Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

431–440 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#431

Earlier quoted context omitted.

I would argue that iMessage is way to problematic to be used safetly, at all. By anyone. Full-stop. It also seems to be the primary attack vector of NSO related zero-days as well and its become known that phone country/area codes have relevance to its chance of succes in past exploits, which suggests a phone/messaging type attack vector.

That fact that Apple blended iMessages, SMS text messages, and email into an extremely confusing mess may also be the reason for so many security issues related to iMessage. Perhaps not directly responsible for this particular NGO exploit, but I find iMessage's logic and behavior bewildering at times. For example: If you stop using WhatsApp for example, nothing bad happens if you try to send messages another way. But…

There is no email (the protocol) in iMessage (the app). You can use somebody's email address as the recipient for an iMessage (the protocol). No email is ever sent.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#433
post #329

I find it interesting that most comments here are blaming the victim (Apple’s iMessage and by transitivity its users) rather than the aggressor (NSO and its users). How come NSO isn’t yet designated as a (cyber-)terrorist group worth hunting down and extinguishing?

Apple makes security claims in a world where these types of attacks are known about and expected. They are responsible for fulfilling their own claims. If an air bag fails, you fault the manufacturer. They don’t escape responsibility by saying it’s the other drivers fault. I’ll also add that Apple is not the victim here, the targeted end users are.

This is a false comparison. Being hacked by NSO isn’t an accident. There’s an agent involved here with clear intent to harm and significant monetary motives.

If in a car accident we knew one party intentionally caused the crash (and were paid for it handsomely), we’d hold them responsible, regardless what claims car companies make regarding safety.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#434
post #427
post #425

Earlier quoted context omitted.

the more interesting thing is why the default state has to be made vulnerable in the first place instead of just making lockdown the default method of using an apple device

Because it turns off a lot of functionality people like: https://support.apple.com/en-us/HT212650 This is a classic challenge for security: every feature expands the attack surface, but users often pick what to buy based on those features.

Isn't there something like a 50% performance hit too, since it turns off a lot of optimizations?

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#435
post #369
post #361

Earlier quoted context omitted.

It's also insecure. The sync keys for iMessage are backed up in the non-e2ee iCloud Backup, which means that iCloud serves as a key escrow for iMessage's e2ee, rendering it useless (as Apple, which is definitively not an endpoint, has a private key of the participant and can read all the messages in real-time). iMessage should be assiduously avoided.

This is less true now, with the option to enable “advanced data protection”. Turning this setting on disables Apple’s access to your iMessage keys along with a bunch of other stuff, though of course if you get locked out, Apple can’t help you

Yeah, and this is the sort of thing that I think drives Apple's care in recommending the most secure modes; they don't want people causally turning it on and discovered that they've buggered themselves up.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#436

These fixes came out today, apparently timed with the announcement, make sure updates are applied for you and yours. https://support.apple.com/en-us/HT201222

Curious why no fix is out for iOS 15 yet. Is iOS 15 not vulnerable to this attack? Or is there often a delay in backporting security fixes that I'm not aware of? And if so, should I be implementing a workaround if I wanted to protect against these exploits?

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#437

I find it interesting that most comments here are blaming the victim (Apple’s iMessage and by transitivity its users) rather than the aggressor (NSO and its users). How come NSO isn’t yet designated as a (cyber-)terrorist group worth hunting down and extinguishing?

While NSO is, of course, not a good group, I think the larger problem is how prevent these exploits are. If NSO didn't find them, someone else would. I don't consider NSO to be the big problem here.

Is this the standard we apply to other cyber-criminals? Or any crime for that matter? Do we ask how vulnerable the victims were? And how we should make them less vulnerable and give a free pass to the aggressors?

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#438
post #394

Earlier quoted context omitted.

So stop shipping iPhones to Israel until they play ball. If they're that smart they can roll their own phones. These companies do immense damage and endanger lives the world over. Given enough time and budget there is nothing that can't be cracked and it's the very worst actors that have access to this stuff.

Good luck finding politicians willing to play hardball with Israel. Most won't even cut off arms sales to them.

There’s very few candidates in that region for good allies so Israel has a stronghold in US politics.

If we had made Iraq a powerful ally, it would have weakened support for Israel but that whole area of the world is too embroiled in conflict.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#439

Earlier quoted context omitted.

It does make iOS slightly more inconvenient, such as when adding each other on iMessage. And it severely reduces JavaScript performance in Safari. I think Apple wants to avoid making iOS feel slower or clunkier than Android. And zero-day spyware is usually targeted towards important individuals, not used for mass surveillance, so it indeed is a smaller risk to individual people. I'd prefer a third mode that compromis…

I would argue that iMessage is way to problematic to be used safetly, at all. By anyone. Full-stop. It also seems to be the primary attack vector of NSO related zero-days as well and its become known that phone country/area codes have relevance to its chance of succes in past exploits, which suggests a phone/messaging type attack vector.

I agree, and there really need to be controls on it. I understand they want the "IMessage Network" to have predictable functionality, but I care about security more, and IMessage has been demonstrably unsafe for a long time.

I would really prefer to keep it text-only, and am fine with the goofy symbols. If they want to make photo exchange safe, they have the hardware to securely sign images taken on-device and only allow those.[1] (Although that would probably piss off regulators even more.)

[1] With some work, this could be a new feature, used to demonstrate images haven't been altered. With some lockdown of the clock, it could have secure timestamps. (Location could still be spoofed with a GPS hijack.)

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#440

Earlier quoted context omitted.

> If Apple were liable for their defective products then they might decide not to ship them at all until they can be sure enough that the risk of the lawsuits putting them out of business is small enough that they can absorb it. > This worked wonders for other industries (notably: automotive, airlines, medicine). It may slow them down a bit, you may have a wait a bit longer for the next iteration of some gadget. But…

If there is anything that is life critical for a large number of people then it is their phones.

I think pacemakers are a lot more life critical than your phone.

I broke my phone once. I did not die in the next five minutes

Post reply on HN