Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

441–450 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#442

Earlier quoted context omitted.

If your software can cause billions of damage and you don't have billions in the bank you are in the wrong business, or acting very irresponsibly.

Small companies can't cause billions in damage though...

Yes they can? It's totally possible for a small, well connected, group to be writing small pieces of custom code in very critical applications, like core reactor controls system for navy submarines.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#443
post #428

I don't need to be able to accept iMessage messages from random numbers. I'd be happy to enable "Prevent messages from unknown numbers" for example. Is this possible?

There is a "Filter Unknown Senders" feature. https://support.apple.com/en-au/guide/iphone/iph203ab0be4/io...

Notably this doesn't actually prevent a zero-click exploit from being received.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#444
post #329

Earlier quoted context omitted.

Apple makes security claims in a world where these types of attacks are known about and expected. They are responsible for fulfilling their own claims. If an air bag fails, you fault the manufacturer. They don’t escape responsibility by saying it’s the other drivers fault. I’ll also add that Apple is not the victim here, the targeted end users are.

This is a false comparison. Being hacked by NSO isn’t an accident. There’s an agent involved here with clear intent to harm and significant monetary motives. If in a car accident we knew one party intentionally caused the crash (and were paid for it handsomely), we’d hold them responsible, regardless what claims car companies make regarding safety.

It doesn't make sense to talk about IT safety if you exclude intentional hacking. To take your example, we do hold car companies responsible for harm from collisions with other vehicles, regardless of which driver was at fault.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#445
post #124
post #38

Earlier quoted context omitted.

Please... Androids no better. At least Apple will have it patched within the year of discovery. Can't say the same for other Android vendors.

>Please... Androids no better. The Pixel is. >At least Apple will have it patched within the year of discovery. Can't say the same for other Android vendors. And the Pixel would have the patch released quicker.

Pixel is not an OS, is not Android. Pixel is a series of hardware that make up less than five percent of the android hardware market.

One device series does not offer a glimpse of the market.

Op’s point stands.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#446
post #329

Earlier quoted context omitted.

Apple makes security claims in a world where these types of attacks are known about and expected. They are responsible for fulfilling their own claims. If an air bag fails, you fault the manufacturer. They don’t escape responsibility by saying it’s the other drivers fault. I’ll also add that Apple is not the victim here, the targeted end users are.

This is a false comparison. Being hacked by NSO isn’t an accident. There’s an agent involved here with clear intent to harm and significant monetary motives. If in a car accident we knew one party intentionally caused the crash (and were paid for it handsomely), we’d hold them responsible, regardless what claims car companies make regarding safety.

That doesn’t matter.

If your air bag fails to deploy after a crash, the manufacture is responsible for the product defect. It doesn’t matter if the crash was an accident or someone intentionally and specifically crashing into you, the manufacturer is responsible for a defective air bag. The manufacturer is not responsible for the crash, only the defective product. The other driver is not less responsible for a death or injury resulting from the crash.

Responsibility for the crash and its consequence's rest on the driver at fault.

Responsibility for a defective air bag rests on the manufacturer.

They are two separate issues and not zero-sum.

If someone clips your airbag wires before the crash, that is not a product defect and the manufacturer is not liable, but that is not what happened here. There was no prior access or modification to the device or software. Apple claims to have a secure phone yet has a critical zero click vulnerability similar to an earlier vulnerability they previously fixed.

Pointing a finger at NSO could one day lead to some government’s action aimed at influencing another government’s actions toward a private organization. NSO doesn’t care if they’re unpopular online.

Highlighting Apple’s responsibility in this is how we incentivize better security in consumer products.

I don’t think companies should be responsible for every exploit all the time. Nobody is pointing fingers at ViaSat for being hacked by the Russians. There have been repeated iMeassage exploits that could be prevented with easy to implement defaults or simple opt-in settings (do not implicitly trust unknown numbers) which have been asked for after each exploit and ignored.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#447
post #123

Earlier quoted context omitted.

Again buffer overflow in image decoding. Would think apple might just #threatmodel and #fuzz that to death... but you would be wrong. 2.7T market cap company can't do this...

A while ago I was surprised to learn that MS Internet Explorer had team of about 10 developers (I expected more) when MS already had more than 50000 employees total. Now knowing a bit more how sausages are made I would not be surprised to learn that this particular image decoder was maintained in Apple by a couple developers. To some extent this can be seen in corporations too: https://xkcd.com/2347/

[deleted]

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#448
post #416

I don't understand Apple here. Just put an army of people on fuzzing the shit out of iMessage and all its possible file attachments. You tried and failed? Fire the bozo who lead the effort. Try again. You did not even try? Fire the c-level bozo who failed to see it coming and failed to approve such an effort. But cynically, more and more it feels like some bugs have to stay unfixed, for NSA use, just that NSO is also…

Given all the major tech companies aggressively fuzz everything maybe, just maybe, you're missing the additional possibility: fuzzing is still random and extensive fuzzing does not mean you will encounter the same code paths as anyone else.

You need to understand "do fuzzing" is not a magic trick to find all bugs in software.

Similarly: definitionally you will only ever see the bugs that are not found prior to shipping - any bugs that are found prior to software shipping will have been fixed.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#449
post #429

Earlier quoted context omitted.

> If Apple were liable for their defective products then they might decide not to ship them at all until they can be sure enough that the risk of the lawsuits putting them out of business is small enough that they can absorb it. > This worked wonders for other industries (notably: automotive, airlines, medicine). It may slow them down a bit, you may have a wait a bit longer for the next iteration of some gadget. But…

A billion times more complex than the safety-critical parts of an airplane? I think you lack perspective on avionics packages and the safety measures that are undertaken in that industry. Additionally, I think you're vastly over estimating how complex a smartphone is.

A billion might be hyperoble (although i dont think its a totally unreasonable guess either), but phone software is many GB large, i could easily believe that there are a million more MC/DC points in phone software, than in the safety critical part of airplane software.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#450
post #416

I don't understand Apple here. Just put an army of people on fuzzing the shit out of iMessage and all its possible file attachments. You tried and failed? Fire the bozo who lead the effort. Try again. You did not even try? Fire the c-level bozo who failed to see it coming and failed to approve such an effort. But cynically, more and more it feels like some bugs have to stay unfixed, for NSA use, just that NSO is also…

Cynical reductionist me thinks Apple gets more ROI spending on marketing than in security.

They also spend a ton of engineering resources to prevent customers from using their products as general computing devices with the pretense of hardening security. It works to an extent and the tradeoffs are debatable, at least among tech-savvy folks in HN.

Post reply on HN