Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

761–770 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#761
post #588

Earlier quoted context omitted.

It's more like they leverage it for diplomacy. The auditing means nothing really, it's being given to authoritarian government like Saudi Arabia as long as they are OK with Israel existing. The bar to get access to NSO tools is too low...

They don't really leverage it for diplomacy. Israeli arms exports policy consistently prioritizes getting better R&D economies of scale over actually affecting foreign states' behavior.

Definitely part of diplomacy effort of netanyahu with the despots if the world. NSO CEO travelled with him to Saudi t among other places. It's software there's economics of scale by default.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#762

How many exploits has iMessage had now? Isn't it time we made first messages from all new contacts plain text only, and all other messages some very restricted subset rather than some crazy extensible system that isn't so different from ActiveX? And on top of that, maybe the whole app should run in a sandbox. And on top of that, perhaps it should all be a webview to give one more layer of protection.

There is even precedent for doing this seamlessly: the Apple Mail client will not render media from unknown senders without user confirmation. iMessage should have the exact same behavior for the same reasons. It’s frustrating to watch greedy project managers re-learning the exact same lessons that a previous generation already learned the hard way, especially when they all work in the same building.

Does the Apple Mail client do this for images included with the message (instead of referencing by URL)? Like another comment mentions, this is done for other reasons, and many clients render embedded images by default.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#763

Earlier quoted context omitted.

The US gov't almost certainly has a say as well.

The US has their own version, called the NSA. Available to hire via really simple framing. Guaranteed whomever is caught will be in prison for years just to get a trial to prove they're innocent.

The US has private firms buying, developing, and selling malware as well. NSO group is just a little more open and shameless about it.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#764

Wow, so much discussion of Apple and their software, and so little of NSO group and why they're even a thing. I just want to add this: these people operate pretty much in the open. They're not ashamed of it either, or else they wouldn't put it on their CV: https://www.linkedin.com/company/nso-group/people/ That right there tells me that we as "the tech community" are way too okay with this sort of application of the…

The NSO group is the easiest to spot. The other parties involved in their operations are not so easily traced, such as Team Jorge, AIMS, Legion, Xaknet etc.

For once, I am not okay with what they are doing, and I've started to fight them actively.

You're welcome to join.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#765

Wow, so much discussion of Apple and their software, and so little of NSO group and why they're even a thing. I just want to add this: these people operate pretty much in the open. They're not ashamed of it either, or else they wouldn't put it on their CV: https://www.linkedin.com/company/nso-group/people/ That right there tells me that we as "the tech community" are way too okay with this sort of application of the…

If NSO did not exist the vulnerabilities they discover would still be there. So I guess the complaint should not be that they exist, so much as their motivations and applications being questionable. It's an argument for something similarly funded to exist, but with an aim to responsibly report the bugs and get them fixed.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#766

Earlier quoted context omitted.

I think sending SMS to emails and receiving SMS from emails is a functionality of the mobile network. You should be able to do that in any app that can send/receive SMS. https://www.att.com/support/article/wireless/KM1061254/

The point is that iMessage lets you send to any contact and it’s not clear if it will send to their iMessage, which uses email as an identifier, or to their actual email inbox through mms.

It is clear in a non group conversation, since the contact will show up in a blue color in the “to” field.

In an MMS, it could be unclear, but only if you choose to put an email address in the “to” field. If you know it is an MMS, and you only use phone numbers, then it will not be an email.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#767

Earlier quoted context omitted.

Sometimes known as "Model-T election" "Any customer can have a car painted any color that he wants so long as it is black."

We have this in the US too but with two colors, both neoliberal.

To compare US elections to Russian or Syrian elections is both incredibly naive and dangerous. In one country, you have a leading political opponent having stolen classified docs treated with kid gloves; in the other, you have political opponents poisoned and literally blown out of the sky.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#768

Earlier quoted context omitted.

It does make iOS slightly more inconvenient, such as when adding each other on iMessage. And it severely reduces JavaScript performance in Safari. I think Apple wants to avoid making iOS feel slower or clunkier than Android. And zero-day spyware is usually targeted towards important individuals, not used for mass surveillance, so it indeed is a smaller risk to individual people. I'd prefer a third mode that compromis…

I would argue that iMessage is way to problematic to be used safetly, at all. By anyone. Full-stop. It also seems to be the primary attack vector of NSO related zero-days as well and its become known that phone country/area codes have relevance to its chance of succes in past exploits, which suggests a phone/messaging type attack vector.

> It also seems to be the primary attack vector of NSO related zero-days as well and its become known that phone country/area codes have relevance to its chance of succes in past exploits, which suggests a phone/messaging type attack vector.

If you are using a phone, you have a phone number. Targeting the phone and SMS handling apps will always be the go-to vector for these sorts of attacks, because you don't want to tell your customer that they can only spy on targets that have Evernote installed and configured.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#769

Earlier quoted context omitted.

What is the significance of the “regents of the University of California, Berkeley” message? Is it the FreeBSD boot message?

iOS has BSD roots.

Right, just BSD, not FreeBSD. Same with macOS, which also features that boot message.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#770

Earlier quoted context omitted.

Yeah I can't believe we are still seeing this happen over and over again. Whenever you see "zero click" you know it's one of the complex payloads like images, fonts. The answer shouldn't be "don't render images". We should be able to trust that a component that parses external data such as an image, simply can't do anything malicious regardless of input. If that means sandboxing, fine. If it means having to rewrite a…

Your problem isn't the quality of your own code, it's that Google exists and is unable to stop their employees from doing stupid things like inventing WebP, because now you need to support WebP too which means using their code to do it. (Worse, WebP is at least two completely different formats - the lossless mode has nothing to do with the lossy mode.)

As opposed to Apple’s formats, for which the parsers are definitely less buggy and likely to be hacked.
Post reply on HN