Live data from Hacker News

0-days exploited by commercial surveillance vendor in Egypt

blog.google

1–10 of 254 posts

Re: 0-days exploited by commercial surveillance vendor in Egypt

#3
Just your regular reminder that for the only security certification that Apple advertises on their website for iOS [1][2] Apple only achieved the lowest possible level of security assurance, EAL1. A level only fit for products where [3]: "some confidence in the correct operation is required, but the threats to security are not viewed as serious" which does not even require "demonstrating resistance to penetration attackers with a basic attack potential" [4]. This is four entire levels lower than "demonstrating resistance to penetration attackers with a moderate attack potential" [5].

Apple has never once, over multiple decades of failed attempts, demonstrated "resistance to penetration attackers with a moderate attack potential" for any of their products. To be fair, neither has Microsoft, Google, Amazon, Cisco, Crowdstrike, etc. It should be no surprise that the companies, processes, and people who lack the ability, knowledge, and experience to make systems resistant to moderate attackers despite nearly unlimited resources are regularly defeated by moderate attacks like commercial surveillance companies. They certify that they absolutely, 100% can not.

[1] https://support.apple.com/guide/certifications/ios-security-...

[2] https://support.apple.com/library/APPLE/APPLECARE_ALLGEOS/CE...

[3] https://www.commoncriteriaportal.org/files/ccfiles/CC2022PAR... Page 14

[4] https://www.commoncriteriaportal.org/files/ccfiles/CC2022PAR... Page 16

[5] https://www.commoncriteriaportal.org/files/ccfiles/CC2022PAR... Page 20

Re: 0-days exploited by commercial surveillance vendor in Egypt

#4
It's good to get some more info, but it is a little disconcerting that they only mention patching Chrome. What was the sandbox escape on Android? Even if you had code execution inside the Chrome process on Android, that shouldn't be enough to enable persistence, so clearly there's another vulnerability.

Also in this case the attack vector was MITM of http and one time links as it was a targeted campaign, but it feels there's nothing preventing someone putting this in an ad campaign or sms/discord/matrix/whatever spam and spraying it everywhere to build a botnet or steal user credentials or whatever.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#5
post #3

Just your regular reminder that for the only security certification that Apple advertises on their website for iOS [1][2] Apple only achieved the lowest possible level of security assurance, EAL1. A level only fit for products where [3]: "some confidence in the correct operation is required, but the threats to security are not viewed as serious" which does not even require "demonstrating resistance to penetration att…

[deleted]

Re: 0-days exploited by commercial surveillance vendor in Egypt

#7
Another company founded by ex-Israeli intelligence.

The funny thing about exploits is, once hundreds of employees or soldiers have access to the exploit, they don't need to physically copy the code. They just need to understand how it works, to then open 10 other companies that use the same exploit, or sell it to 20 other companies on the dark web.

Although the IDF is great at stopping people from copying files outside of their networks, it can't stop people from remembering what they did during their service

Re: 0-days exploited by commercial surveillance vendor in Egypt

#8
Slighty related, but Senator Bob Menendez was just indicted for taking bribes from people connected with the Egyptian military [0]. Gotta say, the Egyptian intelligence services are definitely punching above their weight by regional power standards.

[0] - https://www.politico.com/news/2023/09/22/egypt-guns-money-me...

Re: 0-days exploited by commercial surveillance vendor in Egypt

#9
post #4

It's good to get some more info, but it is a little disconcerting that they only mention patching Chrome. What was the sandbox escape on Android? Even if you had code execution inside the Chrome process on Android, that shouldn't be enough to enable persistence, so clearly there's another vulnerability. Also in this case the attack vector was MITM of http and one time links as it was a targeted campaign, but it feels…

Im not well versed in mobile environments. Presumedly breaking out of the Chrome sandbox would land you within the underlying OS. Can you not build persistence there without abusing further vulns?
Post reply on HN