NSO group iPhone zero-click, zero-day exploit captured in the wild
441–450 of 886 posts
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#442Earlier quoted context omitted.
If your software can cause billions of damage and you don't have billions in the bank you are in the wrong business, or acting very irresponsibly.
Small companies can't cause billions in damage though...
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#443I don't need to be able to accept iMessage messages from random numbers. I'd be happy to enable "Prevent messages from unknown numbers" for example. Is this possible?
There is a "Filter Unknown Senders" feature. https://support.apple.com/en-au/guide/iphone/iph203ab0be4/io...
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#444Earlier quoted context omitted.
Apple makes security claims in a world where these types of attacks are known about and expected. They are responsible for fulfilling their own claims. If an air bag fails, you fault the manufacturer. They don’t escape responsibility by saying it’s the other drivers fault. I’ll also add that Apple is not the victim here, the targeted end users are.
This is a false comparison. Being hacked by NSO isn’t an accident. There’s an agent involved here with clear intent to harm and significant monetary motives. If in a car accident we knew one party intentionally caused the crash (and were paid for it handsomely), we’d hold them responsible, regardless what claims car companies make regarding safety.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#445Earlier quoted context omitted.
Please... Androids no better. At least Apple will have it patched within the year of discovery. Can't say the same for other Android vendors.
>Please... Androids no better. The Pixel is. >At least Apple will have it patched within the year of discovery. Can't say the same for other Android vendors. And the Pixel would have the patch released quicker.
One device series does not offer a glimpse of the market.
Op’s point stands.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#446Earlier quoted context omitted.
Apple makes security claims in a world where these types of attacks are known about and expected. They are responsible for fulfilling their own claims. If an air bag fails, you fault the manufacturer. They don’t escape responsibility by saying it’s the other drivers fault. I’ll also add that Apple is not the victim here, the targeted end users are.
This is a false comparison. Being hacked by NSO isn’t an accident. There’s an agent involved here with clear intent to harm and significant monetary motives. If in a car accident we knew one party intentionally caused the crash (and were paid for it handsomely), we’d hold them responsible, regardless what claims car companies make regarding safety.
If your air bag fails to deploy after a crash, the manufacture is responsible for the product defect. It doesn’t matter if the crash was an accident or someone intentionally and specifically crashing into you, the manufacturer is responsible for a defective air bag. The manufacturer is not responsible for the crash, only the defective product. The other driver is not less responsible for a death or injury resulting from the crash.
Responsibility for the crash and its consequence's rest on the driver at fault.
Responsibility for a defective air bag rests on the manufacturer.
They are two separate issues and not zero-sum.
If someone clips your airbag wires before the crash, that is not a product defect and the manufacturer is not liable, but that is not what happened here. There was no prior access or modification to the device or software. Apple claims to have a secure phone yet has a critical zero click vulnerability similar to an earlier vulnerability they previously fixed.
Pointing a finger at NSO could one day lead to some government’s action aimed at influencing another government’s actions toward a private organization. NSO doesn’t care if they’re unpopular online.
Highlighting Apple’s responsibility in this is how we incentivize better security in consumer products.
I don’t think companies should be responsible for every exploit all the time. Nobody is pointing fingers at ViaSat for being hacked by the Russians. There have been repeated iMeassage exploits that could be prevented with easy to implement defaults or simple opt-in settings (do not implicitly trust unknown numbers) which have been asked for after each exploit and ignored.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#447Earlier quoted context omitted.
Again buffer overflow in image decoding. Would think apple might just #threatmodel and #fuzz that to death... but you would be wrong. 2.7T market cap company can't do this...
A while ago I was surprised to learn that MS Internet Explorer had team of about 10 developers (I expected more) when MS already had more than 50000 employees total. Now knowing a bit more how sausages are made I would not be surprised to learn that this particular image decoder was maintained in Apple by a couple developers. To some extent this can be seen in corporations too: https://xkcd.com/2347/
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#448I don't understand Apple here. Just put an army of people on fuzzing the shit out of iMessage and all its possible file attachments. You tried and failed? Fire the bozo who lead the effort. Try again. You did not even try? Fire the c-level bozo who failed to see it coming and failed to approve such an effort. But cynically, more and more it feels like some bugs have to stay unfixed, for NSA use, just that NSO is also…
You need to understand "do fuzzing" is not a magic trick to find all bugs in software.
Similarly: definitionally you will only ever see the bugs that are not found prior to shipping - any bugs that are found prior to software shipping will have been fixed.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#449Earlier quoted context omitted.
> If Apple were liable for their defective products then they might decide not to ship them at all until they can be sure enough that the risk of the lawsuits putting them out of business is small enough that they can absorb it. > This worked wonders for other industries (notably: automotive, airlines, medicine). It may slow them down a bit, you may have a wait a bit longer for the next iteration of some gadget. But…
A billion times more complex than the safety-critical parts of an airplane? I think you lack perspective on avionics packages and the safety measures that are undertaken in that industry. Additionally, I think you're vastly over estimating how complex a smartphone is.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#450I don't understand Apple here. Just put an army of people on fuzzing the shit out of iMessage and all its possible file attachments. You tried and failed? Fire the bozo who lead the effort. Try again. You did not even try? Fire the c-level bozo who failed to see it coming and failed to approve such an effort. But cynically, more and more it feels like some bugs have to stay unfixed, for NSA use, just that NSO is also…
They also spend a ton of engineering resources to prevent customers from using their products as general computing devices with the pretense of hardening security. It works to an extent and the tradeoffs are debatable, at least among tech-savvy folks in HN.