Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

771–780 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#771
post #767

Earlier quoted context omitted.

We have this in the US too but with two colors, both neoliberal.

To compare US elections to Russian or Syrian elections is both incredibly naive and dangerous. In one country, you have a leading political opponent having stolen classified docs treated with kid gloves; in the other, you have political opponents poisoned and literally blown out of the sky.

or you know, publicly shot in the head for standing up against the deep state and keep delaying the release of secret files even after 50 years.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#772
post #343

Earlier quoted context omitted.

Companies don't do things. People do. Shut down NSO and its skilled people will go elsewhere.

So do we agree that Apple's buying NSO Group wouldn't permanently make the problem better?

Anyone buying them and shutting them down won't even temporarily make the problem better, as NSO has competitors who would immediately hire the best people.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#773

Earlier quoted context omitted.

I think disagree with every single point you brought up, having seeing exploits that involve all of them.

If you've seen an exploit caused by a big pre-allocated array of untrusted RGBA data, please explain how. (If you mean they put evil data through it and then used a separate exploit to run it, that's not a vulnerability, that's just "data transfer exists".) And you seeing someone screw up an IOMMU doesn't disqualify it from being one of the easiest parts of a hardware decoder.

Code to calculate size of preallocated array is incorrect. Size ends up too small or underflows.

Buffer is reused across calls. Buffer is actually mapped across processes and thus page-aligned. Code to check how much space is needed checks number of pages versus actual number of bytes, and fails to clear leftover data correctly.

Code receives RGBA buffer but expects some other encoding. Accidentally reads out of bounds as a result.

You can definitely say “oh these are stupid and I wouldn’t screw this up” but people do and that’s what really matters.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#774

Earlier quoted context omitted.

The OS vendors refuse to implement lawful intercept capability because there is no such thing as a lawful intercept capability. There is only intercept capability for any purpose because ROM bootloaders and secure enclaves cannot vet the lawfulness of a request to subvert their owners. You can make a phone relatively secure against people trying to break into it, but only if it has unique access keys for the owner. I…

>The Saudis have one very big lever they can use to force the west to do what it wants: gas prices. The United States gets most of its petroleum from Canada. Saudi Arabia accounts for only 7% of U.S. petroleum and crude oil imports. Source: https://www.eia.gov/energyexplained/oil-and-petroleum-produc...

The US is the largest oil producing country in the world. Mostly from Texas. https://www.eia.gov/tools/faqs/faq.php?id=709&t=6

2nd is Saudi Arabia then Russia. However it happens that US is also the largest consumer and their production doesn't meet the demand so they have to import from other countries like Canada and Saudi Arabia

So Saudi Arabia most definitely does have a lever, and so does Russia since the rest of the world including US allies like Japan, South Korea, Australia, NATO countries depend on their lovely black gold to have functioning economies.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#775

Earlier quoted context omitted.

If you've seen an exploit caused by a big pre-allocated array of untrusted RGBA data, please explain how. (If you mean they put evil data through it and then used a separate exploit to run it, that's not a vulnerability, that's just "data transfer exists".) And you seeing someone screw up an IOMMU doesn't disqualify it from being one of the easiest parts of a hardware decoder.

Code to calculate size of preallocated array is incorrect. Size ends up too small or underflows. Buffer is reused across calls. Buffer is actually mapped across processes and thus page-aligned. Code to check how much space is needed checks number of pages versus actual number of bytes, and fails to clear leftover data correctly. Code receives RGBA buffer but expects some other encoding. Accidentally reads out of boun…

> Code to calculate size of preallocated array is incorrect. Size ends up too small or underflows.

If you go outside the array you copied/mapped out of the sandbox, then that doesn't let the attacker code escape the sandbox, you just put some of your own data onto the screen.

If you mean the sandbox isn't given enough memory, then that will make the sandbox exit when it hits unmapped addresses.

And how did you screw up length x width x 4?

> Buffer is reused across calls. Buffer is actually mapped across processes and thus page-aligned. Code to check how much space is needed checks number of pages versus actual number of bytes, and fails to clear leftover data correctly.

The sandboxed process doesn't have any way to exfiltrate data. At most it can display it back to you, which is not really any worse than innocent code which could also send back the leftover data.

> Code receives RGBA buffer but expects some other encoding. Accidentally reads out of bounds as a result.

Reads out of bounds and does what with it? That doesn't sound like a vulnerability to me. It might display private data or crash, but that's entirely of its own volition. The behavior would be the same between innocent code in the sandbox and malicious code in the sandbox.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#776

Earlier quoted context omitted.

How many does it have?

Unknowable

True but a useless fact. One way to interpret u/seanhunter's comment is to make the comparison between imessage and activex in the known exploit space and then extrapolate into the unknown space assuming equal proportions. Seems reasonable to me.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#777

Wow, so much discussion of Apple and their software, and so little of NSO group and why they're even a thing. I just want to add this: these people operate pretty much in the open. They're not ashamed of it either, or else they wouldn't put it on their CV: https://www.linkedin.com/company/nso-group/people/ That right there tells me that we as "the tech community" are way too okay with this sort of application of the…

The 0-day market does not only exist for iOS. There are many perfectly "official" companies in the west advertising and selling those.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#778

How many exploits has iMessage had now? Isn't it time we made first messages from all new contacts plain text only, and all other messages some very restricted subset rather than some crazy extensible system that isn't so different from ActiveX? And on top of that, maybe the whole app should run in a sandbox. And on top of that, perhaps it should all be a webview to give one more layer of protection.

What's not clear to me is given all of the layers/security features Apple has, say you are able to get an iMessage exploit where you can run code... you can't access the file system/cache of other apps (like your banking app to get cookies/tokens), can you?

Not directly, but now you can exploit vulnerabilities in other parts of the OS.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#779

Earlier quoted context omitted.

Do you think private companies should be allowed to, say, arrest people?

Depending on the circumstances, absolutely. Assuming that serious unjustified injury or death would occur if they failed to act, there should be some legal window in which they’re allowed to prevent the harm. Private companies (and individuals) should not be required to stand by helplessly while people are hurt. Indeed, legally, private individuals and companies are allowed to act in emergencies. For example, I gener…

This is obviously a bad idea, private companies or individuals having the power to arrest people because they want to? Look at the recent few years of history in the US where multiple experienced and distinguished (at least by resume), members of the us govt, senators, reps, tried to subvert an elections, dozens of lawyers told them it was illegal, we have their email and texts telling them. That group still acted to do many illegal actions, lie about it, tried to cover it up. And they still deny any problems with their behavior and choices.

Private companies having arrest rights is just a nonstarter of an idea (putting it kindly).

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#780

Its super interesting to me how much its emphasized that you shouldn't use Lockdown Mode unless you are a journalist or otherwise in direct palpable danger. They really do try to talk you out of it. Its curious, because there's very little difference in functionality (as experienced by the user) other than disabling a lot of Apple nonsense from running in the background expanding your attack surface. And everybody pa…

I use Lockdown Mode on my Mac because I don’t use iMessage, FaceTime, or other apple services on that device. It’s literally just a computer for software dev and maybe YouTube videos. I haven’t noticed any difference with web content either, but I also use Firefox / Chrome instead of Safari. What I would really like to see is options. For example on iOS I use shared photo albums, so it would be nice to keep that feat…

Lockdown mode? How do I enable it? As someone who owns a Macbook as their only Apple product, I hate seeing or dealing with Apple pushing their services to me
Post reply on HN