Live data from Hacker News

0-days exploited by commercial surveillance vendor in Egypt

blog.google

51–60 of 254 posts

Re: 0-days exploited by commercial surveillance vendor in Egypt

#51

Slighty related, but Senator Bob Menendez was just indicted for taking bribes from people connected with the Egyptian military [0]. Gotta say, the Egyptian intelligence services are definitely punching above their weight by regional power standards. [0] - https://www.politico.com/news/2023/09/22/egypt-guns-money-me...

From the Google disclosure I can't tell what Egypt has to do with this though. Intellexa is a Greek firm founded by an ex-IDF (aka Israeli) guy. In general, while Egypt has definitely been caught using tech like this, it rarely has the sophistication to develop it itself.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#53
post #3

Just your regular reminder that for the only security certification that Apple advertises on their website for iOS [1][2] Apple only achieved the lowest possible level of security assurance, EAL1. A level only fit for products where [3]: "some confidence in the correct operation is required, but the threats to security are not viewed as serious" which does not even require "demonstrating resistance to penetration att…

There is a near zero chance that being EAL4 or higher certified would’ve prevented these attacks.

CC might be better than PCI-DSS, but not by much.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#54
Here is what I do not understand:

Spyware firms and 0-day vendors both have staff dedicating to finding 0-days. Why do Google and Apple not simply poach these staff?

I am sure Google and Apple can offer very competitive salaries, so why do they not do so? Is it because the cost of basically poaching all of the skilled 0-day hunters is deemed to be greater than the cost of just issuing patches?

Re: 0-days exploited by commercial surveillance vendor in Egypt

#55
post #47

Earlier quoted context omitted.

Going EAL5 and above doesn't make sense from a cost to security ratio UNLESS the customer is open to paying more for that level of verification. Certain agencies and bureaus within the DoD do ask for this and pay for it, but most are good enough with EAL4. Most attacks can be resolved by following the bare minimum recommendations of the MITRE ATTACK framework (marketing buzzwords aside). Least Priviliged Access, Enti…

No. The US government briefly had procurement requirements for high security deployments. They were forced to relax them because Microsoft could not make bids that met the minimum requirements for DoD and high security projects and that made their Senators mad. They relaxed them to EAL4+ because that was the most that Microsoft could do. They since relaxed them further to EAL2 because that is all the most large AV an…

EAL5 is mainly about having a semi- formal description and for 6-7 you also need formal verification.

Outside some very limited cases, we don't have the tools to go there yet. EAL4+ is what people should aim for.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#56

Here is what I do not understand: Spyware firms and 0-day vendors both have staff dedicating to finding 0-days. Why do Google and Apple not simply poach these staff? I am sure Google and Apple can offer very competitive salaries, so why do they not do so? Is it because the cost of basically poaching all of the skilled 0-day hunters is deemed to be greater than the cost of just issuing patches?

Some of them wouldn't want to work for Google and Apple in the first place, regardless of the salary.

But while they could try and poach them today, tomorrow there will be a whole load of new people working for those companies, and it'll just be a never-ending cycle.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#57
post #3

Just your regular reminder that for the only security certification that Apple advertises on their website for iOS [1][2] Apple only achieved the lowest possible level of security assurance, EAL1. A level only fit for products where [3]: "some confidence in the correct operation is required, but the threats to security are not viewed as serious" which does not even require "demonstrating resistance to penetration att…

I mean, it occurs to me that maybe all of these companies aren't doing this for a reason - because common criteria and compliance are often stupid and don't represent real security. Perhaps these policies are the exception? But I've managed SOC2 for example and I can definitely say that there are plenty of ways to get your SOC2 without giving a shit about actual security.

They failed. Repeatedly. For decades. They spent billions trying. The failed so much that the standard writers determined the only logical conclusion is that it must be practically impossible to retrofit a system that failed EAL5 certification to achieve EAL5 or higher certification without a complete rewrite and redesign. It says so right there in the standard [1]: "EAL4 is the highest level at which it is likely to be economically feasible to retrofit to an existing product line". That was added due to the decades of experience where everybody who ever tried to do that failed no matter how much time or money they spent.

We also have plenty of evidence that it does matter, they just can not do it. Here is Google touting their Common Criteria certification for the Titan M2 security chip hardware which is EAL4 + AVA_VAN.5 (resistance against penetration attackers with a high attack potential) [2]. Note that this is only the hardware (software was not certified; a critical severity vulnerability was actually disclosed in the software allowing complete takeover if I remember correctly) and only cherry picks AVA_VAN.5 so is still only EAL4, not a holistic EAL6 certification. Getting that certification was a deliberate effort and cost. If they literally did not care about the Common Criteria then they would just certify to the checkbox level like everybody else. It is because they could certify it to a higher level than most other can achieve that they chose to do it because then they could tout their unique advantage.

Basically everybody gets a certification and basically everybody displays their certification on their page. There is something to be said about them opting for a EAL1 over a EAL4. It is basically assumed that any serious vendor could probably get a EAL4 with some effort. So, there is no differential advantage to displaying a EAL4 since everybody could get it. It is just a zero-sum game to pay for certification if everybody knows nobody has a true advantage. However, if you can achieve EAL5 or higher, then you do have a unique advantage because basically nobody else can do it. The fact that none of the major vendors attempts EAL5, shows that they can not do it.

[1] https://www.commoncriteriaportal.org/files/ccfiles/CC2022PAR... Page 18

[2] https://security.googleblog.com/2022/10/google-pixel-7-and-p...

Re: 0-days exploited by commercial surveillance vendor in Egypt

#58

Here is what I do not understand: Spyware firms and 0-day vendors both have staff dedicating to finding 0-days. Why do Google and Apple not simply poach these staff? I am sure Google and Apple can offer very competitive salaries, so why do they not do so? Is it because the cost of basically poaching all of the skilled 0-day hunters is deemed to be greater than the cost of just issuing patches?

Isn't this akin to asking why Google and Apple end up acquiring companies at very high prices if they could just hire the founders and have them build the products in-house?

Re: 0-days exploited by commercial surveillance vendor in Egypt

#59
post #31

Earlier quoted context omitted.

Huge difference between being tricked into clicking a link vs just browsing the web and getting owned.

Is there?

It definitely matters. Just think about what sort of how much Dr. Evil would pay for an exploit that relies on user action versus one that doesn't.

https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator

Re: 0-days exploited by commercial surveillance vendor in Egypt

#60

Here is what I do not understand: Spyware firms and 0-day vendors both have staff dedicating to finding 0-days. Why do Google and Apple not simply poach these staff? I am sure Google and Apple can offer very competitive salaries, so why do they not do so? Is it because the cost of basically poaching all of the skilled 0-day hunters is deemed to be greater than the cost of just issuing patches?

Isn't this akin to asking why Google and Apple end up acquiring companies at very high prices if they could just hire the founders and have them build the products in-house?

Poaching founders is an entirely different kettle of fish than just poaching line employees.
Post reply on HN