Live data from Hacker News

NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

citizenlab.org

141–150 of 255 posts

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#141

Earlier quoted context omitted.

I'm not saying it's impossible to generate an intellectually coherent set of regulations for exploits, just that the process of doing so is going to damage the 1A protections of a lot of other things over the long run. Is it worth it? I don't think so. Unless you also regulate research , which is a non-starter, you're just driving exploit development out of the US. Substantial amounts of exploit dev are already done…

> If virtually all of it leaves the country, what public policy problem have you solved? A good point. A couple ideas, though neither is sufficient: * International agreements control distribution of other dangerous goods; that's doable. However, look at how well that works with drugs, and even nukes get around. * At least stop sophisticated organizations (defense contractors, SV firms, etc.) from making them for for…

I don't think you fully follow. The skills can't be regulated: they're pure research. The US research community will continuing doing the fundamental enabling work relied on by exploit developers; it's just the people who do the testing and integration work who'll have to have their paychecks sent to Southeast Asia.

It's a very difficult problem.

There's also some bigtime cognitive availability bias happening here. We read lurid stories centering on "zero-day exploits" and say "something must be done". But no matter what these articles say, it seems cosmically unlikely that an exploit dealer is worth a billion dollars; the entire exploit trade is a rounding error compared to the switching and filtering equipment companies knowingly sell China and Iran for use in putting dissidents to death.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#142
post #42

NSO sells tools that when used violate the CFAA act. It is an Israeli company but a majority share was bought by a San Francisco based VC [0]. It doesn't seem like it should be legally allowed to exist as an American owned company. Maybe Ahmed Mansoor could sue the VC in American courts. [0] http://jewishbusinessnews.com/2014/03/19/francisco-partners-...

a) Selling tools itself doesn't violate the CFAA act. A separate entity uses the tools and assumes that liability, which as we see is mitigated by sovereign immunity.

b) And even if selling tools began to violate CFAA, then NSO itself would be sued. As it is a separate entity than the investors, which is the whole point of limited liability....

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#143
post #15

Earlier quoted context omitted.

So we have cyber arms dealers now. I continue to be amazed at the prophecies of William Gibson. Makes me wonder if there's anything to "remote viewing." Did he just look forward into the 21st century and write down what he saw? :) BRB, gonna go slot me an icebreaker...

I think Gibson's explanation is that the future is here, it's just not evenly distributed yet. Others like Doctorow and Stross has voiced similar views. In Stross' case, he apparently shelved the third part of a trilogy because the NSA was outpacing him.

Yep, apparently he did:

http://www.antipope.org/charlie/blog-static/2013/12/psa-why-...

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#144
post #82

Earlier quoted context omitted.

Debian? If it's anyone that's even 1/10 as targeted as Mansoor was, then they shouldn't use anything less than Qubes, Subgraph, or TAILS.

you realize TAILS is just debian with TOR, and non persistent storage? I'm sure you can find a way to spear phish somebody and send them a Linux ELF binary that they will then execute, but accomplishing that is considerably harder than on Windows/OSX/Android/iOS.

> I'm sure you can find a way to spear phish somebody and send them a Linux ELF binary that they will then execute, but accomplishing that is considerably harder than on Windows/OSX/Android/iOS.

I'm afraid people are just as foolable and code just as executable on Debian as on any other platform. Additionally, vulnerabilities on Android are likely exploitable on Debian.

You will not survive an attack from a state adversary because you used Qubes, or OpenBSD, and certainly not TAILS (which is not particularly secure, just well integrated with Tor). You will survive because you are familiar with your tools of choice and you know how to secure them.

As a final note, if you're being targeted by a nation state, getting an pre-owned ThinkPad will probably result in getting a pre-0wn3d ThinkPad.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#145
post #63

Earlier quoted context omitted.

