Live data from Hacker News

NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

citizenlab.org

11–20 of 255 posts

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#11
The article mentions how this may have been use all the way back in iOS 7 which is crazy.

If you are being targeted for surveillance smartphones are a very bad idea depending on your adversary. A cheap phone that is refreshed regularly will probably be your best bet.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#12

This vulnerability sounds like this: https://www.zerodium.com/ios9.html It was claimed November of last year. I wouldn't be surprised if this "Trident" was sold by Zerodium. Glad it's patched. Edit: I just saw the Citizen Lab article on this: https://citizenlab.org/2016/08/million-dollar-dissident-ipho... They mention the Zerodium bounty as well.

Article mentions that there are indications this was in the wild as far back as iOS 7, suggesting this isn't directly linked to that Zerodium bounty.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#14
https://citizenlab.org/2016/08/million-dollar-dissident-ipho...

  > Alarmingly, some of the names suggested a willingness on
  > the part of the operators to impersonate governments and
  > international organizations. For example, we found two
  > domain names that appear intended to masquerade as an
  > official site of the International Committee of the Red
  > Cross (ICRC):  icrcworld.com and redcrossworld.com.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#15
post #3

Vice has a nice writeup on the exploits as well: https://motherboard.vice.com/read/government-hackers-iphone-...

FTA: It appears that the company that provided the spyware and the zero-day exploits to the hackers targeting Mansoor is a little-known Israeli surveillance vendor called NSO, which Lookout’s vice president of research Mike Murray labeled as “basically a cyber arms dealer.” Phineas Fisher, we need you now.

So we have cyber arms dealers now. I continue to be amazed at the prophecies of William Gibson. Makes me wonder if there's anything to "remote viewing." Did he just look forward into the 21st century and write down what he saw? :)

BRB, gonna go slot me an icebreaker...

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#16
post #12

This vulnerability sounds like this: https://www.zerodium.com/ios9.html It was claimed November of last year. I wouldn't be surprised if this "Trident" was sold by Zerodium. Glad it's patched. Edit: I just saw the Citizen Lab article on this: https://citizenlab.org/2016/08/million-dollar-dissident-ipho... They mention the Zerodium bounty as well.

Article mentions that there are indications this was in the wild as far back as iOS 7, suggesting this isn't directly linked to that Zerodium bounty.

You're right, missed that. Still possible the Zerodium exploit uses the same vulnerabilities.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#17
post #4

An untethered stealth jailbreak that installs without user interaction from a webview, that's almost as bad as it gets. And for iOS 7.0.0 - 9.3.4 inclusive. And with exfiltration of audio, video, whatsapp, viber, etc etc. So thorough and so bad :-/

I wonder if you can hit this via 4G/LTE networks? I also wonder if it works over VPNs? Or is hardware L2 adjacency (WiFi) required?

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#18
post #14

https://citizenlab.org/2016/08/million-dollar-dissident-ipho... > Alarmingly, some of the names suggested a willingness on > the part of the operators to impersonate governments and > international organizations. For example, we found two > domain names that appear intended to masquerade as an > official site of the International Committee of the Red > Cross (ICRC): icrcworld.com and redcrossworld.com.

This is a much more informative source. Moderators may want to merge everything into this story: https://news.ycombinator.com/item?id=12360714

Edit: that story is now flagged as dupe, can we at least get the URL changed to this much more in-depth article? https://citizenlab.org/2016/08/million-dollar-dissident-ipho...

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#19
post #11

The article mentions how this may have been use all the way back in iOS 7 which is crazy. If you are being targeted for surveillance smartphones are a very bad idea depending on your adversary. A cheap phone that is refreshed regularly will probably be your best bet.

I'm not sure how much I believe in any counter-surveillance methods anymore that involve a phone. Then again, I'm happy that my life doesn't include the need for that level of secrecy.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#20
post #17
post #4

An untethered stealth jailbreak that installs without user interaction from a webview, that's almost as bad as it gets. And for iOS 7.0.0 - 9.3.4 inclusive. And with exfiltration of audio, video, whatsapp, viber, etc etc. So thorough and so bad :-/

I wonder if you can hit this via 4G/LTE networks? I also wonder if it works over VPNs? Or is hardware L2 adjacency (WiFi) required?

It would affect anything capable of rendering html.
Post reply on HN