How many exploits has iMessage had now? Isn't it time we made first messages from all new contacts plain text only, and all other messages some very restricted subset rather than some crazy extensible system that isn't so different from ActiveX? And on top of that, maybe the whole app should run in a sandbox. And on top of that, perhaps it should all be a webview to give one more layer of protection.
This is very different from ActiveX. ActiveX had hundreds of exploits widely available freely on the dark parts of usenet, and exploited by every proverbial scriptkiddie in a basement against a swath of computers across the world. iMessage has had a handful of exploits which are licensed out for extortionate amounts by people like NSO to a very small number of scummy nationstate threat actors in extremely targetted b…
NSO group iPhone zero-click, zero-day exploit captured in the wild
501–510 of 886 posts
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#502Earlier quoted context omitted.
> Even though Apple is the largest company on the planet an entity that has a small fraction of the budget is apparently able to do a better job. NSO Group is Israeli and (most likely) filled to the brim with former Unit 8200 staff. About the best of the best what the IDF has to offer - they've been said to match the NSA in quality. > I don't see why Apple couldn't make those people an offer they can't refuse. For al…
So stop shipping iPhones to Israel until they play ball. If they're that smart they can roll their own phones. These companies do immense damage and endanger lives the world over. Given enough time and budget there is nothing that can't be cracked and it's the very worst actors that have access to this stuff.
I mean what next, stop selling to the KSA because of their gay rights issues? Iran? Russia? Where does that end? Well, it won't even begin, and rightly so. This is a state matter and they should stay in their lane. They're doing all they can, and should.
BTW, I bet there's more than a few USA organisations who are quietly very annoyed about Apple's relentless bug-fixing. Organisations like NSO are tolerated for a reason.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#503Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#504Earlier quoted context omitted.
I think sending SMS to emails and receiving SMS from emails is a functionality of the mobile network. You should be able to do that in any app that can send/receive SMS. https://www.att.com/support/article/wireless/KM1061254/
The point is that those other apps don’t use email addresses as the handle to contact someone. If someone iMessages you, the iMessage might (appear to) come from their phone number, or it could (appear to) come from their email. If you have an iMessage contact that’s just an email and you iMessage them, it works fine. If you try to then add Android users to your group chat, everyone gets SMS and the iMessage user wit…
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#505Earlier quoted context omitted.
It does make iOS slightly more inconvenient, such as when adding each other on iMessage. And it severely reduces JavaScript performance in Safari. I think Apple wants to avoid making iOS feel slower or clunkier than Android. And zero-day spyware is usually targeted towards important individuals, not used for mass surveillance, so it indeed is a smaller risk to individual people. I'd prefer a third mode that compromis…
The only bothersome issue I see on lockdown mode is not being able to search through text messages anymore :’( Please bring that back (safely) if you can, Apple.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#506Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#507How many exploits has iMessage had now? Isn't it time we made first messages from all new contacts plain text only, and all other messages some very restricted subset rather than some crazy extensible system that isn't so different from ActiveX? And on top of that, maybe the whole app should run in a sandbox. And on top of that, perhaps it should all be a webview to give one more layer of protection.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#508Its super interesting to me how much its emphasized that you shouldn't use Lockdown Mode unless you are a journalist or otherwise in direct palpable danger. They really do try to talk you out of it. Its curious, because there's very little difference in functionality (as experienced by the user) other than disabling a lot of Apple nonsense from running in the background expanding your attack surface. And everybody pa…
If they didn't want people to have all of the background stuff running, they wouldn't put it on there in the first place. It's not super surprising that they want people to use the features (whether "nonsense" or not) that they purposely put there.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#509Another day, another reason to be glad I don't have a single fucking Apple product in my house.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#510How many exploits has iMessage had now? Isn't it time we made first messages from all new contacts plain text only, and all other messages some very restricted subset rather than some crazy extensible system that isn't so different from ActiveX? And on top of that, maybe the whole app should run in a sandbox. And on top of that, perhaps it should all be a webview to give one more layer of protection.
EDIT: found it. For anyone who's interested:
> Turn off iMessage:
> On your iPhone, go to Settings.
> Tap Messages.
> Set iMessage to Off.