Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

741–750 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#741
post #721

Earlier quoted context omitted.

So then, by this logic, once you've worked for NSO Group or the like, there's no way back for you. How then, can someone reform or "see the light"? Is someone once tainted, always tainted? Or do they have to do 10 years in the NFP space before we see them as worthy? The problem is that by walling off developers who participate in these activities, we essentially force them to continue these activities. I'm not sure t…

It’s not like we don’t accept that people change, but stigma is useful for both discouraging starting there or staying. If your first job out of college or the military is a defense contractor, oil company, Palantir, etc. a lot of people will sympathize with needing to make rent. If you’re still there a decade later, they’ll assume you’re okay with what they do.

Don't hate the player hate the game. At the end of the day it's the policy makers that choose to look the other way

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#742
post #723

Earlier quoted context omitted.

>Clearly putting the NSO group on the Commerce Department blacklist didn't go far enough Somewhere in a nondescript subterranean hangar north of vegas an unacknowledged aerial platform is getting an itchy nose

Please don't suggest that people should be murdered with drone-launched missiles for making software. Making software is a peaceful act, regardless of what purpose that software serves.

That is not a reasonable position, "peacefully" writing software that you know is to be used to murder and silence other people makes you just as complicit those crimes (definitely an accessory). No better than a getaway driver.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#743
post #721

Earlier quoted context omitted.

It’s not like we don’t accept that people change, but stigma is useful for both discouraging starting there or staying. If your first job out of college or the military is a defense contractor, oil company, Palantir, etc. a lot of people will sympathize with needing to make rent. If you’re still there a decade later, they’ll assume you’re okay with what they do.

Don't hate the player hate the game. At the end of the day it's the policy makers that choose to look the other way

That’s a personal ethics shirk. For example, policy makers haven’t outright banned tobacco companies but a large number of people would not spend their time trying to make such companies successful.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#744

Earlier quoted context omitted.

Oh, but you see, NSO targets only "terrorists and criminals", so if you're a law-abiding citizen with nothing to hide, there's nothing to be concerned about. Right? It's not like there's any regimes out there where, say, casual investigative journalism or opposition politics would ever land you with criminal or terrorist charges, no sirree.

In Hungary, for example, which is an EU country and democracy (i.e. there are elections), investigative journalists have been targeted with Pegasus by the government.

In Israel, these kinds of weapons are being illegally used by the police against activists and other figures. The irony!

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#745

I don't need to be able to accept iMessage messages from random numbers. I'd be happy to enable "Prevent messages from unknown numbers" for example. Is this possible?

Yeah, its starting to get weird that they refuse to implement this. Its almost like certain stakeholders need to be able to randomly text you with malware and refuse the notion of being silenced.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#746
post #577

Earlier quoted context omitted.

There is a nice PBS documentary about Pegasus's NSO https://www.pbs.org/wgbh/frontline/documentary/global-spywar... . It looks like NSO is backed up by the Israeli government. They say their software is only sold to governments which were previously vetted, but the reality is that most of the time they sell to authoritarian states which monitor and persecute people opposing the regime.

The ties to government are a red herring. Hacking into people’s private phones and computer systems is generally immoral and illegal. It generally continues to be immoral and illegal when governments do it. Except it also becomes more outrageous, because governments are supposed to protect us from this sort of thing.

Also, it is not "backed" by the government, more like under regulated in a convenient way. It's a gray area.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#747
post #46

Clearly putting the NSO group on the Commerce Department blacklist didn't go far enough. These scumbags belong in the Hague(metaphorically at least).

>Clearly putting the NSO group on the Commerce Department blacklist didn't go far enough Somewhere in a nondescript subterranean hangar north of vegas an unacknowledged aerial platform is getting an itchy nose

This is gross, and I am SPECIFICALLY not advocating for extrajudicial violence.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#748

Earlier quoted context omitted.

AFAIK Israeli government audits NSO and stuff, but they are separate... And Intellexa (authors of Predator I think?) doesn't even get audited because it's "not israeli" on paper

The important part is export control - i.e. deciding who can buy the stuff: https://en.wikipedia.org/wiki/NSO_Group

If they are dumb and get caught during audit for selling to Sudan or something then sure, Israeli government will probably tell them they're bad. (And what, shut them down? Lol.)

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#749
post #434
post #427

Earlier quoted context omitted.

Because it turns off a lot of functionality people like: https://support.apple.com/en-us/HT212650 This is a classic challenge for security: every feature expands the attack surface, but users often pick what to buy based on those features.

Isn't there something like a 50% performance hit too, since it turns off a lot of optimizations?

In Safari, yes, losing the JavaScript JIT is hefty but I’d somewhat cynically argue that it’s probably balanced out performance-wise if you install an ad blocker.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#750

Earlier quoted context omitted.

The OS vendors refuse to implement lawful intercept capability because there is no such thing as a lawful intercept capability. There is only intercept capability for any purpose because ROM bootloaders and secure enclaves cannot vet the lawfulness of a request to subvert their owners. You can make a phone relatively secure against people trying to break into it, but only if it has unique access keys for the owner. I…

>The Saudis have one very big lever they can use to force the west to do what it wants: gas prices. The United States gets most of its petroleum from Canada. Saudi Arabia accounts for only 7% of U.S. petroleum and crude oil imports. Source: https://www.eia.gov/energyexplained/oil-and-petroleum-produc...

Gas and oil are fungible. Anyone dropping supply affects the entire market. You need to look at total global production percent.
Post reply on HN