Live data from Hacker News

NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

citizenlab.org

121–130 of 255 posts

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#121

Earlier quoted context omitted.

Or this, from the detailed writeup linked elsewhere on this page: > To use NSO Group’s zero-click vector, an operator instead sends the same link via a special type of SMS message, like a WAP Push Service Loading (SL) message. A WAP Push SL message causes a phone to automatically open a link in a web browser instance, eliminating the need for a user to click on the link to become infected. It goes on to say that mess…

I wonder if it can be triggered from the webview it automatically pops up when a captive wifi portal is accessed. Needs proximity to the user, but still straightforward.

If the attacker controls the wifi, he doesn't need to put it in the captive portal page; he can intercept any non-secure http page and put his exploit there.

You really shouldn't connect to untrusted networks at all if you want to be safe from this kind of attack.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#122
post #71

I thought it was interesting that they're using Cydia Substrate to hook into specific third-party apps for monitoring. I wonder if we'll ever see privacy conscious apps using some sort of obfuscation. So that every time you update your app, the attacker will have to reverse-engineer the symbol names again. It seems like a compile or link time tool could find method call & selector references. As long as your app isn'…

The trouble is that nearly every app does "something tricky" because it's so baked into Apple's frameworks. Every UI control calls methods using strings when you interact with it. Key-value coding and observing works extract method names from strings. Core Data uses method names to look stuff up in the underlying storage. And these things are so easy to do that it's pretty common for third-party code to do similar stuff. Reliably figuring out which methods were safe to change would be really tough.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#123
post #63

Earlier quoted context omitted.

No, exploits are more widely used in industry (for testing and red-teaming) than they are by governments, simply because there are more red teams than there are government-sponsored intelligence and police agencies. It's hard to imagine a scheme under which exploits could be regulated in the US that wouldn't set precedents for whether code was protected speech. I think very few people on HN would be comfortable with…

EDIT: As kbenson points out below, it's not just red teams but people wanting to tinker with their own equipment: Get data out of a proprietary app, install a 3rd party OS, unlock their phone, etc. That seems like a very difficult problem. > It's hard to imagine a scheme under which exploits could be regulated in the US that wouldn't set precedents for whether code was protected speech Yeah, I was thinking about that…

I'm not saying it's impossible to generate an intellectually coherent set of regulations for exploits, just that the process of doing so is going to damage the 1A protections of a lot of other things over the long run.

Is it worth it? I don't think so. Unless you also regulate research, which is a non-starter, you're just driving exploit development out of the US. Substantial amounts of exploit dev are already done by foreign nationals. If virtually all of it leaves the country, what public policy problem have you solved?

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#124

I have an iPad 1 which long ago was left behind by upgrades. It'd be nice to know when the vulnerabilities were introduced too. Should I stop doing anything networked with it?

I would definitely not trust it, at the very least. Even if this particular vulnerability didn't exist for it, there are bound to be many others that did.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#125
post #14

https://citizenlab.org/2016/08/million-dollar-dissident-ipho... > Alarmingly, some of the names suggested a willingness on > the part of the operators to impersonate governments and > international organizations. For example, we found two > domain names that appear intended to masquerade as an > official site of the International Committee of the Red > Cross (ICRC): icrcworld.com and redcrossworld.com.

Money quote for me from that link:

    That the companies whose spyware was used to 
    target Mansoor are all owned and operated from 
    democracies speaks volumes about the lack of 
    accountability and effective regulation in the 
    cross-border commercial spyware trade.
    
    While these spyware tools are developed in 
    democracies, they continue to be sold to 
    countries with notorious records of abusive
    targeting of human rights defenders. Such 
    sales occur despite the existence of 
    applicable export controls.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#126
post #84
post #60

Earlier quoted context omitted.

This is the problem with surveillance technologies: they frequently end up being used not just against enemies, but anyone who disagrees with the government or threatens the status quo. Sadly, this happens even in democratic "free" countries.

> not just against enemies, but anyone who disagrees with the government or threatens the status quo. Those are enemies of the state. What you consider enemies are not who everybody regards as enemies. That is why there is no such thing as allowing 'good guys' using these tools for good and preventing 'bad guys' using them for bad.

[deleted]

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#127

Earlier quoted context omitted.

EDIT: As kbenson points out below, it's not just red teams but people wanting to tinker with their own equipment: Get data out of a proprietary app, install a 3rd party OS, unlock their phone, etc. That seems like a very difficult problem. > It's hard to imagine a scheme under which exploits could be regulated in the US that wouldn't set precedents for whether code was protected speech Yeah, I was thinking about that…

I'm not saying it's impossible to generate an intellectually coherent set of regulations for exploits, just that the process of doing so is going to damage the 1A protections of a lot of other things over the long run. Is it worth it? I don't think so. Unless you also regulate research , which is a non-starter, you're just driving exploit development out of the US. Substantial amounts of exploit dev are already done…

> If virtually all of it leaves the country, what public policy problem have you solved?

A good point. A couple ideas, though neither is sufficient:

* International agreements control distribution of other dangerous goods; that's doable. However, look at how well that works with drugs, and even nukes get around.

* At least stop sophisticated organizations (defense contractors, SV firms, etc.) from making them for foreign governments. Their skills are harder, though not impossible, to replace. Perhaps ban the sale of exploits - taking away the profit motive - but permit distribution for personal, research, etc. purposes.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#128
Aside, but does anybody else find the switch from right-to-left to left-to-right really jarring in this screenshot?

https://citizenlab.org/wp-content/uploads/2016/08/image13-76...

It has the effect of introducing a line-break into the middle of a line, rather than at either end. I've never encountered this before and it took my brain a few seconds to catch on.

I'd be really curious how native bilingual readers of both a right-to-left and left-to-right language would read that. Does it look natural? Where do your eyes go first?

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#129
post #14

https://citizenlab.org/2016/08/million-dollar-dissident-ipho... > Alarmingly, some of the names suggested a willingness on > the part of the operators to impersonate governments and > international organizations. For example, we found two > domain names that appear intended to masquerade as an > official site of the International Committee of the Red > Cross (ICRC): icrcworld.com and redcrossworld.com.

Ok, since most people seem to agree that that URL is the best source, we've changed to it from https://blog.lookout.com/blog/2016/08/25/trident-pegasus/. Thanks.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#130
post #18
post #14

https://citizenlab.org/2016/08/million-dollar-dissident-ipho... > Alarmingly, some of the names suggested a willingness on > the part of the operators to impersonate governments and > international organizations. For example, we found two > domain names that appear intended to masquerade as an > official site of the International Committee of the Red > Cross (ICRC): icrcworld.com and redcrossworld.com.

This is a much more informative source. Moderators may want to merge everything into this story: https://news.ycombinator.com/item?id=12360714 Edit: that story is now flagged as dupe, can we at least get the URL changed to this much more in-depth article? https://citizenlab.org/2016/08/million-dollar-dissident-ipho...

Yes. Done.
Post reply on HN