Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

631–640 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#631
post #510

How many exploits has iMessage had now? Isn't it time we made first messages from all new contacts plain text only, and all other messages some very restricted subset rather than some crazy extensible system that isn't so different from ActiveX? And on top of that, maybe the whole app should run in a sandbox. And on top of that, perhaps it should all be a webview to give one more layer of protection.

can one actually disable iMessage on their iPhones? At this point I only use WhatsApp, I couldn't care less about super SMS. EDIT: found it. For anyone who's interested: > Turn off iMessage: > On your iPhone, go to Settings. > Tap Messages. > Set iMessage to Off.

It seems that even turning off iMessage is not enough ?

This a zero-click exploit, which means you don't even have to open the message to get hacked.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#632

Earlier quoted context omitted.

Looking at their history you’re likely right. Downvoted.

What's the point? It'll get feedback and get better at dressing up the noise.

Do we want to encourage the use of LLMs in discussion? Soon there will be just LLMs...

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#633
post #531

Earlier quoted context omitted.

> I would argue that iMessage is way to problematic to be used safely, at all. Maybe I'm missing something but every single time the only part of iMessage (actually Messages.app) that is insecure is the bit that automatically unfurls attachments and the payload is exploiting a vulnerability elsewhere. So any other app unfurling the attachment thus triggering the payload would be equally vulnerable. Imagine ping had a…

> So any other app unfurling the attachment thus triggering the payload would be equally vulnerable. What you're missing is that iPhone's app sandboxing applies to other apps, not to iMessage. Sure, imessage does have blastdoor and some sandboxing, but it also still has imagent: https://googleprojectzero.blogspot.com/2021/01/a-look-at-ime... imagent runs as root and processes incoming messages. whatsapp or signal or…

> imagent [...] processes incoming messages

does it?

IIUC (from a cursory look) according to the diagram it delegates all message processing to MessageBlastDoorService/IM{Transfer,Transcoder,Persistence}Agent, relying only on locally computed boolean-ish metadata replies from these services, and merely transparently forwarding actual data between those.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#635
post #577

Earlier quoted context omitted.

There is a nice PBS documentary about Pegasus's NSO https://www.pbs.org/wgbh/frontline/documentary/global-spywar... . It looks like NSO is backed up by the Israeli government. They say their software is only sold to governments which were previously vetted, but the reality is that most of the time they sell to authoritarian states which monitor and persecute people opposing the regime.

The ties to government are a red herring. Hacking into people’s private phones and computer systems is generally immoral and illegal. It generally continues to be immoral and illegal when governments do it. Except it also becomes more outrageous, because governments are supposed to protect us from this sort of thing.

I don't see why the government doing it would make it more outrageous. If democratically elected leaders pass a law outlining when and how the cops should be able to access private devices, a judge looks over a specific case and signs a warrant, the cops use a hacking tool to catch a terrorist and the evidence is presented in court, this seems like the most excusable use of hacking tools that I can think of.

The government is given power over people in order to protect us from other people and this is one tool to do it. They have cops with guns and soldiers with tanks, they can break in, search and seize, they can lock people in prison. All of these things are tools and it's they way they're used that decides what's immoral or outrageous.

The bigger problem here is that a private company has these tools and can use and sell then with no oversight.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#636
post #577

Earlier quoted context omitted.

There is a nice PBS documentary about Pegasus's NSO https://www.pbs.org/wgbh/frontline/documentary/global-spywar... . It looks like NSO is backed up by the Israeli government. They say their software is only sold to governments which were previously vetted, but the reality is that most of the time they sell to authoritarian states which monitor and persecute people opposing the regime.

The ties to government are a red herring. Hacking into people’s private phones and computer systems is generally immoral and illegal. It generally continues to be immoral and illegal when governments do it. Except it also becomes more outrageous, because governments are supposed to protect us from this sort of thing.

[deleted]

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#637

Wow, so much discussion of Apple and their software, and so little of NSO group and why they're even a thing. I just want to add this: these people operate pretty much in the open. They're not ashamed of it either, or else they wouldn't put it on their CV: https://www.linkedin.com/company/nso-group/people/ That right there tells me that we as "the tech community" are way too okay with this sort of application of the…

Well it's like complaining about the sun or wearing sun screen. Bad guys will always be there. Bears pandas eagles...

We wear sun screen and maybe get pissed if the sun screen company is not doing a good job. But go ahead yell at the sun. Those dam UV rays!!!

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#638

Earlier quoted context omitted.

Much of this stuff is classified as a weapon, and thus really sold by the Israeli government, not by the company. It's no different from a MANPADS that sometimes is used to destroy a Ka-52 over Ukraine, and sometimes is used to shoot down a civilian airliner - that is to say it's directed by the foreign policy (and foreign policy errors) of the manufacturing country. There's no reason to expect the world to disarm an…

There's multiple responses echoing this idea that it's a defense company like any other and thus an evil we'll have to accept exists. That may be true, but these companies (NSO group is by no means worse than the rest of them, just more notorious) have been caught over and over again, selling these "weapons" to dictators, companies, etc, who in turn use them to spy on journalists and activists, not terrorists or anyt…

So then, by this logic, once you've worked for NSO Group or the like, there's no way back for you. How then, can someone reform or "see the light"? Is someone once tainted, always tainted? Or do they have to do 10 years in the NFP space before we see them as worthy?

The problem is that by walling off developers who participate in these activities, we essentially force them to continue these activities. I'm not sure that's net positive.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#639
post #637

Wow, so much discussion of Apple and their software, and so little of NSO group and why they're even a thing. I just want to add this: these people operate pretty much in the open. They're not ashamed of it either, or else they wouldn't put it on their CV: https://www.linkedin.com/company/nso-group/people/ That right there tells me that we as "the tech community" are way too okay with this sort of application of the…

Well it's like complaining about the sun or wearing sun screen. Bad guys will always be there. Bears pandas eagles... We wear sun screen and maybe get pissed if the sun screen company is not doing a good job. But go ahead yell at the sun. Those dam UV rays!!!

I generally agree but it's nuanced. Think about your physical home security.

Just like bad guys are always gonna be there, so will the bugs.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#640
post #630

Earlier quoted context omitted.

Almost all people don't want to or aren't capable of implementing image codecs, the safer languages aren't fast enough to do it in, and the people who are capable of it don't want to learn them.

I call bullshit on this one. I don't buy that being able to manually copy data into a memory buffer is critical for performance when implementing image codecs. Nor do I accept that, even if we do want to manually copy data into memory, a bounds check at runtime would degrade performance to a noticeable extent.

"Manually copy data into a memory buffer" is pretty vague… try "writing a DSP function that does qpel motion compensation without having to calculate and bounds check each source memory access from the start of the image because you're on x86-32 and you only have like six GPRs".

Though that one's for video; images are simpler but you also have to deploy the code to a lot more platforms.

Post reply on HN