Earlier quoted context omitted.
Is there?
Yes. The move from 0 to 1 click exploits (thanks to putting Flash/Java behind a click) in the early 2000s marked a massive negative shift in attacker capabilities and ultimately destroyed multiple (black market) exploit dev businesses.
0-days exploited by commercial surveillance vendor in Egypt
101–110 of 254 posts
Re: 0-days exploited by commercial surveillance vendor in Egypt
#102Earlier quoted context omitted.
EAL5 is mainly about having a semi- formal description and for 6-7 you also need formal verification. Outside some very limited cases, we don't have the tools to go there yet. EAL4+ is what people should aim for.
EAL4+ is useless against the prevailing threat actors as can be seen time and time again. There is no point at aiming for inadequate; even if you get there you still get nothing. EAL6-7 certifications are basically the only known, existing certifications that have any evidence supporting that they are adequate to defend against the known and expected threats. As far as I am aware, there are no other certifications ev…
Re: 0-days exploited by commercial surveillance vendor in Egypt
#103Just your regular reminder that for the only security certification that Apple advertises on their website for iOS [1][2] Apple only achieved the lowest possible level of security assurance, EAL1. A level only fit for products where [3]: "some confidence in the correct operation is required, but the threats to security are not viewed as serious" which does not even require "demonstrating resistance to penetration att…
> Apple has never once, over multiple decades of failed attempts, demonstrated "resistance to penetration attackers with a moderate attack potential" for any of their products. To be fair, neither has Microsoft, Google, Amazon, Cisco, Crowdstrike, etc. So, OK I guess? It's worth noting that CC evaluation does not score the actual practical security of a device or system, but the level of testing it was submitted to,…
You are complaining that the 40 cm high jump test does not score actual jumping ability. You are right, it is a low bar that they should all be able to pass. You can not use the 40 cm high jump test to distinguish them. What you need to do is use the 100 cm high jump test. Some can pass it, but none of the large commercial vendors can. Sure, it would be nice if we had more gradations like the 60 cm and 80 cm tests, but we do not really know how to do that, so the best we can do is the 100 cm test.
Re: 0-days exploited by commercial surveillance vendor in Egypt
#104I’m not an expert, but would’t a VPN (commercial or to a server with known exit IP) prevent such attacks? It will kick out the MITM. Also I wonder if the lock down mode could block it.
These attacks when launched by government entities pretty much always rely on placing a box at the ISP that does the targeted interception/MiTM against a subset of subscribers.
So using a VPN would ensure your traffic is tunnelled “beyond” their reach.
Lockdown mode also would have prevented the iOS exploit chain, apparently.
Re: 0-days exploited by commercial surveillance vendor in Egypt
#105Here is what I do not understand: Spyware firms and 0-day vendors both have staff dedicating to finding 0-days. Why do Google and Apple not simply poach these staff? I am sure Google and Apple can offer very competitive salaries, so why do they not do so? Is it because the cost of basically poaching all of the skilled 0-day hunters is deemed to be greater than the cost of just issuing patches?
They probably don't want to hire criminals to work at their companies.
Re: 0-days exploited by commercial surveillance vendor in Egypt
#106It's good to get some more info, but it is a little disconcerting that they only mention patching Chrome. What was the sandbox escape on Android? Even if you had code execution inside the Chrome process on Android, that shouldn't be enough to enable persistence, so clearly there's another vulnerability. Also in this case the attack vector was MITM of http and one time links as it was a targeted campaign, but it feels…
Android version was pretty similar but I think needed two more exploits to bypass Linux kernel mitigations.
PZ has a good technical writeup.
Re: 0-days exploited by commercial surveillance vendor in Egypt
#107Earlier quoted context omitted.
I'm interested at your suggestion that Digicert et al are doing some sort of "keeping the streets safe" checking. I have zero experience of using them but I thought all they were doing was confirming the applicant represented some entity that matched the domain name. If I manage to get a company registered called G00gle, buy a corresponding domain and then send them my $500 are you suggesting they're going to refuse…
I don't see GP claiming CAs should be checking reputability for domain issuance certificates. But the thread originator mentioned subverting CAs! Something to remember about even the most advanced attackers is that they value the continued effectiveness of their tactics, tools and procedures. Even nation-states in possession of CA subversion abilities won't burn their malicious CA on someone if they can conduct the a…
Re: 0-days exploited by commercial surveillance vendor in Egypt
#108Earlier quoted context omitted.
> Apple has never once, over multiple decades of failed attempts, demonstrated "resistance to penetration attackers with a moderate attack potential" for any of their products. To be fair, neither has Microsoft, Google, Amazon, Cisco, Crowdstrike, etc. So, OK I guess? It's worth noting that CC evaluation does not score the actual practical security of a device or system, but the level of testing it was submitted to,…
Sure it does, it is just that EAL4+, the highest level any of them can reach, does not certify "resistance to penetration attackers with a moderate attack potential". Guess what, commercial hackers have "moderate attack potential". You are complaining that the 40 cm high jump test does not score actual jumping ability. You are right, it is a low bar that they should all be able to pass. You can not use the 40 cm high…
It is also misleading to assert that a device or a system are less secure because they haven't been certified. Vendors submit requests to validate against specific levels or certifications, and it is not the goal of the certification authority to determine "how high" they score.
Re: 0-days exploited by commercial surveillance vendor in Egypt
#109Here is what I do not understand: Spyware firms and 0-day vendors both have staff dedicating to finding 0-days. Why do Google and Apple not simply poach these staff? I am sure Google and Apple can offer very competitive salaries, so why do they not do so? Is it because the cost of basically poaching all of the skilled 0-day hunters is deemed to be greater than the cost of just issuing patches?
Re: 0-days exploited by commercial surveillance vendor in Egypt
#110Earlier quoted context omitted.
that sounds like terrible joke sandbox in sandbox in sandbox in sandbox in sandbox in sandbox in sandbox and stuff still manages to escape
That’s the thing about sand. It’s course and rough and irritating and it gets everywhere.