Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

331–340 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#331

Earlier quoted context omitted.

The article references Lockdown mode [0] which appears to be Apple's solution for this (and other) class of zero days. [0] https://support.apple.com/en-ca/HT212650

Lockdown mode means you're able to use less stuff. In this case the "pass" feature doesn't exist in Lockdown mode and that's the attack target AIUI. So, if most people don't use it (because less stuff works) then it can be "successful" statistically because maybe the attackers aren't targeting the stuff you're allowed to use and you don't get exploited. But this isn't a stable solution really. If Lockdown is populari…

Of all the apps that I ran, only one banking app has failed in Lockdown mode. Everything else works just fine.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#333

Earlier quoted context omitted.

I’m not much into security but I’ll never forget this one. Fascinating.

Somebody know articles like this on different exploits? What a great read!

https://googleprojectzero.blogspot.com is a good place to start.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#334
post #214
post #111

Earlier quoted context omitted.

How on Earth do you not see how those are related?

Who needs zero-days if you control the entire software (client and server side) and hardware ecosystem?

It's impossible to create a backdoor that can only be used by the intended party

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#335
post #268

Earlier quoted context omitted.

> Even though Apple is the largest company on the planet an entity that has a small fraction of the budget is apparently able to do a better job. NSO Group is Israeli and (most likely) filled to the brim with former Unit 8200 staff. About the best of the best what the IDF has to offer - they've been said to match the NSA in quality. > I don't see why Apple couldn't make those people an offer they can't refuse. For al…

> No one can pay these guys enough I’m sure there are a lot of committed patriots there but I doubt it’s the whole company. Tim Cook could drop 1% of their cash on hand and see how many of them would turn down a million or two as a signing bonus, and if that didn’t work he could escalate to 10% or toss in some stock. I find it unlikely that wouldn’t tempt a lot of people, especially since the U.S. is one of Israel’s…

I think you’re misunderstanding. Mossad likely wouldn’t let anyone pay enough. Or let NSO accept.

Unless they were already friends enough to not need to worry much about cost.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#336

Its super interesting to me how much its emphasized that you shouldn't use Lockdown Mode unless you are a journalist or otherwise in direct palpable danger. They really do try to talk you out of it. Its curious, because there's very little difference in functionality (as experienced by the user) other than disabling a lot of Apple nonsense from running in the background expanding your attack surface. And everybody pa…

It does make iOS slightly more inconvenient, such as when adding each other on iMessage. And it severely reduces JavaScript performance in Safari. I think Apple wants to avoid making iOS feel slower or clunkier than Android. And zero-day spyware is usually targeted towards important individuals, not used for mass surveillance, so it indeed is a smaller risk to individual people. I'd prefer a third mode that compromis…

I would argue that iMessage is way to problematic to be used safetly, at all. By anyone. Full-stop. It also seems to be the primary attack vector of NSO related zero-days as well and its become known that phone country/area codes have relevance to its chance of succes in past exploits, which suggests a phone/messaging type attack vector.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#337

Earlier quoted context omitted.

It's not knowable for any, but it is knowable for some. You just have to build systems that are in the some and are inherently safe. Difficult, not impossible.

Difficult often implies additional resourcing and development related costs. Something that many companies are not willing to invest in since it will have a negative impact on the shareholder values. Often risks are accepted, and cybersecurity insurance is used to mitigate those risks.

I agree, I just wanted to clarify that isn't mathematically impossible to make provably secure systems. It's just hard enough that it's not often done.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#338
post #70

Again a buffer overflow in image decoding, that sounds similar to the one from 2021 [1]. That one was wild, building a CPU out of primitives offered by an arcane image compression format embedded in pdf, to be able to do enough arithmetic to further escalate to arbitrary code execution! [1]: https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...

[deleted]

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#339
post #23

Here we go again... NSO Group has a long history of 0-click, 0-days against iMessage, and just a few months ago Kaspersky caught a different zero day iMessage exploit targeting their staff. If Apple repeatedly fails at securing their devices from an attack vector that has been demonstrated over, and over, and over... no wonder China is banning government officials from using their devices.

[deleted]

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#340

Earlier quoted context omitted.

> Even though Apple is the largest company on the planet an entity that has a small fraction of the budget is apparently able to do a better job. NSO Group is Israeli and (most likely) filled to the brim with former Unit 8200 staff. About the best of the best what the IDF has to offer - they've been said to match the NSA in quality. > I don't see why Apple couldn't make those people an offer they can't refuse. For al…

NSO seems more like a business. If Israel wanted to, they could pay NSO to keep their software internal/private, no? The more devices that get exploited, the more exploits that get closed. That's how you lose your edge against your enemies. Unless they're so confident in their stream of exploits that it's worth burning a few. Or these nation states are buying the devices to operate these exploits and operating them i…

It appears that the Israeli government operates the same way as the Russian government with respect to their private black/gray hat companies and groups: hacking other people is OK, just don't hack our nationals or our institutions, and we're cool. And if they hack companies or people seen as hostile, so much the better.
Post reply on HN