Live data from Hacker News

0-days exploited by commercial surveillance vendor in Egypt

blog.google

191–200 of 254 posts

Re: 0-days exploited by commercial surveillance vendor in Egypt

#191

Earlier quoted context omitted.

What browsers actually do that? And do all CAs support it? Besides, if you have enough access to the CA, you can just get whatever cert is in the transparency log, though that's almost certainly harder for most nations and CAs.

> you can just get whatever cert is in the transparency log That would require compromising the certificate requester .

A lot of certificate management services for enterprise customers "helpfully" store the private key files. How many cloud or SaaS vendors automatically handle the private keys as well instead of them being generated and staying securely only on the systems using them? So there are still points of centralization to attack, potentially.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#192

Earlier quoted context omitted.

> you can just get whatever cert is in the transparency log That would require compromising the certificate requester .

A lot of certificate management services for enterprise customers "helpfully" store the private key files. How many cloud or SaaS vendors automatically handle the private keys as well instead of them being generated and staying securely only on the systems using them? So there are still points of centralization to attack, potentially.

Yes, state actors have been known to steal things like codesigning keys. Microsoft had that happen recently where someone with persistence on a dev machine sniffed them out of crash logs(!).

But it requires a lot more steps.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#193
post #10

Though HTTPS is better than nothing, and this attack relies on HTTP to inject the initial payload, state sponsored attackers in some countries can likely just subvert CA or CDN infrastructure instead.

Note that it only took/takes one http visit (to any site) to compromise the device.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#194

Earlier quoted context omitted.

Only if you pay $$$$ for OV/EV. If you get the normal DV cert they don't provide any more verification than Letsencrypt. And since browsers have moved away from indicating OV/EV certs to end users, not many organizations are paying for those anymore.

Can confirm as someone who has to renew a non-Let’s Encrypt cert every year (for reasons). The CA sends an automated email to the email address listed in WHOIS, you click a link in the email, and they issue the certificate. No human interaction necessary.

EV certs have a slightly more rigorous approach. They’ll call the registered agent for the business as registered/licensed with the state, not the phone number from whois or an email to webmaster@

Re: 0-days exploited by commercial surveillance vendor in Egypt

#195
post #187

Earlier quoted context omitted.

The archetypical EAL5 product is a smartcard or cryptographic coprocessor (same thing, different package). They're certifiable because they don't do much. But if you'd like an example from the EAL4 list: start with FortiOS.

EAL4 and under is junk (with respect to security). I already said that. The standards committee has also always maintained that there is no meaningful security at EAL4. Earlier drafts of the standards said EAL4 is only meant to protect against “casual and inadvertent attacks”. The general crappiness of EAL4 goes all the way back to the Orange Book where EAL4 maps approximately to Level C2 (contemporaneous projects go…

If you're saying "EAL4 and below is junk" (I'd say EAL* is junk, but whatever), all you're really saying is that minimal-function cryptographic coprocessors are safer than operating systems and applications. Well, yeah, sure. I don't think you needed the farce of Common Criteria to tell you that, though.

But upthread, you knocked Apple for not achieving an adequate assurance level. As you can see now, and from your own last comment, that doesn't make any sense. It's possible (though deeply silly) that there's some iPhone configuration that could "achieve" EAL4, but you yourself don't believe that has any meaning. I don't either.

I don't think EAL5 or EAL6 do, either, except that if you tell me your product is EAL5, I'll assume it's a small fixed-function device.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#196
post #16

Earlier quoted context omitted.

Or get someone to click on a spoofed domain, certified by our beloved LetsEncrypt! Apparently al that is needed is an HTTP 302/307 redirect response (or html redirect payload, maybe even DNS?) pointing the client toward c.betly[.]me

Coincidentally, the ACME DNS verification process that LetsEncrypt uses is vulnerable to the QUANTUM attack. If NSA injects a fake DNS response in the right spot, and have the their response arrive before the official response, they can get the domain verified. OTOH, Certificate Transparency Logs will give the game away, so there's that.

Doesn't Let's Encrypt check the DNS record from multiple widely-distributed endpoints to avoid this attack?

Re: 0-days exploited by commercial surveillance vendor in Egypt

#197

If I were a government security regulator or intelligence agency, I would monitor bank accounts associated with Zerodium and similar 0day and payload marketplaces and offensive sec tools to issue a secret, internal threat forecast that marks the beginning potential of increasing, directed, high-value attacks. Probably already exists in various forms, but taking it semi-public to sensitive industries might be useful.

This is basically “can the government prosecute money laundering and tax evasion”.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#198

Earlier quoted context omitted.

> Why do Google and Apple not simply poach these staff They do. Plenty of white hat teams hire 8200 vets, but sometimes they'd rather make their own company instead of being a cog within an amaphorous foreign corporation.

This. IIRC some famous security researcher responsible for iOS jail-breaks was poached by Apple only to leave after 3 months. Successful and skilled security people with a proven track record, don't have the paciente of putting up with the charade such large orgs require.

Plenty of jailbreak developers have been poached by Apple. Whether they're still at their A-game still is questionable, I follow one on Twitter and there's regular tweets about depression, suicide, debt and other gloomy topics.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#199
post #187

Earlier quoted context omitted.

EAL4 and under is junk (with respect to security). I already said that. The standards committee has also always maintained that there is no meaningful security at EAL4. Earlier drafts of the standards said EAL4 is only meant to protect against “casual and inadvertent attacks”. The general crappiness of EAL4 goes all the way back to the Orange Book where EAL4 maps approximately to Level C2 (contemporaneous projects go…

If you're saying "EAL4 and below is junk" (I'd say EAL* is junk, but whatever), all you're really saying is that minimal-function cryptographic coprocessors are safer than operating systems and applications. Well, yeah, sure. I don't think you needed the farce of Common Criteria to tell you that, though. But upthread, you knocked Apple for not achieving an adequate assurance level. As you can see now, and from your o…

No. The Separation Kernel Protection Profile (SKPP) defines a model for a operating system kernel at EAL6+. So all I am really saying is that safe operating systems are safer than non-safe operating systems. You could also look backwards to the TCSEC and the comparable certified Level A1 systems for other operating systems designed for actual high security work.

You keep calling it a farce, but you keep pointing at EAL4 and lower systems. Yes, those levels are farces, that was the whole point. Those are the levels for the certification of toys where documentation and paperwork is all that is needed, not proper design.

Complaining about the Common Criteria in the context of EAL4 and lower systems is like complaining about tissue paper manufacturers putting their tissue paper through bulletproof vest testing and certifying that it does not stop bullets. Yes, that is pretty stupid, farcical, and probably a waste of time. But no, the test is not stupid. It can test actual bulletproof vests, you just keep seeing stupid waste of time tests proving a useless fact that everybody already knows, the EAL4 quality system sucks and has no place in a serious security organization.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#200

Here is what I do not understand: Spyware firms and 0-day vendors both have staff dedicating to finding 0-days. Why do Google and Apple not simply poach these staff? I am sure Google and Apple can offer very competitive salaries, so why do they not do so? Is it because the cost of basically poaching all of the skilled 0-day hunters is deemed to be greater than the cost of just issuing patches?

Why would you need to poach all of them, just enough to find bugs faster

Though poaching all is simply impossible, by raising prices you'll incentivize more people to become vulnerability researches, so more will always be available to the spyware firms

Post reply on HN