Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

711–720 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#711
post #689

Earlier quoted context omitted.

I don't know- I imagine deserting your brothers in arms (which may include your literal brother or sister) would be akin to deserting your family in a deadly situation. Regardless of how stupid the causes, once you're in the shit and people are at risk that you care about, the reasons you're there probably arent your biggest concern. The people that should be held accountable are the ones who orchestrated and perpetu…

I mean, to follow that analogy, yeah people absolutely should abandon their families if the families are out there actively murdering innocents. The person saying that they're only staying to murder with their families because they care about them is not a redeeming quality, and they should definitely be held accountable and not excused for their crimes. For the record, I consider any armed person outside their home…

I agree, but the world just isn't this simple. It's not about murdering with you family- it's about protecting your family. Kids I knew that went to Iraq were the protective types, not murderous. People can enlist in the military with the intention of protecting their country only to be ordered overseas caught up in some bullshit war. Historically, drafts were the main reason. And no man is an island, so whatever situation pulls one person in, is bound to ripple through other people's lives and pull others in as well.

> I consider any armed person outside their home country should be considered as a terrorist and a militia

I mean, there are situations like hostage crises where foreign countries send in soldiers that I think are completely justified. But, I agree, in general. Our foreign policy has been fucked since the CIA started after WWII. I'm just grateful I never had to fight a war- chances are I would've being born in the last couple hundred years

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#712
post #684

Earlier quoted context omitted.

Devil's advocate: we have a reasonable expectation that governments using due process to obtain warrants for criminal investigations have a right to break and enter into digital property or wiretap to catch and prosecute malefactors. How far do you really expect any tech outfit to vet the legitimacy of the warrants issued?

How about the legitimacy of the government? Most of the abuses are governments which have a long history of abusing their power and it wouldn’t be unreasonable to say that entire countries should not be trusted with sales.

Legitimacy based on what? Recongition by the UN? Lots of governments even predating the UN have been long accused of rights abuses. How many people affected, and proven so by what basis constitutes infractions beyond moral right to be trusted by NSO. I'm asking people to really grapple with this.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#713

Earlier quoted context omitted.

It does make iOS slightly more inconvenient, such as when adding each other on iMessage. And it severely reduces JavaScript performance in Safari. I think Apple wants to avoid making iOS feel slower or clunkier than Android. And zero-day spyware is usually targeted towards important individuals, not used for mass surveillance, so it indeed is a smaller risk to individual people. I'd prefer a third mode that compromis…

I would argue that iMessage is way to problematic to be used safetly, at all. By anyone. Full-stop. It also seems to be the primary attack vector of NSO related zero-days as well and its become known that phone country/area codes have relevance to its chance of succes in past exploits, which suggests a phone/messaging type attack vector.

I'm no security pro, but last night I iMessaged a friend a TikTok video and according to him, the link initiated an App Clip. Perhaps it's totally safe and I'm just naive but it just seems like the risks of a link initiating code like that outweigh any rewards. Even if it's totally safe and all involved can be trusted, that experience is enough to creep me out.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#714

Earlier quoted context omitted.

This is a lie. It’s a UK owned company, part of Novalpina Capital. A division of their QCyber Group based out of Luxemburg.

[flagged]

> NSO Group is a subsidiary of the Q Cyber Technologies group of companies.[7] Q Cyber Technologies is the name the NSO Group uses in Israel, but the company goes by OSY Technologies in Luxembourg, and in North America, a subsidiary formerly known as Westbridge. It has operated through various other companies around the world.[18]

> Owner > Novalpina Capital

Source: https://en.wikipedia.org/wiki/NSO_Group

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#715
post #684

Earlier quoted context omitted.

How about the legitimacy of the government? Most of the abuses are governments which have a long history of abusing their power and it wouldn’t be unreasonable to say that entire countries should not be trusted with sales.

Legitimacy based on what? Recongition by the UN? Lots of governments even predating the UN have been long accused of rights abuses. How many people affected, and proven so by what basis constitutes infractions beyond moral right to be trusted by NSO. I'm asking people to really grapple with this.

Imagine if, say, there was a law saying they could only sell to countries scoring 85 or better:

https://freedomhouse.org/countries/freedom-world/scores

My point being that there’s precedent for restrictions - we don’t sell nukes to anyone, and the companies which make advanced weapons systems have to get things like ITAR approvals. What would be especially powerful would be revocation: if a country is found abusing their access to this tool, they are blocked from purchases of any sort for a decade. Unfortunately, given Israel’s current politics it’s extremely unlikely that anything would happen since there’s no way to write a policy which would continue to allow their own usage.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#718

Its super interesting to me how much its emphasized that you shouldn't use Lockdown Mode unless you are a journalist or otherwise in direct palpable danger. They really do try to talk you out of it. Its curious, because there's very little difference in functionality (as experienced by the user) other than disabling a lot of Apple nonsense from running in the background expanding your attack surface. And everybody pa…

It does make iOS slightly more inconvenient, such as when adding each other on iMessage. And it severely reduces JavaScript performance in Safari. I think Apple wants to avoid making iOS feel slower or clunkier than Android. And zero-day spyware is usually targeted towards important individuals, not used for mass surveillance, so it indeed is a smaller risk to individual people. I'd prefer a third mode that compromis…

> Apple wants to avoid making iOS feel slower or clunkier than Android

Then they should let us selectively disable all background processes

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#719

Wow, so much discussion of Apple and their software, and so little of NSO group and why they're even a thing. I just want to add this: these people operate pretty much in the open. They're not ashamed of it either, or else they wouldn't put it on their CV: https://www.linkedin.com/company/nso-group/people/ That right there tells me that we as "the tech community" are way too okay with this sort of application of the…

I dont think its the "tech community" being okay with this application of the tech as much as it is fear of standing up to Israelis in any way.

Imagine you own a infosec company and an applicant with excellent skills applies. You look at the CV in detail before the interview and you see that they proudly declare their NSO background. Tell me what will you do? Cancel the interview? How comfortable would you be to deny the applicant a job for that reason alone?

I would wager the majority would consciously hire them out of fear of blowback and most of the remainder would unconsciously suppress their opinions on the NSO.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#720

Earlier quoted context omitted.

Yeah I can't believe we are still seeing this happen over and over again. Whenever you see "zero click" you know it's one of the complex payloads like images, fonts. The answer shouldn't be "don't render images". We should be able to trust that a component that parses external data such as an image, simply can't do anything malicious regardless of input. If that means sandboxing, fine. If it means having to rewrite a…

Your problem isn't the quality of your own code, it's that Google exists and is unable to stop their employees from doing stupid things like inventing WebP, because now you need to support WebP too which means using their code to do it. (Worse, WebP is at least two completely different formats - the lossless mode has nothing to do with the lossy mode.)

I think that:

a) Google should be doing that in a memory safe language, kinda nuts that they haven't started doing that already

b) Apple could definitely write their own? Unless I'm missing something crazy here, it seems like they could burn 8 figures and just have their own implementations that are safe

Post reply on HN