Live data from Hacker News

NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

citizenlab.org

131–140 of 255 posts

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#131

Amazing work by Lookout and Citizen Lab. Until this point I was not aware that Lookout provided any value-add for mobile devices. I was under the impression it was the McAfee of mobile. It sounds mean but this is the first reference to actual vulnerability discovery done by themselves on their blog, which usually reports on security updates that Google's Android security team discovered. Previous entries include such…

> Amazing work by Lookout and Citizen Lab.

Hopefully Apple "made it rain" on these guys (with cash).

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#132

Amazing work by Lookout and Citizen Lab. Until this point I was not aware that Lookout provided any value-add for mobile devices. I was under the impression it was the McAfee of mobile. It sounds mean but this is the first reference to actual vulnerability discovery done by themselves on their blog, which usually reports on security updates that Google's Android security team discovered. Previous entries include such…

When I wrote the above comment, this thread was linked to the Lookout blog page, not the more appropriate citizenlab page.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#133

Earlier quoted context omitted.

I don't get the point you're trying to make here. We've lost control because there's a serious vulnerability? We've lost control because Apple can patch the OS?

Well its sort of a general thing. We can't even control what runs on our devices and they run so fast you might not even notice something new running. Also stopping hacker from getting in remotely is hard for 24/7 connected devices. Even on desktop machines (Linux or Mac for me), there are processes running that I don't really know what they are doing. The OS is actually very complex and you could insert another proc…

> Even on desktop machines (Linux or Mac for me), there are processes running that I don't really know what they are doing.

That's been the case pretty much since Windows 2000 (or even 98).

> In the past when everything wasn't connected together and the connections were slower this wasn't as much of an issue

Viruses were really bad even when everything was pretty much airgapped. They were not vectors for state-level attacks only because of cultural elements (you weren't walking with an exploitable beacon in your pocket; there was little value in exploiting what were basically glorified typewriters; and established interests weren't taking this sort of thing particularly seriously outside of the US).

> Maybe safer languages will lead to less hackable code.

JavaScript is fairly safe: it runs in a VM, right? Guess what was used to persist this exploit across reboots...

I don't think this is something that we can "fix" at all. Door locks are ridiculously ineffective and exploitable, but very few people feel the need to use anything different. Similarly, computing devices will always be exploitable one way or the other, but people will keep using them; what we can do is to limit the surface attack as much as possible, and to avoid placing everything online (hello, IoT!) just for the hell of it.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#134
post #4

An untethered stealth jailbreak that installs without user interaction from a webview, that's almost as bad as it gets. And for iOS 7.0.0 - 9.3.4 inclusive. And with exfiltration of audio, video, whatsapp, viber, etc etc. So thorough and so bad :-/

Would something like proofpoint help?

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#135
post #87

Earlier quoted context omitted.

Would it then be illegal for Google Project Zero to publish a blog post about a vulnerability that a vendor refuses to fix?

I was thinking less of the knowledge being considered an armament, and more that an actual program that takes advantage of it being one. I don't consider the the scientific knowledge required to create a gun as an armament, nor even specific schematics, but governments may view it differently (indeed, they weren't happy about the 3D printable gun). Also, I don't think this concept is limited specifically to exploitin…

Separating code from knowledge was part of the fun of the decss debacle. "That's not a haiku; that's an illegal perl script!"

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#137

The story is great but I really doubt this. I'm wondering what made him suspect the link? Does he send all the links he receives to Citizen Lab?

Yes, who doesn't click on random links received from unknown numbers over (get this) SMS?

Some people.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#138
post #32

Earlier quoted context omitted.

Chaining this with some form of SMS/MMS bug (a la Stagefright) would make this unbelievably powerful. That's essentially the worst case scenario I can imagine for mobile security.

Or this, from the detailed writeup linked elsewhere on this page: > To use NSO Group’s zero-click vector, an operator instead sends the same link via a special type of SMS message, like a WAP Push Service Loading (SL) message. A WAP Push SL message causes a phone to automatically open a link in a web browser instance, eliminating the need for a user to click on the link to become infected. It goes on to say that mess…

Uh... I can send those WAP push SL messages from my rooted android with an app that costed like 5USD.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#139
post #29

The UAE really hates on activists, and appears to be hiring a bunch of people specifically to suppress activists/dissidents within the country. [1] Unfortunately, due to the amount of wealth the country has, it won't stop almost anybody from dealing with them unless Western sanctions are placed on the country, which are unlikely given the current geopolitical situation. https://www.evilsocket.net/2016/07/27/How-The-U…

Don't forget the time they pushed an "update" for blackberries: http://news.bbc.co.uk/2/hi/8161190.stm

Don't forget that Etisalat is now the majority shareholder and pretty much runs PTCL, the incumbent/largest telephone and telecom company in Pakistan, either... PTCL is to Pakistan as Verizon, Frontier or Centurylink are to various regions of the US. It's the ILEC.

Etisalat is not your friend. Etisalat has great marketing and is building GSM-based (LTE, etc) networks in many developing nations but it is no friend of an open internet or democratic institutions.

Etisalat is the reason why in some places in the world if you try to run a VoIP to Phone system gateway, armed men with carbines will show up and ransack your offices and home. They will use their influence with whatever local government exists to "deal with" threats to their revenue and/or tax base. This has happened in Pakistan and the UAE.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#140
post #130
post #18

Earlier quoted context omitted.

This is a much more informative source. Moderators may want to merge everything into this story: https://news.ycombinator.com/item?id=12360714 Edit: that story is now flagged as dupe, can we at least get the URL changed to this much more in-depth article? https://citizenlab.org/2016/08/million-dollar-dissident-ipho...

Yes. Done.

Thanks!
Post reply on HN