Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

351–360 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#351
post #122

Earlier quoted context omitted.

What is frustrating is the NSO group continues to exist despite all the bad they do. How many people are they responsible for being on the receiving end of a bone saw?

At the risk of being boring: software liability would go a long way towards getting companies to do this work themselves. Even though Apple is the largest company on the planet an entity that has a small fraction of the budget is apparently able to do a better job. I don't see why Apple couldn't make those people an offer they can't refuse. That takes them off the market and has them doing something productive.

[flagged]

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#352
post #90

Earlier quoted context omitted.

Some of the problems with iMessage have to do with the fact that it's integrated with the system SMS app. It seems that there are a large number of legacy requirements in the GSM spec that require the Messages app to be privileged in some way, especially with regards to automatic processing of data received. There have been plenty of iMessage or Messages related vulnerabilities. I do wish there was a way to turn off…

One can't even mark all messages as read in iMessage, which seems to me like the most basic functionality. Something is really messed up in how this thing has to run if you can't do that

Try the ... menu > Select Messages > Read All at the bottom of the screen.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#353
post #209
post #124

Earlier quoted context omitted.

>Please... Androids no better. The Pixel is. >At least Apple will have it patched within the year of discovery. Can't say the same for other Android vendors. And the Pixel would have the patch released quicker.

The pixel is decent if using graphene is . Not sure if any system is good by default. Apple fans think their defaults are somehow more private or secure, mostly due to marketing.

Decent? From a security perspective it's superior to the iPhone. As for Graphene, unless you've personally vetted the code I don't see how it can be trusted. And I won't even go into the drama that OS comes with.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#354

Earlier quoted context omitted.

At the risk of being boring: software liability would go a long way towards getting companies to do this work themselves. Even though Apple is the largest company on the planet an entity that has a small fraction of the budget is apparently able to do a better job. I don't see why Apple couldn't make those people an offer they can't refuse. That takes them off the market and has them doing something productive.

Software liability would effectively crush smaller companies, unable to keep up with the lawsuits, because they don't have billions in the bank.

I think you should really think about what you're saying. Would you cut makers of physical artifacts the same slack, say a small prepared food producer who just can't afford to vet their supply chain or final product to make sure it's not contaminated?

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#355

Earlier quoted context omitted.

Apple has more employees than Kiribati's population. More employees than the smallest 60 countries.

Most of those people are not engineers.

Micronesians or Apple employees?

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#356
post #108
post #95

Earlier quoted context omitted.

If it makes you feel better the click was actually unnecessary theater.

Yeah, the whole way that the jailbreaks installed was scary enough for me to never want to go near them.

Your phone would reboot with a pineapple logo and console messages flying across the screen like a 1337 h4cker, starting with the "regents of the University of California, Berkeley" message. Then you'd go install a ton of Cydia hacks.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#357
post #348
post #335

Earlier quoted context omitted.

I think you’re misunderstanding. Mossad likely wouldn’t let anyone pay enough. Or let NSO accept. Unless they were already friends enough to not need to worry much about cost.

I understood but am skeptical of that - they'd block sale of the entire company but I think it'd be a surprise if they prevented a bunch of Israeli nationals from accepting prestigious jobs with an American company.

1) of course they would. Or worse (see Gerald bull).

2) any company doing that would have to be insanely naive or reckless.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#358
post #208

Earlier quoted context omitted.

Almost all people don't want to or aren't capable of implementing image codecs, the safer languages aren't fast enough to do it in, and the people who are capable of it don't want to learn them.

All good points, but hopefully Google would be able to find the resources to overcome these?

Google encourages all new native code in Android to be written in Rust. Rust-based codecs can certainly reach the speeds of C++. And it does rule out memory safety bugs. https://security.googleblog.com/2022/12/memory-safe-language...

Of course as the blog post says, just because memory safety bugs are overcome doesn't mean vulnerabilities have stopped; people find other kinds of vulnerability now.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#359
post #343

Earlier quoted context omitted.

If Apple buys NSO Group and shuts it down, other firms are incentivized to enter the market especially because of the prospect of a nice payday if Apple buys the new firm, too.

Companies don't do things. People do. Shut down NSO and its skilled people will go elsewhere.

So do we agree that Apple's buying NSO Group wouldn't permanently make the problem better?

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#360

Earlier quoted context omitted.

At the risk of being boring: software liability would go a long way towards getting companies to do this work themselves. Even though Apple is the largest company on the planet an entity that has a small fraction of the budget is apparently able to do a better job. I don't see why Apple couldn't make those people an offer they can't refuse. That takes them off the market and has them doing something productive.

[flagged]

Edited. Decided not to engage.
Post reply on HN