Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

171–180 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#171
How many exploits has iMessage had now?

Isn't it time we made first messages from all new contacts plain text only, and all other messages some very restricted subset rather than some crazy extensible system that isn't so different from ActiveX?

And on top of that, maybe the whole app should run in a sandbox.

And on top of that, perhaps it should all be a webview to give one more layer of protection.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#172
post #99

Earlier quoted context omitted.

Android is moving away from C and towards more secure languages. From one of their recent blog posts, the majority of code written for android is now in memory safe languages.

Is the programming language likely the issue here?

Yes, almost all of these major exploits are memory safety related and would be mostly impossible in a memory safe language.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#173
post #123

Earlier quoted context omitted.

Again buffer overflow in image decoding. Would think apple might just #threatmodel and #fuzz that to death... but you would be wrong. 2.7T market cap company can't do this...

Apple isn’t going to have internal bounties that can compete with nation state budgets.

Apple has annual revenue greater than the GDP of any of the bottom ~4/5 of nation-states.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#174
post #97

Earlier quoted context omitted.

These things are not mutually exclusive, iirc they are doing appliances & cars, it's just that phones are often highlighted & batteries are usually the first thing that fails and can be easily replaced in all cases die to how build electronics. Charger standardization was in the pipeline for about a decade so not exactly a priority it being only passed now.

Yes and 10 years ago the EU wanted to standardize on Micro USB. That’s not exactly a rousing endorsement on EU regulation.

They didn't specify micro-b just that the phonemakers should settle on a port (which is partially why they didn't mandate it, the hope was that the industry would figure itself out but it didn't). Micro-b at the time was the most popular port for any handheld appliance. USB-C was only published in 2014.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#175
post #99

Earlier quoted context omitted.

Android is moving away from C and towards more secure languages. From one of their recent blog posts, the majority of code written for android is now in memory safe languages.

Is the programming language likely the issue here?

That's like asking whether it is the lack of a seatbelt that was the issue after sometime died in a car crash.

Well, of course the real issue was the car crash. But wearing a seatbelt would have sure helped!

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#176

Earlier quoted context omitted.

Apple isn’t going to have internal bounties that can compete with nation state budgets.

Apple is a nation state.

Apple has more employees than Kiribati's population.

More employees than the smallest 60 countries.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#177
post #143

Earlier quoted context omitted.

Why not implement all image codecs in a safer language instead? That would seem to tackle the problem at its root rather than relying on an implementation's age as a proxy for safety, given that that clearly isn't a good measure.

That's a great question, and I'd love to know the answer.

Adding something in rust into a browser means you now need to bundle all of the needed crates and that your browser now also needs rustc to build… at a minimum.

You also need potentially to audit all the crates and keep them up to date and so on… without crates you can't do so much.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#178
post #123

Earlier quoted context omitted.

Again buffer overflow in image decoding. Would think apple might just #threatmodel and #fuzz that to death... but you would be wrong. 2.7T market cap company can't do this...

Apple isn’t going to have internal bounties that can compete with nation state budgets.

Apples revenue isn’t much lower than Israel’s GDP and NSO isn’t really a nation state actor.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#179
post #38
post #23

Here we go again... NSO Group has a long history of 0-click, 0-days against iMessage, and just a few months ago Kaspersky caught a different zero day iMessage exploit targeting their staff. If Apple repeatedly fails at securing their devices from an attack vector that has been demonstrated over, and over, and over... no wonder China is banning government officials from using their devices.

Please... Androids no better. At least Apple will have it patched within the year of discovery. Can't say the same for other Android vendors.

I have friends with Android phones that are running 5-year-old operating systems.

I have one friend that absolutely refuses to update his 7-year-old Samsung.

I got the fix on my phones (including my 8), iPads and Watch, today.

Post reply on HN