I find it interesting that most comments here are blaming the victim (Apple’s iMessage and by transitivity its users) rather than the aggressor (NSO and its users). How come NSO isn’t yet designated as a (cyber-)terrorist group worth hunting down and extinguishing?
NSO group iPhone zero-click, zero-day exploit captured in the wild
341–350 of 886 posts
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#342Again a buffer overflow in image decoding, that sounds similar to the one from 2021 [1]. That one was wild, building a CPU out of primitives offered by an arcane image compression format embedded in pdf, to be able to do enough arithmetic to further escalate to arbitrary code execution! [1]: https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...
Maybe a dumb question, but why are media decoders, which are notoriously high risk, not well sandboxed?
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#343Earlier quoted context omitted.
At the risk of being boring: software liability would go a long way towards getting companies to do this work themselves. Even though Apple is the largest company on the planet an entity that has a small fraction of the budget is apparently able to do a better job. I don't see why Apple couldn't make those people an offer they can't refuse. That takes them off the market and has them doing something productive.
If Apple buys NSO Group and shuts it down, other firms are incentivized to enter the market especially because of the prospect of a nice payday if Apple buys the new firm, too.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#344I appreciate that a solution is for people to update immediately. It really makes me wonder if my Android phones over the years have had 1-days exploited by the sheer incompetence of the ecosystem in updating phones. Not much confidence when you get an update with security patches from 2-3 months ago.
These exploits are highly targeted, they aren't just flying around hitting random devices.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#345Earlier quoted context omitted.
I’d settle for being able to toggle the individual controls (specifically iMessage attachments) instead of full lockdown mode.
YES! Current lockdown mode proposition of all-or-nothing is inconvenient.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#346Earlier quoted context omitted.
I’d settle for being able to toggle the individual controls (specifically iMessage attachments) instead of full lockdown mode.
YES! Current lockdown mode proposition of all-or-nothing is inconvenient.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#347Does anyone know to what extent this compromises the device? I might have missed it, but didn’t see it explained in the article. Does the attacker get full access to the device, or do they only compromise a subset of the devices functionality?
They say at the top that the exploit can install Pegasus, so probably some or all of Pegasus's functionality. That doesn't really narrow it down, but it likely can constantly run in the background, use the sensors, read texts, and send info over the internet at least.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#348Earlier quoted context omitted.
> No one can pay these guys enough I’m sure there are a lot of committed patriots there but I doubt it’s the whole company. Tim Cook could drop 1% of their cash on hand and see how many of them would turn down a million or two as a signing bonus, and if that didn’t work he could escalate to 10% or toss in some stock. I find it unlikely that wouldn’t tempt a lot of people, especially since the U.S. is one of Israel’s…
I think you’re misunderstanding. Mossad likely wouldn’t let anyone pay enough. Or let NSO accept. Unless they were already friends enough to not need to worry much about cost.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#349Earlier quoted context omitted.
If they didn’t exist it would be a different company in Russia or China. The demand exists.
Maybe that’s true, it probably is, but they should still be sanctioned into oblivion considering they consistently are in the headlines on the wrong end of this being used for deeply questionable purposes.
Regardless, sanctions don’t, and never have, actually solved anything. We just ignore the data because no one has a better idea.
NSO group will be its own worst enemy anyways as greed leads them into bed with the wrong people.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#350Earlier quoted context omitted.
Or you’d have separate rules, similar to how you can make kit cars or ultralight airplanes without being held to the same scrutiny as Boeing or GM.
...implying the scrutiny Boeing is held to does anything beneficial . The regulatory capture resulted in a pathological operating module that put over 346 in an early grave because they couldn't be arsed to not cut corners; then on top of ot all, there's no substantive finding of liability or wrongdoing. Laws that are ultimately unenforced due to 2B2F might as well not exist at all.