Live data from Hacker News

0-days exploited by commercial surveillance vendor in Egypt

blog.google

131–140 of 254 posts

Re: 0-days exploited by commercial surveillance vendor in Egypt

#131
post #4

It's good to get some more info, but it is a little disconcerting that they only mention patching Chrome. What was the sandbox escape on Android? Even if you had code execution inside the Chrome process on Android, that shouldn't be enough to enable persistence, so clearly there's another vulnerability. Also in this case the attack vector was MITM of http and one time links as it was a targeted campaign, but it feels…

> What was the sandbox escape on Android? Even if you had code execution inside the Chrome process on Android, that shouldn't be enough to enable persistence, so clearly there's another vulnerability. This is such a crucial point. Forced to read between the lines of the blog post (because the above information is missing), it sounds like there are currently unpatched issues in Android revolving around this?

Likely yes, they were unable to capture the following stages so they don’t know what was exploited after gaining initial execution within the chrome sandbox.

Likely there’s a chrome sandbox escape and a kernel exploit remaining “unknown and unpatched”.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#132

Earlier quoted context omitted.

Isn't this akin to asking why Google and Apple end up acquiring companies at very high prices if they could just hire the founders and have them build the products in-house?

Poaching founders is an entirely different kettle of fish than just poaching line employees.

Oh, I thought finding these vulns was a highly open-ended endeavor with variable payouts.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#133
post #3

Just your regular reminder that for the only security certification that Apple advertises on their website for iOS [1][2] Apple only achieved the lowest possible level of security assurance, EAL1. A level only fit for products where [3]: "some confidence in the correct operation is required, but the threats to security are not viewed as serious" which does not even require "demonstrating resistance to penetration att…

Please don't post "regular reminder" style comments - they're too generic, and generic discussion is consistently less interesting. Good threads require being unpredictable. The best way to get that is to respond to specific new information in an article.

https://news.ycombinator.com/newsguidelines.html

Re: 0-days exploited by commercial surveillance vendor in Egypt

#134

Here is what I do not understand: Spyware firms and 0-day vendors both have staff dedicating to finding 0-days. Why do Google and Apple not simply poach these staff? I am sure Google and Apple can offer very competitive salaries, so why do they not do so? Is it because the cost of basically poaching all of the skilled 0-day hunters is deemed to be greater than the cost of just issuing patches?

I am this person. I work as a researcher finding 0-days.

From the employee perspective: Wages are equal. Big Tech work is less interesting (build big bug finding machines that find have high quantity of bugs) and report the bugs that sit into some bug tracker only to maybe be fixed in 3 months. Offensive security work is more interesting. It requires intimate knowledge of the systems you research, since you only need a handful and the shallow ones get found by Big Tech. You must go deep. Additionally offensive security requires the know-how to go from vulnerability to code execution. Exploitation is not an easy task. I can't explain why engineers work for companies that I deem immoral, but that's probably because they don't feel the same way as I do.

From the employer perspective: How much does the rate of X vulnerabilities per year cost me? If our code has bugs but is still considered the securest code on the market, it may not benefit the company to increase the security budget. If the company expands the security budget then which division is getting cut because of it, and what is the net result to the company health?

If you want to fix the vulnerabilities you need to make the price of finding and exploiting them higher than the people buying them can afford. And you must keep the price higher as advances in offensive security work to lower the price of finding and exploiting them. Since defensive companies don't primarily make money from preventing bugs and offensive companies do primarily make money by finding bugs, there is a mismatch. The ultimate vulnerability in a company, or any entity, is finite resources.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#136

Here is what I do not understand: Spyware firms and 0-day vendors both have staff dedicating to finding 0-days. Why do Google and Apple not simply poach these staff? I am sure Google and Apple can offer very competitive salaries, so why do they not do so? Is it because the cost of basically poaching all of the skilled 0-day hunters is deemed to be greater than the cost of just issuing patches?

Because that would eat into profit margins, and at the end of the day very very few paying customers actually make their purchasing decisions based on security. On top of that almost nobody is really knowledgeable enough to make an informed decision in the first place. So the money doesn’t get spent.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#137

Earlier quoted context omitted.

> What was the sandbox escape on Android? Even if you had code execution inside the Chrome process on Android, that shouldn't be enough to enable persistence, so clearly there's another vulnerability. This is such a crucial point. Forced to read between the lines of the blog post (because the above information is missing), it sounds like there are currently unpatched issues in Android revolving around this?

Likely yes, they were unable to capture the following stages so they don’t know what was exploited after gaining initial execution within the chrome sandbox. Likely there’s a chrome sandbox escape and a kernel exploit remaining “unknown and unpatched”.

> Likely there’s a chrome sandbox escape and a kernel exploit remaining “unknown and unpatched”.

There is certainly many of those that we don't know about, if this was done in Egypt, imagine what a 3 letters agency have

Re: 0-days exploited by commercial surveillance vendor in Egypt

#138
post #69

Here is what I do not understand: Spyware firms and 0-day vendors both have staff dedicating to finding 0-days. Why do Google and Apple not simply poach these staff? I am sure Google and Apple can offer very competitive salaries, so why do they not do so? Is it because the cost of basically poaching all of the skilled 0-day hunters is deemed to be greater than the cost of just issuing patches?

who's to say they're not doing this? there are a lot of security companies and researchers in the world though or alternatively: as lovely as the hacker -> employee fairytale sounds, a certain % of the "I would never work for Google/Apple" types would come in with the sole purpose of installing backdoors from the inside

A lot of the really good hackers won’t pass HR screening, or be able to cope with corporate bullshit beyond a year.

So there’s also that.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#139
post #76

Here is what I do not understand: Spyware firms and 0-day vendors both have staff dedicating to finding 0-days. Why do Google and Apple not simply poach these staff? I am sure Google and Apple can offer very competitive salaries, so why do they not do so? Is it because the cost of basically poaching all of the skilled 0-day hunters is deemed to be greater than the cost of just issuing patches?

I think this is similar to looking at the budget of the US government and asking why they don't simply pay off all the potential criminals such that most crime in the US is then mitigated.

That’s not equivalent at all. Paying off criminals creates an incentive for there to be more criminals. Paying more security researchers does not incentivize people writing buggy C code to write even buggier C code.
Post reply on HN