Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

211–220 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#211

Earlier quoted context omitted.

The article references Lockdown mode [0] which appears to be Apple's solution for this (and other) class of zero days. [0] https://support.apple.com/en-ca/HT212650

Lockdown mode means you're able to use less stuff. In this case the "pass" feature doesn't exist in Lockdown mode and that's the attack target AIUI. So, if most people don't use it (because less stuff works) then it can be "successful" statistically because maybe the attackers aren't targeting the stuff you're allowed to use and you don't get exploited. But this isn't a stable solution really. If Lockdown is populari…

Lockdown mode massively reduces the attack surface, which would make it far harder to find an exploit.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#213
post #123

Earlier quoted context omitted.

Again buffer overflow in image decoding. Would think apple might just #threatmodel and #fuzz that to death... but you would be wrong. 2.7T market cap company can't do this...

Apple has a long history of investing in all kinds of mitigations and security devices that make the App Store model secure and an equally long history of procrastinating on what is again and again and again causing their customers to be exploited.

plausible deniability?

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#214
post #111
post #103

Earlier quoted context omitted.

China not worried about 0-clicks on Apple. They are worried about US-Apple collusion with iOS software.

How on Earth do you not see how those are related?

Who needs zero-days if you control the entire software (client and server side) and hardware ecosystem?

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#215

Earlier quoted context omitted.

And a much older bug with TIF rendering in iOS 4 used by jailbreakme.com back in the day. It was wonderful pressing a button in Safari and suddenly seeing my iPod touch reboot with Cydia installed.

I would describe a one click rootkit as terrifying as opposed to wonderful.

I guess you've never had sudo before.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#216
post #122
post #109

Earlier quoted context omitted.

This is the frustrating part: that is cool from a technical perspective but terrifying when you think about this stuff being used to target journalists, activists, etc. Maybe not everyone gets the bone saw but some will - and from the sounds of it it’s people standing up to abusive people: > Last week, while checking the device of an individual employed by a Washington DC-based civil society organization with interna…

What is frustrating is the NSO group continues to exist despite all the bad they do. How many people are they responsible for being on the receiving end of a bone saw?

At the risk of being boring: software liability would go a long way towards getting companies to do this work themselves. Even though Apple is the largest company on the planet an entity that has a small fraction of the budget is apparently able to do a better job. I don't see why Apple couldn't make those people an offer they can't refuse. That takes them off the market and has them doing something productive.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#217

Earlier quoted context omitted.

Probably seven figures

8 figures. easily. Apple itself pays $1-million for bug bounties of this type. https://security.apple.com/bounty/categories/

And worth every penny of that to avoid the PR that ensues with one of these in the wild.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#218
post #143

Earlier quoted context omitted.

Why not implement all image codecs in a safer language instead? That would seem to tackle the problem at its root rather than relying on an implementation's age as a proxy for safety, given that that clearly isn't a good measure.

Almost all people don't want to or aren't capable of implementing image codecs, the safer languages aren't fast enough to do it in, and the people who are capable of it don't want to learn them.

I'm sure that given a middling-to-Google (say, 30k) bounty it would be done. I'd give it a shot, anyways.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#219
post #70

Again a buffer overflow in image decoding, that sounds similar to the one from 2021 [1]. That one was wild, building a CPU out of primitives offered by an arcane image compression format embedded in pdf, to be able to do enough arithmetic to further escalate to arbitrary code execution! [1]: https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...

I’m not much into security but I’ll never forget this one. Fascinating.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#220

I appreciate that a solution is for people to update immediately. It really makes me wonder if my Android phones over the years have had 1-days exploited by the sheer incompetence of the ecosystem in updating phones. Not much confidence when you get an update with security patches from 2-3 months ago.

Google devices offer such better security posture than other Android manufactures.

Then there's the issue of privacy regarding Google devices.

I strongly suggest checking out the GrapheneOS project if Android security is of concern.

Post reply on HN