Live data from Hacker News

A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

googleprojectzero.blogspot.com

181–190 of 360 posts

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#181
post #52

From the top of the article: > We want to thank Citizen Lab for sharing a sample of the FORCEDENTRY exploit with us, and Apple’s Security Engineering and Architecture (SEAR) group for collaborating with us on the technical analysis. This reminded me that NSO went after Citizen Lab on multiple fronts. They even tried to use a spy to talk to JSR ( https://www.johnscottrailton.com ) and make him say controversial things…

Darknet Diaries is so good. To anyone who hasn't listened, highly recommend. Jack hits a homerun each week and the story about JSR and NSO was buck wild

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#182
post #52

From the top of the article: > We want to thank Citizen Lab for sharing a sample of the FORCEDENTRY exploit with us, and Apple’s Security Engineering and Architecture (SEAR) group for collaborating with us on the technical analysis. This reminded me that NSO went after Citizen Lab on multiple fronts. They even tried to use a spy to talk to JSR ( https://www.johnscottrailton.com ) and make him say controversial things…

Darknet Diaries is so good. To anyone who hasn't listened, highly recommend. Jack hits a homerun each week and the story about JSR and NSO was buck wild

every other week release for the podcast, not weekly*

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#183

It's a real shame that the people who came up with this exploit are working for NSO and not on solving P = NP or something. I'm sure if we got them and the ones working on crypto at NSA in a room together, we'd have it and clean unlimited energy in a week. I often feel sad thinking about how many brilliant engineers are dedicating their time to helping governments spy on people or other governments.

I feel the opposite. All this stuff and even more hardcore crypto stuff is all relatively simple math. It's not even close to comparable to the things mathematicians do. Or even what physicist have achieved with LHC or fusion research.

Surely cracking cryptographic algorithms is pretty hard math given people don't have that much success with it, even with a huge incentive (decrypting all communications worldwide)?

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#184
post #36

TL;DR - the ending of the post is all you need: “JBIG2 doesn't have scripting capabilities, but when combined with a vulnerability, it does have the ability to emulate circuits of arbitrary logic gates operating on arbitrary memory. So why not just use that to build your own computer architecture and script that!? That's exactly what this exploit does. Using over 70,000 segment commands defining logical bit operation…

They must have spent tons of engineering effort to create this virtual computer to act as their foundation for further exploits. They don't deserve any sympathy of course, but it must really suck that their foundation disappears immediately with the fixed vulnerability.

I suspect once written it can be adapted to a wide range of Turing complete instruction sets.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#185

Earlier quoted context omitted.

Darknet Diaries is so good. To anyone who hasn't listened, highly recommend. Jack hits a homerun each week and the story about JSR and NSO was buck wild

every other week release for the podcast, not weekly*

every other week release for STORIES FROM THE DARK SIDE OF THE INTERNET*

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#186
post #175

And still, in 2021, after so many exploits, realizing the futility of trying to fix these bugs and adding their "blast door" process, some Apple dev calls image parsing code where it doesn't belong. The people that are supposed to maintain the element of the OS that has been abused most by nation states do not know the internal APIs they are working with, even just to display looping GIFs. This negligence is killing…

How do we know this code was written in 2021? GIF support was added to iMessage (I think) in 2016 or 2016; I couldn't find an exact date.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#187
post #183

Earlier quoted context omitted.

I feel the opposite. All this stuff and even more hardcore crypto stuff is all relatively simple math. It's not even close to comparable to the things mathematicians do. Or even what physicist have achieved with LHC or fusion research.

Surely cracking cryptographic algorithms is pretty hard math given people don't have that much success with it, even with a huge incentive (decrypting all communications worldwide)?

It's considered to be impossible. I doubt there is much (if any) serious research going on to mathematically crack RSA or ECC. Besides that is not what OP was talking about. That was about hackers finding standard vulnerabilities in code and exploiting it. Not about any mathematical flaws in crypto.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#188

Earlier quoted context omitted.

There was this one: https://en.wikipedia.org/wiki/Operation_Aurora It seems that the level of access gained could have been used for a larger breach but fortunately the attackers had different motives.

Google banned Windows throughout the organisation in 2010 due to this (with some well fenced exceptions where Windows was unavoidable). 1. Google will do costly things to be secure. 2. At the time I did not hear of any other organisation following Google’s lead. 3. They did not reverse the ban later.

[deleted]

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#189
post #66

Earlier quoted context omitted.

It's still pretty expensive! NSO charged a flat $500,000 fee for installing Pegasus. It charged government agencies $650,000 to spy on 10 iPhones; $650,000 for 10 Android users; $500,000 for five BlackBerry users; or $300,000 for five Symbian users.

Feels weird that a private company can target individuals for a price. How was this legal? Isn’t it illegal to hack the phone of a private individual? Or do they simply say here’s the tool, here’s the manual, do what you want just don’t tell us?

> Feels weird that a private company can target individuals for a price. How was this legal? Isn’t it illegal to hack the phone of a private individual? Or do they simply say here’s the tool, here’s the manual, do what you want just don’t tell us?

It's only illegal if you get caught. And then find someone to prosecute you.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#190
post #116
post #52

From the top of the article: > We want to thank Citizen Lab for sharing a sample of the FORCEDENTRY exploit with us, and Apple’s Security Engineering and Architecture (SEAR) group for collaborating with us on the technical analysis. This reminded me that NSO went after Citizen Lab on multiple fronts. They even tried to use a spy to talk to JSR ( https://www.johnscottrailton.com ) and make him say controversial things…

https://9to5mac.com/2021/12/15/pegasus-spyware-maker-nso-run... hopefully this company is on the way out...

I'd assume they're using the Erik Prince/Constellis business model, taking some time off and getting the band back together under a different name to do the same work.
Post reply on HN