Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

341–350 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#341

I find it interesting that most comments here are blaming the victim (Apple’s iMessage and by transitivity its users) rather than the aggressor (NSO and its users). How come NSO isn’t yet designated as a (cyber-)terrorist group worth hunting down and extinguishing?

While NSO is, of course, not a good group, I think the larger problem is how prevent these exploits are. If NSO didn't find them, someone else would. I don't consider NSO to be the big problem here.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#342
post #70

Again a buffer overflow in image decoding, that sounds similar to the one from 2021 [1]. That one was wild, building a CPU out of primitives offered by an arcane image compression format embedded in pdf, to be able to do enough arithmetic to further escalate to arbitrary code execution! [1]: https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...

Maybe a dumb question, but why are media decoders, which are notoriously high risk, not well sandboxed?

And why haven’t they been rewritten yet considering it keeps happening.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#343

Earlier quoted context omitted.

At the risk of being boring: software liability would go a long way towards getting companies to do this work themselves. Even though Apple is the largest company on the planet an entity that has a small fraction of the budget is apparently able to do a better job. I don't see why Apple couldn't make those people an offer they can't refuse. That takes them off the market and has them doing something productive.

If Apple buys NSO Group and shuts it down, other firms are incentivized to enter the market especially because of the prospect of a nice payday if Apple buys the new firm, too.

Companies don't do things. People do. Shut down NSO and its skilled people will go elsewhere.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#344
post #131

I appreciate that a solution is for people to update immediately. It really makes me wonder if my Android phones over the years have had 1-days exploited by the sheer incompetence of the ecosystem in updating phones. Not much confidence when you get an update with security patches from 2-3 months ago.

These exploits are highly targeted, they aren't just flying around hitting random devices.

Only when they’re unknown. Once they’re known they’re built into shit like kali Linux.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#345
post #313

Earlier quoted context omitted.

I’d settle for being able to toggle the individual controls (specifically iMessage attachments) instead of full lockdown mode.

YES! Current lockdown mode proposition of all-or-nothing is inconvenient.

Why increase your security bug surface 2x when you can increase it exponentially!

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#346
post #313

Earlier quoted context omitted.

I’d settle for being able to toggle the individual controls (specifically iMessage attachments) instead of full lockdown mode.

YES! Current lockdown mode proposition of all-or-nothing is inconvenient.

I assume that inconvenience is intentional -- otherwise everyone would enable it.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#347

Does anyone know to what extent this compromises the device? I might have missed it, but didn’t see it explained in the article. Does the attacker get full access to the device, or do they only compromise a subset of the devices functionality?

They say at the top that the exploit can install Pegasus, so probably some or all of Pegasus's functionality. That doesn't really narrow it down, but it likely can constantly run in the background, use the sensors, read texts, and send info over the internet at least.

Doesn’t a reboot of the phone “fix” this?

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#348
post #335
post #268

Earlier quoted context omitted.

> No one can pay these guys enough I’m sure there are a lot of committed patriots there but I doubt it’s the whole company. Tim Cook could drop 1% of their cash on hand and see how many of them would turn down a million or two as a signing bonus, and if that didn’t work he could escalate to 10% or toss in some stock. I find it unlikely that wouldn’t tempt a lot of people, especially since the U.S. is one of Israel’s…

I think you’re misunderstanding. Mossad likely wouldn’t let anyone pay enough. Or let NSO accept. Unless they were already friends enough to not need to worry much about cost.

I understood but am skeptical of that - they'd block sale of the entire company but I think it'd be a surprise if they prevented a bunch of Israeli nationals from accepting prestigious jobs with an American company.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#349

Earlier quoted context omitted.

If they didn’t exist it would be a different company in Russia or China. The demand exists.

Maybe that’s true, it probably is, but they should still be sanctioned into oblivion considering they consistently are in the headlines on the wrong end of this being used for deeply questionable purposes.

Sanction who? Israel? Talk about political suicide!

Regardless, sanctions don’t, and never have, actually solved anything. We just ignore the data because no one has a better idea.

NSO group will be its own worst enemy anyways as greed leads them into bed with the wrong people.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#350
post #293

Earlier quoted context omitted.

Or you’d have separate rules, similar to how you can make kit cars or ultralight airplanes without being held to the same scrutiny as Boeing or GM.

...implying the scrutiny Boeing is held to does anything beneficial . The regulatory capture resulted in a pathological operating module that put over 346 in an early grave because they couldn't be arsed to not cut corners; then on top of ot all, there's no substantive finding of liability or wrongdoing. Laws that are ultimately unenforced due to 2B2F might as well not exist at all.

I don't want to defend Boeing's management but even with the worst failure in, what, half a century? it's still much safer to fly than drive so I wouldn't be so quick to throw aviation security culture under the bus.
Post reply on HN