How many exploits has iMessage had now? Isn't it time we made first messages from all new contacts plain text only, and all other messages some very restricted subset rather than some crazy extensible system that isn't so different from ActiveX? And on top of that, maybe the whole app should run in a sandbox. And on top of that, perhaps it should all be a webview to give one more layer of protection.
There is even precedent for doing this seamlessly: the Apple Mail client will not render media from unknown senders without user confirmation. iMessage should have the exact same behavior for the same reasons. It’s frustrating to watch greedy project managers re-learning the exact same lessons that a previous generation already learned the hard way, especially when they all work in the same building.
NSO group iPhone zero-click, zero-day exploit captured in the wild
521–530 of 886 posts
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#522Earlier quoted context omitted.
There is no email (the protocol) in iMessage (the app). You can use somebody's email address as the recipient for an iMessage (the protocol). No email is ever sent.
You can type in a contact with an email address by just their name and send an email from iMessage. I have done it to contacts accidentally many times.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#523Earlier quoted context omitted.
I think sending SMS to emails and receiving SMS from emails is a functionality of the mobile network. You should be able to do that in any app that can send/receive SMS. https://www.att.com/support/article/wireless/KM1061254/
The point is that those other apps don’t use email addresses as the handle to contact someone. If someone iMessages you, the iMessage might (appear to) come from their phone number, or it could (appear to) come from their email. If you have an iMessage contact that’s just an email and you iMessage them, it works fine. If you try to then add Android users to your group chat, everyone gets SMS and the iMessage user wit…
I don't remember if MMS is enabled by default in iOS but theres a toggle to disable it, and realistically there's very minimal real world use-case for MMS these days.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#524[flagged]
https://support.apple.com/en-us/HT213906
I wonder though, wasn’t Blastdoor supposed to stop these privilege escalations in their tracks?
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#525Earlier quoted context omitted.
Again buffer overflow in image decoding. Would think apple might just #threatmodel and #fuzz that to death... but you would be wrong. 2.7T market cap company can't do this...
While not discounting the need to increase investment in this area, I will mention that there are very few things that can be solved by #buzzwords and #hashtags.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#526Earlier quoted context omitted.
NSO is reported to consist of mostly Unit 8200 staff. No way they're not deeply connected with the Israeli government.
This is a lie. It’s a UK owned company, part of Novalpina Capital. A division of their QCyber Group based out of Luxemburg.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#527Earlier quoted context omitted.
And why haven’t they been rewritten yet considering it keeps happening.
It takes a while. At Google at least, new systems in android are required to be built in rust and there are major efforts to rewrite significant systems. But it takes time and rewrites are dangerous in other ways. And you need all the tooling to handle everything else an engineer does beyond simply writing code. From where I sit, it also feels like the industry has really only coalesced around "the only real solution…
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#528Earlier quoted context omitted.
> Even though Apple is the largest company on the planet an entity that has a small fraction of the budget is apparently able to do a better job. NSO Group is Israeli and (most likely) filled to the brim with former Unit 8200 staff. About the best of the best what the IDF has to offer - they've been said to match the NSA in quality. > I don't see why Apple couldn't make those people an offer they can't refuse. For al…
So stop shipping iPhones to Israel until they play ball. If they're that smart they can roll their own phones. These companies do immense damage and endanger lives the world over. Given enough time and budget there is nothing that can't be cracked and it's the very worst actors that have access to this stuff.
Apple being a public company with many institutional portfolios holding their stock would not survive these portfolios dumping their shares due to pressure if they announced this. This could even be enough to force remove Tim Cook from his role. Why would he take such a drastic position?
This rot is at all layers of the western world(UK, Canada, AUS, NZ, France at least). All the way from state governments passing laws saying you cannot boycott Israel or else you'll be barred from contracts(Anti-BDS laws) to congress removing members from their committees if they criticize Israel(eg. Illhan Omar) and signing loyalty pledges to Israel. When ANY new resistance appears against Israel, multiple groups in all of these countries move at light speed to enact a response.
The downsides of having these exploits is clearly acceptable to all the people that make the decisions. And it's not like a regular person can use these exploits against members of congress to make them feel the pain. They'll just 'Julian Assange' you.
What you are proposing requires massive reform at ALL level of government and across the western world as this is not only a US problem. Good luck with that.
This requires changing fundamental beliefs of the majority of people who vote in these governments. They have a special "bond" with Israel and they wont willingly let go of that. You'll be better off just reverse engineering the complete iOS binary and finding every possible exploit.
[1]:https://en.wikipedia.org/wiki/Anti-BDS_laws
[2]:https://en.wikipedia.org/wiki/Ilhan_Omar#Remarks_on_AIPAC_an...
[3]:https://apnews.com/article/israel-republican-vote-pramila-ja...
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#529It is good to know lockdown mode stopped this attach chain.
Given this has happened so many times, new security posture for a normal/regular security conscious person should be:
1. Disable iMessage.
2. Enable lockdown mode.
3. Disable iCloud. (If you choose to keep iCloud enabled, definitely enable Advanced Data Protection and disable iCloud Web, disable passcodes and keychain on iCloud. Disable iCloud mail – it uses 3rdparty proofpoint for scanning – more surface area for compromise).
4. Don't store password and 2FA together in the same system like 1password. Always use FIDO2 physical key based 2FA, if available.