Earlier quoted context omitted.
Or get someone to click on a spoofed domain, certified by our beloved LetsEncrypt! Apparently al that is needed is an HTTP 302/307 redirect response (or html redirect payload, maybe even DNS?) pointing the client toward c.betly[.]me
Huge difference between being tricked into clicking a link vs just browsing the web and getting owned.
0-days exploited by commercial surveillance vendor in Egypt
31–40 of 254 posts
Re: 0-days exploited by commercial surveillance vendor in Egypt
#32Earlier quoted context omitted.
Huge difference between being tricked into clicking a link vs just browsing the web and getting owned.
Is there?
Re: 0-days exploited by commercial surveillance vendor in Egypt
#33Just your regular reminder that for the only security certification that Apple advertises on their website for iOS [1][2] Apple only achieved the lowest possible level of security assurance, EAL1. A level only fit for products where [3]: "some confidence in the correct operation is required, but the threats to security are not viewed as serious" which does not even require "demonstrating resistance to penetration att…
Do you by any chance have this data on Google, Samsung, Huawei, LG, and other cell phone manufacturers? I’ve never looked into these certifications and I wouldn’t know where to start looking. Do the above companies publish the results like Apple?
Generally only components are EAL certified. For example, the iPhone is not on there, but the security protecting access to Apple Pay on the iPhone 13 with A15 Bionic running iOS 15.4.1 (19E258) is EAL2+.
Re: 0-days exploited by commercial surveillance vendor in Egypt
#34Though HTTPS is better than nothing, and this attack relies on HTTP to inject the initial payload, state sponsored attackers in some countries can likely just subvert CA or CDN infrastructure instead.
Or get someone to click on a spoofed domain, certified by our beloved LetsEncrypt! Apparently al that is needed is an HTTP 302/307 redirect response (or html redirect payload, maybe even DNS?) pointing the client toward c.betly[.]me
My impression was the CA's made the likes of Standard and Poor look rigorous, but I'm happy to learn more from actual experience of them rejecting such an application.
Re: 0-days exploited by commercial surveillance vendor in Egypt
#35Just your regular reminder that for the only security certification that Apple advertises on their website for iOS [1][2] Apple only achieved the lowest possible level of security assurance, EAL1. A level only fit for products where [3]: "some confidence in the correct operation is required, but the threats to security are not viewed as serious" which does not even require "demonstrating resistance to penetration att…
So, OK I guess?
It's worth noting that CC evaluation does not score the actual practical security of a device or system, but the level of testing it was submitted to, which is consistent with pretty much every single governmental certification out there.
Re: 0-days exploited by commercial surveillance vendor in Egypt
#36Just your regular reminder that for the only security certification that Apple advertises on their website for iOS [1][2] Apple only achieved the lowest possible level of security assurance, EAL1. A level only fit for products where [3]: "some confidence in the correct operation is required, but the threats to security are not viewed as serious" which does not even require "demonstrating resistance to penetration att…
Re: 0-days exploited by commercial surveillance vendor in Egypt
#37Earlier quoted context omitted.
Or get someone to click on a spoofed domain, certified by our beloved LetsEncrypt! Apparently al that is needed is an HTTP 302/307 redirect response (or html redirect payload, maybe even DNS?) pointing the client toward c.betly[.]me
> certified by our beloved LetsEncrypt Are you saying that CAs should be refusing to issue certs for potentially spoofed domains?
I just mentioned LetsEncrypt because it's free and exceptionally easy to use. I'm not implying in any way they aren't providing a great service, it's just that that service also gets misused because it's cheap and easy.
Re: 0-days exploited by commercial surveillance vendor in Egypt
#38Just your regular reminder that for the only security certification that Apple advertises on their website for iOS [1][2] Apple only achieved the lowest possible level of security assurance, EAL1. A level only fit for products where [3]: "some confidence in the correct operation is required, but the threats to security are not viewed as serious" which does not even require "demonstrating resistance to penetration att…
Do you by any chance have this data on Google, Samsung, Huawei, LG, and other cell phone manufacturers? I’ve never looked into these certifications and I wouldn’t know where to start looking. Do the above companies publish the results like Apple?
For many companies you just search: "{Product} Common Criteria" and they will usually have a page for it on their website somewhere.
You can also go directly to the certified products page: https://www.commoncriteriaportal.org/products/
For smartphones you can see them there under "Mobility".
Unfortunately, it is fairly hard to parse if you are not familiar with the terminology. The general structure of Common Criteria certifications is Security Functional Requirements (SFR) which are basically the specification of what the product is supposed to do and the Security Assurance Requirements (SAR) which are basically how you certify the SFRs are met (and what level of assurance you can have that the SFRs are met). SARs can be bundled into Evaluation Assurance Levels (EAL) which define collections that reasonably map to levels of confidence. You can add SARs beyond the current EAL which is how you get a EAL level with a +, but it is important to keep in mind that just cherry picking certain SARs does not necessarily give you a holistic assurance improvement.
SARs and SFRs can be further pre-bundled into Protection Profiles (PP) which basically exist to provide pre-defined requirements and testing methodologies instead of doing it one-off every time. Some Protection Profiles support variable EAL/SAR levels, but these days people generally just certify against a Protection Profile with a fixed SAR bundle. This is what PP Compliant means. If you want to see what they certified against, you would need to look at the Protection Profile itself.
For smartphones, the standard Protection Profile for the phone itself is Mobile Device Fundamentals. If you look at the SAR bundle there you will see that they correspond to EAL1 + a small number of EAL2, resulting in a overall level of EAL1+. As they are in-between EAL1 and EAL2 I just classified it as EAL1 for my earlier post. If you peruse further you will see that basically every Protection Profile that companies certify to as PP Compliant are basically the same EAL1+ or thereabouts. So, if you see PP Compliant, it probably means EAL1+ or so.
Hope that helps.
Re: 0-days exploited by commercial surveillance vendor in Egypt
#39Ouch. Apparently Firefox has "Https First" also but requires the pref dom.security.https_first to be set. "HTTPS-Only Mode" is obviously best if you can do that.
Re: 0-days exploited by commercial surveillance vendor in Egypt
#40Slighty related, but Senator Bob Menendez was just indicted for taking bribes from people connected with the Egyptian military [0]. Gotta say, the Egyptian intelligence services are definitely punching above their weight by regional power standards. [0] - https://www.politico.com/news/2023/09/22/egypt-guns-money-me...