Apple needs to do a serious architecture of how its own apps work. Its clearly unacceptable that their own apps are not sandboxed to the same level as everything else. If its not possible to implement all of imessage with the public APIs then they need to find a way to expose those private APIs publicly in a safe way. imessage and facetime have been a constant source of exploits.
Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit
11–20 of 314 posts
Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit
#12Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit
#13Apple needs to do a serious architecture of how its own apps work. Its clearly unacceptable that their own apps are not sandboxed to the same level as everything else. If its not possible to implement all of imessage with the public APIs then they need to find a way to expose those private APIs publicly in a safe way. imessage and facetime have been a constant source of exploits.
Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit
#14Apple needs to do a serious architecture of how its own apps work. Its clearly unacceptable that their own apps are not sandboxed to the same level as everything else. If its not possible to implement all of imessage with the public APIs then they need to find a way to expose those private APIs publicly in a safe way. imessage and facetime have been a constant source of exploits.
I wonder if this weakens their "security" argument in the appstore walled garden case.
Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit
#15Earlier quoted context omitted.
This is a dupe but seems to go into more technical detail. There’s no mention of iMessage in The Guardian’s coverage.
It's all sensational articles though. Show me the bug they used to exploit iMessage. That'd be far more interesting that this Cold War madness we read everyday.
The initial vector appears to exploit imagent, to cause the download and install Pegasus, in most cases. This is likely because imagent runs under the root user.
[0] https://citizenlab.ca/2020/12/the-great-ipwn-journalists-hac...
Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit
#16Apple needs to do a serious architecture of how its own apps work. Its clearly unacceptable that their own apps are not sandboxed to the same level as everything else. If its not possible to implement all of imessage with the public APIs then they need to find a way to expose those private APIs publicly in a safe way. imessage and facetime have been a constant source of exploits.
Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit
#17Apple needs to do a serious architecture of how its own apps work. Its clearly unacceptable that their own apps are not sandboxed to the same level as everything else. If its not possible to implement all of imessage with the public APIs then they need to find a way to expose those private APIs publicly in a safe way. imessage and facetime have been a constant source of exploits.
Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit
#18Is anyone aware of any (FOSS) software (presumably intrusion detectors or indicators of compromise) for mobile phones that might help flag or even prevent such attacks?
TinyCheck [0] comes to mind, but it isn't truly mobile. TrackerControl [1] and Guardian Firewall [2] are perhaps the closest to something like this but concentrate on privacy more than on security.
[0] https://github.com/KasperskyLab/tinycheck
Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit
#19Apple needs to do a serious architecture of how its own apps work. Its clearly unacceptable that their own apps are not sandboxed to the same level as everything else. If its not possible to implement all of imessage with the public APIs then they need to find a way to expose those private APIs publicly in a safe way. imessage and facetime have been a constant source of exploits.
This is why no amount of "but apple cares about privacy" will ever make me drop the "Trust but verify" I try to live by (money allowing), even if I believe they care more than most.
Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit
#20Apple needs to do a serious architecture of how its own apps work. Its clearly unacceptable that their own apps are not sandboxed to the same level as everything else. If its not possible to implement all of imessage with the public APIs then they need to find a way to expose those private APIs publicly in a safe way. imessage and facetime have been a constant source of exploits.
This is why no amount of "but apple cares about privacy" will ever make me drop the "Trust but verify" I try to live by (money allowing), even if I believe they care more than most.