No, exploits are more widely used in industry (for testing and red-teaming) than they are by governments, simply because there are more red teams than there are government-sponsored intelligence and police agencies. It's hard to imagine a scheme under which exploits could be regulated in the US that wouldn't set precedents for whether code was protected speech. I think very few people on HN would be comfortable with…

EDIT: As kbenson points out below, it's not just red teams but people wanting to tinker with their own equipment: Get data out of a proprietary app, install a 3rd party OS, unlock their phone, etc. That seems like a very difficult problem. > It's hard to imagine a scheme under which exploits could be regulated in the US that wouldn't set precedents for whether code was protected speech Yeah, I was thinking about that…

Under that logic tape recorders should be regulated because they could be sold to people who would record your conversations illegally, then used to create a fake conversation using your own words in order to achieve some illegal end. Treating spyware as a munition is a dangerously slippery slope.

And slander is not a criminal offense but a civil one -- one has to prove actual damages to win a slander suit (at least in the US.) So spyware could fall under the slander concept where the victims could sure based on actual damages incurred.

So one would need to prove that a piece of spyware caused them actual damages. Then you get into some other interesting unintended consequences: could a browser extension or even a cookie be construed as being spyware? They kind of are -- except (generally) you consent to those things. However were would the line be drawn? Could a company like Mixpanel find themselves inadvertently having their product being considered a munition?

I take to to a slightly absurd extreme to illustrate how good intentions can have ridiculous consequences. Governments don't have the best track record when it comes to anticipating unintended consequences.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#146
post #46

Will 9.3.5 disable/remove the spyware on infected phones? Or does it just prevent one from becoming infected?

From the article: "The kit appears to persist even when the device software is updated and can update itself to easily replace exploits if they become obsolete."

And, even if your phone is updating it may be doing a fake update and then show you that you did update to whatever version Apple says is "safe" for this exploit but in fact Pegasus was in control the entire time. Get a new phone ASAP.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#147
post #45

There is a frustration, as a user, that as the value of the iOS exploits increase, they become more and more 'underground'. The time between OS release and public jailbreak is continually growing - and it doesn't seem to only be due to the hardening of the OS. People are selling their exploits rather than releasing them publicly. And the further underground they go, the more likely they will be utilized for nefarious…

You say Apple's security isn't sufficient. It certainly appears that as time goes on Apple's security is pretty sufficient for most users. We're talking about exploits worth 1+ million dollars being used in a targeted attack against a single individual (or, more likely, a relatively small number of targeted individuals over time). This isn't something that the overwhelming majority of users need to be concerned about. Obviously it would be great if Apple's security was so good that not even nation states could get past it, but that's an incredibly high bar.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#148
post #12

Earlier quoted context omitted.

Article mentions that there are indications this was in the wild as far back as iOS 7, suggesting this isn't directly linked to that Zerodium bounty.

The Article mentions that the exploit has kernel mappings going as far as iOS7. This doesn't mean this predates the bounty at all, the bug that received the bounty payout for all we know might have been simply functional on iOS 7-9 or even earlier (and who ever made the final commercial product just didn't bother). iOS7/8 is most likely still used since older iPhones stop receiving updates at some point and older iPh…

Older iPhones become the "kids" phone when daddy buys the new one. There are more of them out there then you think.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#149
I'm a beginner when it comes to software development (mostly web development), but it seems to me that the majority of complex exploits like this involve some type of memory overflow and subsequent code execution.

Shouldn't there be methods for detecting these kinds of things in source code or more priority given to preventing it in the C/low-level community?

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#150

Earlier quoted context omitted.

you realize TAILS is just debian with TOR, and non persistent storage? I'm sure you can find a way to spear phish somebody and send them a Linux ELF binary that they will then execute, but accomplishing that is considerably harder than on Windows/OSX/Android/iOS.

> I'm sure you can find a way to spear phish somebody and send them a Linux ELF binary that they will then execute, but accomplishing that is considerably harder than on Windows/OSX/Android/iOS. I'm afraid people are just as foolable and code just as executable on Debian as on any other platform. Additionally, vulnerabilities on Android are likely exploitable on Debian. You will not survive an attack from a state adv…

If you're being targeted by a nation state you will face all sorts of things to deal with that can't be handled by buying a Thinkpad with cash from a randomly chosen used computer store. Like bugging your residence and office, bugging your car, putting advanced GPS tracking devices on your car, rubber hose cryptography, hardware keystroke loggers inserted in your equipment while you're known to be away from your home or office, full disk copies of your laptop/desktop being taken (clonezille-type) by breaking into your office while you're away, all sorts of shit.
Post reply on HN