Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

731–740 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#731
post #631
post #510

Earlier quoted context omitted.

can one actually disable iMessage on their iPhones? At this point I only use WhatsApp, I couldn't care less about super SMS. EDIT: found it. For anyone who's interested: > Turn off iMessage: > On your iPhone, go to Settings. > Tap Messages. > Set iMessage to Off.

It seems that even turning off iMessage is not enough ? This a zero-click exploit, which means you don't even have to open the message to get hacked.

It means it runs through iMessage. Whether the "turn off iMessage" feature is enough I don't know. But if turning off iMessage actually stops any messages and SMS/MMS etc from running through iMessage at all, it's a pretty decent bet.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#732
post #651

Earlier quoted context omitted.

Elections != democaracy. In Russia, there are also elections. So are they in Syria, and so on.

Sometimes known as "Model-T election" "Any customer can have a car painted any color that he wants so long as it is black."

We have this in the US too but with two colors, both neoliberal.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#733

Earlier quoted context omitted.

Depending on the circumstances, absolutely. Assuming that serious unjustified injury or death would occur if they failed to act, there should be some legal window in which they’re allowed to prevent the harm. Private companies (and individuals) should not be required to stand by helplessly while people are hurt. Indeed, legally, private individuals and companies are allowed to act in emergencies. For example, I gener…

You mean something like citizen's arrest? https://en.m.wikipedia.org/wiki/Citizen%27s_arrest

Exactly. Indeed, in Phoenix v State, 455 So.2d 1024, the Florida Supreme Court implies that a private citizen could request and receive a warrant to arrest a felon. They say the citizen could be excused for failing to obtain a warrant by proving the person arrested was actually guilty.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#734
post #630

Earlier quoted context omitted.

I call bullshit on this one. I don't buy that being able to manually copy data into a memory buffer is critical for performance when implementing image codecs. Nor do I accept that, even if we do want to manually copy data into memory, a bounds check at runtime would degrade performance to a noticeable extent.

"Manually copy data into a memory buffer" is pretty vague… try "writing a DSP function that does qpel motion compensation without having to calculate and bounds check each source memory access from the start of the image because you're on x86-32 and you only have like six GPRs". Though that one's for video; images are simpler but you also have to deploy the code to a lot more platforms.

Why would an iPhone be running x86-specific code?

I don't dispute that these optimizations may have been necessary on older hardware, but I think the current generation of Apple CPUs should have plenty of power to not need these micro optimizations (and the hardware video decoder would take care of this anyway).

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#735
post #632

Earlier quoted context omitted.

What's the point? It'll get feedback and get better at dressing up the noise.

Do we want to encourage the use of LLMs in discussion? Soon there will be just LLMs...

As an HN poster I endorse $yc and dislike $microsoft

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#736

Earlier quoted context omitted.

I think sending SMS to emails and receiving SMS from emails is a functionality of the mobile network. You should be able to do that in any app that can send/receive SMS. https://www.att.com/support/article/wireless/KM1061254/

On Apple's end, iMessage also supports email addresses as a user identifier (and it's the only one you get if you don't have an iPhone with an assigned phone number). It's still not sending emails, though. The iPhone Messages app sends SMS, MMS, and iMessage; email is the responsibility of the Mail app.

They support email address for sms id as well. Pretty common for phishing.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#737

Earlier quoted context omitted.

> have been caught over and over again, selling these "weapons" to dictators, companies, etc Meanwhile, a nice silent worm propagates among their network... I have 0-faith that the version they have sold to bad actors is clean when they probably are begging you to take their software into your internal network.

How convenient. It almost makes the dead journalists seem like a win!

From being in MI, collateral damage is a thing... decisions like "if we act on this information, 100 people will be saved but they'll know we know and 1,000s could die. If we let 100 people die, we can save 1,000s" are more common than we'd like.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#738

Earlier quoted context omitted.

The way this works is that in addition to the more colorful clients, you absolutely need to make sure that you have a sufficient number of clients among law enforcement and security services in countries with a decent(-ish) track record regarding human rights. This way, your products and services are not obviously illegal. You can even tell your employees that your products and services are saving lives because it's…

The OS vendors refuse to implement lawful intercept capability because there is no such thing as a lawful intercept capability. There is only intercept capability for any purpose because ROM bootloaders and secure enclaves cannot vet the lawfulness of a request to subvert their owners. You can make a phone relatively secure against people trying to break into it, but only if it has unique access keys for the owner. I…

>The Saudis have one very big lever they can use to force the west to do what it wants: gas prices.

The United States gets most of its petroleum from Canada.

Saudi Arabia accounts for only 7% of U.S. petroleum and crude oil imports.

Source: https://www.eia.gov/energyexplained/oil-and-petroleum-produc...

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#739
post #390

Earlier quoted context omitted.

Because sandboxing on iOS is terrible. Not that any of the other commercial vendors are any better. If they could provide good sandboxes do you think the highest security certifications advertised on their website [1][2] would only certify protection against attackers with “basic attack potential”, the lowest possible level. Three whole levels below “moderate attack potential”. I mean, seriously, they certify their s…

From a security perspective, Common Criteria certification isn’t particularly meaningful. Plus, it’s not really worth getting certified at a higher level than you need. Why expend extra effort?

No. From a security perspective a Common Criteria certification to the lowest possible level does not establish meaningful security. That is kind of the point.

The companies that develop easily hacked systems that are repeatedly hacked hundreds of times a year like Apple, Microsoft, Cisco, Amazon, Google, etc. can only achieve certification levels indicating they are easily hacked. They have never once succeeded at certifying meaningful security. The certification is pinpoint accurate, just the trillion dollar commercial IT companies do not like the results.

I agree it is largely not a useful differentiator, but that is because all of the commercial IT vendors are certified incompetent. The Common Criteria will not help you determine which fish in the barrel is hardest to shoot. Its job is to distinguish serious security by professionals.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#740

Earlier quoted context omitted.

The way this works is that in addition to the more colorful clients, you absolutely need to make sure that you have a sufficient number of clients among law enforcement and security services in countries with a decent(-ish) track record regarding human rights. This way, your products and services are not obviously illegal. You can even tell your employees that your products and services are saving lives because it's…

The OS vendors refuse to implement lawful intercept capability because there is no such thing as a lawful intercept capability. There is only intercept capability for any purpose because ROM bootloaders and secure enclaves cannot vet the lawfulness of a request to subvert their owners. You can make a phone relatively secure against people trying to break into it, but only if it has unique access keys for the owner. I…

[deleted]
Post reply on HN