Live data from Hacker News

NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

citizenlab.org

191–200 of 255 posts

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#191
post #45

There is a frustration, as a user, that as the value of the iOS exploits increase, they become more and more 'underground'. The time between OS release and public jailbreak is continually growing - and it doesn't seem to only be due to the hardening of the OS. People are selling their exploits rather than releasing them publicly. And the further underground they go, the more likely they will be utilized for nefarious…

This is what happens when the concepts of security, DRM and commercial restriction get entangled.

This reminds me of the PlayStation 3. It remained an un-hacked console for so long and the theory goes that the people who wanted to tinker with it could do so without being forced to fight on the same side as the bad guys, because Sony allowed 'Other OS'. When Sony closed off 'Other OS', this gave incentive for people to actually try and jailbreak the system [1].

Yet now the people that just wanted to tinker had to take the same route that people who just wanted to pirate would have to take. By locking the platform down further, Sony only succeeded in merging the two camps (benign tinkerers and pirates). I think there's a lot of validity in this theory.

It's a tough choice. As an iOS user I've long since come to the same acceptance as you - that the added security is worth the extra restrictions. Yet it doesn't have to be this way. Protecting your platform from hackers shouldn't be the same as protecting your platform from SNES emulators or games with adult themes.

[1] I believe it was this talk where this view was put forward, but I might be wrong (at work, can't really double-check): https://www.youtube.com/watch?v=PR9tFXz4Quc

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#192
post #79

Is there any way to check if an iOS device has Pegasus installed, without installing and registering for the Lookout app?

Sounds like an exploited device should be jailbroken, you could try running an unsigned binary (if it's easy to find & install one - I'm not sure). I believe the article also says it disables the auto-update mechanism. So if you've seen an auto-update prompt recently, your odds are better. The background audio recording must be terrible for battery life.

(From the lookout paper): "In order to maintain its ability to run, communicate, and monitor its own status, the software disable's the phone's 'Deep Sleep' functionality."

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#193

Earlier quoted context omitted.

They also require a few other things: - a single person or committee with the authority to sign off on $1 million for this sort of thing. - a willingness to risk the legal and PR consequences of being discovered. Which cuts out a lot of potential corporate espionage

This presumes that the exploits can only be found by companies with deep pockets, which are probably deep only because they are willing to sell them. What if there are equally good teams who are not in it for the money?

Why would a corporation maintain an espionage team for any other reason?

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#194
post #45

There is a frustration, as a user, that as the value of the iOS exploits increase, they become more and more 'underground'. The time between OS release and public jailbreak is continually growing - and it doesn't seem to only be due to the hardening of the OS. People are selling their exploits rather than releasing them publicly. And the further underground they go, the more likely they will be utilized for nefarious…

I look at it the other way: as exploits become more and more underground, I feel safer: I know those exploits are more likely to be used by state actors against activists and other people who are doing illegal stuff, and less likely to be used against me and millions of other users to install malware on our phones (to make them send spam, to make them send expensive texts...) So yes I feel safer now.

"I know those exploits are more likely to be used by state actors against activists and other people who are doing illegal stuff"

State actors usually have their own opinions about what's legal and what's not, and they tend to give themselves the benefit of the doubt because... the mission must succeed! So no, this "undergrounding" should not make you feel safer. You never know when you're going to cross paths with the next Snowden or any whistleblower or human rights activist.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#195

"we did not have an iPhone 6 available for testing" Big budget operation!

It's a human rights lab at an academic institution. Small budget is hardly a shock.

Somewhat hilariously, they appear to be funded in part by donations from Palantir.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#196
post #28

Earlier quoted context omitted.

> So we have cyber arms dealers now. See https://www.zerodium.com/program.html Someone who discovers/developers a remote Jailbreak like this can apparently sell it for a cool half-million.

For iOS, $500k was quoted in HN-featured media recently. However, $750k was quoted on HN in response to a query perhaps two years ago.

The same company I linked above issued a $1 million bounty for an iOS remote jailbreak vuln late last year (for a maximum of 3 different winners).

By the time the bounty expired only 1 team had won.

https://www.zerodium.com/ios9.html

So pricing has some fluidity, but you're looking at at least 500k.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#197
post #45

There is a frustration, as a user, that as the value of the iOS exploits increase, they become more and more 'underground'. The time between OS release and public jailbreak is continually growing - and it doesn't seem to only be due to the hardening of the OS. People are selling their exploits rather than releasing them publicly. And the further underground they go, the more likely they will be utilized for nefarious…

You say Apple's security isn't sufficient. It certainly appears that as time goes on Apple's security is pretty sufficient for most users. We're talking about exploits worth 1+ million dollars being used in a targeted attack against a single individual (or, more likely, a relatively small number of targeted individuals over time). This isn't something that the overwhelming majority of users need to be concerned about…

Just as an aside; The 1M USD exploit was a bug bounty/publicity stunt. While that also was a chain exploit, that doesn't automatically mean this is a "1M USD" exploit, like everyone is claiming. Or am I missing something?

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#198

Earlier quoted context omitted.

If you don't keep your airgapped laptop on your person or in a tamper evident container at all times, it isn't an airgapped laptop. And if it isn't an airgapped laptop, it shouldn't know any secrets.

At which point if you're a UAE dissident and trying to deal with all this while living in the territory of the UAE , you might say "fuck it" and find a way to move to Toronto. replace "UAE" with "Ethiopia" or any other authoritarian regime.

They took his passport.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#199
post #128

Aside, but does anybody else find the switch from right-to-left to left-to-right really jarring in this screenshot? https://citizenlab.org/wp-content/uploads/2016/08/image13-76... It has the effect of introducing a line-break into the middle of a line, rather than at either end. I've never encountered this before and it took my brain a few seconds to catch on. I'd be really curious how native bilingual readers of bot…

BiDi sucks, and as an RTL language speaker you learn to live with it. My native language is Hebrew, and we don't bother translating most technical terms to Hebrew. You end up with technical documents looking something like this: ".yadot patch a desaeler Apple .iOS 9.3 ni ytilibarenluv privilege-escalation a dnuof srehcraeser ehT" In newspapers, where lines are typically short, you get the effect in the screenshot in…

Thanks for this – I really appreciate the insight. That changing-input lag sounds like an absolute nightmare.

Since I left my previous comment, I came across some Apple presentations on new work they've been doing in iOS 9 and iOS 10 on internationalisation including RTL and mixed-content support. It sounds like there's a lot of work still to do, but I was pleased to see they've at least started multilingual input sources now (in iOS 10, autocorrect can work with multiple languages without having to switch keyboards, though I'm guessing this only works with Latin alphabet languages for now?).

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#200
Unless you are a high-value target, Apple's security seems fairly sufficient for normal use (I have Android ;)). Companies like NSO Group that state that they play both sides without any moral compass seem like a great target for Anonymous or others. Imagine the client list, and banking information as a trail to blaze!
Post reply on HN