Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

261–270 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#261

> The exploit chain was capable of compromising iPhones running the latest version of iOS (16.6) without any interaction from the victim. I’m, in no way, a security savvy but the above achievement must be a lot of work by the NSO group!

Aren't these zero-days sold to highest bidders? Just an honest days work...

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#262

Earlier quoted context omitted.

Or just slow. If you don't care about optimization and run things in really inefficient sandboxes, security becomes a lot easier.

How fast does iMessage image decoding need to be? And I mean this extremely rhetorically. The software launched along with the iPhone 4S. Going by geekbench, that CPU was 20-30 times weaker than a modern iPhone on a per-core basis. I know the screens on the new phones are 5x bigger, but there is plenty of room for that sandbox.

I'm guessing it's a shared systemwide decoder that happens to be exploitable in Message, but idk.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#263
post #38
post #23

Here we go again... NSO Group has a long history of 0-click, 0-days against iMessage, and just a few months ago Kaspersky caught a different zero day iMessage exploit targeting their staff. If Apple repeatedly fails at securing their devices from an attack vector that has been demonstrated over, and over, and over... no wonder China is banning government officials from using their devices.

Please... Androids no better. At least Apple will have it patched within the year of discovery. Can't say the same for other Android vendors.

> Androids no better.

That does not make the situation right for Apple.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#264

Earlier quoted context omitted.

> Even though Apple is the largest company on the planet an entity that has a small fraction of the budget is apparently able to do a better job. NSO Group is Israeli and (most likely) filled to the brim with former Unit 8200 staff. About the best of the best what the IDF has to offer - they've been said to match the NSA in quality. > I don't see why Apple couldn't make those people an offer they can't refuse. For al…

So stop shipping iPhones to Israel until they play ball. If they're that smart they can roll their own phones. These companies do immense damage and endanger lives the world over. Given enough time and budget there is nothing that can't be cracked and it's the very worst actors that have access to this stuff.

? They'll just buy iPhones in some other country.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#266
post #23

Here we go again... NSO Group has a long history of 0-click, 0-days against iMessage, and just a few months ago Kaspersky caught a different zero day iMessage exploit targeting their staff. If Apple repeatedly fails at securing their devices from an attack vector that has been demonstrated over, and over, and over... no wonder China is banning government officials from using their devices.

>no wonder China is banning government officials from using their devices. Do you actually think security is the reason they are being banned? I think the reasons are far more political than technical.

>I think the reasons are far more political than technical.

You may be right but sometimes the local optics track better when a political reason is given and the local authorities might also expect better compliance with political reasoning. Similarly, "We are getting pwned," never tracks well. There are solid reasons, long ago, why China stopped using Nortel.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#267

[flagged]

I've never met a person who threw away a phone because of the lack of updates.

I've decided to upgrade instead of fix a 3-year-old phone that was because even if I could fix the hardware I still would not be able to safely enable bluetooth due to an arbitrary code execution bug in android that was not patched. It was otherwise perfectly good for my needs. I could not install a custom ROM because my model was not well supported and any I could not rely on such ROMs passing safetynet/play secure checks which the extremely vulnerable OEM ROM would reliably pass.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#268

Earlier quoted context omitted.

At the risk of being boring: software liability would go a long way towards getting companies to do this work themselves. Even though Apple is the largest company on the planet an entity that has a small fraction of the budget is apparently able to do a better job. I don't see why Apple couldn't make those people an offer they can't refuse. That takes them off the market and has them doing something productive.

> Even though Apple is the largest company on the planet an entity that has a small fraction of the budget is apparently able to do a better job. NSO Group is Israeli and (most likely) filled to the brim with former Unit 8200 staff. About the best of the best what the IDF has to offer - they've been said to match the NSA in quality. > I don't see why Apple couldn't make those people an offer they can't refuse. For al…

> No one can pay these guys enough

I’m sure there are a lot of committed patriots there but I doubt it’s the whole company. Tim Cook could drop 1% of their cash on hand and see how many of them would turn down a million or two as a signing bonus, and if that didn’t work he could escalate to 10% or toss in some stock. I find it unlikely that wouldn’t tempt a lot of people, especially since the U.S. is one of Israel’s staunchest allies so it’d be pretty easy to tell yourself that pile of cash isn’t selling out.

The real reason they don’t do that is trust: how could you ever be confident that someone wasn’t passing information back to Unit 8200 or even helping them out?

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#269
post #83
post #36

Earlier quoted context omitted.

Your comment does not make sense at all. You are confusing security (no exploits) with privacy (encryption). The iMessage system is really private (no third party not even Apple can read your messages) but traditionally full of security holes (messages once decrypted can harm the rest of your device).

You appear to be the one confused. I'm not confusing anything. The entire point of the exploits in question are to BREAK the privacy provided by messenger. Google doesn't provide any in the first place, and actively mines your data. Who needs an exploit when it's never encrypted in the first place? To further this: you realize NSO isn't selling these exploits to Russian kiddies to steal your bank info, right? These e…

> Who needs an exploit when it's never encrypted in the first place?

Someone that can't get a valid subpoena.

Someone that wants to track anything else you do on your phone outside the messaging app.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#270

Earlier quoted context omitted.

So stop shipping iPhones to Israel until they play ball. If they're that smart they can roll their own phones. These companies do immense damage and endanger lives the world over. Given enough time and budget there is nothing that can't be cracked and it's the very worst actors that have access to this stuff.

? They'll just buy iPhones in some other country.

GPS is a thing. iPhones have GPS.
Post reply on HN