Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

591–600 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#592

Wow, so much discussion of Apple and their software, and so little of NSO group and why they're even a thing. I just want to add this: these people operate pretty much in the open. They're not ashamed of it either, or else they wouldn't put it on their CV: https://www.linkedin.com/company/nso-group/people/ That right there tells me that we as "the tech community" are way too okay with this sort of application of the…

In the current environment of Internet-powered inane mob behavior, we should try to avoid pointing the mob at individuals.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#593
post #380

Earlier quoted context omitted.

You can turn off lockdown mode per site and per-app in safari. I had to do that to get Obsidian to work, but I also use it for specific trusted sites.

What do you mean "per-app in safari"? I'd like to turn it on globally, with a single exception: I want to be able to continue using shared photos albums with my two best friends. I don't care enough about JS performance or, more generally, the mobile web, to want to disable it on safari, or even parts of it.

You can disable lockdown mode in web views for specific apps. You do it in settings because those apps don’t have the usual Safari UI for configuring that.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#594

Wow, so much discussion of Apple and their software, and so little of NSO group and why they're even a thing. I just want to add this: these people operate pretty much in the open. They're not ashamed of it either, or else they wouldn't put it on their CV: https://www.linkedin.com/company/nso-group/people/ That right there tells me that we as "the tech community" are way too okay with this sort of application of the…

Much of this stuff is classified as a weapon, and thus really sold by the Israeli government, not by the company. It's no different from a MANPADS that sometimes is used to destroy a Ka-52 over Ukraine, and sometimes is used to shoot down a civilian airliner - that is to say it's directed by the foreign policy (and foreign policy errors) of the manufacturing country. There's no reason to expect the world to disarm an…

There's multiple responses echoing this idea that it's a defense company like any other and thus an evil we'll have to accept exists.

That may be true, but these companies (NSO group is by no means worse than the rest of them, just more notorious) have been caught over and over again, selling these "weapons" to dictators, companies, etc, who in turn use them to spy on journalists and activists, not terrorists or anything of the sort. And that doesn't even go into keeping 0-days for the benefit of the few, keeping literally everyone on the planet less safe, which is arguably as big an issue, if more systemic.

These companies may exist in some form or another because the nation state & private surveillance systems that form their client base want them to exist.

But my point is that the individuals working at this company should be ashamed of themselves. I'm not appealing to their sense of morals, I'm talking purely about "us the tech community" making it abundantly clear that having one of these companies on your CV will make it very hard to find any decent job afterwards. It needs to be socially expensive to work there. To loan from Max Goldt's opinion on the BILD newspaper [1]:

> NSO Group and the like are an organ of infamy. It is wrong to use their products. Someone who contributes to these products is absolutely socially unacceptable. It would be remiss to be friendly or even polite to any of their developers or managers. One must be as unkind to them as the law will just allow. They are bad people who do wrong.

[1]: https://www.goodreads.com/quotes/6758128-die-bild-zeitung-is...

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#595
post #128

Earlier quoted context omitted.

No that's not true. Google just fails miserably at anything social, but almost every chat attempt from them eas encrypted, and now they are pushing RCS, which is also E2EE.

So YouTube isn't a social platform?

Is it? I thinks its rather more like entertainment

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#596
post #588

Earlier quoted context omitted.

AFAIK Israeli government audits NSO and stuff, but they are separate... And Intellexa (authors of Predator I think?) doesn't even get audited because it's "not israeli" on paper

It's more like they leverage it for diplomacy. The auditing means nothing really, it's being given to authoritarian government like Saudi Arabia as long as they are OK with Israel existing. The bar to get access to NSO tools is too low...

They don't really leverage it for diplomacy. Israeli arms exports policy consistently prioritizes getting better R&D economies of scale over actually affecting foreign states' behavior.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#599

Earlier quoted context omitted.

> Even though Apple is the largest company on the planet an entity that has a small fraction of the budget is apparently able to do a better job. NSO Group is Israeli and (most likely) filled to the brim with former Unit 8200 staff. About the best of the best what the IDF has to offer - they've been said to match the NSA in quality. > I don't see why Apple couldn't make those people an offer they can't refuse. For al…

So stop shipping iPhones to Israel until they play ball. If they're that smart they can roll their own phones. These companies do immense damage and endanger lives the world over. Given enough time and budget there is nothing that can't be cracked and it's the very worst actors that have access to this stuff.

> So stop shipping iPhones to Israel until they play ball.

For what purpose? They would still procure iPhones through gray channels and hack them because that's what their victims use. Should Apple also stop selling phones in every other country, because that's where many of NSO's exploits are actually used?

What other purpose? Annoy the local population? Create a grey/black market where you're even more likely to be given a "pre-hacked" unit?

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#600

I find it interesting that most comments here are blaming the victim (Apple’s iMessage and by transitivity its users) rather than the aggressor (NSO and its users). How come NSO isn’t yet designated as a (cyber-)terrorist group worth hunting down and extinguishing?

Because it's an arms supplier to states, who use them on domestic targets. Selling tear gas rounds to tinpot dictatorships generally doesn't get you treated as a terrorist group either, just economic sanctions (which were already placed on the company by the US DoC, IIRC).
Post reply on HN