Live data from Hacker News

0-days exploited by commercial surveillance vendor in Egypt

blog.google

221–230 of 254 posts

Re: 0-days exploited by commercial surveillance vendor in Egypt

#221

Earlier quoted context omitted.

Every government with money has exploits for every device imaginable. The going price was $1m for a full exploit chain on iPhone a while ago, and I’m sure it’s gone up, but I’m also sure it is minuscule compared to the amount of money governments have. Everyone should assume this is fact, and not imagine some secret spy world. If you ever become interesting enough to hack, you will be, and there is little recourse (c…

I'd go a step further and state: everybody is interesting enough to fully automatically hack. I have 0 doubt that literally everybody is being scraped by 1 or more governments and/or companies. Because if they can, why not?

Because every time you do it, you run the risk of discovery. This can be expensive (you burn your exploit) and politically embarrassing.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#222

Earlier quoted context omitted.

Every government with money has exploits for every device imaginable. The going price was $1m for a full exploit chain on iPhone a while ago, and I’m sure it’s gone up, but I’m also sure it is minuscule compared to the amount of money governments have. Everyone should assume this is fact, and not imagine some secret spy world. If you ever become interesting enough to hack, you will be, and there is little recourse (c…

I'd go a step further and state: everybody is interesting enough to fully automatically hack. I have 0 doubt that literally everybody is being scraped by 1 or more governments and/or companies. Because if they can, why not?

The answer to “why not” is this blog post. Lots of people are likely very unhappy that their expensive exploit has been patched. This is what The Citizen Lab does!

Re: 0-days exploited by commercial surveillance vendor in Egypt

#224
post #215

Earlier quoted context omitted.

Kinda surprising that Apple wouldn't be the highest bidder for a full exploit chain. They've been known to give out $100,000 bug bounties, but you'd think one million would be a pretty good deal for closing a vulnerability vs having it sold to companies that professionally surveil people.

One million dollars is what some states pay _per target_. Every major black hat group operates with the blessing of some state. It’s about more than just money. Actual exploits are probably traded for “favours” (e.g. votes in international bodies, collaboration on thorny dossiers, extraditions, etc.). The infiltration of electronic communication is a major aspect in determining a state’s level of “soft power” and - i…

>Every major black hat group operates with the blessing of some state.

Citation needed. As far as I know that's true. Yes, some groups cooperate with the state (true in Russia after the escalation of the war in Ukraine, for example). But that's certainly not true for everyone - not every group has uses as an APT unit, most are just common criminals.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#225
post #12

Earlier quoted context omitted.

There's nested sandboxes for browsers in mobile environments. There's the inner layer which the web content is running in, but then the browser itself is sandboxed so it can't do things like access OS APIs it doesn't have permission for, install apps that run in the background, etc. This is why the iOS example needed 3 exploits chained. The fact that a similar example worked on Android, which also has app sandboxing,…

that sounds like terrible joke sandbox in sandbox in sandbox in sandbox in sandbox in sandbox in sandbox and stuff still manages to escape

Defence in depth. Now you need a working chain of 3 exploits instead of one. It's about raising the bar, perfect security is impossible.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#226
Ofc, the "services" have enough CA certificates private keys to legitimate any "man-in-the-middle" attack for any browsers. Worst case scenario they have root-kits they can easily inject on user systems in order to intercept some trafic before encryption. They have probably a significantly sized "library" at their disposal to work from, depending on the "targets", and it could even be kind of automated (up to a certain point) with proper finger-printing of user system/components.

Presuming the other way around would be unreasonable.

Re: 0-days exploited by commercial surveillance vendor in Egypt

#227

Earlier quoted context omitted.

None of the mentioned privileges should net you a persistence though, so there's clearly still another vulnerability.

Above says access to SD card. I think that means write ability. Which means persistence.

Android has clamped down hard on access to the SD card. Chrome certainly doesn't have the special All Files Access, and on my device it doesn't even have Photos or Music, since I never use those permissions with Chrome, and Android regularly turns off permissions that haven't been used recently

Re: 0-days exploited by commercial surveillance vendor in Egypt

#228

Earlier quoted context omitted.

None of the mentioned privileges should net you a persistence though, so there's clearly still another vulnerability.

But smartphones are rarely rebooted so maybe you don't need persistence that much?

You still want priv escalation if you're trying to spy on someone. The content process can't see anything you're doing in other apps, and the browser can only access a very restricted view of the storage

Living in memory or living off the land is generally a good idea, but you still want a chain of exploits anyways

Re: 0-days exploited by commercial surveillance vendor in Egypt

#229
post #16

Earlier quoted context omitted.

Or get someone to click on a spoofed domain, certified by our beloved LetsEncrypt! Apparently al that is needed is an HTTP 302/307 redirect response (or html redirect payload, maybe even DNS?) pointing the client toward c.betly[.]me

Huge difference between being tricked into clicking a link vs just browsing the web and getting owned.

The vector is an image file. Put your image in a display ad, now you don't need the user to click anything

Re: 0-days exploited by commercial surveillance vendor in Egypt

#230
post #201

Earlier quoted context omitted.

I am this person. I work as a researcher finding 0-days. From the employee perspective: Wages are equal. Big Tech work is less interesting (build big bug finding machines that find have high quantity of bugs) and report the bugs that sit into some bug tracker only to maybe be fixed in 3 months. Offensive security work is more interesting. It requires intimate knowledge of the systems you research, since you only need…

You don't need to cut any division, profits can also change

Most investors back companies with a kind of “extraction” mindset. They only want to Solve The Problem in so far as they can turn that into a stream of income.

Why would they give that to the employees to improve The Solution? It’s already solved as far as The Market is concerned. That would be Bloat

Post reply on HN