Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

701–710 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#701

Earlier quoted context omitted.

Grsecurity generally focuses on the kernel side of things, although it does include a number of userspace mitigations as well. Still, when you have such ripe primitives not even Grsecurity can protect you. What we really need is to just have radically lower bug density. Buffer overflows need to die. UAFs need to be made far less common. The "distance" between vulns needs to be greatly increased. Having design and val…

Grsec would make achieving code exec much harder or impossible.

I'm not convinced that that's true. All we know is that one vulnerability was a "buffer overflow" - pretty vague. If this were, for example, an overflow on the heap, which Grsecurity mitigations would even impact it? Improved ASLR? Mprotect restrictions? There are very few mitigations in the Grsecurity patches that even touch userspace in a way that isn't focused on kernel protection.

Maybe if it's a stack based overflow something like PAX_RANDUSTACK would have had some impact but it depends.

And in case this at all comes off as me thinking anything negative about Grsecurity, I assure you that's not the case. I proudly wear the "Grsecurity Cheerleader" badge that Spender threw my way over a decade ago.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#702
post #678

Wow, so much discussion of Apple and their software, and so little of NSO group and why they're even a thing. I just want to add this: these people operate pretty much in the open. They're not ashamed of it either, or else they wouldn't put it on their CV: https://www.linkedin.com/company/nso-group/people/ That right there tells me that we as "the tech community" are way too okay with this sort of application of the…

Actual headline: mentions NSO group and nothing about Apple. Top comment (+50 comments): Why do we talk about Apple so much and so little about NSO group. The absurdly pro-Apple PR on HN is tough to bear. I have to say it's so overt it made me more hostile to Apple (NSO is obviously a worthy topic, but we do discuss it).

(responding to a deleted comment)

Plenty of these comments are about NSO. And that's fine! But trying to catch every blackhat won't solve our security problems. Ultimately, the only solution to these security holes is more secure software, and the only way to get that is to pressure Apple to invest more resources. The main question should be how come 'secure' Apple software keeps having 0-click exploits.

Pressuring Microsoft led them to adopt a much more secure culture compared to previously. Apple shouldn't be exempt from the same pressure.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#703

Wow, so much discussion of Apple and their software, and so little of NSO group and why they're even a thing. I just want to add this: these people operate pretty much in the open. They're not ashamed of it either, or else they wouldn't put it on their CV: https://www.linkedin.com/company/nso-group/people/ That right there tells me that we as "the tech community" are way too okay with this sort of application of the…

This is a problem of legislation. It would be trivially easy to stop this behavior, but governments in the western sphere tend to like surveillance as well.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#704

Earlier quoted context omitted.

Much of this stuff is classified as a weapon, and thus really sold by the Israeli government, not by the company. It's no different from a MANPADS that sometimes is used to destroy a Ka-52 over Ukraine, and sometimes is used to shoot down a civilian airliner - that is to say it's directed by the foreign policy (and foreign policy errors) of the manufacturing country. There's no reason to expect the world to disarm an…

There's multiple responses echoing this idea that it's a defense company like any other and thus an evil we'll have to accept exists. That may be true, but these companies (NSO group is by no means worse than the rest of them, just more notorious) have been caught over and over again, selling these "weapons" to dictators, companies, etc, who in turn use them to spy on journalists and activists, not terrorists or anyt…

Same could be said about weapon development.

They should be ashamed of themselves, but you are still barking at the wrong tree in the long run. You should demand your own government to outlaw this type of surveillance.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#705

Earlier quoted context omitted.

Do you think private companies should be allowed to, say, arrest people?

Depending on the circumstances, absolutely. Assuming that serious unjustified injury or death would occur if they failed to act, there should be some legal window in which they’re allowed to prevent the harm. Private companies (and individuals) should not be required to stand by helplessly while people are hurt. Indeed, legally, private individuals and companies are allowed to act in emergencies. For example, I gener…

You mean something like citizen's arrest?

https://en.m.wikipedia.org/wiki/Citizen%27s_arrest

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#706
post #681

Earlier quoted context omitted.

It does if we grant the two the same assumptions. If we assume that serious, unjustified harm would occur by failing to act, and they are in a reasonable position to act… then I’d say a private company is equally justified in doing the same thing. However, you’re assuming the government is justified merely because it’s the government.

Maybe it depends on the country, but private companies cant generally get warrants to infringe on people's rights afaik. If justified is interpreted as 'legally justified', then it would make sense that only government agents could be justified to act in this manner. Of course, government agents are known to operate outside the law as well.

I wouldn’t assume that private companies and individuals cannot get warrants.

