Live data from Hacker News

NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

citizenlab.org

21–30 of 255 posts

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#21
The UAE really hates on activists, and appears to be hiring a bunch of people specifically to suppress activists/dissidents within the country. [1] Unfortunately, due to the amount of wealth the country has, it won't stop almost anybody from dealing with them unless Western sanctions are placed on the country, which are unlikely given the current geopolitical situation.

https://www.evilsocket.net/2016/07/27/How-The-United-Arab-Em...

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#24
post #12

This vulnerability sounds like this: https://www.zerodium.com/ios9.html It was claimed November of last year. I wouldn't be surprised if this "Trident" was sold by Zerodium. Glad it's patched. Edit: I just saw the Citizen Lab article on this: https://citizenlab.org/2016/08/million-dollar-dissident-ipho... They mention the Zerodium bounty as well.

Article mentions that there are indications this was in the wild as far back as iOS 7, suggesting this isn't directly linked to that Zerodium bounty.

The Article mentions that the exploit has kernel mappings going as far as iOS7. This doesn't mean this predates the bounty at all, the bug that received the bounty payout for all we know might have been simply functional on iOS 7-9 or even earlier (and who ever made the final commercial product just didn't bother). iOS7/8 is most likely still used since older iPhones stop receiving updates at some point and older iPhones are the ones you might actually find in emerging markets and developing countries. While rare you can still see people even in "developed" countries running Iphone 4's, if you go to the middle east, africa, or asia you probably see considerably more of them through being sold on the secondary markets.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#25
post #11

The article mentions how this may have been use all the way back in iOS 7 which is crazy. If you are being targeted for surveillance smartphones are a very bad idea depending on your adversary. A cheap phone that is refreshed regularly will probably be your best bet.

On the other hand, smartphones are invaluable to most activists because they allow you to provide documentation of abuses through its various sensors (audio, video, photos, etc).

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#26

Amazing work by Lookout and Citizen Lab. Until this point I was not aware that Lookout provided any value-add for mobile devices. I was under the impression it was the McAfee of mobile. It sounds mean but this is the first reference to actual vulnerability discovery done by themselves on their blog, which usually reports on security updates that Google's Android security team discovered. Previous entries include such…

And quite the heads up move by Ahmed Mansoor to recognize the suspicious text for what it was and send it to the research team instead of clicking the link. If this thing really has been going since iOS 7 that means he is the outlier in taking precautions.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#27
post #4

An untethered stealth jailbreak that installs without user interaction from a webview, that's almost as bad as it gets. And for iOS 7.0.0 - 9.3.4 inclusive. And with exfiltration of audio, video, whatsapp, viber, etc etc. So thorough and so bad :-/

> An untethered stealth jailbreak that installs without user interaction from a webview, that's almost as bad as it gets. And for iOS 7.0.0 - 9.3.4 inclusive. And with exfiltration of audio, video, whatsapp, viber, etc etc. So thorough and so bad :-/

Short of being triggered completely in the background by an UDP packet, what's worse than this?

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#28
post #15

Earlier quoted context omitted.

FTA: It appears that the company that provided the spyware and the zero-day exploits to the hackers targeting Mansoor is a little-known Israeli surveillance vendor called NSO, which Lookout’s vice president of research Mike Murray labeled as “basically a cyber arms dealer.” Phineas Fisher, we need you now.

So we have cyber arms dealers now. I continue to be amazed at the prophecies of William Gibson. Makes me wonder if there's anything to "remote viewing." Did he just look forward into the 21st century and write down what he saw? :) BRB, gonna go slot me an icebreaker...

> So we have cyber arms dealers now.

See https://www.zerodium.com/program.html

Someone who discovers/developers a remote Jailbreak like this can apparently sell it for a cool half-million.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#29

The UAE really hates on activists, and appears to be hiring a bunch of people specifically to suppress activists/dissidents within the country. [1] Unfortunately, due to the amount of wealth the country has, it won't stop almost anybody from dealing with them unless Western sanctions are placed on the country, which are unlikely given the current geopolitical situation. https://www.evilsocket.net/2016/07/27/How-The-U…

Don't forget the time they pushed an "update" for blackberries: http://news.bbc.co.uk/2/hi/8161190.stm
Post reply on HN