Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

231–240 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#231
post #208

Earlier quoted context omitted.

Almost all people don't want to or aren't capable of implementing image codecs, the safer languages aren't fast enough to do it in, and the people who are capable of it don't want to learn them.

All good points, but hopefully Google would be able to find the resources to overcome these?

It can be overcome with time and it is getting better, those are just the historical reasons it's not already better.

Google has contributed lots of fuzzing time and security improvements to eg ffmpeg already.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#232
post #54

[flagged]

I just checked for updates for my Apple Watch as well, and I see an update for it ("This update provides important security fixes and is recommended for all users" - watchOS 9.6.2). I remember attempting to update earlier in the week (Tuesday?), and I don't remember seeing anything that day. I don't know if the update is related or not, but I decided to share anyway.

It is related: https://support.apple.com/en-ca/HT213907

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#233

Earlier quoted context omitted.

The article references Lockdown mode [0] which appears to be Apple's solution for this (and other) class of zero days. [0] https://support.apple.com/en-ca/HT212650

Lockdown mode means you're able to use less stuff. In this case the "pass" feature doesn't exist in Lockdown mode and that's the attack target AIUI. So, if most people don't use it (because less stuff works) then it can be "successful" statistically because maybe the attackers aren't targeting the stuff you're allowed to use and you don't get exploited. But this isn't a stable solution really. If Lockdown is populari…

The downsides of using Lockdown Mode are minimal and well worth if you are an at-risk target. It's about reducing the attack surface and potentially getting notified if nation state actors try to attack your phone.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#234
Its super interesting to me how much its emphasized that you shouldn't use Lockdown Mode unless you are a journalist or otherwise in direct palpable danger. They really do try to talk you out of it. Its curious, because there's very little difference in functionality (as experienced by the user) other than disabling a lot of Apple nonsense from running in the background expanding your attack surface.

And everybody parrots the nonsense caveat that everyone shouldn't use it, only those special enough should like it was a zero-sum game or scarce resource. Everyone should use it because it disables a lot of nonsense that doesn't serve you and probably even saves battery power. Also, the more people use it, the less it can be used to fingerprint specific users.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#235
post #70

Again a buffer overflow in image decoding, that sounds similar to the one from 2021 [1]. That one was wild, building a CPU out of primitives offered by an arcane image compression format embedded in pdf, to be able to do enough arithmetic to further escalate to arbitrary code execution! [1]: https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...

Will Rust be able to prevent such overflows?

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#236

Wow this sounds like stagefright was way back when. So for those keeping score, is Android now ahead of iOS in this aspect of security?

The price of an Android zero-click is now 500k more than the price of an iOS zero-click for Zerodium now. It would appear they have a significant stock of iOS zero-clicks and a lesser amount for Android:

https://zerodium.com/program.html

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#237
post #109

Earlier quoted context omitted.

And a much older bug with TIF rendering in iOS 4 used by jailbreakme.com back in the day. It was wonderful pressing a button in Safari and suddenly seeing my iPod touch reboot with Cydia installed.

This is the frustrating part: that is cool from a technical perspective but terrifying when you think about this stuff being used to target journalists, activists, etc. Maybe not everyone gets the bone saw but some will - and from the sounds of it it’s people standing up to abusive people: > Last week, while checking the device of an individual employed by a Washington DC-based civil society organization with interna…

The interesting thing is that, as the article states, Lockdown Mode, which is intended for users with exactly that kind of risk profile, does in fact prevent this attack.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#238
post #122

Earlier quoted context omitted.

What is frustrating is the NSO group continues to exist despite all the bad they do. How many people are they responsible for being on the receiving end of a bone saw?

At the risk of being boring: software liability would go a long way towards getting companies to do this work themselves. Even though Apple is the largest company on the planet an entity that has a small fraction of the budget is apparently able to do a better job. I don't see why Apple couldn't make those people an offer they can't refuse. That takes them off the market and has them doing something productive.

I don’t understand your comment. Are you saying that involving trial lawyers and US juries to collect big settlements from Apple is going to stop the NSO Group? Or is it that the NSO Group should be liable for the actions of their clients?

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#239

Earlier quoted context omitted.

Apple isn’t going to have internal bounties that can compete with nation state budgets.

Apples revenue isn’t much lower than Israel’s GDP and NSO isn’t really a nation state actor.

NSO is reported to consist of mostly Unit 8200 staff. No way they're not deeply connected with the Israeli government.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#240

Earlier quoted context omitted.

Apple isn’t going to have internal bounties that can compete with nation state budgets.

Apple has annual revenue greater than the GDP of any of the bottom ~4/5 of nation-states.

Those countries aren't the ones using these exploits either.
Post reply on HN