitted.

I would describe a one click rootkit as terrifying as opposed to wonderful.

If it makes you feel better the click was actually unnecessary theater.

Running an exploit against any visiting device without a disclaimer/button probably gets you into very spicy territory from a legal point of view.
Post reply on HN