Live data from Hacker News

0-days exploited by commercial surveillance vendor in Egypt

blog.google

151–160 of 254 posts

Re: 0-days exploited by commercial surveillance vendor in Egypt

#151
post #111

Earlier quoted context omitted.

Low certification levels certify low levels of security. High certification levels certify high levels of security. EAL4 is known to be too low against modern threats that will attack commercial users. We know this from experience where EAL4 systems are routinely defeated. Higher certification levels, such as the SKPP at EAL6/7, are known to be able to resist against much harder threats such as state actors like the…

> Low certification levels certify low levels of security. High certification levels certify high levels of security. I guess I don't know enough to say but I just doubt that, knowing what I know about other certifications. I expect that they're perhaps lightly correlated with security.

You said that I was arguing the certification is useless. I was arguing that certifying to low levels is useless. Those are not even close to the same argument.

For example, a squat test is a reasonable measure of leg strength. Only squatting 20 kg means your leg strength is extremely weak. The test procedure is fine, getting results like that is not. If that is all you can do, that is quite problematic.

As to the certification itself, it is pretty good. Easily hacked products like iOS, Linux, and Windows are consistently unable to certify as moderately secure. That is vastly different than basically every other certification where products like Windows pass with flying colors even though we all know that is nonsense.

So, at the very least, low certification levels like EAL4 provide high confidence of lackluster security. You can withhold judgement of high assurance levels corresponding to high security if you like, but low assurance levels corresponding to low security is pretty clearly established.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#152

Earlier quoted context omitted.

> law/power is continually traded for cash/favors I worked on the Hill and that's not how it works. Yes, lobbying happens, but the what Menendez is indicted for goes well beyond anything a lobbyist would do legally. On top of that, foreign lobbyists need to formally register with the DoJ, which obviously didn't happen, but that's just the icing on the cake.

>> law/power is continually traded for cash/favors > I worked on the Hill and that's not how it works. Your are asserting that law/power is not continually traded for cash/favors. That's a pretty clear assertion and I appreciate it. To follow, you would also assert that this chain doesn't exist in any meaningful way: Major campaign donations are used by legislator -> Legislator benefiting from funds is critical to cr…

Yes, that doesn't happen.

If a legislator agrees with you, you want to keep them in the legislature, not retiring into industry.

Also, campaign donations are capped at like $5000 and most of what people think is corruption is them recklessly misreading the donation reports.

Similarly, it's Bernie and similar people who get the most donations these days because of ActBlue, and it doesn't help them win elections, because voters actually like the legislators you think are owned by corporations and actually vote for them.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#153
post #114

Earlier quoted context omitted.

I'm not really complaining, though. I'm just saying that security certifications are more about compliance than actual proof that a system cannot be easily compromised. In other words, they are more about legal requirements than guarantees. It is also misleading to assert that a device or a system are less secure because they haven't been certified. Vendors submit requests to validate against specific levels or certi…

They can not certify against useful assurance levels. They have tried repeatedly for decades and spent huge gobs of money. It is not a choice, they are incapable of it. I am judging them by their maximum ability ever demonstrated under the most favorable circumstances and they still can certify resistance against moderate attackers. They have never developed systems that can protect against the prevailing threat land…

> They have tried repeatedly for decades and spent huge gobs of money. It is not a choice, they are incapable of it.

First of all, I don't think that's true, and if it is, I would like to see proof of Apple submitting their products for evaluation.

Second, you are judging an entire industry. This is not about Apple shortcomings, there isn't a single vendor doing what you say needs to be done.

Regardless, and this is more a personal opinion than a hard fact, most certifications out there are BS. PCI-DSS is basically a checklist of best practices, CC goes from common sense stuff to essentially impossible to achieve unless designed for the specific purpose, etc. Yes, all these helped create a very healthy - and profitable - industry where consultants have thrived on Powerpoints and PDFs, without really creating any tangible value.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#154

Earlier quoted context omitted.

Likely yes, they were unable to capture the following stages so they don’t know what was exploited after gaining initial execution within the chrome sandbox. Likely there’s a chrome sandbox escape and a kernel exploit remaining “unknown and unpatched”.

Is it possible that it was detected but without a sandbox escape? would it still be described as "an exploit" if so?

Yes.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#155

Earlier quoted context omitted.

