Earlier quoted context omitted.
> I'm sure you can find a way to spear phish somebody and send them a Linux ELF binary that they will then execute, but accomplishing that is considerably harder than on Windows/OSX/Android/iOS. I'm afraid people are just as foolable and code just as executable on Debian as on any other platform. Additionally, vulnerabilities on Android are likely exploitable on Debian. You will not survive an attack from a state adv…
If you're being targeted by a nation state you will face all sorts of things to deal with that can't be handled by buying a Thinkpad with cash from a randomly chosen used computer store. Like bugging your residence and office, bugging your car, putting advanced GPS tracking devices on your car, rubber hose cryptography, hardware keystroke loggers inserted in your equipment while you're known to be away from your home…
NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
151–160 of 255 posts
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#152There is a frustration, as a user, that as the value of the iOS exploits increase, they become more and more 'underground'. The time between OS release and public jailbreak is continually growing - and it doesn't seem to only be due to the hardening of the OS. People are selling their exploits rather than releasing them publicly. And the further underground they go, the more likely they will be utilized for nefarious…
You say Apple's security isn't sufficient. It certainly appears that as time goes on Apple's security is pretty sufficient for most users. We're talking about exploits worth 1+ million dollars being used in a targeted attack against a single individual (or, more likely, a relatively small number of targeted individuals over time). This isn't something that the overwhelming majority of users need to be concerned about…
- $1M Cash
- skilled working knowledge of Apple's software and hardware
- fast reflexes to quickly react and apply a newly-public exploit derived from any of the above
Together, the number of world-wide actors who fall into one of those categories is actually fairly large. Those all have the capability to have total 'access' to my device. Given the value (to me) and the amount of data on that device, that's a huge hole, even for the majority of people. Further, with these networked exploits, the distinction between having one individual targeted, and all individuals running that OS is actually fairly slight. It wouldn't take that much more work to spam a well-designed exploit against an entire class of (normal) users.
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#153Should exploits like this be treated as munitions, with sale to foreign governments restricted? Or any sale at all restricted? Some thoughts: * The only uses for the exploits are either illegal or by government security organizations * I don't think you can just make an explosive and sell it to a foreign government; I think there are strict export controls (though I know very few details, I only read about companies…
The only legitimate use of this is a jailbreak tool. Obviously 'this' being the root exploit and not the malware/data capturing portion. I agree malware like that should be treated as munitions.
Malware shouldn't be considered a munition any more than encryption should have been.
Unless the malware actually makes your phone explode, then it's a stretch to call it a munition.
Do we really want governments getting into the code review business?
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#154Earlier quoted context omitted.
If you're being targeted by a nation state you will face all sorts of things to deal with that can't be handled by buying a Thinkpad with cash from a randomly chosen used computer store. Like bugging your residence and office, bugging your car, putting advanced GPS tracking devices on your car, rubber hose cryptography, hardware keystroke loggers inserted in your equipment while you're known to be away from your home…
If you don't keep your airgapped laptop on your person or in a tamper evident container at all times, it isn't an airgapped laptop. And if it isn't an airgapped laptop, it shouldn't know any secrets.
replace "UAE" with "Ethiopia" or any other authoritarian regime.
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#155Earlier quoted context omitted.
As consumers we don't face very good choices right now. When you buy an iPhone, you don't own it. You are a sharecropper on Apple's OS license. If you buy an Android with an unlockable bootloader, you own it. But if attacked, the adversary owns the device. It's a shitty situation but it's hard not to recommend iOS to most users.
And if an iPhone is attacked the attacker...doesn't own the device? I don't follow your reasoning.
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#156Earlier quoted context omitted.
I had the same thought as hackuser when reading the article, and then it was quickly followed by your point. I think an important first step would be to get certain things classified as arms. Once that's done, normal options may be able to handle them appropriately, such as not allowing the purchase or sale of certain types of arms within or over borders, etc. This would of course open up a whole new can of worms in…
> we are constitutionally guaranteed the right to bear arms It doesn't extend to all arms; e.g., you don't have a right to own anti-aircraft guns, weaponized anthrax, or even fully automatic rifles. What side of the line the exploits fall on is of course a question, but if I'm right that their only civilian use is illegal harm to others (e.g., you don't use them to protect your home or hunt deer) then it's simpler.
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#157Make sure to update to 9.3.5 on all of your iOS devices ASAP!
Sad face. Right now, on my iPhone: "iOS 9.3.5 provides an important security update for your iPhone" 40.5 MB. Great! Tapped "Download and install". It's greyed out. Huh? Oh, "this important security update requires a Wi-Fi network connection to download". Really? It's only 40.5 MB. Let me decide, please, how I use my data. Am I missing a setting that allows me to install an important security update on a network of m…
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#158There is a frustration, as a user, that as the value of the iOS exploits increase, they become more and more 'underground'. The time between OS release and public jailbreak is continually growing - and it doesn't seem to only be due to the hardening of the OS. People are selling their exploits rather than releasing them publicly. And the further underground they go, the more likely they will be utilized for nefarious…
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#159Amazing work by Lookout and Citizen Lab. Until this point I was not aware that Lookout provided any value-add for mobile devices. I was under the impression it was the McAfee of mobile. It sounds mean but this is the first reference to actual vulnerability discovery done by themselves on their blog, which usually reports on security updates that Google's Android security team discovered. Previous entries include such…
Direct links to other resources: Technical analysis: https://info.lookout.com/rs/051-ESQ-475/images/lookout-pegas... CitizenLab analysis of the nation-state side of things: https://citizenlab.org/2016/08/million-dollar-dissident-ipho... Apple update: https://support.apple.com/en-us/HT207107
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#160Amazing work by Lookout and Citizen Lab. Until this point I was not aware that Lookout provided any value-add for mobile devices. I was under the impression it was the McAfee of mobile. It sounds mean but this is the first reference to actual vulnerability discovery done by themselves on their blog, which usually reports on security updates that Google's Android security team discovered. Previous entries include such…
Direct links to other resources: Technical analysis: https://info.lookout.com/rs/051-ESQ-475/images/lookout-pegas... CitizenLab analysis of the nation-state side of things: https://citizenlab.org/2016/08/million-dollar-dissident-ipho... Apple update: https://support.apple.com/en-us/HT207107
If Apple, Google, MS, Linux distribution does the following:
* Create sha1, sha256, sha256 chksums of every system, app files and store them in a secure database somewhere.
* Check and audit the system files from time to time and notify the user when change happen.
Would it prevent these type attack or at lease notify the user that system security has be compromised?