Earlier quoted context omitted.
The article references Lockdown mode [0] which appears to be Apple's solution for this (and other) class of zero days. [0] https://support.apple.com/en-ca/HT212650
Lockdown mode means you're able to use less stuff. In this case the "pass" feature doesn't exist in Lockdown mode and that's the attack target AIUI. So, if most people don't use it (because less stuff works) then it can be "successful" statistically because maybe the attackers aren't targeting the stuff you're allowed to use and you don't get exploited. But this isn't a stable solution really. If Lockdown is populari…
NSO group iPhone zero-click, zero-day exploit captured in the wild
211–220 of 886 posts
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#212[flagged]
The problem there isn't commercial Android phones, it's open source projects that can't guarantee anything.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#213Earlier quoted context omitted.
Again buffer overflow in image decoding. Would think apple might just #threatmodel and #fuzz that to death... but you would be wrong. 2.7T market cap company can't do this...
Apple has a long history of investing in all kinds of mitigations and security devices that make the App Store model secure and an equally long history of procrastinating on what is again and again and again causing their customers to be exploited.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#214Earlier quoted context omitted.
China not worried about 0-clicks on Apple. They are worried about US-Apple collusion with iOS software.
How on Earth do you not see how those are related?
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#215Earlier quoted context omitted.
And a much older bug with TIF rendering in iOS 4 used by jailbreakme.com back in the day. It was wonderful pressing a button in Safari and suddenly seeing my iPod touch reboot with Cydia installed.
I would describe a one click rootkit as terrifying as opposed to wonderful.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#216Earlier quoted context omitted.
This is the frustrating part: that is cool from a technical perspective but terrifying when you think about this stuff being used to target journalists, activists, etc. Maybe not everyone gets the bone saw but some will - and from the sounds of it it’s people standing up to abusive people: > Last week, while checking the device of an individual employed by a Washington DC-based civil society organization with interna…
What is frustrating is the NSO group continues to exist despite all the bad they do. How many people are they responsible for being on the receiving end of a bone saw?
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#217Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#218Earlier quoted context omitted.
Why not implement all image codecs in a safer language instead? That would seem to tackle the problem at its root rather than relying on an implementation's age as a proxy for safety, given that that clearly isn't a good measure.
Almost all people don't want to or aren't capable of implementing image codecs, the safer languages aren't fast enough to do it in, and the people who are capable of it don't want to learn them.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#219Again a buffer overflow in image decoding, that sounds similar to the one from 2021 [1]. That one was wild, building a CPU out of primitives offered by an arcane image compression format embedded in pdf, to be able to do enough arithmetic to further escalate to arbitrary code execution! [1]: https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#220I appreciate that a solution is for people to update immediately. It really makes me wonder if my Android phones over the years have had 1-days exploited by the sheer incompetence of the ecosystem in updating phones. Not much confidence when you get an update with security patches from 2-3 months ago.
Then there's the issue of privacy regarding Google devices.
I strongly suggest checking out the GrapheneOS project if Android security is of concern.