Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

201–210 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#201
post #70

Again a buffer overflow in image decoding, that sounds similar to the one from 2021 [1]. That one was wild, building a CPU out of primitives offered by an arcane image compression format embedded in pdf, to be able to do enough arithmetic to further escalate to arbitrary code execution! [1]: https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...

Maybe a dumb question, but why are media decoders, which are notoriously high risk, not well sandboxed?

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#202
post #52
post #42

For anyone interested in learning more about the NSO group, I'd recommend this podcast episode: https://darknetdiaries.com/episode/100/

[flagged]

No, we don’t pay them to hack our phones.

Most governments are paying for these services as spying is a recognized arm of statecraft that has actually prevented many wars/conflicts.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#203

So at what point does the world bring sanctions against Israel for allowing organizations like this to exist there? Everyone knows NSO is just a dubiously legal version of common APT groups, so how do they still exist after these years?

Game theory. They alert the big players of who is doing what, if they didn’t exist, China and Russia would get all this business and be at the cutting edge (and not share the most pertinent info).

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#204
post #143

Earlier quoted context omitted.

Which actually makes me more sympathetic to Chrome not (yet) adopting JPEG-XL. Don't get me wrong, I think JPEG-XL is a great idea, but to everyone saying "how can supporting another image format possibly do any harm", this is the answer.

Why not implement all image codecs in a safer language instead? That would seem to tackle the problem at its root rather than relying on an implementation's age as a proxy for safety, given that that clearly isn't a good measure.

Firefox led a hand in making Rust, so I imagine if there is a browser that can make a more secure browsing experience, it would be Firefox, by making media decoders in Rust.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#205

Earlier quoted context omitted.

Apple isn’t going to have internal bounties that can compete with nation state budgets.

Apple has annual revenue greater than the GDP of any of the bottom ~4/5 of nation-states.

The problem with internal bounties is that you'd be granting them to the people with power to put in the security holes they find.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#206
post #23

Here we go again... NSO Group has a long history of 0-click, 0-days against iMessage, and just a few months ago Kaspersky caught a different zero day iMessage exploit targeting their staff. If Apple repeatedly fails at securing their devices from an attack vector that has been demonstrated over, and over, and over... no wonder China is banning government officials from using their devices.

Hahha what? True banned them because they’re American.

There may be some zero days that NSO has exploited but it’s nothing like the cluster that is Android.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#207
post #143

Earlier quoted context omitted.

Which actually makes me more sympathetic to Chrome not (yet) adopting JPEG-XL. Don't get me wrong, I think JPEG-XL is a great idea, but to everyone saying "how can supporting another image format possibly do any harm", this is the answer.

Why not implement all image codecs in a safer language instead? That would seem to tackle the problem at its root rather than relying on an implementation's age as a proxy for safety, given that that clearly isn't a good measure.

Almost all people don't want to or aren't capable of implementing image codecs, the safer languages aren't fast enough to do it in, and the people who are capable of it don't want to learn them.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#208
post #143

Earlier quoted context omitted.

Why not implement all image codecs in a safer language instead? That would seem to tackle the problem at its root rather than relying on an implementation's age as a proxy for safety, given that that clearly isn't a good measure.

Almost all people don't want to or aren't capable of implementing image codecs, the safer languages aren't fast enough to do it in, and the people who are capable of it don't want to learn them.

All good points, but hopefully Google would be able to find the resources to overcome these?

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#209
post #124
post #38

Earlier quoted context omitted.

Please... Androids no better. At least Apple will have it patched within the year of discovery. Can't say the same for other Android vendors.

>Please... Androids no better. The Pixel is. >At least Apple will have it patched within the year of discovery. Can't say the same for other Android vendors. And the Pixel would have the patch released quicker.

The pixel is decent if using graphene is. Not sure if any system is good by default. Apple fans think their defaults are somehow more private or secure, mostly due to marketing.
Post reply on HN