Earlier quoted context omitted.
I would argue that iMessage is way to problematic to be used safetly, at all. By anyone. Full-stop. It also seems to be the primary attack vector of NSO related zero-days as well and its become known that phone country/area codes have relevance to its chance of succes in past exploits, which suggests a phone/messaging type attack vector.
That fact that Apple blended iMessages, SMS text messages, and email into an extremely confusing mess may also be the reason for so many security issues related to iMessage. Perhaps not directly responsible for this particular NGO exploit, but I find iMessage's logic and behavior bewildering at times. For example: If you stop using WhatsApp for example, nothing bad happens if you try to send messages another way. But…
NSO group iPhone zero-click, zero-day exploit captured in the wild
431–440 of 886 posts
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#432Is there a honeypot in a comment on this page? /paranoid
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#433I find it interesting that most comments here are blaming the victim (Apple’s iMessage and by transitivity its users) rather than the aggressor (NSO and its users). How come NSO isn’t yet designated as a (cyber-)terrorist group worth hunting down and extinguishing?
Apple makes security claims in a world where these types of attacks are known about and expected. They are responsible for fulfilling their own claims. If an air bag fails, you fault the manufacturer. They don’t escape responsibility by saying it’s the other drivers fault. I’ll also add that Apple is not the victim here, the targeted end users are.
If in a car accident we knew one party intentionally caused the crash (and were paid for it handsomely), we’d hold them responsible, regardless what claims car companies make regarding safety.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#434Earlier quoted context omitted.
the more interesting thing is why the default state has to be made vulnerable in the first place instead of just making lockdown the default method of using an apple device
Because it turns off a lot of functionality people like: https://support.apple.com/en-us/HT212650 This is a classic challenge for security: every feature expands the attack surface, but users often pick what to buy based on those features.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#435Earlier quoted context omitted.
It's also insecure. The sync keys for iMessage are backed up in the non-e2ee iCloud Backup, which means that iCloud serves as a key escrow for iMessage's e2ee, rendering it useless (as Apple, which is definitively not an endpoint, has a private key of the participant and can read all the messages in real-time). iMessage should be assiduously avoided.
This is less true now, with the option to enable “advanced data protection”. Turning this setting on disables Apple’s access to your iMessage keys along with a bunch of other stuff, though of course if you get locked out, Apple can’t help you
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#436These fixes came out today, apparently timed with the announcement, make sure updates are applied for you and yours. https://support.apple.com/en-us/HT201222
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#437I find it interesting that most comments here are blaming the victim (Apple’s iMessage and by transitivity its users) rather than the aggressor (NSO and its users). How come NSO isn’t yet designated as a (cyber-)terrorist group worth hunting down and extinguishing?
While NSO is, of course, not a good group, I think the larger problem is how prevent these exploits are. If NSO didn't find them, someone else would. I don't consider NSO to be the big problem here.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#438Earlier quoted context omitted.
So stop shipping iPhones to Israel until they play ball. If they're that smart they can roll their own phones. These companies do immense damage and endanger lives the world over. Given enough time and budget there is nothing that can't be cracked and it's the very worst actors that have access to this stuff.
Good luck finding politicians willing to play hardball with Israel. Most won't even cut off arms sales to them.
If we had made Iraq a powerful ally, it would have weakened support for Israel but that whole area of the world is too embroiled in conflict.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#439Earlier quoted context omitted.
It does make iOS slightly more inconvenient, such as when adding each other on iMessage. And it severely reduces JavaScript performance in Safari. I think Apple wants to avoid making iOS feel slower or clunkier than Android. And zero-day spyware is usually targeted towards important individuals, not used for mass surveillance, so it indeed is a smaller risk to individual people. I'd prefer a third mode that compromis…
I would argue that iMessage is way to problematic to be used safetly, at all. By anyone. Full-stop. It also seems to be the primary attack vector of NSO related zero-days as well and its become known that phone country/area codes have relevance to its chance of succes in past exploits, which suggests a phone/messaging type attack vector.
I would really prefer to keep it text-only, and am fine with the goofy symbols. If they want to make photo exchange safe, they have the hardware to securely sign images taken on-device and only allow those.[1] (Although that would probably piss off regulators even more.)
[1] With some work, this could be a new feature, used to demonstrate images haven't been altered. With some lockdown of the clock, it could have secure timestamps. (Location could still be spoofed with a GPS hijack.)
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#440Earlier quoted context omitted.
> If Apple were liable for their defective products then they might decide not to ship them at all until they can be sure enough that the risk of the lawsuits putting them out of business is small enough that they can absorb it. > This worked wonders for other industries (notably: automotive, airlines, medicine). It may slow them down a bit, you may have a wait a bit longer for the next iteration of some gadget. But…
If there is anything that is life critical for a large number of people then it is their phones.
I broke my phone once. I did not die in the next five minutes