Live data from Hacker News

NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

citizenlab.org

161–170 of 255 posts

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#161

The story is great but I really doubt this. I'm wondering what made him suspect the link? Does he send all the links he receives to Citizen Lab?

Yes, who doesn't click on random links received from unknown numbers over (get this) SMS? Some people.

Yeah that's almost dumb enough to indicate that this whole thing has been a cat's paw. Burn an old vuln, get everybody riled up about it, but distract them from looking for the sophisticated things you're doing when you actually want to spy on a troublesome subject.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#162

Earlier quoted context omitted.

My Android has an unlockable bootloader but you need to actually request the key from the manufacturer. Malware can't unlock it against my will without a jailbreak. Seems like a decent arrangement to me- safe by default, but if I want to root my phone I can.

What i would love to see is a bootlader where i can load my own signatures. Preferably done via USB only, and by putting the device into a mode that require certain button inputs during power up. Signed boot has uses, but we need to be sure that the user does the signing.

I was tripped up trying to unlock an LG G5 yesterday by the secure boot validation.

Turns out, in Android 6, there's a Developer Option called "Allow OEM Unlock" which does enable the ability to unlock the bootloader through fastboot.

While I can't sign my own bootloader, having a developer option to enable the unlock that can only be triggered from inside the OS is an interesting trade off.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#163

The story is great but I really doubt this. I'm wondering what made him suspect the link? Does he send all the links he receives to Citizen Lab?

Sounds like he has been targeted by state-level actors before. He's probably suspicious of any unsolicited information sent to him.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#164
post #148

Earlier quoted context omitted.

The Article mentions that the exploit has kernel mappings going as far as iOS7. This doesn't mean this predates the bounty at all, the bug that received the bounty payout for all we know might have been simply functional on iOS 7-9 or even earlier (and who ever made the final commercial product just didn't bother). iOS7/8 is most likely still used since older iPhones stop receiving updates at some point and older iPh…

Older iPhones become the "kids" phone when daddy buys the new one. There are more of them out there then you think.

I guess so, but it's rare to see iPhone 4's at this point when the iPhone 7 is almost out of the door.

Also depending on how old the kids are it might actually work in reverse =)

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#165
post #160

Earlier quoted context omitted.

Direct links to other resources: Technical analysis: https://info.lookout.com/rs/051-ESQ-475/images/lookout-pegas... CitizenLab analysis of the nation-state side of things: https://citizenlab.org/2016/08/million-dollar-dissident-ipho... Apple update: https://support.apple.com/en-us/HT207107

Love that Technical Analysis. If Apple, Google, MS, Linux distribution does the following: * Create sha1, sha256, sha256 chksums of every system, app files and store them in a secure database somewhere. * Check and audit the system files from time to time and notify the user when change happen. Would it prevent these type attack or at lease notify the user that system security has be compromised?

Tripwire is a linux util for doing just that. However you need some read-only media to store the hashes and I think rootkits can still just intercept the read calls.

http://linux.die.net/man/8/tripwire

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#166
post #87

Earlier quoted context omitted.

I was thinking less of the knowledge being considered an armament, and more that an actual program that takes advantage of it being one. I don't consider the the scientific knowledge required to create a gun as an armament, nor even specific schematics, but governments may view it differently (indeed, they weren't happy about the 3D printable gun). Also, I don't think this concept is limited specifically to exploitin…

Separating code from knowledge was part of the fun of the decss debacle. "That's not a haiku; that's an illegal perl script!"

And fundamentally it's the knowledge that matters. Programmers are "expensive" but not that expensive. Give any decent off-the-shelf code monkey the specifics of a vulnerability and he can give you exploit code.

Which means restricting the exploit code is quite useless. But restricting the knowledge itself doesn't work because the same knowledge is necessary to mitigate the vulnerability and to test that the mitigation is effective.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#167
post #152

Earlier quoted context omitted.

You say Apple's security isn't sufficient. It certainly appears that as time goes on Apple's security is pretty sufficient for most users. We're talking about exploits worth 1+ million dollars being used in a targeted attack against a single individual (or, more likely, a relatively small number of targeted individuals over time). This isn't something that the overwhelming majority of users need to be concerned about…

I don't think the bar is just nation-states. The bar also includes those with any of the following: - $1M Cash - skilled working knowledge of Apple's software and hardware - fast reflexes to quickly react and apply a newly-public exploit derived from any of the above Together, the number of world-wide actors who fall into one of those categories is actually fairly large. Those all have the capability to have total 'a…

They also require a few other things:

- a single person or committee with the authority to sign off on $1 million for this sort of thing.

- a willingness to risk the legal and PR consequences of being discovered.

Which cuts out a lot of potential corporate espionage

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#168
post #32

Earlier quoted context omitted.

Chaining this with some form of SMS/MMS bug (a la Stagefright) would make this unbelievably powerful. That's essentially the worst case scenario I can imagine for mobile security.

Or this, from the detailed writeup linked elsewhere on this page: > To use NSO Group’s zero-click vector, an operator instead sends the same link via a special type of SMS message, like a WAP Push Service Loading (SL) message. A WAP Push SL message causes a phone to automatically open a link in a web browser instance, eliminating the need for a user to click on the link to become infected. It goes on to say that mess…

When your service provider is owned by the state, all you can rely on is the OS provider.

Maybe we should all just go back to carrying dumbphones.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#169

Earlier quoted context omitted.

Yes, and that's what I meant about making it hard, not impossible. That said, there are uses of exploits which can be said are for the purpose of protecting property. I might conceivably want to use an Android or iOS exploit to liberate some of my data from my phone if some apps are less forthcoming with that data than I would like.

> I might conceivably want to use an Android or iOS exploit to liberate some of my data from my phone if some apps are less forthcoming with that data than I would like. A great point that I should have thought of. I wish I could edit my original post and add that consideration. I can draw a conceptual line: Ban using exploits on other people's equipment. But practically, I don't see how to stop that without criminal…

> I can draw a conceptual line: Ban using exploits on other people's equipment. But practically, I don't see how to stop that without criminalizing distribution, in which case I can't get my data from my phone (or install a 3rd party OS) without the vendor's permission.

I don't understand what the problem is supposed to be. You don't need laws against knives because there are already laws against assault and murder and there is no harm in having a knife you use to cut carrots. Then you prosecute people for the bad things they actually do.

The justifiable laws against specific weapons are for the exceedingly dangerous ones like plutonium and smallpox. That isn't this.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#170
post #42

NSO sells tools that when used violate the CFAA act. It is an Israeli company but a majority share was bought by a San Francisco based VC [0]. It doesn't seem like it should be legally allowed to exist as an American owned company. Maybe Ahmed Mansoor could sue the VC in American courts. [0] http://jewishbusinessnews.com/2014/03/19/francisco-partners-...

a) Selling tools itself doesn't violate the CFAA act. A separate entity uses the tools and assumes that liability, which as we see is mitigated by sovereign immunity. b) And even if selling tools began to violate CFAA, then NSO itself would be sued. As it is a separate entity than the investors, which is the whole point of limited liability....

If you can tie the tool to any circumvention of copyright protections -- pretty broad argument (DMCA), you can be sued or arrested.
Post reply on HN