Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

521–530 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#521

How many exploits has iMessage had now? Isn't it time we made first messages from all new contacts plain text only, and all other messages some very restricted subset rather than some crazy extensible system that isn't so different from ActiveX? And on top of that, maybe the whole app should run in a sandbox. And on top of that, perhaps it should all be a webview to give one more layer of protection.

There is even precedent for doing this seamlessly: the Apple Mail client will not render media from unknown senders without user confirmation. iMessage should have the exact same behavior for the same reasons. It’s frustrating to watch greedy project managers re-learning the exact same lessons that a previous generation already learned the hard way, especially when they all work in the same building.

This is for a different reason (all useful e-mail clients do the same thing!). If Mail (or thunderbird or whatever) loaded the media, then the sender could know you opened the e-mail (by sending each recipient a unique image), leaking information.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#522
post #431

Earlier quoted context omitted.

There is no email (the protocol) in iMessage (the app). You can use somebody's email address as the recipient for an iMessage (the protocol). No email is ever sent.

You can type in a contact with an email address by just their name and send an email from iMessage. I have done it to contacts accidentally many times.

You are referring to MMS.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#523

Earlier quoted context omitted.

I think sending SMS to emails and receiving SMS from emails is a functionality of the mobile network. You should be able to do that in any app that can send/receive SMS. https://www.att.com/support/article/wireless/KM1061254/

The point is that those other apps don’t use email addresses as the handle to contact someone. If someone iMessages you, the iMessage might (appear to) come from their phone number, or it could (appear to) come from their email. If you have an iMessage contact that’s just an email and you iMessage them, it works fine. If you try to then add Android users to your group chat, everyone gets SMS and the iMessage user wit…

I'm fairly certain that "text to email" is a feature of MMS - I've used it a few times years before iPhones were around.

I don't remember if MMS is enabled by default in iOS but theres a toggle to disable it, and realistically there's very minimal real world use-case for MMS these days.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#524
post #520

[flagged]

That’s in line with Apple’s security note, which says that it’s a vulnerability in ImageIO:

https://support.apple.com/en-us/HT213906

I wonder though, wasn’t Blastdoor supposed to stop these privilege escalations in their tracks?

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#525
post #123

Earlier quoted context omitted.

Again buffer overflow in image decoding. Would think apple might just #threatmodel and #fuzz that to death... but you would be wrong. 2.7T market cap company can't do this...

While not discounting the need to increase investment in this area, I will mention that there are very few things that can be solved by #buzzwords and #hashtags.

Then a few of those things are very important like security exploits, so #memory-safe it all the way

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#526

Earlier quoted context omitted.

NSO is reported to consist of mostly Unit 8200 staff. No way they're not deeply connected with the Israeli government.

This is a lie. It’s a UK owned company, part of Novalpina Capital. A division of their QCyber Group based out of Luxemburg.

[flagged]

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#527

Earlier quoted context omitted.

And why haven’t they been rewritten yet considering it keeps happening.

It takes a while. At Google at least, new systems in android are required to be built in rust and there are major efforts to rewrite significant systems. But it takes time and rewrites are dangerous in other ways. And you need all the tooling to handle everything else an engineer does beyond simply writing code. From where I sit, it also feels like the industry has really only coalesced around "the only real solution…

But it's already been a while...

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#528

Earlier quoted context omitted.

> Even though Apple is the largest company on the planet an entity that has a small fraction of the budget is apparently able to do a better job. NSO Group is Israeli and (most likely) filled to the brim with former Unit 8200 staff. About the best of the best what the IDF has to offer - they've been said to match the NSA in quality. > I don't see why Apple couldn't make those people an offer they can't refuse. For al…

So stop shipping iPhones to Israel until they play ball. If they're that smart they can roll their own phones. These companies do immense damage and endanger lives the world over. Given enough time and budget there is nothing that can't be cracked and it's the very worst actors that have access to this stuff.

Ha! Thats some nice fan fiction. Look at how Elon is torpedoing himself even further trying to take on ADL(lets be frank they clearly have ties to Israel). It took far right wing people + Elon bringing the issue up to even have a discussion on pushing back against ADL (and now ADL can just say thats just clearly anti-semetic people being anti-semetic) so the issue is already dead.

Apple being a public company with many institutional portfolios holding their stock would not survive these portfolios dumping their shares due to pressure if they announced this. This could even be enough to force remove Tim Cook from his role. Why would he take such a drastic position?

This rot is at all layers of the western world(UK, Canada, AUS, NZ, France at least). All the way from state governments passing laws saying you cannot boycott Israel or else you'll be barred from contracts(Anti-BDS laws) to congress removing members from their committees if they criticize Israel(eg. Illhan Omar) and signing loyalty pledges to Israel. When ANY new resistance appears against Israel, multiple groups in all of these countries move at light speed to enact a response.

The downsides of having these exploits is clearly acceptable to all the people that make the decisions. And it's not like a regular person can use these exploits against members of congress to make them feel the pain. They'll just 'Julian Assange' you.

What you are proposing requires massive reform at ALL level of government and across the western world as this is not only a US problem. Good luck with that.

This requires changing fundamental beliefs of the majority of people who vote in these governments. They have a special "bond" with Israel and they wont willingly let go of that. You'll be better off just reverse engineering the complete iOS binary and finding every possible exploit.

[1]:https://en.wikipedia.org/wiki/Anti-BDS_laws

[2]:https://en.wikipedia.org/wiki/Ilhan_Omar#Remarks_on_AIPAC_an...

[3]:https://apnews.com/article/israel-republican-vote-pramila-ja...

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#529
I would expect them to get to iCloud via this attach chain even with advanced data protection on. Which means if you are targeted, they not only get data from your iPhone but also all the data you backed up to iCloud from your other apple devices. I suspect they would be able to compromise apps like 1Password through this. Which means all services whose password and 2FA is stored together in 1Password is compromised.

It is good to know lockdown mode stopped this attach chain.

Given this has happened so many times, new security posture for a normal/regular security conscious person should be:

1. Disable iMessage.

2. Enable lockdown mode.

3. Disable iCloud. (If you choose to keep iCloud enabled, definitely enable Advanced Data Protection and disable iCloud Web, disable passcodes and keychain on iCloud. Disable iCloud mail – it uses 3rdparty proofpoint for scanning – more surface area for compromise).

4. Don't store password and 2FA together in the same system like 1password. Always use FIDO2 physical key based 2FA, if available.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#530
post #520

[flagged]

That’s in line with Apple’s security note, which says that it’s a vulnerability in ImageIO: https://support.apple.com/en-us/HT213906 I wonder though, wasn’t Blastdoor supposed to stop these privilege escalations in their tracks?

[flagged]
Post reply on HN