Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

421–430 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#421

Earlier quoted context omitted.

GPS is a thing. iPhones have GPS.

So tourists (or people visiting for family or work) who own iPhones wouldn't be able to use them in Israel? You can probably see how that's a tough sell.

Yes, that's exactly it: you harbor this sort of company you will not be able to pretend it's business as usual on other fronts.

After the 500,000th Facebook post of tourists linking NSO to 'my holiday in Israel was spoiled and I won't be going back there' I'm pretty sure they'd get the message.

I'm ok with whitehat hackers but this shit has to stop. Mind you, I have an old Nokia so it's not as if I'm affected, the only thing I have to worry about is the baseband processor and my telco. But there are plenty of people who need a smartphone for their work and their opsec is pretty much as good as their phones' security.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#423

I just received a random image of a champagne bottle via iMessage from an unknown number. Any way to tell if this is the attempted exploit? I had patched my phone prior to receiving the image.

I recently got that one as well. It's a crypto scam.

https://cybernews.com/crypto/romance-scams-southeast-asian-t...

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#424
post #416

I don't understand Apple here. Just put an army of people on fuzzing the shit out of iMessage and all its possible file attachments. You tried and failed? Fire the bozo who lead the effort. Try again. You did not even try? Fire the c-level bozo who failed to see it coming and failed to approve such an effort. But cynically, more and more it feels like some bugs have to stay unfixed, for NSA use, just that NSO is also…

[deleted]

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#425
post #237
post #109

Earlier quoted context omitted.

This is the frustrating part: that is cool from a technical perspective but terrifying when you think about this stuff being used to target journalists, activists, etc. Maybe not everyone gets the bone saw but some will - and from the sounds of it it’s people standing up to abusive people: > Last week, while checking the device of an individual employed by a Washington DC-based civil society organization with interna…

The interesting thing is that, as the article states, Lockdown Mode, which is intended for users with exactly that kind of risk profile, does in fact prevent this attack.

the more interesting thing is why the default state has to be made vulnerable in the first place instead of just making lockdown the default method of using an apple device

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#426

Its super interesting to me how much its emphasized that you shouldn't use Lockdown Mode unless you are a journalist or otherwise in direct palpable danger. They really do try to talk you out of it. Its curious, because there's very little difference in functionality (as experienced by the user) other than disabling a lot of Apple nonsense from running in the background expanding your attack surface. And everybody pa…

Just like disabling JavaScript in the browser by default, or using LTSC versions of Windows --- it's propaganda to keep you on the path they want, and not the path you want, because there are powerful interests in the former direction.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#427
post #425
post #237

Earlier quoted context omitted.

The interesting thing is that, as the article states, Lockdown Mode, which is intended for users with exactly that kind of risk profile, does in fact prevent this attack.

the more interesting thing is why the default state has to be made vulnerable in the first place instead of just making lockdown the default method of using an apple device

Because it turns off a lot of functionality people like:

https://support.apple.com/en-us/HT212650

This is a classic challenge for security: every feature expands the attack surface, but users often pick what to buy based on those features.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#428

I don't need to be able to accept iMessage messages from random numbers. I'd be happy to enable "Prevent messages from unknown numbers" for example. Is this possible?

There is a "Filter Unknown Senders" feature.

https://support.apple.com/en-au/guide/iphone/iph203ab0be4/io...

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#429

Earlier quoted context omitted.

I don't understand your comment either. You say you don't understand and then you give a choice between two narrow interpretations neither of which seems to cover what I wrote. To make this a bit more productive: If Apple were liable for their defective products then they might decide not to ship them at all until they can be sure enough that the risk of the lawsuits putting them out of business is small enough that…

> If Apple were liable for their defective products then they might decide not to ship them at all until they can be sure enough that the risk of the lawsuits putting them out of business is small enough that they can absorb it. > This worked wonders for other industries (notably: automotive, airlines, medicine). It may slow them down a bit, you may have a wait a bit longer for the next iteration of some gadget. But…

A billion times more complex than the safety-critical parts of an airplane? I think you lack perspective on avionics packages and the safety measures that are undertaken in that industry. Additionally, I think you're vastly over estimating how complex a smartphone is.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#430
post #46

Clearly putting the NSO group on the Commerce Department blacklist didn't go far enough. These scumbags belong in the Hague(metaphorically at least).

>Clearly putting the NSO group on the Commerce Department blacklist didn't go far enough

Somewhere in a nondescript subterranean hangar north of vegas an unacknowledged aerial platform is getting an itchy nose

Post reply on HN