> What was the sandbox escape on Android? Even if you had code execution inside the Chrome process on Android, that shouldn't be enough to enable persistence, so clearly there's another vulnerability. This is such a crucial point. Forced to read between the lines of the blog post (because the above information is missing), it sounds like there are currently unpatched issues in Android revolving around this?

Read it again, no sandbox attack on Android MITM and one time link attack only .

That’s all they were able to gather.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#156

Here is what I do not understand: Spyware firms and 0-day vendors both have staff dedicating to finding 0-days. Why do Google and Apple not simply poach these staff? I am sure Google and Apple can offer very competitive salaries, so why do they not do so? Is it because the cost of basically poaching all of the skilled 0-day hunters is deemed to be greater than the cost of just issuing patches?

I want to fight terrorism. I’ll work for a company finding ways to get data from bad actors’ phones before I’d work for Google or Apple, at any price.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#157

Earlier quoted context omitted.

>> law/power is continually traded for cash/favors > I worked on the Hill and that's not how it works. Your are asserting that law/power is not continually traded for cash/favors. That's a pretty clear assertion and I appreciate it. To follow, you would also assert that this chain doesn't exist in any meaningful way: Major campaign donations are used by legislator -> Legislator benefiting from funds is critical to cr…

Yes, that doesn't happen. If a legislator agrees with you, you want to keep them in the legislature, not retiring into industry. Also, campaign donations are capped at like $5000 and most of what people think is corruption is them recklessly misreading the donation reports. Similarly, it's Bernie and similar people who get the most donations these days because of ActBlue, and it doesn't help them win elections, becau…

> Yes, that doesn't happen.

I invested 15 seconds into a search query.

Former Members Dick Armey. Tom Daschle. Tom Foley. Trent Lott.

Once, these politicos ranked among Congress' most powerful members. Today, they share another distinction: They're lobbyists (or "senior advisors" performing very similar work). And they're hardly alone. Dozens of former members of Congress now receive handsome compensation from corporations and special interests as they attempt to influence the very federal government in which they used to serve.

ref: https://www.opensecrets.org/revolving/top.php?display=Z

This is an incomplete list of just one body of lawmakers who went to work for just one industry. It's a very limited reference to the much, much larger whole.

>If a legislator agrees with you, you want to keep them

Although I included people tied to legislators (and their interests) you opted to limit your response to just legislators and even that seemed more platitude than substance.

> Also, campaign donations are capped at like $5000

So what? This falsely implies no donor can get more than $5k into any one campaign fund. Tossing it out there as primarily defining detail seems disingenuous. It omits non-cash contributions. It omits donations to traditional PACs, Super PACs, 527s, political parties, 501(c)4,5 & 6.

It omits all the possible avenues of getting money to candidates that someone with a CapHill political background almost certainly knows.

It does dovetail nicely with an alternate narrative about revolving doors not existing, however.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#158
post #10

Though HTTPS is better than nothing, and this attack relies on HTTP to inject the initial payload, state sponsored attackers in some countries can likely just subvert CA or CDN infrastructure instead.

You probably can't forge a certificate like that without all the browsers noticing and dropping your CA; there's protections against it.

If you're a nation you can just force the CAs that are in your jurisdiction to do whatever you want, or sneak in in various ways so they won't know.

If you use the MITM judiciously, it's very likely that nobody will notice, or that those that notice can be compelled not to say anything.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#159

Here is what I do not understand: Spyware firms and 0-day vendors both have staff dedicating to finding 0-days. Why do Google and Apple not simply poach these staff? I am sure Google and Apple can offer very competitive salaries, so why do they not do so? Is it because the cost of basically poaching all of the skilled 0-day hunters is deemed to be greater than the cost of just issuing patches?

I am this person. I work as a researcher finding 0-days. From the employee perspective: Wages are equal. Big Tech work is less interesting (build big bug finding machines that find have high quantity of bugs) and report the bugs that sit into some bug tracker only to maybe be fixed in 3 months. Offensive security work is more interesting. It requires intimate knowledge of the systems you research, since you only need…

I mean wages might be equal (are they, though? Big tech pays a lot as you go up) on average but there’s a lot of difference in how they pay out. Big tech usually provides compensation bands where your salary is pretty stable. Vulnerability research frequently has your compensation hinge on your performance to a much larger extent.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#160

I've a question. This 0-day is a 0-click that didn't require any document download or anything. Simply visiting a http site would do it. What if you have JavaScript disabled be default. Would this exploit still work?

Needing to visit a website makes it a 1-click attack, unless you can do passive redirection.
Post reply on HN