Live data from Hacker News

0-days exploited by commercial surveillance vendor in Egypt

blog.google

71–80 of 254 posts

Re: 0-days exploited by commercial surveillance vendor in Egypt

#71
post #3

Just your regular reminder that for the only security certification that Apple advertises on their website for iOS [1][2] Apple only achieved the lowest possible level of security assurance, EAL1. A level only fit for products where [3]: "some confidence in the correct operation is required, but the threats to security are not viewed as serious" which does not even require "demonstrating resistance to penetration att…

Isn't EAL1 what you get for just showing up? Basically, here is the product. Here are some design documents. We don't have anything more. Can we get our EAL1 please?

Yup. Want to have a laugh? Here is the Apple iOS certification report [1].

On PDF page 26 (document page 21) they describe the rigorous AVA_VAN.1 vulnerability analysis certification process they faced. The evaluation team basically typed in: "ios vulnerabilities" into Google and then typed in "ios iphone" into the NVD and verified that all of the search results were fixed. AVA_VAN.1 certification please.

To explain why, AVA_VAN.1 does not require a independent security analysis, it only requires a survey of the public domain for known vulnerabilities [2]. You need AVA_VAN.2 (which is only required in EAL2 and EAL3) before they actually attempt to look at for vulnerabilities themselves.

[1] https://www.commoncriteriaportal.org/files/epfiles/st_vid112...

[2] https://www.commoncriteriaportal.org/files/ccfiles/CC2022PAR... Page 154

Re: 0-days exploited by commercial surveillance vendor in Egypt

#72

Here is what I do not understand: Spyware firms and 0-day vendors both have staff dedicating to finding 0-days. Why do Google and Apple not simply poach these staff? I am sure Google and Apple can offer very competitive salaries, so why do they not do so? Is it because the cost of basically poaching all of the skilled 0-day hunters is deemed to be greater than the cost of just issuing patches?

Poach them to do what? There’s not much use to Apple or Google to have an implant developer around, and just having them do nothing is likely to be frustrating if the corporate lifestyle wasn’t enough already.

> Poach them to do what?

Poach them to discover 0-days in their software, as I said.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#73
post #61
post #56

Earlier quoted context omitted.

Some of them wouldn't want to work for Google and Apple in the first place, regardless of the salary. But while they could try and poach them today, tomorrow there will be a whole load of new people working for those companies, and it'll just be a never-ending cycle.

> Some of them wouldn't want to work for Google and Apple in the first place, regardless of the salary. For moral reasons do you mean? I would be surprised to learn there are a lot of people that are open to selling 0 day exploits to "bad actors" (granted that this term is doing a lot of heavy lifting here), but wouldn't want to work for Google or Apple. > ...it'll just be a never-ending cycle I think the idea is you…

> “bad actors", but wouldn't want to work for Google or Apple

- Everyone who doesn’t like US hegemony. Which happens about everywhere but US, in varied proportion, but even in Europe, and even worse in Middle-East,

- Everyone who doesn’t like monopolies. Capitalism of competition (as opposed to state capitalism, when the state borrows a trillion per semester, ahem) requires that monopolies be broken down to avoid distortion of competition. Helping bad actors can be, under their viewpoint, less bad than the damage done to a billion consumers consumers at a time. Plus monopolies impose a monoculture of occidentalism, with certain values that a firm in Egypt might consider worse than sponsoring bad actors.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#74

Here is what I do not understand: Spyware firms and 0-day vendors both have staff dedicating to finding 0-days. Why do Google and Apple not simply poach these staff? I am sure Google and Apple can offer very competitive salaries, so why do they not do so? Is it because the cost of basically poaching all of the skilled 0-day hunters is deemed to be greater than the cost of just issuing patches?

They probably don't want to hire criminals to work at their companies.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#75

Slighty related, but Senator Bob Menendez was just indicted for taking bribes from people connected with the Egyptian military [0]. Gotta say, the Egyptian intelligence services are definitely punching above their weight by regional power standards. [0] - https://www.politico.com/news/2023/09/22/egypt-guns-money-me...

> Senator Bob Menendez was just indicted for taking bribes from people connected with the Egyptian military At a federal level law/power is continually traded for cash/favors. Heck, DoJ itself gets deployed in response to lobbyist demands (eg:copyright enforcement). From what I see this case was egregious and involved a non-favored foreign state. Maybe that's the bar at which DoJ begins to care about political ethics…

> involved a non-favored foreign state

Egypt is not 'non-favored'. The US has very close ties with Egypt's dictatorial regime[0], despite its awful domestic human rights record[1].

[0]https://thehill.com/blogs/congress-blog/foreign-policy/58552...

[1]https://www.amnesty.org/en/latest/news/2022/09/egypt-human-r...

Re: 0-days exploited by commercial surveillance vendor in Egypt

#76

Here is what I do not understand: Spyware firms and 0-day vendors both have staff dedicating to finding 0-days. Why do Google and Apple not simply poach these staff? I am sure Google and Apple can offer very competitive salaries, so why do they not do so? Is it because the cost of basically poaching all of the skilled 0-day hunters is deemed to be greater than the cost of just issuing patches?

I think this is similar to looking at the budget of the US government and asking why they don't simply pay off all the potential criminals such that most crime in the US is then mitigated.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#77

Here is what I do not understand: Spyware firms and 0-day vendors both have staff dedicating to finding 0-days. Why do Google and Apple not simply poach these staff? I am sure Google and Apple can offer very competitive salaries, so why do they not do so? Is it because the cost of basically poaching all of the skilled 0-day hunters is deemed to be greater than the cost of just issuing patches?

They probably don't want to hire criminals to work at their companies.

Already very well-paid criminals for that matter

Re: 0-days exploited by commercial surveillance vendor in Egypt

#78
post #61

Earlier quoted context omitted.

> Some of them wouldn't want to work for Google and Apple in the first place, regardless of the salary. For moral reasons do you mean? I would be surprised to learn there are a lot of people that are open to selling 0 day exploits to "bad actors" (granted that this term is doing a lot of heavy lifting here), but wouldn't want to work for Google or Apple. > ...it'll just be a never-ending cycle I think the idea is you…

> “bad actors", but wouldn't want to work for Google or Apple - Everyone who doesn’t like US hegemony. Which happens about everywhere but US, in varied proportion, but even in Europe, and even worse in Middle-East, - Everyone who doesn’t like monopolies. Capitalism of competition (as opposed to state capitalism, when the state borrows a trillion per semester, ahem) requires that monopolies be broken down to avoid dis…

If the number of skilled 0-day hunters who will work for a paycheck is > 0, then yours is a moot point, since a poaching program would still make an impact even if there are some people who work for spyware companies who would not work for FAANG.

I think you will also find that morals for many people are inversely proportional to the offered salary. An 0-day developer being compensated $130k may well abandon their particular morals if offered a $240k salary instead.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#80
post #56

Earlier quoted context omitted.

Some of them wouldn't want to work for Google and Apple in the first place, regardless of the salary. But while they could try and poach them today, tomorrow there will be a whole load of new people working for those companies, and it'll just be a never-ending cycle.

> But while they could try and poach them today, tomorrow there will be a whole load of new people working for those companies, and it'll just be a never-ending cycle. The number of people who successfully find 0-click 0-days for iOS/Android is very small. It's not a vastly replenishable resource.

It's a small group but a wide pool. It's not like the same person finds 10 0days. And until they do find their one exploit most of them have pretty much no credentials at all. So how do you avoid hiring 10,000 up and comers that never actually come up?
Post reply on HN