Live data from Hacker News

0-days exploited by commercial surveillance vendor in Egypt

blog.google

171–180 of 254 posts

Re: 0-days exploited by commercial surveillance vendor in Egypt

#171

Earlier quoted context omitted.

The browser will notice that it's being given a cert that isn't in the CA transparency log + other hardcoded known certs for top sites and will phone home about it.

What browsers actually do that? And do all CAs support it? Besides, if you have enough access to the CA, you can just get whatever cert is in the transparency log, though that's almost certainly harder for most nations and CAs.

> you can just get whatever cert is in the transparency log

That would require compromising the certificate requester.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#172
post #4

It's good to get some more info, but it is a little disconcerting that they only mention patching Chrome. What was the sandbox escape on Android? Even if you had code execution inside the Chrome process on Android, that shouldn't be enough to enable persistence, so clearly there's another vulnerability. Also in this case the attack vector was MITM of http and one time links as it was a targeted campaign, but it feels…

> What was the sandbox escape on Android? Even if you had code execution inside the Chrome process on Android, that shouldn't be enough to enable persistence, so clearly there's another vulnerability. This is such a crucial point. Forced to read between the lines of the blog post (because the above information is missing), it sounds like there are currently unpatched issues in Android revolving around this?

Can be multiple vendor specific exploits.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#174
post #133
post #3

Just your regular reminder that for the only security certification that Apple advertises on their website for iOS [1][2] Apple only achieved the lowest possible level of security assurance, EAL1. A level only fit for products where [3]: "some confidence in the correct operation is required, but the threats to security are not viewed as serious" which does not even require "demonstrating resistance to penetration att…

Please don't post "regular reminder" style comments - they're too generic, and generic discussion is consistently less interesting. Good threads require being unpredictable. The best way to get that is to respond to specific new information in an article. https://news.ycombinator.com/newsguidelines.html

[deleted]

Re: 0-days exploited by commercial surveillance vendor in Egypt

#175

Earlier quoted context omitted.

The browser will notice that it's being given a cert that isn't in the CA transparency log + other hardcoded known certs for top sites and will phone home about it.

What browsers actually do that? And do all CAs support it? Besides, if you have enough access to the CA, you can just get whatever cert is in the transparency log, though that's almost certainly harder for most nations and CAs.

> What browsers actually do that?

Chrome, Safari, Firefox.

> And do all CAs support it?

Yes, the browsers made them.

> Besides, if you have enough access to the CA, you can just get whatever cert is in the transparency log

No, the CA doesn't have the private key of certs.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#176
post #3

Just your regular reminder that for the only security certification that Apple advertises on their website for iOS [1][2] Apple only achieved the lowest possible level of security assurance, EAL1. A level only fit for products where [3]: "some confidence in the correct operation is required, but the threats to security are not viewed as serious" which does not even require "demonstrating resistance to penetration att…

Common Criteria EALs have nothing whatsoever to do with practical security. I'd be surprised to hear anybody on this site who has managed a CCTL security review for a product saying anything positive about the program.

A fun exercise: find a list of commercial mainstream products with "high" EAL audits, and then look at their vulnerability histories.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#177
post #3

Just your regular reminder that for the only security certification that Apple advertises on their website for iOS [1][2] Apple only achieved the lowest possible level of security assurance, EAL1. A level only fit for products where [3]: "some confidence in the correct operation is required, but the threats to security are not viewed as serious" which does not even require "demonstrating resistance to penetration att…

Common Criteria EALs have nothing whatsoever to do with practical security. I'd be surprised to hear anybody on this site who has managed a CCTL security review for a product saying anything positive about the program. A fun exercise: find a list of commercial mainstream products with "high" EAL audits, and then look at their vulnerability histories.

Since it is fun can you link some of these EAL5 or higher products with sordid vulnerability histories?

Re: 0-days exploited by commercial surveillance vendor in Egypt

#178
If I were a government security regulator or intelligence agency, I would monitor bank accounts associated with Zerodium and similar 0day and payload marketplaces and offensive sec tools to issue a secret, internal threat forecast that marks the beginning potential of increasing, directed, high-value attacks. Probably already exists in various forms, but taking it semi-public to sensitive industries might be useful.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#179
post #177

Earlier quoted context omitted.

Common Criteria EALs have nothing whatsoever to do with practical security. I'd be surprised to hear anybody on this site who has managed a CCTL security review for a product saying anything positive about the program. A fun exercise: find a list of commercial mainstream products with "high" EAL audits, and then look at their vulnerability histories.

Since it is fun can you link some of these EAL5 or higher products with sordid vulnerability histories?

The archetypical EAL5 product is a smartcard or cryptographic coprocessor (same thing, different package). They're certifiable because they don't do much.

But if you'd like an example from the EAL4 list: start with FortiOS.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#180
post #168

Earlier quoted context omitted.

If you're a nation you can just force the CAs that are in your jurisdiction to do whatever you want, or sneak in in various ways so they won't know. If you use the MITM judiciously, it's very likely that nobody will notice, or that those that notice can be compelled not to say anything.

CT means a CA can’t do whatever they want. Your comment is handwavy, do you have any details on the “various ways” you’re talking about?

Physically, or by compromising employees or business owners in whatever legal or illegal means, depending on the country.

Sounds from other comments like my knowledge is out of date though, and browsers have real protections against the obvious ways that used to be possible, which is great news.

Post reply on HN