Earlier quoted context omitted.
There's multiple responses echoing this idea that it's a defense company like any other and thus an evil we'll have to accept exists. That may be true, but these companies (NSO group is by no means worse than the rest of them, just more notorious) have been caught over and over again, selling these "weapons" to dictators, companies, etc, who in turn use them to spy on journalists and activists, not terrorists or anyt…
This is true, but then you have to also socially shame a large part of the US military, for invading Iraq. At least those that didn't resign as soon as it became clear that there are no WMDs there, and the large amount of Iraqis were killed pretty much for nothing. In short - you have a point, but it's not quite that simple.
NSO group iPhone zero-click, zero-day exploit captured in the wild
661–670 of 886 posts
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#662Earlier quoted context omitted.
Elections != democaracy. In Russia, there are also elections. So are they in Syria, and so on.
Sounds like you don't like the outcome and dismiss the possibility that it's the result of the system. From what I understand Orban has a decent approval rating in his country. For Putin it's hard to say since Russia is so foreign and separated, just like China - the only source of info is random crap by your preferred biased media source. But for Hungary - I've been there multiple times in the last few years, know a…
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#663Earlier quoted context omitted.
There are some misconceptions in your comments that I think could be useful to clear up. When exploiting a running system, your goal typically won't be to disable ASLR (which would only impact newly spawned processes), but instead to 'infoleak' where ASLR has placed important things you care about, so you know where to access them. Modern devices have mechanisms like KPP/KTRR, though, which make it impossible to modi…
> You also propose that CoreGraphics might not be sandboxed. CoreGraphics is a dynamic library which can be loaded into any process. It's _processes_ that are sandboxed, not dynamic libraries, so CoreGraphics can definitely exist in a process that has a sandbox profile applied just fine. Surprisingly, the decoding process had an extra step that did decoding out of the sandbox not so long ago, hopefully it's fixed now…
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#664I've personally utilized the mvt-ios tool to investigate iPhone backups. Within these backups, there is a SQLite file that mvt-ios scans for potentially malicious process names. (I've examined all publicly available STIX2 IOCs and having tooling that simply reports the names of processes from mobile phone to a central SIEM would be adequate for identifying these attacks.) Unfortunately, this method cannot be used in real-time across all devices. To employ it, one must first create a complete backup of the phone and then scrutinize that backup. If we had a tool similar to the Endpoint Security Framework available for mobile devices, we could activate enterprise-level security monitoring systems and potentially establish secure communications in the current era, rather than waiting for everything to be rewritten in Rust (a bit of irony).
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#665Earlier quoted context omitted.
> It took far right wing people + Elon bringing the issue up to even have a discussion on pushing back against ADL (and now ADL can just say thats just clearly anti-semetic people being anti-semetic) so the issue is already dead. The issue is dead because Elon's grievance is patently absurd. He's accusing the ADL of singlehandedly engineering a 60% drop in Twitter ad sales. It would be genuine comedy were it not for…
Thats my point. Pushing back against the ADL is almost impossible and when it finally happens it is associated with these knuckleheads. Therefore it is easy to dismiss...but there are serious abuses done by the ADL (just look up their history) and they now get to skate free.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#666Earlier quoted context omitted.
Thats my point. Pushing back against the ADL is almost impossible and when it finally happens it is associated with these knuckleheads. Therefore it is easy to dismiss...but there are serious abuses done by the ADL (just look up their history) and they now get to skate free.
You seem to be implying the issue is the messenger and his dimwitted minions, when really it's the message itself. If these guys are as nefarious as you're implying, surely the richest man on the planet could dig up something that's not prima facie absurd?
[1]:https://en.wikipedia.org/wiki/Anti-Defamation_League#Recepti...
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#667Earlier quoted context omitted.
The ties to government are a red herring. Hacking into people’s private phones and computer systems is generally immoral and illegal. It generally continues to be immoral and illegal when governments do it. Except it also becomes more outrageous, because governments are supposed to protect us from this sort of thing.
I don't see why the government doing it would make it more outrageous. If democratically elected leaders pass a law outlining when and how the cops should be able to access private devices, a judge looks over a specific case and signs a warrant, the cops use a hacking tool to catch a terrorist and the evidence is presented in court, this seems like the most excusable use of hacking tools that I can think of. The gove…
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#668Earlier quoted context omitted.
Oh, but you see, NSO targets only "terrorists and criminals", so if you're a law-abiding citizen with nothing to hide, there's nothing to be concerned about. Right? It's not like there's any regimes out there where, say, casual investigative journalism or opposition politics would ever land you with criminal or terrorist charges, no sirree.
In Hungary, for example, which is an EU country and democracy (i.e. there are elections), investigative journalists have been targeted with Pegasus by the government.
It was another country, we still don’t know which one it was but some think it was Morocco.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#669Earlier quoted context omitted.
There's multiple responses echoing this idea that it's a defense company like any other and thus an evil we'll have to accept exists. That may be true, but these companies (NSO group is by no means worse than the rest of them, just more notorious) have been caught over and over again, selling these "weapons" to dictators, companies, etc, who in turn use them to spy on journalists and activists, not terrorists or anyt…
This is true, but then you have to also socially shame a large part of the US military, for invading Iraq. At least those that didn't resign as soon as it became clear that there are no WMDs there, and the large amount of Iraqis were killed pretty much for nothing. In short - you have a point, but it's not quite that simple.
However, those who develop the NSO spyware are middle class Israeli citizens who easily could get a well-paying job at a less repugnant company. There are no extenuating circumstances, no "had to put food on my table", no claims of being fooled/brainwashed. They 100% deserve to be punished and they 100% deserve our disgust.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#670Earlier quoted context omitted.
There is a nice PBS documentary about Pegasus's NSO https://www.pbs.org/wgbh/frontline/documentary/global-spywar... . It looks like NSO is backed up by the Israeli government. They say their software is only sold to governments which were previously vetted, but the reality is that most of the time they sell to authoritarian states which monitor and persecute people opposing the regime.
The ties to government are a red herring. Hacking into people’s private phones and computer systems is generally immoral and illegal. It generally continues to be immoral and illegal when governments do it. Except it also becomes more outrageous, because governments are supposed to protect us from this sort of thing.
How far do you really expect any tech outfit to vet the legitimacy of the warrants issued?