Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

251–260 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#251

Earlier quoted context omitted.

At the risk of being boring: software liability would go a long way towards getting companies to do this work themselves. Even though Apple is the largest company on the planet an entity that has a small fraction of the budget is apparently able to do a better job. I don't see why Apple couldn't make those people an offer they can't refuse. That takes them off the market and has them doing something productive.

> Even though Apple is the largest company on the planet an entity that has a small fraction of the budget is apparently able to do a better job. NSO Group is Israeli and (most likely) filled to the brim with former Unit 8200 staff. About the best of the best what the IDF has to offer - they've been said to match the NSA in quality. > I don't see why Apple couldn't make those people an offer they can't refuse. For al…

So stop shipping iPhones to Israel until they play ball. If they're that smart they can roll their own phones. These companies do immense damage and endanger lives the world over. Given enough time and budget there is nothing that can't be cracked and it's the very worst actors that have access to this stuff.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#252
post #122
post #109

Earlier quoted context omitted.

This is the frustrating part: that is cool from a technical perspective but terrifying when you think about this stuff being used to target journalists, activists, etc. Maybe not everyone gets the bone saw but some will - and from the sounds of it it’s people standing up to abusive people: > Last week, while checking the device of an individual employed by a Washington DC-based civil society organization with interna…

What is frustrating is the NSO group continues to exist despite all the bad they do. How many people are they responsible for being on the receiving end of a bone saw?

Are you sure they are doing so much bad? They get some press for it, but the rule about news is they report only the non-typical thing.

The vast majority of the NSO's work is stuff you would not object to, but that's boring and doesn't qualify as news.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#253

Earlier quoted context omitted.

And a much older bug with TIF rendering in iOS 4 used by jailbreakme.com back in the day. It was wonderful pressing a button in Safari and suddenly seeing my iPod touch reboot with Cydia installed.

Huh? I could've sworn the TIFF bug was during the iPhoneOS 1.x days. I recall jailbreakme's exploit using corrupted fonts in a PDF, not TIFF images. A quick Google search led me to this https://appleinsider.com/articles/10/08/03/browser_based_ios...

Yeah, the tiff bug was one of the the first few iOS jailbreaks. The wiki says 1.0-1.1.1: https://www.theiphonewiki.com/wiki/LibTiff_Exploit

I wrote a patch to fix it that one of the jailbreaks used. I wasn't in the scene, but wanted to protect my ipod touch. So I figured out a patch and gave it to somebody named "pumpkin" on IRC. It's been a long time, but I remember it was fun to learn ARM assembly and figure out how to rewrite the code to get enough space to insert a test and return.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#254
post #204
post #143

Earlier quoted context omitted.

Why not implement all image codecs in a safer language instead? That would seem to tackle the problem at its root rather than relying on an implementation's age as a proxy for safety, given that that clearly isn't a good measure.

Firefox led a hand in making Rust, so I imagine if there is a browser that can make a more secure browsing experience, it would be Firefox, by making media decoders in Rust.

They also have an interesting sandbox thing using WebAssembly: https://blog.mozilla.org/attack-and-defense/2021/12/06/webas...

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#255
post #109

Earlier quoted context omitted.

And a much older bug with TIF rendering in iOS 4 used by jailbreakme.com back in the day. It was wonderful pressing a button in Safari and suddenly seeing my iPod touch reboot with Cydia installed.

This is the frustrating part: that is cool from a technical perspective but terrifying when you think about this stuff being used to target journalists, activists, etc. Maybe not everyone gets the bone saw but some will - and from the sounds of it it’s people standing up to abusive people: > Last week, while checking the device of an individual employed by a Washington DC-based civil society organization with interna…

Honestly I find it a little reassuring that these are the lenghts you have to go to find a reproducible exploit. Granted the failure mode is not great…

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#256

Earlier quoted context omitted.

> Even though Apple is the largest company on the planet an entity that has a small fraction of the budget is apparently able to do a better job. NSO Group is Israeli and (most likely) filled to the brim with former Unit 8200 staff. About the best of the best what the IDF has to offer - they've been said to match the NSA in quality. > I don't see why Apple couldn't make those people an offer they can't refuse. For al…

So stop shipping iPhones to Israel until they play ball. If they're that smart they can roll their own phones. These companies do immense damage and endanger lives the world over. Given enough time and budget there is nothing that can't be cracked and it's the very worst actors that have access to this stuff.

As much as I agree with you... I think it's most likely that the US NSA, UK's MI(whatever), Israel's Mossad and a bunch of other secret services all cooperate with each other. No way these guys get taken down, and no way that the sanctions that have been nominally announced actually get enforced at the murky, intransparent bottom layer of the secret services.

Someone has to crack open the phones of drug kingpins, terrorists etc. after all.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#257

Earlier quoted context omitted.

At the risk of being boring: software liability would go a long way towards getting companies to do this work themselves. Even though Apple is the largest company on the planet an entity that has a small fraction of the budget is apparently able to do a better job. I don't see why Apple couldn't make those people an offer they can't refuse. That takes them off the market and has them doing something productive.

I don’t understand your comment. Are you saying that involving trial lawyers and US juries to collect big settlements from Apple is going to stop the NSO Group? Or is it that the NSO Group should be liable for the actions of their clients?

I don't understand your comment either. You say you don't understand and then you give a choice between two narrow interpretations neither of which seems to cover what I wrote.

To make this a bit more productive:

If Apple were liable for their defective products then they might decide not to ship them at all until they can be sure enough that the risk of the lawsuits putting them out of business is small enough that they can absorb it.

This worked wonders for other industries (notably: automotive, airlines, medicine). It may slow them down a bit, you may have a wait a bit longer for the next iteration of some gadget. But that's a small price to pay in my opinion.

As for the NSO group: I'm suggesting that Apple use their well filled cash coffers to buy these guys out, and failing that that they use some of that money to sue them for all of the damages that Apple incurs as a result of their actions as well as any criminal charges that they might get to stick. See 'Skylarov'.

It wouldn't be the first time that a US judge finds fault with a foreign company. At a minimum it would slow them and their employees down to the point that they will be in a US jail the next time they visit Disneyland. If it works against illegal gambling operations I see no reason why that sort of mechanism can't be brought to bear against state sponsored hacking groups and their employees.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#258
post #215

Earlier quoted context omitted.

I would describe a one click rootkit as terrifying as opposed to wonderful.

I guess you've never had sudo before.

I don’t see the analogy. If I could visit a website and it runs sudo commands on my machine without my input then I would be scared.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#259
post #103
post #23

Here we go again... NSO Group has a long history of 0-click, 0-days against iMessage, and just a few months ago Kaspersky caught a different zero day iMessage exploit targeting their staff. If Apple repeatedly fails at securing their devices from an attack vector that has been demonstrated over, and over, and over... no wonder China is banning government officials from using their devices.

China not worried about 0-clicks on Apple. They are worried about US-Apple collusion with iOS software.

Funny because at the same time US govt is worried about China-Apple relationship

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#260

Earlier quoted context omitted.

If you show me software that's immune to advanced 0-days, I'll show you software that isn't usable.

Or just slow. If you don't care about optimization and run things in really inefficient sandboxes, security becomes a lot easier.

How fast does iMessage image decoding need to be?

And I mean this extremely rhetorically. The software launched along with the iPhone 4S. Going by geekbench, that CPU was 20-30 times weaker than a modern iPhone on a per-core basis.

I know the screens on the new phones are 5x bigger, but there is plenty of room for that sandbox.

Post reply on HN