Live data from Hacker News

NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

citizenlab.org

111–120 of 255 posts

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#111
post #108
post #104

Earlier quoted context omitted.

It does have reboot persistence. That's what untethered usually means.

yeah, I'm wondering if it's re-exploit on boot or actual subversion of the OS though

What's the difference? :)

It's explained in detail here: https://info.lookout.com/rs/051-ESQ-475/images/lookout-pegas...

Apparently it overwrites a system binary that's launched on boot with another apple-signed binary "jsc" (a console javascript interpreter), which will evaluate some sort of .js that re-exploits everything. Pretty clever to re-use apple-signed binaries for nefarious purposes. (The binary must be apple-signed because when booting the kernel isn't exploited yet and so it enforces code signing, obviously).

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#112
post #10

Does anyone know if the iOS 10 developer beta 7 (public beta 6) got this patch, or are we vulnerable?

According to Ars the bugs have already been fixed in iOS10: http://arstechnica.com/apple/2016/08/apple-releases-ios-9-3-...

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#113
post #10

Does anyone know if the iOS 10 developer beta 7 (public beta 6) got this patch, or are we vulnerable?

Apple told Ars:

"Apple also tells us that these bugs were fixed in the latest versions of the iOS 10 public and developer betas, which were released last week."

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#114
post #68

Earlier quoted context omitted.

I had the same thought as hackuser when reading the article, and then it was quickly followed by your point. I think an important first step would be to get certain things classified as arms. Once that's done, normal options may be able to handle them appropriately, such as not allowing the purchase or sale of certain types of arms within or over borders, etc. This would of course open up a whole new can of worms in…

> we are constitutionally guaranteed the right to bear arms It doesn't extend to all arms; e.g., you don't have a right to own anti-aircraft guns, weaponized anthrax, or even fully automatic rifles. What side of the line the exploits fall on is of course a question, but if I'm right that their only civilian use is illegal harm to others (e.g., you don't use them to protect your home or hunt deer) then it's simpler.

Yes, and that's what I meant about making it hard, not impossible. That said, there are uses of exploits which can be said are for the purpose of protecting property. I might conceivably want to use an Android or iOS exploit to liberate some of my data from my phone if some apps are less forthcoming with that data than I would like.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#115
post #63

Should exploits like this be treated as munitions, with sale to foreign governments restricted? Or any sale at all restricted? Some thoughts: * The only uses for the exploits are either illegal or by government security organizations * I don't think you can just make an explosive and sell it to a foreign government; I think there are strict export controls (though I know very few details, I only read about companies…

No, exploits are more widely used in industry (for testing and red-teaming) than they are by governments, simply because there are more red teams than there are government-sponsored intelligence and police agencies. It's hard to imagine a scheme under which exploits could be regulated in the US that wouldn't set precedents for whether code was protected speech. I think very few people on HN would be comfortable with…

EDIT: As kbenson points out below, it's not just red teams but people wanting to tinker with their own equipment: Get data out of a proprietary app, install a 3rd party OS, unlock their phone, etc. That seems like a very difficult problem.

> It's hard to imagine a scheme under which exploits could be regulated in the US that wouldn't set precedents for whether code was protected speech

Yeah, I was thinking about that too ... and fully support freedom-to-tinker, etc. ...

First, no right is absolute. We can't slander people despite free speech rights, or commit human sacrifice despite freedom of religion, or own a fully automatic machine gun despite a right to bear arms (in the U.S.).

We'd want to create exceptions for research, etc (see below) but I don't think the line is prohibitively hard to draw. The big problem I see is open source security bug reporting: There should be a way to openly notify the vendor and public without releasing the exploit into the wild, but it is a little tricky.

> exploits are more widely used in industry (for testing and red-teaming) than they are by governments

Good point, but I don't think that's a big challenge. Exceptions could be made as they are for other 'munitions' and other illegal products (e.g., drugs used for research).

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#116
post #82

This is a REALLY, REALLY good reason why "activists" of any variety should be trained in how to acquire an old Thinkpad and install Debian on it (plus a reasonably xorg/XFCE4 desktop environment). If you're dealing with authoritarian regimes you can do a lot to reduce your attack surface. However at the end it all comes down to rubber hose cryptography. If your government, for example Bahrain decides to detain and to…

Debian? If it's anyone that's even 1/10 as targeted as Mansoor was, then they shouldn't use anything less than Qubes, Subgraph, or TAILS.

you realize TAILS is just debian with TOR, and non persistent storage?

I'm sure you can find a way to spear phish somebody and send them a Linux ELF binary that they will then execute, but accomplishing that is considerably harder than on Windows/OSX/Android/iOS.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#117

Earlier quoted context omitted.

Or this, from the detailed writeup linked elsewhere on this page: > To use NSO Group’s zero-click vector, an operator instead sends the same link via a special type of SMS message, like a WAP Push Service Loading (SL) message. A WAP Push SL message causes a phone to automatically open a link in a web browser instance, eliminating the need for a user to click on the link to become infected. It goes on to say that mess…

I wonder if it can be triggered from the webview it automatically pops up when a captive wifi portal is accessed. Needs proximity to the user, but still straightforward.

Likely. Then again, good opsec would imply that you don't join untrusted networks, period.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#118

The UAE really hates on activists, and appears to be hiring a bunch of people specifically to suppress activists/dissidents within the country. [1] Unfortunately, due to the amount of wealth the country has, it won't stop almost anybody from dealing with them unless Western sanctions are placed on the country, which are unlikely given the current geopolitical situation. https://www.evilsocket.net/2016/07/27/How-The-U…

It's just sealing their fate somewhere down the line really, in a part of the world where people have famously good memories for wrongs committed against them. Like the Saudi's, they're fine while the world desperately needs them, and the day after they don't, they'll all be dead.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#119

Earlier quoted context omitted.

> we are constitutionally guaranteed the right to bear arms It doesn't extend to all arms; e.g., you don't have a right to own anti-aircraft guns, weaponized anthrax, or even fully automatic rifles. What side of the line the exploits fall on is of course a question, but if I'm right that their only civilian use is illegal harm to others (e.g., you don't use them to protect your home or hunt deer) then it's simpler.

Yes, and that's what I meant about making it hard, not impossible. That said, there are uses of exploits which can be said are for the purpose of protecting property. I might conceivably want to use an Android or iOS exploit to liberate some of my data from my phone if some apps are less forthcoming with that data than I would like.

> I might conceivably want to use an Android or iOS exploit to liberate some of my data from my phone if some apps are less forthcoming with that data than I would like.

A great point that I should have thought of. I wish I could edit my original post and add that consideration.

I can draw a conceptual line: Ban using exploits on other people's equipment. But practically, I don't see how to stop that without criminalizing distribution, in which case I can't get my data from my phone (or install a 3rd party OS) without the vendor's permission.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#120
post #48

Earlier quoted context omitted.

As consumers we don't face very good choices right now. When you buy an iPhone, you don't own it. You are a sharecropper on Apple's OS license. If you buy an Android with an unlockable bootloader, you own it. But if attacked, the adversary owns the device. It's a shitty situation but it's hard not to recommend iOS to most users.

My Android has an unlockable bootloader but you need to actually request the key from the manufacturer. Malware can't unlock it against my will without a jailbreak. Seems like a decent arrangement to me- safe by default, but if I want to root my phone I can.

> Malware can't unlock it against my will without a jailbreak.

By jailbreak, you really mean "vulnerability" and unfortunately those are quite common in the Android hardware/software/bootloader realms.

Post reply on HN