Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

641–650 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#641

How many exploits has iMessage had now? Isn't it time we made first messages from all new contacts plain text only, and all other messages some very restricted subset rather than some crazy extensible system that isn't so different from ActiveX? And on top of that, maybe the whole app should run in a sandbox. And on top of that, perhaps it should all be a webview to give one more layer of protection.

Yeah I can't believe we are still seeing this happen over and over again. Whenever you see "zero click" you know it's one of the complex payloads like images, fonts. The answer shouldn't be "don't render images". We should be able to trust that a component that parses external data such as an image, simply can't do anything malicious regardless of input. If that means sandboxing, fine. If it means having to rewrite a…

Your problem isn't the quality of your own code, it's that Google exists and is unable to stop their employees from doing stupid things like inventing WebP, because now you need to support WebP too which means using their code to do it.

(Worse, WebP is at least two completely different formats - the lossless mode has nothing to do with the lossy mode.)

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#642

Earlier quoted context omitted.

Yeah I can't believe we are still seeing this happen over and over again. Whenever you see "zero click" you know it's one of the complex payloads like images, fonts. The answer shouldn't be "don't render images". We should be able to trust that a component that parses external data such as an image, simply can't do anything malicious regardless of input. If that means sandboxing, fine. If it means having to rewrite a…

Your problem isn't the quality of your own code, it's that Google exists and is unable to stop their employees from doing stupid things like inventing WebP, because now you need to support WebP too which means using their code to do it. (Worse, WebP is at least two completely different formats - the lossless mode has nothing to do with the lossy mode.)

I think Apple should either sandbox or reimplement even the most complex formats. Video formats might be painfully complex to implement, but to avoid zero-click you don't even need to safeguard the whole process. You stop autoplaying and you ensure the safety of the parts that parse the metadata/thumbnails required to show the preview. Then worst case you have at least a 1-click threat when someone plays the video which then calls into some 3rd party code.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#643
post #592

Wow, so much discussion of Apple and their software, and so little of NSO group and why they're even a thing. I just want to add this: these people operate pretty much in the open. They're not ashamed of it either, or else they wouldn't put it on their CV: https://www.linkedin.com/company/nso-group/people/ That right there tells me that we as "the tech community" are way too okay with this sort of application of the…

In the current environment of Internet-powered inane mob behavior, we should try to avoid pointing the mob at individuals.

Nobody is forcing anyone to work for these scumbags. It is a choice.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#644

Earlier quoted context omitted.

Oh, but you see, NSO targets only "terrorists and criminals", so if you're a law-abiding citizen with nothing to hide, there's nothing to be concerned about. Right? It's not like there's any regimes out there where, say, casual investigative journalism or opposition politics would ever land you with criminal or terrorist charges, no sirree.

In Hungary, for example, which is an EU country and democracy (i.e. there are elections), investigative journalists have been targeted with Pegasus by the government.

In Poland, opposition party election campaign leaders were invigilated by Pegasus.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#645
post #457

Earlier quoted context omitted.

What code auditing? Are you claiming NSO has access to iMessage and iOS source code? NSO seems to be finding more and more bugs by poking a black-box alone, while Apple cannot seem to be able to fix by looking at the source code with all the fuzzing and verification tools, and much more $$$ at their disposal.

You can audit binary code with tools like Ghidra and IDA Pro. It takes a different mindset to find these type of bugs than it takes to develop software. I won't quite say they're orthogonal skill sets, but pretty close. If the people finding these bugs don't want to work for Apple, Google Project Zero, etc. there's not really much Apple can do about it.

It’s not orthogonal, it’s complementary.

Programming mindset is about making sure what’s in the spec works.

Security mindset is about making sure that what isn’t in the spec doesn’t work.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#646

Earlier quoted context omitted.

I would argue that iMessage is way to problematic to be used safetly, at all. By anyone. Full-stop. It also seems to be the primary attack vector of NSO related zero-days as well and its become known that phone country/area codes have relevance to its chance of succes in past exploits, which suggests a phone/messaging type attack vector.

It’s an attack vector because it’s convenient. If iMessage didn’t exist people would email you exploits.

Are there zero click exploits in email?

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#648
post #601

Wow, so much discussion of Apple and their software, and so little of NSO group and why they're even a thing. I just want to add this: these people operate pretty much in the open. They're not ashamed of it either, or else they wouldn't put it on their CV: https://www.linkedin.com/company/nso-group/people/ That right there tells me that we as "the tech community" are way too okay with this sort of application of the…

[flagged]

Take it down a notch, please.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#649
post #436

These fixes came out today, apparently timed with the announcement, make sure updates are applied for you and yours. https://support.apple.com/en-us/HT201222

Curious why no fix is out for iOS 15 yet. Is iOS 15 not vulnerable to this attack? Or is there often a delay in backporting security fixes that I'm not aware of? And if so, should I be implementing a workaround if I wanted to protect against these exploits?

Active support ended a year ago (12 Sep 2022), but somehow it still saw a security release on 24 Jul 2023. Perhaps we will see one more?

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#650

Earlier quoted context omitted.

Ha! Thats some nice fan fiction. Look at how Elon is torpedoing himself even further trying to take on ADL(lets be frank they clearly have ties to Israel). It took far right wing people + Elon bringing the issue up to even have a discussion on pushing back against ADL (and now ADL can just say thats just clearly anti-semetic people being anti-semetic) so the issue is already dead. Apple being a public company with ma…

> It took far right wing people + Elon bringing the issue up to even have a discussion on pushing back against ADL (and now ADL can just say thats just clearly anti-semetic people being anti-semetic) so the issue is already dead. The issue is dead because Elon's grievance is patently absurd. He's accusing the ADL of singlehandedly engineering a 60% drop in Twitter ad sales. It would be genuine comedy were it not for…

Thats my point. Pushing back against the ADL is almost impossible and when it finally happens it is associated with these knuckleheads. Therefore it is easy to dismiss...but there are serious abuses done by the ADL (just look up their history) and they now get to skate free.
Post reply on HN