Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

851–860 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#851
post #774

Earlier quoted context omitted.

The US is the largest oil producing country in the world. Mostly from Texas. https://www.eia.gov/tools/faqs/faq.php?id=709&t=6 2nd is Saudi Arabia then Russia. However it happens that US is also the largest consumer and their production doesn't meet the demand so they have to import from other countries like Canada and Saudi Arabia So Saudi Arabia most definitely does have a lever, and so does Russia since the rest o…

> [...] so does Russia since the rest of the world including US allies like Japan, South Korea, Australia, NATO countries depend on their lovely black gold to have functioning economies. Have you been following the news for the past two years? Russia's sanctioned up the wazoo. No NATO country is buying Russian oil. India is now their number one costumer.

There is truth in that Europe isn’t buying directly from Russia. However plenty are buying from countries are buying refined oil products from India (and possibly others) where the source is Russian crude oil.

https://www.aljazeera.com/amp/news/2023/5/16/eu-to-curb-indi...

If the US was like Saudi Arabia where they exported half of their oil, and could supply most of the world at competitive prices, Russia would have really felt the Sanctions.

But right now Russia doesn’t feel the Sanctions. They’re more isolated and Putin’s propaganda has somewhat worked at making the general population anti-west and support the Ukraine invasion.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#852
post #795
post #606

Earlier quoted context omitted.

Are you an NSO psychopath or something?! Those funny propaganda jokes you're spewing are not working. The Israeli Hasbara lies are so bad and funny (Oh we won the land instead of we are scumy occupiers and land thieves haha.) This Israeli murder cult is sad and pathetic.

your bigotry doesn't do your argument any favors. of course there isn't really an argument here, just hate.

You're the one who has no argument, other than pure hatred. Any sane human being would be against criminal genocidal ideologies like Zionism and Nazism. Cheering the monstrous crimes of those political ideologies is nothing but vile hate. It is a murder cult, come with an argument or f off. It is not my job to educate you if you're brainwashed.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#853

Earlier quoted context omitted.

> An internal struct[...] It sounds like you picked option 1 then, which means you don't need to take control of the sandbox. "Create an image that put arbitrary bytes into the buffer that stores its decoded form." simplifies to just "Create an image." There is no vulnerability here. This is just image display happening in a normal way. It's something to keep an eye on but not important itself. You have to add a vuln…

> you don't need to take control of the sandbox Your original request was: “If you've seen an exploit caused by a big pre-allocated array of untrusted RGBA data, please explain how.” > It's something to keep an eye on but not important itself. You have to add a vulnerability to get a vulnerability. Which is exactly how exploit chains work. A single vulnerability usually doesn’t achieve something dangerous on its own.…

> Your original request was: “If you've seen an exploit caused by a big pre-allocated array of untrusted RGBA data, please explain how.”

I asked that in a context of whether you can contain vulnerabilities in a sandbox. If something doesn't even require a vulnerability, then it doesn't fit.

Also please note the words "caused by". A few helper bytes sitting somewhere are not the cause.

> Which is exactly how exploit chains work.

> A single vulnerability usually doesn’t achieve something dangerous on its own. But remove it from the chain and you lose your exploit.

Being part of an exploit chain doesn't by itself make something qualify as a vulnerability. (Consider arbitrary gadgets already in the program. You can't remove all bytes.) And I've never seen "you can send it bytes" described as a vulnerability before. Not even if you know the bytes will be stored at the start of a page!

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#854

Earlier quoted context omitted.

Are those breaking changes? I'd assume that a decoder would continue to work, just would not support the lossless mode/ VP9.

It will work on old files (since they've already been encoded) but not on new files with the same file extension, and not on, say, YouTube.

Interesting, thanks.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#855

Earlier quoted context omitted.

This is how Lockdown Mode works.

This should be the default. It is the default on apple mail from what I'm reading, so why not the I message app?

Mail does this for privacy, not security. Emails can load remote content and this can be used to track you. This is not generally true of images sent in iMessage because they get sent directly.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#856

Earlier quoted context omitted.

iPhones can be provisioned with pretty extensive profiles/MDM so I doubt that part. They probably see all the zero-days and decide game respects game. Just not secure enough for such an incredibly insular power structure as theirs, even without the US connections.

>decide game respects game Elaborating on this, the US banning Huawei doesn't help either.

I don't get why they wouldn't already insist on Huwawei and HarmonyOS unless this is more of an Inner Party issue where all the high-ups use iPhone intentionally because its more private than Huawei

I wonder what phone Z has been using all this time...

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#857

I worked for NSO and later at a very similar company in Barcelona. AMA

Were you not concerned with unethical and potentially fatal outcomes of your work?

I’m trying to phrase this in a way that doesn’t come standoffish - in some way you clearly _weren’t_, since you did the work. But I’m wondering whether this ever entered the picture for you, and how you dealt with that.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#858

Earlier quoted context omitted.

Software liability would effectively crush smaller companies, unable to keep up with the lawsuits, because they don't have billions in the bank.

I think you should really think about what you're saying. Would you cut makers of physical artifacts the same slack, say a small prepared food producer who just can't afford to vet their supply chain or final product to make sure it's not contaminated?

[deleted]

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#859

Earlier quoted context omitted.

Software liability would effectively crush smaller companies, unable to keep up with the lawsuits, because they don't have billions in the bank.

I think you should really think about what you're saying. Would you cut makers of physical artifacts the same slack, say a small prepared food producer who just can't afford to vet their supply chain or final product to make sure it's not contaminated?

This has already played out. Most consumer software specifies that it cannot be used in medical devices, or for nuclear energy production. So some version of this already exists. But should this apply to video games? Horoscope websites? Random number generators? I'm just pointing out that it isn't a universal argument.
Post reply on HN