Earlier quoted context omitted.
can one actually disable iMessage on their iPhones? At this point I only use WhatsApp, I couldn't care less about super SMS. EDIT: found it. For anyone who's interested: > Turn off iMessage: > On your iPhone, go to Settings. > Tap Messages. > Set iMessage to Off.
It seems that even turning off iMessage is not enough ? This a zero-click exploit, which means you don't even have to open the message to get hacked.
NSO group iPhone zero-click, zero-day exploit captured in the wild
731–740 of 886 posts
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#732Earlier quoted context omitted.
Elections != democaracy. In Russia, there are also elections. So are they in Syria, and so on.
Sometimes known as "Model-T election" "Any customer can have a car painted any color that he wants so long as it is black."
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#733Earlier quoted context omitted.
Depending on the circumstances, absolutely. Assuming that serious unjustified injury or death would occur if they failed to act, there should be some legal window in which they’re allowed to prevent the harm. Private companies (and individuals) should not be required to stand by helplessly while people are hurt. Indeed, legally, private individuals and companies are allowed to act in emergencies. For example, I gener…
You mean something like citizen's arrest? https://en.m.wikipedia.org/wiki/Citizen%27s_arrest
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#734Earlier quoted context omitted.
I call bullshit on this one. I don't buy that being able to manually copy data into a memory buffer is critical for performance when implementing image codecs. Nor do I accept that, even if we do want to manually copy data into memory, a bounds check at runtime would degrade performance to a noticeable extent.
"Manually copy data into a memory buffer" is pretty vague… try "writing a DSP function that does qpel motion compensation without having to calculate and bounds check each source memory access from the start of the image because you're on x86-32 and you only have like six GPRs". Though that one's for video; images are simpler but you also have to deploy the code to a lot more platforms.
I don't dispute that these optimizations may have been necessary on older hardware, but I think the current generation of Apple CPUs should have plenty of power to not need these micro optimizations (and the hardware video decoder would take care of this anyway).
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#735Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#736Earlier quoted context omitted.
I think sending SMS to emails and receiving SMS from emails is a functionality of the mobile network. You should be able to do that in any app that can send/receive SMS. https://www.att.com/support/article/wireless/KM1061254/
On Apple's end, iMessage also supports email addresses as a user identifier (and it's the only one you get if you don't have an iPhone with an assigned phone number). It's still not sending emails, though. The iPhone Messages app sends SMS, MMS, and iMessage; email is the responsibility of the Mail app.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#737Earlier quoted context omitted.
> have been caught over and over again, selling these "weapons" to dictators, companies, etc Meanwhile, a nice silent worm propagates among their network... I have 0-faith that the version they have sold to bad actors is clean when they probably are begging you to take their software into your internal network.
How convenient. It almost makes the dead journalists seem like a win!
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#738Earlier quoted context omitted.
The way this works is that in addition to the more colorful clients, you absolutely need to make sure that you have a sufficient number of clients among law enforcement and security services in countries with a decent(-ish) track record regarding human rights. This way, your products and services are not obviously illegal. You can even tell your employees that your products and services are saving lives because it's…
The OS vendors refuse to implement lawful intercept capability because there is no such thing as a lawful intercept capability. There is only intercept capability for any purpose because ROM bootloaders and secure enclaves cannot vet the lawfulness of a request to subvert their owners. You can make a phone relatively secure against people trying to break into it, but only if it has unique access keys for the owner. I…
The United States gets most of its petroleum from Canada.
Saudi Arabia accounts for only 7% of U.S. petroleum and crude oil imports.
Source: https://www.eia.gov/energyexplained/oil-and-petroleum-produc...
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#739Earlier quoted context omitted.
Because sandboxing on iOS is terrible. Not that any of the other commercial vendors are any better. If they could provide good sandboxes do you think the highest security certifications advertised on their website [1][2] would only certify protection against attackers with “basic attack potential”, the lowest possible level. Three whole levels below “moderate attack potential”. I mean, seriously, they certify their s…
From a security perspective, Common Criteria certification isn’t particularly meaningful. Plus, it’s not really worth getting certified at a higher level than you need. Why expend extra effort?
The companies that develop easily hacked systems that are repeatedly hacked hundreds of times a year like Apple, Microsoft, Cisco, Amazon, Google, etc. can only achieve certification levels indicating they are easily hacked. They have never once succeeded at certifying meaningful security. The certification is pinpoint accurate, just the trillion dollar commercial IT companies do not like the results.
I agree it is largely not a useful differentiator, but that is because all of the commercial IT vendors are certified incompetent. The Common Criteria will not help you determine which fish in the barrel is hardest to shoot. Its job is to distinguish serious security by professionals.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#740Earlier quoted context omitted.
The way this works is that in addition to the more colorful clients, you absolutely need to make sure that you have a sufficient number of clients among law enforcement and security services in countries with a decent(-ish) track record regarding human rights. This way, your products and services are not obviously illegal. You can even tell your employees that your products and services are saving lives because it's…
The OS vendors refuse to implement lawful intercept capability because there is no such thing as a lawful intercept capability. There is only intercept capability for any purpose because ROM bootloaders and secure enclaves cannot vet the lawfulness of a request to subvert their owners. You can make a phone relatively secure against people trying to break into it, but only if it has unique access keys for the owner. I…