Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

601–610 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#601

Wow, so much discussion of Apple and their software, and so little of NSO group and why they're even a thing. I just want to add this: these people operate pretty much in the open. They're not ashamed of it either, or else they wouldn't put it on their CV: https://www.linkedin.com/company/nso-group/people/ That right there tells me that we as "the tech community" are way too okay with this sort of application of the…

[flagged]

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#602

Earlier quoted context omitted.

Much of this stuff is classified as a weapon, and thus really sold by the Israeli government, not by the company. It's no different from a MANPADS that sometimes is used to destroy a Ka-52 over Ukraine, and sometimes is used to shoot down a civilian airliner - that is to say it's directed by the foreign policy (and foreign policy errors) of the manufacturing country. There's no reason to expect the world to disarm an…

There's multiple responses echoing this idea that it's a defense company like any other and thus an evil we'll have to accept exists. That may be true, but these companies (NSO group is by no means worse than the rest of them, just more notorious) have been caught over and over again, selling these "weapons" to dictators, companies, etc, who in turn use them to spy on journalists and activists, not terrorists or anyt…

Yeah, I think the appropriate comparison is if a weapons manufacturer made "selling to dictatorships for suppressing dissidents" the core of its business strategy.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#603

Earlier quoted context omitted.

> And WhatsApp is almost unusable unless you consent to uploading all your contacts to Facebook. What? How-so? I've never allowed it to do that and it works fine for me, across iOS/Mac/Windows.

It works but it shows phone numbers rather than contact names and you can’t assign a name to a number without giving access to your entire contacts … it ticks me off.

Contact scoping on grapheneos solves that.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#604
post #577

Wow, so much discussion of Apple and their software, and so little of NSO group and why they're even a thing. I just want to add this: these people operate pretty much in the open. They're not ashamed of it either, or else they wouldn't put it on their CV: https://www.linkedin.com/company/nso-group/people/ That right there tells me that we as "the tech community" are way too okay with this sort of application of the…

There is a nice PBS documentary about Pegasus's NSO https://www.pbs.org/wgbh/frontline/documentary/global-spywar... . It looks like NSO is backed up by the Israeli government. They say their software is only sold to governments which were previously vetted, but the reality is that most of the time they sell to authoritarian states which monitor and persecute people opposing the regime.

To sell the software, they need approval from Israel’s govt, as the software is treated as a weapon

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#605

Wow, so much discussion of Apple and their software, and so little of NSO group and why they're even a thing. I just want to add this: these people operate pretty much in the open. They're not ashamed of it either, or else they wouldn't put it on their CV: https://www.linkedin.com/company/nso-group/people/ That right there tells me that we as "the tech community" are way too okay with this sort of application of the…

No big political leaders out of the tech world yet. So "the tech community" doesnt have anyone to rally around. And this more a political prob than a technical problem.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#606
post #490

Earlier quoted context omitted.

And the US barely has an inherent interest in Saudi Arabia. Israel is credited for helping the US "fight terrorism in the Middle East" or maintain those puppets, but really they're just helping us help them. When it comes to things that don't directly benefit Israel, they don't care. Israel has never even fought ISIS for example, the largest recent terrorist threat in the region. And they're allowed to maintain some…

It’s truly shocking how misinformed you are about foreign policy. Israel attempted to maintain some level of neutrality wrt Russia bec when they show preferences, Russia punishes the local Jewish population… which they promptly did as soon as Israel showed any support for Ukraine. Israel shares a ton of intel with the US regarding many of the local terrorist organizations in the ME. Not to mention they’re flying sort…

Are you an NSO psychopath or something?! Those funny propaganda jokes you're spewing are not working. The Israeli Hasbara lies are so bad and funny (Oh we won the land instead of we are scumy occupiers and land thieves haha.) This Israeli murder cult is sad and pathetic.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#607
post #23

Here we go again... NSO Group has a long history of 0-click, 0-days against iMessage, and just a few months ago Kaspersky caught a different zero day iMessage exploit targeting their staff. If Apple repeatedly fails at securing their devices from an attack vector that has been demonstrated over, and over, and over... no wonder China is banning government officials from using their devices.

>no wonder China is banning government officials from using their devices A totalitarian regime can have a different, plausible reason: no sufficient control over said devices.

[dead]

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#608
post #520

[flagged]

There are some misconceptions in your comments that I think could be useful to clear up. When exploiting a running system, your goal typically won't be to disable ASLR (which would only impact newly spawned processes), but instead to 'infoleak' where ASLR has placed important things you care about, so you know where to access them. Modern devices have mechanisms like KPP/KTRR, though, which make it impossible to modi…

> You also propose that CoreGraphics might not be sandboxed. CoreGraphics is a dynamic library which can be loaded into any process. It's _processes_ that are sandboxed, not dynamic libraries, so CoreGraphics can definitely exist in a process that has a sandbox profile applied just fine.

Surprisingly, the decoding process had an extra step that did decoding out of the sandbox not so long ago, hopefully it's fixed now.

https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#609

Earlier quoted context omitted.

There's multiple responses echoing this idea that it's a defense company like any other and thus an evil we'll have to accept exists. That may be true, but these companies (NSO group is by no means worse than the rest of them, just more notorious) have been caught over and over again, selling these "weapons" to dictators, companies, etc, who in turn use them to spy on journalists and activists, not terrorists or anyt…

Yeah, I think the appropriate comparison is if a weapons manufacturer made "selling to dictatorships for suppressing dissidents" the core of its business strategy.

[deleted]
Post reply on HN