Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

491–500 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#491
post #369

Earlier quoted context omitted.

This is less true now, with the option to enable “advanced data protection”. Turning this setting on disables Apple’s access to your iMessage keys along with a bunch of other stuff, though of course if you get locked out, Apple can’t help you

Yeah, and this is the sort of thing that I think drives Apple's care in recommending the most secure modes; they don't want people causally turning it on and discovered that they've buggered themselves up.

I agree with you; Amazon servers receiving 80,000 or 800,000 requests per second or 8,000,000 is all a different ballgame than it is for 800 individual actual families around the world (or 8,000 or 80,000) to get their telephones totally buggered up before work that morning on any given workday -- just because somebody trustworthy has advised them to play it super safe without making equally sure the listeners were understanding the UX difficulties of recovering their smartphone's functionality in certain mundane use cases, etc, which would ensue. That's a lot of panic to deal with. Apple user help forum volunteers would be helpless to reach all the affected frustrated people.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#492
post #380

Earlier quoted context omitted.

It does make iOS slightly more inconvenient, such as when adding each other on iMessage. And it severely reduces JavaScript performance in Safari. I think Apple wants to avoid making iOS feel slower or clunkier than Android. And zero-day spyware is usually targeted towards important individuals, not used for mass surveillance, so it indeed is a smaller risk to individual people. I'd prefer a third mode that compromis…

You can turn off lockdown mode per site and per-app in safari. I had to do that to get Obsidian to work, but I also use it for specific trusted sites.

What do you mean "per-app in safari"? I'd like to turn it on globally, with a single exception: I want to be able to continue using shared photos albums with my two best friends.

I don't care enough about JS performance or, more generally, the mobile web, to want to disable it on safari, or even parts of it.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#493

How many exploits has iMessage had now? Isn't it time we made first messages from all new contacts plain text only, and all other messages some very restricted subset rather than some crazy extensible system that isn't so different from ActiveX? And on top of that, maybe the whole app should run in a sandbox. And on top of that, perhaps it should all be a webview to give one more layer of protection.

This is very different from ActiveX. ActiveX had hundreds of exploits widely available freely on the dark parts of usenet, and exploited by every proverbial scriptkiddie in a basement against a swath of computers across the world. iMessage has had a handful of exploits which are licensed out for extortionate amounts by people like NSO to a very small number of scummy nationstate threat actors in extremely targetted b…

You don't know how many exploits iMessage has.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#494

Its super interesting to me how much its emphasized that you shouldn't use Lockdown Mode unless you are a journalist or otherwise in direct palpable danger. They really do try to talk you out of it. Its curious, because there's very little difference in functionality (as experienced by the user) other than disabling a lot of Apple nonsense from running in the background expanding your attack surface. And everybody pa…

It does make iOS slightly more inconvenient, such as when adding each other on iMessage. And it severely reduces JavaScript performance in Safari. I think Apple wants to avoid making iOS feel slower or clunkier than Android. And zero-day spyware is usually targeted towards important individuals, not used for mass surveillance, so it indeed is a smaller risk to individual people. I'd prefer a third mode that compromis…

The only bothersome issue I see on lockdown mode is not being able to search through text messages anymore :’(

Please bring that back (safely) if you can, Apple.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#495

Its super interesting to me how much its emphasized that you shouldn't use Lockdown Mode unless you are a journalist or otherwise in direct palpable danger. They really do try to talk you out of it. Its curious, because there's very little difference in functionality (as experienced by the user) other than disabling a lot of Apple nonsense from running in the background expanding your attack surface. And everybody pa…

I use Lockdown Mode on my Mac because I don’t use iMessage, FaceTime, or other apple services on that device. It’s literally just a computer for software dev and maybe YouTube videos. I haven’t noticed any difference with web content either, but I also use Firefox / Chrome instead of Safari. What I would really like to see is options. For example on iOS I use shared photo albums, so it would be nice to keep that feat…

> For example on iOS I use shared photo albums, so it would be nice to keep that feature but disable all the other capabilities.

I'm in the same boat. I was a bit confused, since I'm pretty sure I read somewhere that you could selectively disable it for some "apps", but I've never found out how to disable it for photos specifically.

My requirements of my phone being otherwise slim, I didn't encounter any other issue with lockdown mode.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#496
post #425

Earlier quoted context omitted.

the more interesting thing is why the default state has to be made vulnerable in the first place instead of just making lockdown the default method of using an apple device

The even more interesting thing is that all functionality increases the attack surface and therefore makes all devices more vulnerable. The most secure state is not to have the device at all or, failing that, to have it permanently turned off. This is true of every device, not just apple. The reason people possess devices is to use functionality and therefore they have to make some tradeoffs in terms of security. The…

Great reply, but don't forget to add Apple's bottom line to the balance beam of user risk and device functionality there

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#497

Earlier quoted context omitted.

You can type in a contact with an email address by just their name and send an email from iMessage. I have done it to contacts accidentally many times.

I think sending SMS to emails and receiving SMS from emails is a functionality of the mobile network. You should be able to do that in any app that can send/receive SMS. https://www.att.com/support/article/wireless/KM1061254/

The point is that those other apps don’t use email addresses as the handle to contact someone. If someone iMessages you, the iMessage might (appear to) come from their phone number, or it could (appear to) come from their email. If you have an iMessage contact that’s just an email and you iMessage them, it works fine. If you try to then add Android users to your group chat, everyone gets SMS and the iMessage user with an email handle gets an empty body email from AT&T with an attachment containing the SMS as a plaintext file. And then this user gets another empty email for every reply to that group text.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#498

Earlier quoted context omitted.

You can type in a contact with an email address by just their name and send an email from iMessage. I have done it to contacts accidentally many times.

I think sending SMS to emails and receiving SMS from emails is a functionality of the mobile network. You should be able to do that in any app that can send/receive SMS. https://www.att.com/support/article/wireless/KM1061254/

On Apple's end, iMessage also supports email addresses as a user identifier (and it's the only one you get if you don't have an iPhone with an assigned phone number).

It's still not sending emails, though. The iPhone Messages app sends SMS, MMS, and iMessage; email is the responsibility of the Mail app.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#499

Its super interesting to me how much its emphasized that you shouldn't use Lockdown Mode unless you are a journalist or otherwise in direct palpable danger. They really do try to talk you out of it. Its curious, because there's very little difference in functionality (as experienced by the user) other than disabling a lot of Apple nonsense from running in the background expanding your attack surface. And everybody pa…

> Everyone should use it because it disables a lot of nonsense that doesn't serve you and probably even saves battery power.

Lockdown mode acts as a natural ad block which is great (as a reader). But it also disables JIT. I assume this causes wasted CPU cycles and perhaps, on balance, worse battery life?

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#500
post #468

There needs to be a more fine tuned lockdown mode, for example to disable automations and risks in imessage and safari but leave device accessories working. Losing bluetooth accessories to protect yourself from zero click imessage exploits is just bad. imessage is the major wide open attack surface.

iMessage is also a huge part of Apple's moat - it's unlikely Apple will ever allow green-bubble alternative text apps that may be more secure.

> will ever

As part of Europe's DMA plan they have precisely 6 months to do that.

Post reply on HN