How many exploits has iMessage had now? Isn't it time we made first messages from all new contacts plain text only, and all other messages some very restricted subset rather than some crazy extensible system that isn't so different from ActiveX? And on top of that, maybe the whole app should run in a sandbox. And on top of that, perhaps it should all be a webview to give one more layer of protection.
NSO group iPhone zero-click, zero-day exploit captured in the wild
401–410 of 886 posts
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#402I find it interesting that most comments here are blaming the victim (Apple’s iMessage and by transitivity its users) rather than the aggressor (NSO and its users). How come NSO isn’t yet designated as a (cyber-)terrorist group worth hunting down and extinguishing?
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#403I find it interesting that most comments here are blaming the victim (Apple’s iMessage and by transitivity its users) rather than the aggressor (NSO and its users). How come NSO isn’t yet designated as a (cyber-)terrorist group worth hunting down and extinguishing?
Answering this would violate HN guidelines/moderation policy.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#404I find it interesting that most comments here are blaming the victim (Apple’s iMessage and by transitivity its users) rather than the aggressor (NSO and its users). How come NSO isn’t yet designated as a (cyber-)terrorist group worth hunting down and extinguishing?
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#405Earlier quoted context omitted.
I think you’re misunderstanding. Mossad likely wouldn’t let anyone pay enough. Or let NSO accept. Unless they were already friends enough to not need to worry much about cost.
Mossad would encourage it. Moosad is not a gang where you cannot leave. They want ex-mossad in high positions because they can leverage that later.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#406Earlier quoted context omitted.
Interestingly, no kernel vulnerability or anything is mentioned. As far as I know, any parsing code for iMessages should run within the BlastDoor sandbox – is there another vulnerability in the chain that is not reported here?
It may be the case that either the kernel vulnerability hasn't been analyzed or fixed yet, or that they were not able to capture it. Many of these exploits have multiple stages and grabbing the later ones is difficult.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#407Earlier quoted context omitted.
? They'll just buy iPhones in some other country.
GPS is a thing. iPhones have GPS.
Trying to hide a hardware device that's sold in billions is not going to happen.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#408Earlier quoted context omitted.
1) of course they would. Or worse (see Gerald bull). 2) any company doing that would have to be insanely naive or reckless.
1. Consider that there might possibly be room between designing long-range weapons for an enemy state and working for an allied country. 2. Indeed: that’s my second paragraph above.
Gerald Bull was annoying. Someone good leaving any of the APT groups in Israel to help Apple get better security or anyone else would be borderline treason.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#409Naive question, does apple have any way of detecting and informing users who are current victims of these types of exploits when security fixes are issued?
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#410Its super interesting to me how much its emphasized that you shouldn't use Lockdown Mode unless you are a journalist or otherwise in direct palpable danger. They really do try to talk you out of it. Its curious, because there's very little difference in functionality (as experienced by the user) other than disabling a lot of Apple nonsense from running in the background expanding your attack surface. And everybody pa…