Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

451–460 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#451

Earlier quoted context omitted.

While NSO is, of course, not a good group, I think the larger problem is how prevent these exploits are. If NSO didn't find them, someone else would. I don't consider NSO to be the big problem here.

Is this the standard we apply to other cyber-criminals? Or any crime for that matter? Do we ask how vulnerable the victims were? And how we should make them less vulnerable and give a free pass to the aggressors?

I'm not saying anything about the vulnerability of the victims of these attacks. I'm saying it's absurd how the trillion dollar corporation fails to protect them. NSO should be stopped, sure. But don't kid yourself — someone will take their place immediately for as long as these vulnerabilities continue to exist.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#452
post #416

I don't understand Apple here. Just put an army of people on fuzzing the shit out of iMessage and all its possible file attachments. You tried and failed? Fire the bozo who lead the effort. Try again. You did not even try? Fire the c-level bozo who failed to see it coming and failed to approve such an effort. But cynically, more and more it feels like some bugs have to stay unfixed, for NSA use, just that NSO is also…

This was likely in a codebase that has been fuzzed extremely heavily. There are a lot of bugs that fuzzing cannot possibly reach. I'm guessing NSO group has a lot of talented vulnerability researchers who do code auditing. Companies need to invest in hiring and training these individuals and paying them what they are deserve. Throwing fuzzers at things and calling them secure is part of the problem.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#453

If you are curious about NSO Group, Pegasus, or Citizen Lab - Darknet Diaries podcast (Episode 100) does a good job diving into the history.

It really is a great episode.

Link for those curious: https://darknetdiaries.com/episode/100/

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#454

Earlier quoted context omitted.

I would argue that iMessage is way to problematic to be used safetly, at all. By anyone. Full-stop. It also seems to be the primary attack vector of NSO related zero-days as well and its become known that phone country/area codes have relevance to its chance of succes in past exploits, which suggests a phone/messaging type attack vector.

That fact that Apple blended iMessages, SMS text messages, and email into an extremely confusing mess may also be the reason for so many security issues related to iMessage. Perhaps not directly responsible for this particular NGO exploit, but I find iMessage's logic and behavior bewildering at times. For example: If you stop using WhatsApp for example, nothing bad happens if you try to send messages another way. But…

[dead]

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#455

Earlier quoted context omitted.

If your software can cause billions of damage and you don't have billions in the bank you are in the wrong business, or acting very irresponsibly.

Small companies can't cause billions in damage though...

SQLite and OpenSSL are prime examples. Both have exceptionally small teams behind them writing software that literally is in everything.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#456
post #52
post #42

For anyone interested in learning more about the NSO group, I'd recommend this podcast episode: https://darknetdiaries.com/episode/100/

[flagged]

NSO Group is a private company owned by UK investment group "Novalpina Capital." Stop spreading misinformation.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#457
post #416

I don't understand Apple here. Just put an army of people on fuzzing the shit out of iMessage and all its possible file attachments. You tried and failed? Fire the bozo who lead the effort. Try again. You did not even try? Fire the c-level bozo who failed to see it coming and failed to approve such an effort. But cynically, more and more it feels like some bugs have to stay unfixed, for NSA use, just that NSO is also…

This was likely in a codebase that has been fuzzed extremely heavily. There are a lot of bugs that fuzzing cannot possibly reach. I'm guessing NSO group has a lot of talented vulnerability researchers who do code auditing. Companies need to invest in hiring and training these individuals and paying them what they are deserve. Throwing fuzzers at things and calling them secure is part of the problem.

What code auditing? Are you claiming NSO has access to iMessage and iOS source code?

NSO seems to be finding more and more bugs by poking a black-box alone, while Apple cannot seem to be able to fix by looking at the source code with all the fuzzing and verification tools, and much more $$$ at their disposal.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#458
post #425
post #237

Earlier quoted context omitted.

The interesting thing is that, as the article states, Lockdown Mode, which is intended for users with exactly that kind of risk profile, does in fact prevent this attack.

the more interesting thing is why the default state has to be made vulnerable in the first place instead of just making lockdown the default method of using an apple device

Lots of people would be blocked iMessaging each other TIF images.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#459

Earlier quoted context omitted.

According to Zerodium [1] it would be up to 2 million USD in this case. [1] http://zerodium.com/program.html

Interesting that android FCPs are worth more than iOS counterparts. Does that mean android is more secure?

Perhaps more users?

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#460

Its super interesting to me how much its emphasized that you shouldn't use Lockdown Mode unless you are a journalist or otherwise in direct palpable danger. They really do try to talk you out of it. Its curious, because there's very little difference in functionality (as experienced by the user) other than disabling a lot of Apple nonsense from running in the background expanding your attack surface. And everybody pa…

Lockdown mode disables shared albums, which I use a lot.

I would rathe have a full app firewall with configurable profiles instead of lockdown mode.

Post reply on HN