Live data from Hacker News

0-days exploited by commercial surveillance vendor in Egypt

blog.google

81–90 of 254 posts

Re: 0-days exploited by commercial surveillance vendor in Egypt

#81
post #4

It's good to get some more info, but it is a little disconcerting that they only mention patching Chrome. What was the sandbox escape on Android? Even if you had code execution inside the Chrome process on Android, that shouldn't be enough to enable persistence, so clearly there's another vulnerability. Also in this case the attack vector was MITM of http and one time links as it was a targeted campaign, but it feels…

> What was the sandbox escape on Android? Even if you had code execution inside the Chrome process on Android, that shouldn't be enough to enable persistence, so clearly there's another vulnerability.

This is such a crucial point. Forced to read between the lines of the blog post (because the above information is missing), it sounds like there are currently unpatched issues in Android revolving around this?

Re: 0-days exploited by commercial surveillance vendor in Egypt

#82

Slighty related, but Senator Bob Menendez was just indicted for taking bribes from people connected with the Egyptian military [0]. Gotta say, the Egyptian intelligence services are definitely punching above their weight by regional power standards. [0] - https://www.politico.com/news/2023/09/22/egypt-guns-money-me...

> Senator Bob Menendez was just indicted for taking bribes from people connected with the Egyptian military At a federal level law/power is continually traded for cash/favors. Heck, DoJ itself gets deployed in response to lobbyist demands (eg:copyright enforcement). From what I see this case was egregious and involved a non-favored foreign state. Maybe that's the bar at which DoJ begins to care about political ethics…

> law/power is continually traded for cash/favors

I worked on the Hill and that's not how it works. Yes, lobbying happens, but the what Menendez is indicted for goes well beyond anything a lobbyist would do legally. On top of that, foreign lobbyists need to formally register with the DoJ, which obviously didn't happen, but that's just the icing on the cake.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#84

Earlier quoted context omitted.

Google has one of the best teams money and prestige can buy: https://en.m.wikipedia.org/wiki/Project_Zero They also have excellent collaboration with independent researchers across the world. But given how much software is written everyday, they can still miss some issues.

Project Zero is amazing, but they 1) seem like a very small team, and 2) their mandate is far too broad (essentially to search for 0-days in anything, versus a specific system). What I am talking about is more like Apple having a dedicated team of 10 vulnerability researchers all looking into iOS 0-days fulltime.

They all do that. I've been in Offensive Security for 10+ years with several spent at FAANGS, and not only do they all have large security teams doing internal testing, they hire multiple contractors like Trail-of-Bits to audit every important service continuously throughout the year.

Apple has way more than 10 full time researchers looking at iOS all day, trust me :). They also have a really generous bug bounty. There is always bugs though.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#85

Here is what I do not understand: Spyware firms and 0-day vendors both have staff dedicating to finding 0-days. Why do Google and Apple not simply poach these staff? I am sure Google and Apple can offer very competitive salaries, so why do they not do so? Is it because the cost of basically poaching all of the skilled 0-day hunters is deemed to be greater than the cost of just issuing patches?

> Why do Google and Apple not simply poach these staff

They do. Plenty of white hat teams hire 8200 vets, but sometimes they'd rather make their own company instead of being a cog within an amaphorous foreign corporation.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#86

Here is what I do not understand: Spyware firms and 0-day vendors both have staff dedicating to finding 0-days. Why do Google and Apple not simply poach these staff? I am sure Google and Apple can offer very competitive salaries, so why do they not do so? Is it because the cost of basically poaching all of the skilled 0-day hunters is deemed to be greater than the cost of just issuing patches?

Money is just one input for why people choose to work at certain places.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#87

Earlier quoted context omitted.

> But while they could try and poach them today, tomorrow there will be a whole load of new people working for those companies, and it'll just be a never-ending cycle. The number of people who successfully find 0-click 0-days for iOS/Android is very small. It's not a vastly replenishable resource.

It's a small group but a wide pool. It's not like the same person finds 10 0days. And until they do find their one exploit most of them have pretty much no credentials at all. So how do you avoid hiring 10,000 up and comers that never actually come up?

The same that it works in any other industry. By hiring those with proven track records, the best of the best. The goal is obviously not to hire 100% of the potential 0-day hunters, but by launching a concentrated poaching effort, to make a sufficient dent.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#88

Here is what I do not understand: Spyware firms and 0-day vendors both have staff dedicating to finding 0-days. Why do Google and Apple not simply poach these staff? I am sure Google and Apple can offer very competitive salaries, so why do they not do so? Is it because the cost of basically poaching all of the skilled 0-day hunters is deemed to be greater than the cost of just issuing patches?

> Why do Google and Apple not simply poach these staff They do. Plenty of white hat teams hire 8200 vets, but sometimes they'd rather make their own company instead of being a cog within an amaphorous foreign corporation.

This. IIRC some famous security researcher responsible for iOS jail-breaks was poached by Apple only to leave after 3 months.

Successful and skilled security people with a proven track record, don't have the paciente of putting up with the charade such large orgs require.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#89

Earlier quoted context omitted.

Project Zero is amazing, but they 1) seem like a very small team, and 2) their mandate is far too broad (essentially to search for 0-days in anything, versus a specific system). What I am talking about is more like Apple having a dedicated team of 10 vulnerability researchers all looking into iOS 0-days fulltime.

They all do that. I've been in Offensive Security for 10+ years with several spent at FAANGS, and not only do they all have large security teams doing internal testing, they hire multiple contractors like Trail-of-Bits to audit every important service continuously throughout the year. Apple has way more than 10 full time researchers looking at iOS all day, trust me :). They also have a really generous bug bounty. The…

> Apple has way more than 10 full time researchers looking at iOS all day.

Yes

> They also have a really generous bug bounty.

Hell no

Re: 0-days exploited by commercial surveillance vendor in Egypt

#90
post #47

Earlier quoted context omitted.

No. The US government briefly had procurement requirements for high security deployments. They were forced to relax them because Microsoft could not make bids that met the minimum requirements for DoD and high security projects and that made their Senators mad. They relaxed them to EAL4+ because that was the most that Microsoft could do. They since relaxed them further to EAL2 because that is all the most large AV an…

EAL5 is mainly about having a semi- formal description and for 6-7 you also need formal verification. Outside some very limited cases, we don't have the tools to go there yet. EAL4+ is what people should aim for.

EAL4+ is useless against the prevailing threat actors as can be seen time and time again. There is no point at aiming for inadequate; even if you get there you still get nothing.

EAL6-7 certifications are basically the only known, existing certifications that have any evidence supporting that they are adequate to defend against the known and expected threats. As far as I am aware, there are no other certifications even able to distinguish products that can viably protect against organized crime and commercial spyware companies. Existing products max out every other certification and we know for a fact those products are ineffective against these threat actors. Therefore, we can conclude that those certifications are useless for identifying actual high security products adequate for the prevailing threat landscape.

Sure, if we had some other certification that could certify at that level and was more direct, that would be nice. But we do not, the only ones that we know to work and that products have been certified against are Common Criteria EAL6-7 (and maybe EAL5). We can either choose certifications that are cheap and do not work, or ones that work. Then, from the ones that work, we can maybe relax the requirements carefully to identify useful intermediate levels, or identify if some of the requirements are excessive and unnecessary for achieving the desired level of assurance.

However, the key takeaway from this is not whether we can certify products to EAL5 and higher or whether those certifications work or the cost-benefit of that certification process. The key takeaway is that EAL4 is certainly inadequate. Any product in commercial use targeting that level or lower is doomed to be useless against the threat actors who we know will attack it.

Post reply on HN