Live data from Hacker News

0-days exploited by commercial surveillance vendor in Egypt

blog.google

141–150 of 254 posts

Re: 0-days exploited by commercial surveillance vendor in Egypt

#141

I've a question. This 0-day is a 0-click that didn't require any document download or anything. Simply visiting a http site would do it. What if you have JavaScript disabled be default. Would this exploit still work?

it's http interception so no, I doubt javascript matters at all

Without knowing more, that's a bit of an assumption. The vulnerability could be in image decoding, in which case an tag is enough and no scripting is needed, but it could also very well require doing something funky with JavaScript.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#143
post #4

It's good to get some more info, but it is a little disconcerting that they only mention patching Chrome. What was the sandbox escape on Android? Even if you had code execution inside the Chrome process on Android, that shouldn't be enough to enable persistence, so clearly there's another vulnerability. Also in this case the attack vector was MITM of http and one time links as it was a targeted campaign, but it feels…

> What was the sandbox escape on Android? Even if you had code execution inside the Chrome process on Android, that shouldn't be enough to enable persistence, so clearly there's another vulnerability. This is such a crucial point. Forced to read between the lines of the blog post (because the above information is missing), it sounds like there are currently unpatched issues in Android revolving around this?

Read it again, no sandbox attack on Android MITM and one time link attack only .

Re: 0-days exploited by commercial surveillance vendor in Egypt

#144

Earlier quoted context omitted.

Poaching founders is an entirely different kettle of fish than just poaching line employees.

Oh, I thought finding these vulns was a highly open-ended endeavor with variable payouts.

It depends. Some companies that buy exploits have public “price lists” for acquisitions.

100k+ for a Safari on iOS code exec, another 200k for the Safari sandbox escape, then another 500k+ for the kernel exploit?

A full chain is real money. Especially when they resell this ability for 1-2M+ per user.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#145
post #111

Earlier quoted context omitted.

I feel like you're arguing that these certifications are useless and uncorrelated with security but then you're trying to say that Apple and others are bad for not having them.

Low certification levels certify low levels of security. High certification levels certify high levels of security. EAL4 is known to be too low against modern threats that will attack commercial users. We know this from experience where EAL4 systems are routinely defeated. Higher certification levels, such as the SKPP at EAL6/7, are known to be able to resist against much harder threats such as state actors like the…

> Low certification levels certify low levels of security. High certification levels certify high levels of security.

I guess I don't know enough to say but I just doubt that, knowing what I know about other certifications. I expect that they're perhaps lightly correlated with security.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#146

Here is what I do not understand: Spyware firms and 0-day vendors both have staff dedicating to finding 0-days. Why do Google and Apple not simply poach these staff? I am sure Google and Apple can offer very competitive salaries, so why do they not do so? Is it because the cost of basically poaching all of the skilled 0-day hunters is deemed to be greater than the cost of just issuing patches?

It’s not just money that motivates.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#147
post #10

Though HTTPS is better than nothing, and this attack relies on HTTP to inject the initial payload, state sponsored attackers in some countries can likely just subvert CA or CDN infrastructure instead.

You probably can't forge a certificate like that without all the browsers noticing and dropping your CA; there's protections against it.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#148

Earlier quoted context omitted.

> What was the sandbox escape on Android? Even if you had code execution inside the Chrome process on Android, that shouldn't be enough to enable persistence, so clearly there's another vulnerability. This is such a crucial point. Forced to read between the lines of the blog post (because the above information is missing), it sounds like there are currently unpatched issues in Android revolving around this?

Likely yes, they were unable to capture the following stages so they don’t know what was exploited after gaining initial execution within the chrome sandbox. Likely there’s a chrome sandbox escape and a kernel exploit remaining “unknown and unpatched”.

Is it possible that it was detected but without a sandbox escape? would it still be described as "an exploit" if so?

Re: 0-days exploited by commercial surveillance vendor in Egypt

#149
post #4

It's good to get some more info, but it is a little disconcerting that they only mention patching Chrome. What was the sandbox escape on Android? Even if you had code execution inside the Chrome process on Android, that shouldn't be enough to enable persistence, so clearly there's another vulnerability. Also in this case the attack vector was MITM of http and one time links as it was a targeted campaign, but it feels…

> What was the sandbox escape on Android? Even if you had code execution inside the Chrome process on Android, that shouldn't be enough to enable persistence, so clearly there's another vulnerability. This is such a crucial point. Forced to read between the lines of the blog post (because the above information is missing), it sounds like there are currently unpatched issues in Android revolving around this?

I mean there are always unpatched issues in everything... There's nothing you can do, whether you know about it or not. You have to just assume you're always actively being exploited at some level

Re: 0-days exploited by commercial surveillance vendor in Egypt

#150
post #137

Earlier quoted context omitted.

Likely yes, they were unable to capture the following stages so they don’t know what was exploited after gaining initial execution within the chrome sandbox. Likely there’s a chrome sandbox escape and a kernel exploit remaining “unknown and unpatched”.

> Likely there’s a chrome sandbox escape and a kernel exploit remaining “unknown and unpatched”. There is certainly many of those that we don't know about, if this was done in Egypt, imagine what a 3 letters agency have

Wouldn't be a stretch to assume this is forced by 3 letter agencies and it's details leaked for sale on an exclusive dark web.

Think of all the insidious corruption we find out about via declassification 50 years later. It's not like human nature has changed.

Post reply on HN