The story is great but I really doubt this. I'm wondering what made him suspect the link? Does he send all the links he receives to Citizen Lab?
Yes, who doesn't click on random links received from unknown numbers over (get this) SMS? Some people.
NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
161–170 of 255 posts
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#162Earlier quoted context omitted.
My Android has an unlockable bootloader but you need to actually request the key from the manufacturer. Malware can't unlock it against my will without a jailbreak. Seems like a decent arrangement to me- safe by default, but if I want to root my phone I can.
What i would love to see is a bootlader where i can load my own signatures. Preferably done via USB only, and by putting the device into a mode that require certain button inputs during power up. Signed boot has uses, but we need to be sure that the user does the signing.
Turns out, in Android 6, there's a Developer Option called "Allow OEM Unlock" which does enable the ability to unlock the bootloader through fastboot.
While I can't sign my own bootloader, having a developer option to enable the unlock that can only be triggered from inside the OS is an interesting trade off.
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#163The story is great but I really doubt this. I'm wondering what made him suspect the link? Does he send all the links he receives to Citizen Lab?
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#164Earlier quoted context omitted.
The Article mentions that the exploit has kernel mappings going as far as iOS7. This doesn't mean this predates the bounty at all, the bug that received the bounty payout for all we know might have been simply functional on iOS 7-9 or even earlier (and who ever made the final commercial product just didn't bother). iOS7/8 is most likely still used since older iPhones stop receiving updates at some point and older iPh…
Older iPhones become the "kids" phone when daddy buys the new one. There are more of them out there then you think.
Also depending on how old the kids are it might actually work in reverse =)
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#165Earlier quoted context omitted.
Direct links to other resources: Technical analysis: https://info.lookout.com/rs/051-ESQ-475/images/lookout-pegas... CitizenLab analysis of the nation-state side of things: https://citizenlab.org/2016/08/million-dollar-dissident-ipho... Apple update: https://support.apple.com/en-us/HT207107
Love that Technical Analysis. If Apple, Google, MS, Linux distribution does the following: * Create sha1, sha256, sha256 chksums of every system, app files and store them in a secure database somewhere. * Check and audit the system files from time to time and notify the user when change happen. Would it prevent these type attack or at lease notify the user that system security has be compromised?
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#166Earlier quoted context omitted.
I was thinking less of the knowledge being considered an armament, and more that an actual program that takes advantage of it being one. I don't consider the the scientific knowledge required to create a gun as an armament, nor even specific schematics, but governments may view it differently (indeed, they weren't happy about the 3D printable gun). Also, I don't think this concept is limited specifically to exploitin…
Separating code from knowledge was part of the fun of the decss debacle. "That's not a haiku; that's an illegal perl script!"
Which means restricting the exploit code is quite useless. But restricting the knowledge itself doesn't work because the same knowledge is necessary to mitigate the vulnerability and to test that the mitigation is effective.
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#167Earlier quoted context omitted.
You say Apple's security isn't sufficient. It certainly appears that as time goes on Apple's security is pretty sufficient for most users. We're talking about exploits worth 1+ million dollars being used in a targeted attack against a single individual (or, more likely, a relatively small number of targeted individuals over time). This isn't something that the overwhelming majority of users need to be concerned about…
I don't think the bar is just nation-states. The bar also includes those with any of the following: - $1M Cash - skilled working knowledge of Apple's software and hardware - fast reflexes to quickly react and apply a newly-public exploit derived from any of the above Together, the number of world-wide actors who fall into one of those categories is actually fairly large. Those all have the capability to have total 'a…
- a single person or committee with the authority to sign off on $1 million for this sort of thing.
- a willingness to risk the legal and PR consequences of being discovered.
Which cuts out a lot of potential corporate espionage
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#168Earlier quoted context omitted.
Chaining this with some form of SMS/MMS bug (a la Stagefright) would make this unbelievably powerful. That's essentially the worst case scenario I can imagine for mobile security.
Or this, from the detailed writeup linked elsewhere on this page: > To use NSO Group’s zero-click vector, an operator instead sends the same link via a special type of SMS message, like a WAP Push Service Loading (SL) message. A WAP Push SL message causes a phone to automatically open a link in a web browser instance, eliminating the need for a user to click on the link to become infected. It goes on to say that mess…
Maybe we should all just go back to carrying dumbphones.
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#169Earlier quoted context omitted.
Yes, and that's what I meant about making it hard, not impossible. That said, there are uses of exploits which can be said are for the purpose of protecting property. I might conceivably want to use an Android or iOS exploit to liberate some of my data from my phone if some apps are less forthcoming with that data than I would like.
> I might conceivably want to use an Android or iOS exploit to liberate some of my data from my phone if some apps are less forthcoming with that data than I would like. A great point that I should have thought of. I wish I could edit my original post and add that consideration. I can draw a conceptual line: Ban using exploits on other people's equipment. But practically, I don't see how to stop that without criminal…
I don't understand what the problem is supposed to be. You don't need laws against knives because there are already laws against assault and murder and there is no harm in having a knife you use to cut carrots. Then you prosecute people for the bad things they actually do.
The justifiable laws against specific weapons are for the exceedingly dangerous ones like plutonium and smallpox. That isn't this.
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#170NSO sells tools that when used violate the CFAA act. It is an Israeli company but a majority share was bought by a San Francisco based VC [0]. It doesn't seem like it should be legally allowed to exist as an American owned company. Maybe Ahmed Mansoor could sue the VC in American courts. [0] http://jewishbusinessnews.com/2014/03/19/francisco-partners-...
a) Selling tools itself doesn't violate the CFAA act. A separate entity uses the tools and assumes that liability, which as we see is mitigated by sovereign immunity. b) And even if selling tools began to violate CFAA, then NSO itself would be sued. As it is a separate entity than the investors, which is the whole point of limited liability....