Live data from Hacker News

NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

citizenlab.org

101–110 of 255 posts

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#101

Earlier quoted context omitted.

FTA: He had been targeted previously by FinFisher AND Hacking Team's malware. Avoiding malware is nothing new to this guy, something this NSO Group should have taken into account when they came up with their spear-phishing attack.

Sure but how is that responsive to parent's point about Mansoor being an "outlier in taking precautions" ? The reason he found out about the previous attacks was likely because he took similar precautions: "When Ahmed Mansoor opened the document, his suspicions were aroused due to garbled text displayed. His email account was later accessed from the following suspicious IPs.." https://citizenlab.org/2012/10/backdoors…

I'm not sure if you call it a "precaution" when you notice someone's pwnd you. Still good job noticing it after the fact.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#102
post #27
post #4

An untethered stealth jailbreak that installs without user interaction from a webview, that's almost as bad as it gets. And for iOS 7.0.0 - 9.3.4 inclusive. And with exfiltration of audio, video, whatsapp, viber, etc etc. So thorough and so bad :-/

> An untethered stealth jailbreak that installs without user interaction from a webview, that's almost as bad as it gets. And for iOS 7.0.0 - 9.3.4 inclusive. And with exfiltration of audio, video, whatsapp, viber, etc etc. So thorough and so bad :-/ Short of being triggered completely in the background by an UDP packet, what's worse than this?

it likely doesn't have persistence due to secure boot chain, so it could get worse.

or attacks against Secure Enclave.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#103
post #7

This is off-topic but at first I thought I was on a Spotify blog page. Lookout has very similar branding.

lol downvotes, ok hn. My initial reaction was "this is crazy Spotify found something like this", which was why I commented.

It's ok. I thought the same thing. You're not the only one.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#104
post #102
post #27

Earlier quoted context omitted.

> An untethered stealth jailbreak that installs without user interaction from a webview, that's almost as bad as it gets. And for iOS 7.0.0 - 9.3.4 inclusive. And with exfiltration of audio, video, whatsapp, viber, etc etc. So thorough and so bad :-/ Short of being triggered completely in the background by an UDP packet, what's worse than this?

it likely doesn't have persistence due to secure boot chain, so it could get worse. or attacks against Secure Enclave.

It does have reboot persistence. That's what untethered usually means.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#105
post #71

I thought it was interesting that they're using Cydia Substrate to hook into specific third-party apps for monitoring. I wonder if we'll ever see privacy conscious apps using some sort of obfuscation. So that every time you update your app, the attacker will have to reverse-engineer the symbol names again. It seems like a compile or link time tool could find method call & selector references. As long as your app isn'…

The attacker could find a way to be in the kernel, or insert a shim between the app and OS if everything was sufficiently obfuscated.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#106

This is a REALLY, REALLY good reason why "activists" of any variety should be trained in how to acquire an old Thinkpad and install Debian on it (plus a reasonably xorg/XFCE4 desktop environment). If you're dealing with authoritarian regimes you can do a lot to reduce your attack surface. However at the end it all comes down to rubber hose cryptography. If your government, for example Bahrain decides to detain and to…

He would look pretty stupid putting a Thinkpad up to his ear when he makes phone calls, though, wouldn't he?

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#107
post #14

https://citizenlab.org/2016/08/million-dollar-dissident-ipho... > Alarmingly, some of the names suggested a willingness on > the part of the operators to impersonate governments and > international organizations. For example, we found two > domain names that appear intended to masquerade as an > official site of the International Committee of the Red > Cross (ICRC): icrcworld.com and redcrossworld.com.

Be very very glad citizenlab exists in the world. They're doing good work against very strong, very well funded adversaries.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#108
post #104
post #102

Earlier quoted context omitted.

it likely doesn't have persistence due to secure boot chain, so it could get worse. or attacks against Secure Enclave.

It does have reboot persistence. That's what untethered usually means.

yeah, I'm wondering if it's re-exploit on boot or actual subversion of the OS though

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#109
post #68

Earlier quoted context omitted.

Which foreign governments though? Not all security researchers are from your country (whichever one that may be).

I had the same thought as hackuser when reading the article, and then it was quickly followed by your point. I think an important first step would be to get certain things classified as arms. Once that's done, normal options may be able to handle them appropriately, such as not allowing the purchase or sale of certain types of arms within or over borders, etc. This would of course open up a whole new can of worms in…

> we are constitutionally guaranteed the right to bear arms

It doesn't extend to all arms; e.g., you don't have a right to own anti-aircraft guns, weaponized anthrax, or even fully automatic rifles. What side of the line the exploits fall on is of course a question, but if I'm right that their only civilian use is illegal harm to others (e.g., you don't use them to protect your home or hunt deer) then it's simpler.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#110
post #78

Earlier quoted context omitted.

> * In the 1990s, strong encryption was called a 'munition' and export was restricted. That turned out to be impractical (it was available in many countries and the Internet has no borders), morally questionable (restricting private citizen's privacy), and it fell apart. IIRC, thats still on the books. Its just one of those sleeping paragraphs since the PGP release.

Debian documents mention that "BXA revised the provisions of the EAR governing cryptographic software" in October 2000. Debian no longer has separate non-us repositories for crypto because of that. https://www.debian.org/legal/cryptoinmain

Open source software is now basically exempt from the crypto export restrictions, which is why Debian doesn't need separate non-US repositories for it anymore. As far as I know closed-source software is still restricted.
Post reply on HN