Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

871–880 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#872
post #468

There needs to be a more fine tuned lockdown mode, for example to disable automations and risks in imessage and safari but leave device accessories working. Losing bluetooth accessories to protect yourself from zero click imessage exploits is just bad. imessage is the major wide open attack surface.

Settings already allows you to "tune your lockdown mode" to suit your preferences. For example Settings > Messages > iMessage is literally a switch to turn off iMessage if you feel that it's problematic. Settings > Safari > Privacy and security has various settings which allow you to have a 'more fine tuned lockdown' for safari.

Yes but it's missing the one thing that would make a huge difference: Blocking images from people not on your contact list.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#873
post #800

Earlier quoted context omitted.

> Even if there's significant ISIS presence in Israel (which I've never heard of), it hasn't convinced them to help fight ISIS next door. Their stance is neutral, and they don't pretend otherwise. this is simply false. They help a ton and as I've said they've directly attacked them both within Israel's 1919 borders and assisted with attacks elsewhere in the region. > I didn't say there was no reason, because obviousl…

And yet you can't point to any evidence of Israel actually fighting ISIS, just your word... > who will be discriminated against due to their religion (much like you are doing right now) ... and supposedly I'm a bigot if I show you otherwise. Not cool, I'm done here.

100% agree not cool to be a bigot, please do better

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#874
post #857

I worked for NSO and later at a very similar company in Barcelona. AMA

Were you not concerned with unethical and potentially fatal outcomes of your work? I’m trying to phrase this in a way that doesn’t come standoffish - in some way you clearly _weren’t_, since you did the work. But I’m wondering whether this ever entered the picture for you, and how you dealt with that.

For some reason my original comment got flagged. It went:

I was concerned. Just as much as an average Facebook employee when it turned out someone built a psyop weapon on top of their data to manipulate elections’ outcomes.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#875
post #857

Earlier quoted context omitted.

Were you not concerned with unethical and potentially fatal outcomes of your work? I’m trying to phrase this in a way that doesn’t come standoffish - in some way you clearly _weren’t_, since you did the work. But I’m wondering whether this ever entered the picture for you, and how you dealt with that.

For some reason my original comment got flagged. It went: I was concerned. Just as much as an average Facebook employee when it turned out someone built a psyop weapon on top of their data to manipulate elections’ outcomes.

That seems like a cop-out?

The number of degrees of separation between average Facebook's engineer work and "direct harm to a human being" seems like it'd be orders of magnitudes higher than when working on exploits for companies with the client list like that of NSO's.

Or do you not think about it in those terms?

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#876

Earlier quoted context omitted.

Google devices offer such better security posture than other Android manufactures. Then there's the issue of privacy regarding Google devices. I strongly suggest checking out the GrapheneOS project if Android security is of concern.

Unless proven by leaked testimonials I would not fully trust GrapheneOS to be fully safe either. Maybe they have zero days as well and we just didn't discover them because of obscurity but NSO bought them and uses them. My dad used to say "Known devil is better than unknown angel."

I'd argue nothing is "fully" safe against zero-days - this is the nature of zero-days.

But GOS takes more security precautions than stock Android, so by that metric there is a greater chance it is unaffected by an unreleased zero-day.

But like I said, there really is no way to know. That goes for Android, GOS, and iOS.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#877
post #875

Earlier quoted context omitted.

For some reason my original comment got flagged. It went: I was concerned. Just as much as an average Facebook employee when it turned out someone built a psyop weapon on top of their data to manipulate elections’ outcomes.

That seems like a cop-out? The number of degrees of separation between average Facebook's engineer work and "direct harm to a human being" seems like it'd be orders of magnitudes higher than when working on exploits for companies with the client list like that of NSO's. Or do you not think about it in those terms?

But number of affected people and the scale of impact was also on another order of magnitude. Moreover, that tool depended on private companies that operated without any oversight. It’s a very different situation for exploits (although I agree that they often end up in the wrong hands)

NSO is probably one of the worst offenders when it comes to screening their clients. This raises ethical issues. It was a factor for me and many of my former colleagues. However, for every abusive operation that gets exposed, there are many legitimate ones conducted by democratic governments. I think we are far from a mass-surveillance scenario, and those exploits are not as widely available as the media might portray.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#878
post #761

Earlier quoted context omitted.

Definitely part of diplomacy effort of netanyahu with the despots if the world. NSO CEO travelled with him to Saudi t among other places. It's software there's economics of scale by default.

Economies of scale only apply if you have scale, ie lots of (paying) users. If you're making this fancy thing for only the Israeli security services you won't be able to pay your developers.

Economy of scale is actually inverted with 0 days. The more you use it the higher the risk it's detected and fixed so value and scale are inversely proportional.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#879

Wow, so much discussion of Apple and their software, and so little of NSO group and why they're even a thing. I just want to add this: these people operate pretty much in the open. They're not ashamed of it either, or else they wouldn't put it on their CV: https://www.linkedin.com/company/nso-group/people/ That right there tells me that we as "the tech community" are way too okay with this sort of application of the…

The NSO is less of an issue to me than the fact they are finding exploits Apple isn't (assuming Apple truly isn't aware of these and/or building them in on request) and that Apple has more than enough to budget for. To me, the NSO (as evil as they are) is like a regulator who cuts through a company's "self-regulation" claims and proves that the company they are regulating is either intentionally making their own platform insecure or is at best, negligent to mitigating and being proactive in addressing obvious issues.

Apple could pay all these people and companies way more than they could ever hope to earn on the free world market to simply fuck off. They are notoriously stingy with bug bounties and constantly disillusion those who are helping to ostensibly make their platforms more secure. I view NSO in a similar light to Correllium, whom Apple has tried to shutdown (unsuccessfully).

Its like trying to blame a whistleblower rather than prosecuting the misconduct that comes to light. The energy and blame is misplaced and this lawsuit only distracts from the fact that iMessage is basically the skeleton key to access anything and everything on a modern iPhone, after all this time.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#880

Earlier quoted context omitted.

Small companies can't cause billions in damage though...

Yes they can? It's totally possible for a small, well connected, group to be writing small pieces of custom code in very critical applications, like core reactor controls system for navy submarines.

Those may be small teams, but they are most definitely not small companies.
Post reply on HN