Earlier quoted context omitted.
There has been plenty of material to reference but all those topics do not benefit space karen so he does not bring them up. [1]: https://en.wikipedia.org/wiki/Anti-Defamation_League#Recepti...
Thanks for clarifying. I'm not familiar enough with this organization to either stake a position for or against, but one passing observation based on that wiki page : > Right-wing groups and pundits, including right-wing Jewish groups, have criticized ADL as having moved too far to the left under Jonathan Greenblatt, labeling it a "Democratic Party auxiliary" > In August 2020, a coalition of progressive organizations…
NSO group iPhone zero-click, zero-day exploit captured in the wild
881–886 of 886 posts
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#882Earlier quoted context omitted.
> I would argue that iMessage is way to problematic to be used safely, at all. Maybe I'm missing something but every single time the only part of iMessage (actually Messages.app) that is insecure is the bit that automatically unfurls attachments and the payload is exploiting a vulnerability elsewhere. So any other app unfurling the attachment thus triggering the payload would be equally vulnerable. Imagine ping had a…
> So any other app unfurling the attachment thus triggering the payload would be equally vulnerable. What you're missing is that iPhone's app sandboxing applies to other apps, not to iMessage. Sure, imessage does have blastdoor and some sandboxing, but it also still has imagent: https://googleprojectzero.blogspot.com/2021/01/a-look-at-ime... imagent runs as root and processes incoming messages. whatsapp or signal or…
What are the odds that something like the NSO just happens to luck into being able to remotely initiate and sustain the building of an entire Turing-complete internal and unauthorized computer internally that also happens to be able to override all hardened protections to the contrary? It just seems so unlikely that there was not a hand in facillitating this internally at Apple. That's what happened with the GreyKey guy...
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#883Earlier quoted context omitted.
Curious why no fix is out for iOS 15 yet. Is iOS 15 not vulnerable to this attack? Or is there often a delay in backporting security fixes that I'm not aware of? And if so, should I be implementing a workaround if I wanted to protect against these exploits?
Active support ended a year ago (12 Sep 2022), but somehow it still saw a security release on 24 Jul 2023. Perhaps we will see one more?
Looks like they just released an update that fixes CVE-2023-41064 at least: https://support.apple.com/en-au/HT213913
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#884Wow, so much discussion of Apple and their software, and so little of NSO group and why they're even a thing. I just want to add this: these people operate pretty much in the open. They're not ashamed of it either, or else they wouldn't put it on their CV: https://www.linkedin.com/company/nso-group/people/ That right there tells me that we as "the tech community" are way too okay with this sort of application of the…
That is a law of nature and no amount of shaming will change it.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#885Earlier quoted context omitted.
> unless you've personally vetted the code I don't see how it can be trusted. As opposed to proprietary Google code that cannot be vetted?
What about the proprietary binary blobs that Graphene is reliant on? Who vetted those?
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#886Earlier quoted context omitted.
You don't have to use iCloud Backup.
It's on by default, which means everyone you iMessage with is escrowing the keys that allow Apple to decrypt all of the messages. Turning it off on only one end of the conversation has no meaningful effect.