Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

471–480 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#471
post #17

Earlier quoted context omitted.

It does. The page even recommends lockdown mode as a mitigation for affected parties (people who aren't updated)

Its super interesting to me how much its emphasized that you shouldn't use this (Lockdown Mode) unless you are a journalist or otherwise in direct danger. They really do try to talk you out of it. Its curious, because there's very little difference in functionality other than disabling a lot of Apple nonsense from running in the background expanding your attack surface.

Apple doesn't want it's users to have an interior experience. It might be subtle so it makes sense that they don't want fully uninformed users from enabling it for no real reason. Currently it's not clear anyone who's not under risk of state sponsored monitoring should bother enabling it. Thus it's not clear why they should message it any other way.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#472
post #431

Earlier quoted context omitted.

There is no email (the protocol) in iMessage (the app). You can use somebody's email address as the recipient for an iMessage (the protocol). No email is ever sent.

You can type in a contact with an email address by just their name and send an email from iMessage. I have done it to contacts accidentally many times.

I think sending SMS to emails and receiving SMS from emails is a functionality of the mobile network. You should be able to do that in any app that can send/receive SMS.

https://www.att.com/support/article/wireless/KM1061254/

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#473

Earlier quoted context omitted.

I would argue that iMessage is way to problematic to be used safetly, at all. By anyone. Full-stop. It also seems to be the primary attack vector of NSO related zero-days as well and its become known that phone country/area codes have relevance to its chance of succes in past exploits, which suggests a phone/messaging type attack vector.

That fact that Apple blended iMessages, SMS text messages, and email into an extremely confusing mess may also be the reason for so many security issues related to iMessage. Perhaps not directly responsible for this particular NGO exploit, but I find iMessage's logic and behavior bewildering at times. For example: If you stop using WhatsApp for example, nothing bad happens if you try to send messages another way. But…

For a new iPhone user are there alternatives to using iMessage for texts to avoid this?

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#474

I appreciate that a solution is for people to update immediately. It really makes me wonder if my Android phones over the years have had 1-days exploited by the sheer incompetence of the ecosystem in updating phones. Not much confidence when you get an update with security patches from 2-3 months ago.

Google devices offer such better security posture than other Android manufactures. Then there's the issue of privacy regarding Google devices. I strongly suggest checking out the GrapheneOS project if Android security is of concern.

Unless proven by leaked testimonials I would not fully trust GrapheneOS to be fully safe either. Maybe they have zero days as well and we just didn't discover them because of obscurity but NSO bought them and uses them.

My dad used to say "Known devil is better than unknown angel."

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#475
post #425
post #237

Earlier quoted context omitted.

The interesting thing is that, as the article states, Lockdown Mode, which is intended for users with exactly that kind of risk profile, does in fact prevent this attack.

the more interesting thing is why the default state has to be made vulnerable in the first place instead of just making lockdown the default method of using an apple device

The even more interesting thing is that all functionality increases the attack surface and therefore makes all devices more vulnerable. The most secure state is not to have the device at all or, failing that, to have it permanently turned off. This is true of every device, not just apple.

The reason people possess devices is to use functionality and therefore they have to make some tradeoffs in terms of security. The default state is what apple currently think is the best tradeoff in terms of risk vs functionality for most people. For people with an extremely unusual threat profile it stands to reason a different tradeoff might be appropriate.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#476
post #473

Earlier quoted context omitted.

That fact that Apple blended iMessages, SMS text messages, and email into an extremely confusing mess may also be the reason for so many security issues related to iMessage. Perhaps not directly responsible for this particular NGO exploit, but I find iMessage's logic and behavior bewildering at times. For example: If you stop using WhatsApp for example, nothing bad happens if you try to send messages another way. But…

For a new iPhone user are there alternatives to using iMessage for texts to avoid this?

You can disable iMessage and the Messages app will then just send SMS. Or you can install Signal or WhatsApp or whatever

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#477
post #468

There needs to be a more fine tuned lockdown mode, for example to disable automations and risks in imessage and safari but leave device accessories working. Losing bluetooth accessories to protect yourself from zero click imessage exploits is just bad. imessage is the major wide open attack surface.

iMessage is also a huge part of Apple's moat - it's unlikely Apple will ever allow green-bubble alternative text apps that may be more secure.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#478
post #194
post #123

Earlier quoted context omitted.

Again buffer overflow in image decoding. Would think apple might just #threatmodel and #fuzz that to death... but you would be wrong. 2.7T market cap company can't do this...

They do, but some of these bugs are beyond what fuzzing can do. We don’t know that this is a buffer overflow or how complex the exploit chain was - the one linked above was anything but something you’d get by fuzzing. I agree it is disappointing that this stuff isn’t all Rust or Swift yet but that’s in process. Of particular interest, did you notice how the new Lockdown mode is apparently a countermeasure? I would no…

Can't you trigger this by fuzzing? Sure, the JBIG VM won't be, but some random fuzzing should easily trigger out of bounds reads or writes.

Lockdown mode alters the iMessage user flow to such an extent that I don't see Apple enabling it by default. I don't think Lockdown prevents the RCE exploit, but I do think it simply blocks iMessage interactions from unknown numbers, so that the exploit can't even load.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#479
In addition to lockdown mode, pair with a vpn and security researcher Jeff Johnsons "stop the madness", and "stop the script". Both are paid safari plugins for ios. Stop the script is the best way to stop inline javascript on ios. Disabling JS on iphone can't do that.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#480
post #473

Earlier quoted context omitted.

For a new iPhone user are there alternatives to using iMessage for texts to avoid this?

You can disable iMessage and the Messages app will then just send SMS. Or you can install Signal or WhatsApp or whatever

Don’t use SMS instead of iMessage though. Then all your texts will be sent across the network without any kind of decent encryption. And WhatsApp is almost unusable unless you consent to uploading all your contacts to Facebook. (IIRC this was the red line that got crossed that caused the WhatsApp founder to quit FB post-acquisition.)

Signal is a good recommendation, but you won’t be able to convince 100% of people you need to interact with over text to use Signal. You might convince friends and family, but not acquaintances or random people who might need to text with (like your electrician etc.)

Given the tradeoffs, iMessage is pretty good for day-to-day messaging.

Post reply on HN