Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

391–400 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#391

Earlier quoted context omitted.

? They'll just buy iPhones in some other country.

GPS is a thing. iPhones have GPS.

So tourists (or people visiting for family or work) who own iPhones wouldn't be able to use them in Israel? You can probably see how that's a tough sell.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#392
post #349

Earlier quoted context omitted.

Maybe that’s true, it probably is, but they should still be sanctioned into oblivion considering they consistently are in the headlines on the wrong end of this being used for deeply questionable purposes.

Sanction who? Israel? Talk about political suicide! Regardless, sanctions don’t, and never have, actually solved anything. We just ignore the data because no one has a better idea. NSO group will be its own worst enemy anyways as greed leads them into bed with the wrong people.

>... as greed leads them into bed with the wrong people.

I'd hope they're at least targeting their own customers as part of state-sanctioned operations. Still, that doesn't justify the dissidents they indirectly facilitate being thrown under the bus. Or on the receiving end of a bone saw, as another commenter put it.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#394

Earlier quoted context omitted.

> Even though Apple is the largest company on the planet an entity that has a small fraction of the budget is apparently able to do a better job. NSO Group is Israeli and (most likely) filled to the brim with former Unit 8200 staff. About the best of the best what the IDF has to offer - they've been said to match the NSA in quality. > I don't see why Apple couldn't make those people an offer they can't refuse. For al…

So stop shipping iPhones to Israel until they play ball. If they're that smart they can roll their own phones. These companies do immense damage and endanger lives the world over. Given enough time and budget there is nothing that can't be cracked and it's the very worst actors that have access to this stuff.

Good luck finding politicians willing to play hardball with Israel. Most won't even cut off arms sales to them.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#395
post #12

I wonder if the lockdown mode would have prevented this attack? Has an iPhone in the lockdown mode been hacked so far, using a zero day vulnerability (not tricking the user to install a malicious program)?

The post recommends using lockdown mode and cites an Apple representative saying it would have prevented this exploit.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#397
post #70

Again a buffer overflow in image decoding, that sounds similar to the one from 2021 [1]. That one was wild, building a CPU out of primitives offered by an arcane image compression format embedded in pdf, to be able to do enough arithmetic to further escalate to arbitrary code execution! [1]: https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...

Maybe a dumb question, but why are media decoders, which are notoriously high risk, not well sandboxed?

1) Because that takes work 2) Because that makes things a bit slower, so it’s a stand-off between Apple and Google because neither of them wants to be the “laggy” phone

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#398

I just received a random image of a champagne bottle via iMessage from an unknown number. Any way to tell if this is the attempted exploit? I had patched my phone prior to receiving the image.

It would be awesome if someone made a site that could check an image.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#400

Its super interesting to me how much its emphasized that you shouldn't use Lockdown Mode unless you are a journalist or otherwise in direct palpable danger. They really do try to talk you out of it. Its curious, because there's very little difference in functionality (as experienced by the user) other than disabling a lot of Apple nonsense from running in the background expanding your attack surface. And everybody pa…

It does make iOS slightly more inconvenient, such as when adding each other on iMessage. And it severely reduces JavaScript performance in Safari. I think Apple wants to avoid making iOS feel slower or clunkier than Android. And zero-day spyware is usually targeted towards important individuals, not used for mass surveillance, so it indeed is a smaller risk to individual people. I'd prefer a third mode that compromis…

>And zero-day spyware is usually targeted towards important individuals,

Yeah but have you ever had someone ImportantTM's old phone number?

What about their IP?

Post reply on HN