However, they look very different. The major distinction is that when a private party requests an injunction allowing them to e.g. trespass on their neighbor’s land, the court will require notice and a hearing for the defendant. So, if a chemical plant needs to do earth works on a neighbor’s land to prevent a collapse, etc. the judiciary may well issue an order requiring the neighbor to let the company enter.

Frankly, notice and hearing should probably be required for some criminal warrants too. I can think of a few indictments and arrest warrants that have recently been issued where there is a genuine question as to probable cause and the alleged illegality of the conduct. It’s not fair for people who are not a flight risk to be arrested (and often imprisoned) with no opportunity to defend themselves.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#707

Earlier quoted context omitted.

This is true, but then you have to also socially shame a large part of the US military, for invading Iraq. At least those that didn't resign as soon as it became clear that there are no WMDs there, and the large amount of Iraqis were killed pretty much for nothing. In short - you have a point, but it's not quite that simple.

Yeah, every single US soldier who voluntarily stepped on Iraqi soil should be sent to the ICC and tried for war crimes. Some of them would be exonerated for being too stupid/brainwashed to understand that they were committing criminal acts. Others wouldn't. However, those who develop the NSO spyware are middle class Israeli citizens who easily could get a well-paying job at a less repugnant company. There are no exte…

Why the soldiers? They aren't the ones that made the decision. Sure, if they committed war crimes themselves, but for anything else you have to address the people that actually were responsible. Prosecuting soldiers would be futile and certainly no justice.

There was a lot of media propaganda to make the war popular. It wasn't at first but it didn't even take half a year until people ate it up. Liberal, conservative, didn't even matter. It was scary to see how quickly people were manipulated. It had large support in the population. People should stop and reflect what made them support the war, which messages and by whom. That is the responsibility they can take here and it would be much more constructive than putting the blame on soldiers...

Israel citizens might have a better excuse to develop weapons than most other countries, so I don't see the point. Not an excuse, but at least an explanation.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#708
post #651

Earlier quoted context omitted.

In Hungary, for example, which is an EU country and democracy (i.e. there are elections), investigative journalists have been targeted with Pegasus by the government.

Elections != democaracy. In Russia, there are also elections. So are they in Syria, and so on.

Sometimes known as "Model-T election"

"Any customer can have a car painted any color that he wants so long as it is black."

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#709
post #577

Earlier quoted context omitted.

There is a nice PBS documentary about Pegasus's NSO https://www.pbs.org/wgbh/frontline/documentary/global-spywar... . It looks like NSO is backed up by the Israeli government. They say their software is only sold to governments which were previously vetted, but the reality is that most of the time they sell to authoritarian states which monitor and persecute people opposing the regime.

The way this works is that in addition to the more colorful clients, you absolutely need to make sure that you have a sufficient number of clients among law enforcement and security services in countries with a decent(-ish) track record regarding human rights. This way, your products and services are not obviously illegal. You can even tell your employees that your products and services are saving lives because it's…

The OS vendors refuse to implement lawful intercept capability because there is no such thing as a lawful intercept capability. There is only intercept capability for any purpose because ROM bootloaders and secure enclaves cannot vet the lawfulness of a request to subvert their owners. You can make a phone relatively secure against people trying to break into it, but only if it has unique access keys for the owner. If you give any government a second key for intercept capabilities, that key will be a single point of failure for the entire system. Eventually it will leak and your phone password will be effectively useless.

I don't even need to invent a scenario for this: you can buy the TSA master keys off Amazon right now. The only reason why it's not a huge problem is that TSA locks are a special thing you buy and use solely for airline luggage that is already in TSA custody anyway. If you use TSA locks on anything else, however, you're just asking for it to be stolen because the locks don't actually provide any security.

The shady clients will get their hands on any intercept key provided by law enforcement, because it's legally unreasonable for Apple or Google to only provide intercept capability to some of the countries they operate in. e.g. if you give the US and UK a decryption key you also have to give it to Saudi Arabia[0]. Hell, in some countries the shady and legit clients are part of the same government - e.g. you can't give the key to just the FBI but not the NSA or CIA.

[0] The Saudis have one very big lever they can use to force the west to do what it wants: gas prices.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#710

Wow, so much discussion of Apple and their software, and so little of NSO group and why they're even a thing. I just want to add this: these people operate pretty much in the open. They're not ashamed of it either, or else they wouldn't put it on their CV: https://www.linkedin.com/company/nso-group/people/ That right there tells me that we as "the tech community" are way too okay with this sort of application of the…

Darknet Diaries had an episode about them a while back. It’s a good listen (as that podcast always is). https://darknetdiaries.com/episode/100/

I just got finished listening to the most recent episode of Darknet Diaries this morning on the way into the office! It was about similar companies to the NSO group: https://darknetdiaries.com/episode/137/
Post reply on HN