Live data from Hacker News

0-days exploited by commercial surveillance vendor in Egypt

blog.google

101–110 of 254 posts

Re: 0-days exploited by commercial surveillance vendor in Egypt

#101
post #31

Earlier quoted context omitted.

Is there?

Yes. The move from 0 to 1 click exploits (thanks to putting Flash/Java behind a click) in the early 2000s marked a massive negative shift in attacker capabilities and ultimately destroyed multiple (black market) exploit dev businesses.

“Click to play” bypasses became incredibly valuable as an enabler for Flash/Java exploits, for a while. They were also few and far between, and if memory serves me, unreliable as fuck.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#102
post #90

Earlier quoted context omitted.

EAL5 is mainly about having a semi- formal description and for 6-7 you also need formal verification. Outside some very limited cases, we don't have the tools to go there yet. EAL4+ is what people should aim for.

EAL4+ is useless against the prevailing threat actors as can be seen time and time again. There is no point at aiming for inadequate; even if you get there you still get nothing. EAL6-7 certifications are basically the only known, existing certifications that have any evidence supporting that they are adequate to defend against the known and expected threats. As far as I am aware, there are no other certifications ev…

I feel like you're arguing that these certifications are useless and uncorrelated with security but then you're trying to say that Apple and others are bad for not having them.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#103
post #3

Just your regular reminder that for the only security certification that Apple advertises on their website for iOS [1][2] Apple only achieved the lowest possible level of security assurance, EAL1. A level only fit for products where [3]: "some confidence in the correct operation is required, but the threats to security are not viewed as serious" which does not even require "demonstrating resistance to penetration att…

> Apple has never once, over multiple decades of failed attempts, demonstrated "resistance to penetration attackers with a moderate attack potential" for any of their products. To be fair, neither has Microsoft, Google, Amazon, Cisco, Crowdstrike, etc. So, OK I guess? It's worth noting that CC evaluation does not score the actual practical security of a device or system, but the level of testing it was submitted to,…

Sure it does, it is just that EAL4+, the highest level any of them can reach, does not certify "resistance to penetration attackers with a moderate attack potential". Guess what, commercial hackers have "moderate attack potential".

You are complaining that the 40 cm high jump test does not score actual jumping ability. You are right, it is a low bar that they should all be able to pass. You can not use the 40 cm high jump test to distinguish them. What you need to do is use the 100 cm high jump test. Some can pass it, but none of the large commercial vendors can. Sure, it would be nice if we had more gradations like the 60 cm and 80 cm tests, but we do not really know how to do that, so the best we can do is the 100 cm test.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#104
post #52

I’m not an expert, but would’t a VPN (commercial or to a server with known exit IP) prevent such attacks? It will kick out the MITM. Also I wonder if the lock down mode could block it.

Yes and also yes.

These attacks when launched by government entities pretty much always rely on placing a box at the ISP that does the targeted interception/MiTM against a subset of subscribers.

So using a VPN would ensure your traffic is tunnelled “beyond” their reach.

Lockdown mode also would have prevented the iOS exploit chain, apparently.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#105

Here is what I do not understand: Spyware firms and 0-day vendors both have staff dedicating to finding 0-days. Why do Google and Apple not simply poach these staff? I am sure Google and Apple can offer very competitive salaries, so why do they not do so? Is it because the cost of basically poaching all of the skilled 0-day hunters is deemed to be greater than the cost of just issuing patches?

They probably don't want to hire criminals to work at their companies.

[deleted]

Re: 0-days exploited by commercial surveillance vendor in Egypt

#106
post #4

It's good to get some more info, but it is a little disconcerting that they only mention patching Chrome. What was the sandbox escape on Android? Even if you had code execution inside the Chrome process on Android, that shouldn't be enough to enable persistence, so clearly there's another vulnerability. Also in this case the attack vector was MITM of http and one time links as it was a targeted campaign, but it feels…

The article is mainly about the iphone exploit chain: Safari exploit -> PAC bypass -> kernel exploit.

Android version was pretty similar but I think needed two more exploits to bypass Linux kernel mitigations.

PZ has a good technical writeup.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#107
post #44
post #34

Earlier quoted context omitted.

I'm interested at your suggestion that Digicert et al are doing some sort of "keeping the streets safe" checking. I have zero experience of using them but I thought all they were doing was confirming the applicant represented some entity that matched the domain name. If I manage to get a company registered called G00gle, buy a corresponding domain and then send them my $500 are you suggesting they're going to refuse…

I don't see GP claiming CAs should be checking reputability for domain issuance certificates. But the thread originator mentioned subverting CAs! Something to remember about even the most advanced attackers is that they value the continued effectiveness of their tactics, tools and procedures. Even nation-states in possession of CA subversion abilities won't burn their malicious CA on someone if they can conduct the a…

I was referring to this comment https://news.ycombinator.com/item?id=37615985

Re: 0-days exploited by commercial surveillance vendor in Egypt

#108
post #103

Earlier quoted context omitted.

> Apple has never once, over multiple decades of failed attempts, demonstrated "resistance to penetration attackers with a moderate attack potential" for any of their products. To be fair, neither has Microsoft, Google, Amazon, Cisco, Crowdstrike, etc. So, OK I guess? It's worth noting that CC evaluation does not score the actual practical security of a device or system, but the level of testing it was submitted to,…

Sure it does, it is just that EAL4+, the highest level any of them can reach, does not certify "resistance to penetration attackers with a moderate attack potential". Guess what, commercial hackers have "moderate attack potential". You are complaining that the 40 cm high jump test does not score actual jumping ability. You are right, it is a low bar that they should all be able to pass. You can not use the 40 cm high…

I'm not really complaining, though. I'm just saying that security certifications are more about compliance than actual proof that a system cannot be easily compromised. In other words, they are more about legal requirements than guarantees.

It is also misleading to assert that a device or a system are less secure because they haven't been certified. Vendors submit requests to validate against specific levels or certifications, and it is not the goal of the certification authority to determine "how high" they score.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#109

Here is what I do not understand: Spyware firms and 0-day vendors both have staff dedicating to finding 0-days. Why do Google and Apple not simply poach these staff? I am sure Google and Apple can offer very competitive salaries, so why do they not do so? Is it because the cost of basically poaching all of the skilled 0-day hunters is deemed to be greater than the cost of just issuing patches?

There is also a chance at play here. Many people are trying to find a hole, some are more lucky than the other. Google has a great team, so they get lucky more, that is why these things are not too common, but at some point a bad guy gets lucky too, even though he is not the smartest in the room.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#110

Earlier quoted context omitted.

that sounds like terrible joke sandbox in sandbox in sandbox in sandbox in sandbox in sandbox in sandbox and stuff still manages to escape

That’s the thing about sand. It’s course and rough and irritating and it gets everywhere.

But there is always time for a glass of good wine!
Post reply on HN