Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

861–870 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#861
post #514

Earlier quoted context omitted.

The keys in advanced protection are derived from your device passcodes, your macOS user password and a recovery key. You'll notice you have to approve from one of your devices to use iCloud web or add a new device. The deviation function takes a while to run and depends on the secure enclave, but you still probably want to avoid 4-digit passcodes.

They are, but they also must be encrypted n separate times where n is the number of signed in devices. Mac iPad iPhone Recovery Key Each of the above would have a separate uniquely encrypted device backup key as a result of the derivation function. I can change the password on any of those (or regenerate the recovery key) without a full iCloud re-encryption or duplication of my iCloud data - therefore Apple must be h…

I'm not sure why you're doing all this speculation, when wrapping keys is a pretty standard technique (i.e. LUKS key slots) and Apple provides the details themselves[1]. Yes, they're doing a handshake with secure enclave keys and transfer the master key to your devices. Turning on Advanced Protection will reencrypt all the data in iCloud in the background whereas turning it off will submit the master key to Apple so they can presumably place it on an HSM. Apple already did this before advanced protection with your Keychain.

[1]: https://help.apple.com/pdf/security/en_US/apple-platform-sec...

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#862

Earlier quoted context omitted.

NSO Group is just one vendor; there are many more: Variston, Dataflow, Azimuth, Cytrox, …

Yet you forgot to mention that you entertain relationships with employees of those companies and go to their conferences. Hypocrisy much?

That's true, but I'm not entirely sure why this would be relevant to include in my comment? It's just pointing out that other vendors exist in this space other than NSO Group. I don't even see the hypocrisy if I had posted that while working at one of the places I mentioned? How would you rephrase it?

(It seems like you know me, are you someone I've met before?)

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#863
post #857

I worked for NSO and later at a very similar company in Barcelona. AMA

Were you not concerned with unethical and potentially fatal outcomes of your work? I’m trying to phrase this in a way that doesn’t come standoffish - in some way you clearly _weren’t_, since you did the work. But I’m wondering whether this ever entered the picture for you, and how you dealt with that.

[flagged]

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#864
post #128

Earlier quoted context omitted.

So YouTube isn't a social platform?

Is it? I thinks its rather more like entertainment

Millions of users interact through comments and live streams. Of course it's a social network.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#865
post #353

Earlier quoted context omitted.

Decent? From a security perspective it's superior to the iPhone. As for Graphene, unless you've personally vetted the code I don't see how it can be trusted. And I won't even go into the drama that OS comes with.

> unless you've personally vetted the code I don't see how it can be trusted. As opposed to proprietary Google code that cannot be vetted?

What about the proprietary binary blobs that Graphene is reliant on? Who vetted those?

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#866
post #124

Earlier quoted context omitted.

>Please... Androids no better. The Pixel is. >At least Apple will have it patched within the year of discovery. Can't say the same for other Android vendors. And the Pixel would have the patch released quicker.

Pixel is not an OS, is not Android. Pixel is a series of hardware that make up less than five percent of the android hardware market. One device series does not offer a glimpse of the market. Op’s point stands.

>Pixel is not an OS

Then what do you call the custom OS that ships on the Pixel? Of course it's a custom built OS that's designed to work with the custom hardware on the Pixel.

>One device series does not offer a glimpse of the market.

Security is defined by the marriage of software and hardware. The reason the Pixel is so secure is because of this. The OP made a blanket statement which did not apply to the Android ecosystem.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#867
post #30
post #9

Earlier quoted context omitted.

Interestingly, no kernel vulnerability or anything is mentioned. As far as I know, any parsing code for iMessages should run within the BlastDoor sandbox – is there another vulnerability in the chain that is not reported here?

One CVE is in Wallet and Citizen Lab mention PassKit. My guess is that BlastDoor deserializes the PassKit payload successfully, then sends it to PassKit which subsequently decodes a malicious image outside of BlastDoor.

Yup. You can just have your crafted webp (This is the patch for the ImageIO bug https://chromium.googlesource.com/webm/libwebp/+/902bc919033...) image with the .png extension (inside your passkit - https://developer.apple.com/library/archive/documentation/Us...) and you send it to your target..

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#868

Earlier quoted context omitted.

As much as I agree with you... I think it's most likely that the US NSA, UK's MI(whatever), Israel's Mossad and a bunch of other secret services all cooperate with each other. No way these guys get taken down, and no way that the sanctions that have been nominally announced actually get enforced at the murky, intransparent bottom layer of the secret services. Someone has to crack open the phones of drug kingpins, ter…

Those groups do not generally deal with NSO.

The NSO Group is Israeli.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#869

Its super interesting to me how much its emphasized that you shouldn't use Lockdown Mode unless you are a journalist or otherwise in direct palpable danger. They really do try to talk you out of it. Its curious, because there's very little difference in functionality (as experienced by the user) other than disabling a lot of Apple nonsense from running in the background expanding your attack surface. And everybody pa…

I use Lockdown Mode on my Mac because I don’t use iMessage, FaceTime, or other apple services on that device. It’s literally just a computer for software dev and maybe YouTube videos. I haven’t noticed any difference with web content either, but I also use Firefox / Chrome instead of Safari. What I would really like to see is options. For example on iOS I use shared photo albums, so it would be nice to keep that feat…

Ironically, you need it all the more specifically on the devices you like to use those services with. Even moreso than on the devices you don't use them with. The fact of the matter is Lockdown makes iMessage as safe as is possible (I still wouldn't take the risk, personally, but YOLO). It doesn't hurt to be using Lockdown everywhere.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#870

How many exploits has iMessage had now? Isn't it time we made first messages from all new contacts plain text only, and all other messages some very restricted subset rather than some crazy extensible system that isn't so different from ActiveX? And on top of that, maybe the whole app should run in a sandbox. And on top of that, perhaps it should all be a webview to give one more layer of protection.

On plain text -- in short, it doesn't exist: https://www.youtube.com/watch?v=gd5uJ7Nlvvo

And there have definitely been UTF-8 parsing bugs before and likely will again.

Post reply on HN