Live data from Hacker News

NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

citizenlab.org

201–210 of 255 posts

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#201
post #183
post #146

Earlier quoted context omitted.

And, even if your phone is updating it may be doing a fake update and then show you that you did update to whatever version Apple says is "safe" for this exploit but in fact Pegasus was in control the entire time. Get a new phone ASAP.

... or you could just hook it up to iTunes and let iTunes flash the whole phone with the latest iOS from scratch (9.3.5 fixes these exploits) instead of letting the on-device updater do it. No need for a whole new phone.

I guess I've never dug deep into how a iPhone restore to default from iTunes works, but does it actually zero out the whole disk or is it possible for this exploit to survive that.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#203

Earlier quoted context omitted.

> I might conceivably want to use an Android or iOS exploit to liberate some of my data from my phone if some apps are less forthcoming with that data than I would like. A great point that I should have thought of. I wish I could edit my original post and add that consideration. I can draw a conceptual line: Ban using exploits on other people's equipment. But practically, I don't see how to stop that without criminal…

> I can draw a conceptual line: Ban using exploits on other people's equipment. But practically, I don't see how to stop that without criminalizing distribution, in which case I can't get my data from my phone (or install a 3rd party OS) without the vendor's permission. I don't understand what the problem is supposed to be. You don't need laws against knives because there are already laws against assault and murder a…

> You don't need laws against knives because there are already laws against assault and murder

A good point. In this case it's so hard to catch perpetrators that to stop the crimes, it could be necessary to ban the weapons or their distribution (if that even is a practical option).

Are the other similar situations, where perpetrators are so hard to catch and you have to ban the means? Counterfeiting is all I can think of, and they don't ban color printers they just put tracking tech in them. Also, color printers are dual-use: They have many legitimate uses, exploits have very few.

> The justifiable laws against specific weapons are for the exceedingly dangerous ones like plutonium and smallpox. That isn't this.

Weapons that help foreign governments oppress large parts of their population might qualify, though clearly not all exploits fit that description.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#204
post #29

Earlier quoted context omitted.

Don't forget the time they pushed an "update" for blackberries: http://news.bbc.co.uk/2/hi/8161190.stm

Don't forget that Etisalat is now the majority shareholder and pretty much runs PTCL, the incumbent/largest telephone and telecom company in Pakistan, either... PTCL is to Pakistan as Verizon, Frontier or Centurylink are to various regions of the US. It's the ILEC. Etisalat is not your friend. Etisalat has great marketing and is building GSM-based (LTE, etc) networks in many developing nations but it is no friend of…

> armed men with carbines will show up and ransack your offices and home

This is a solid reminder that in the end, your ability to use defensive technology does not actually decide who calls the shots. Power is still ultimately controlled by violence.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#205
post #87

Earlier quoted context omitted.

I was thinking less of the knowledge being considered an armament, and more that an actual program that takes advantage of it being one. I don't consider the the scientific knowledge required to create a gun as an armament, nor even specific schematics, but governments may view it differently (indeed, they weren't happy about the 3D printable gun). Also, I don't think this concept is limited specifically to exploitin…

Separating code from knowledge was part of the fun of the decss debacle. "That's not a haiku; that's an illegal perl script!"

I don't recall seeing that spirit and creativity in a long time. Or am I just getting old and cranky?

The battle for end-user control seems surrendered, at least by all but a few.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#206
post #32

Earlier quoted context omitted.

Chaining this with some form of SMS/MMS bug (a la Stagefright) would make this unbelievably powerful. That's essentially the worst case scenario I can imagine for mobile security.

Or this, from the detailed writeup linked elsewhere on this page: > To use NSO Group’s zero-click vector, an operator instead sends the same link via a special type of SMS message, like a WAP Push Service Loading (SL) message. A WAP Push SL message causes a phone to automatically open a link in a web browser instance, eliminating the need for a user to click on the link to become infected. It goes on to say that mess…

Wow this WAP Push SL thing seems egregious. It's understandable that somebody thought it would be useful, for like five minutes. But how could a standards body or any of the several different OS companies who have implemented it not have realized how monumentally unwise it is to just automatically run shit that randomly gets sent to a phone?

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#207
post #32

Earlier quoted context omitted.

Chaining this with some form of SMS/MMS bug (a la Stagefright) would make this unbelievably powerful. That's essentially the worst case scenario I can imagine for mobile security.

Or this, from the detailed writeup linked elsewhere on this page: > To use NSO Group’s zero-click vector, an operator instead sends the same link via a special type of SMS message, like a WAP Push Service Loading (SL) message. A WAP Push SL message causes a phone to automatically open a link in a web browser instance, eliminating the need for a user to click on the link to become infected. It goes on to say that mess…

Anybody know if and what limitations iOS and/or Android put on WAP Push SLs?

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#208

Should exploits like this be treated as munitions, with sale to foreign governments restricted? Or any sale at all restricted? Some thoughts: * The only uses for the exploits are either illegal or by government security organizations * I don't think you can just make an explosive and sell it to a foreign government; I think there are strict export controls (though I know very few details, I only read about companies…

> * In the 1990s, strong encryption was called a 'munition' and export was restricted. That turned out to be impractical (it was available in many countries and the Internet has no borders), morally questionable (restricting private citizen's privacy), and it fell apart. IIRC, thats still on the books. Its just one of those sleeping paragraphs since the PGP release.

"it was available in many countries and the Internet has no borders"

Ummm... tell that to the Chinese or anyone, anywhere in the world trying to watch the complete international Netflix catalog. And as for VPNs, they're like the tunnels under the actual physical borders which are also not impenetrable.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#209

Earlier quoted context omitted.

Tripwire is a linux util for doing just that. However you need some read-only media to store the hashes and I think rootkits can still just intercept the read calls. http://linux.die.net/man/8/tripwire

Some years ago, I had Tripwire installed for a few days but quickly removed it again because whenever I upgraded installed packages, I'd get a storm of messages about files which had changed and that was just annoying since I was the one who had initiated the action that caused the files to change, but at the same time there were so many files that changed of course, that I had no way of distinguishing legitimate cha…

That's precisely what it's supposed to do. If you update the Tripwire db every time you "initiate an action that causes monitored files to change" - then it does a _magnificent_ job of telling you when someone _else_ changes those files.

You need to run 'tripwire --update' every time you run 'apt-get update' or 'pip install foo' or 'npm install bah' or whatever - then you wont get that storm of false positives.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#210
post #45

There is a frustration, as a user, that as the value of the iOS exploits increase, they become more and more 'underground'. The time between OS release and public jailbreak is continually growing - and it doesn't seem to only be due to the hardening of the OS. People are selling their exploits rather than releasing them publicly. And the further underground they go, the more likely they will be utilized for nefarious…

I look at it the other way: as exploits become more and more underground, I feel safer: I know those exploits are more likely to be used by state actors against activists and other people who are doing illegal stuff, and less likely to be used against me and millions of other users to install malware on our phones (to make them send spam, to make them send expensive texts...) So yes I feel safer now.

I know its cliche at this point but I'm going to once again point out that to some state actors, simply being gay is the illegal stuff they are looking for, and the penalty may be death. They do not feel safer now.
Post reply on HN