Live data from Hacker News

NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

citizenlab.org

231–240 of 255 posts

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#231
post #225
post #200

Unless you are a high-value target, Apple's security seems fairly sufficient for normal use (I have Android ;)). Companies like NSO Group that state that they play both sides without any moral compass seem like a great target for Anonymous or others. Imagine the client list, and banking information as a trail to blaze!

This guy seems to be quite the high-value target to warrant 3 zero-days, on ios no less. edit: What platform would be recommended, if you happen to be a high value target though. Using iOS at least seems to raise the cost of infiltration significantly judging by this http://www.forbes.com/sites/andygreenberg/2012/03/23/shoppin... .

I agree with you on iOS being the better choice, which is why there's a wink to my owning Android. I am obviously not a high-valued target.

FWIW - I only journal with ink and paper. I never trust digital files, and I sometimes forget how many backups I have of the same photo or other file.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#232

Earlier quoted context omitted.

Or this, from the detailed writeup linked elsewhere on this page: > To use NSO Group’s zero-click vector, an operator instead sends the same link via a special type of SMS message, like a WAP Push Service Loading (SL) message. A WAP Push SL message causes a phone to automatically open a link in a web browser instance, eliminating the need for a user to click on the link to become infected. It goes on to say that mess…

Wow this WAP Push SL thing seems egregious. It's understandable that somebody thought it would be useful, for like five minutes. But how could a standards body or any of the several different OS companies who have implemented it not have realized how monumentally unwise it is to just automatically run shit that randomly gets sent to a phone?

Not everything that supports WAP has to be a phone. It could also be a standalone device, or sensor, or whatever. And with WAP push you can control it.

For me the strange thing is that it is on by default on user phones.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#233
post #82

Earlier quoted context omitted.

Debian? If it's anyone that's even 1/10 as targeted as Mansoor was, then they shouldn't use anything less than Qubes, Subgraph, or TAILS.

you realize TAILS is just debian with TOR, and non persistent storage? I'm sure you can find a way to spear phish somebody and send them a Linux ELF binary that they will then execute, but accomplishing that is considerably harder than on Windows/OSX/Android/iOS.

Could somebody or a group who needed privacy implement a ground floor system like Menuet OS [1] or KolibriOS [2] running some sort of EC cryptography, and custom communication protocols off of a live CD or USB stick.

Would this even be practical? I realize TAILS is an attempt at bringing these tools to as many people who may not be technical, but for a smaller, more tech-saavy group, would this work?

[1] http://www.menuetos.net/

[2] http://kolibrios.org/en/

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#234
post #152

Earlier quoted context omitted.

You say Apple's security isn't sufficient. It certainly appears that as time goes on Apple's security is pretty sufficient for most users. We're talking about exploits worth 1+ million dollars being used in a targeted attack against a single individual (or, more likely, a relatively small number of targeted individuals over time). This isn't something that the overwhelming majority of users need to be concerned about…

I don't think the bar is just nation-states. The bar also includes those with any of the following: - $1M Cash - skilled working knowledge of Apple's software and hardware - fast reflexes to quickly react and apply a newly-public exploit derived from any of the above Together, the number of world-wide actors who fall into one of those categories is actually fairly large. Those all have the capability to have total 'a…

I don’t know about you, but there are probably zero persons who would pay $1000000 to gain access to the contents of my phone.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#235
post #224

To people who work for companies that sell / invest in products that are used in unethical ways (Francisco Partners, NSO, Cisco, etc), how do you justify it to yourself?

How do the people working for Citizen Lab / lookout justify to themselves blowing active operations by countless police forces around the world? Ops like Mexico vs Cartels? Also, since when is selling weapons to governments unethical?

When the governments are oppressing their people, that's a good clue.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#237

Earlier quoted context omitted.

Sad face. Right now, on my iPhone: "iOS 9.3.5 provides an important security update for your iPhone" 40.5 MB. Great! Tapped "Download and install". It's greyed out. Huh? Oh, "this important security update requires a Wi-Fi network connection to download". Really? It's only 40.5 MB. Let me decide, please, how I use my data. Am I missing a setting that allows me to install an important security update on a network of m…

You have to wonder how many iPhones never see a WiFi connection.

Put your SIM card in another (i)phone, make a personal hotspot, update. If you don't have another phone, use a friends' phone and/or data that shares an access point. If you don't have a SIM card, move to a country where they protect consumer rights, so you can change phone without asking your carrier.

(yes, I realize how silly all of this sounds :-))

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#239

Earlier quoted context omitted.

Or this, from the detailed writeup linked elsewhere on this page: > To use NSO Group’s zero-click vector, an operator instead sends the same link via a special type of SMS message, like a WAP Push Service Loading (SL) message. A WAP Push SL message causes a phone to automatically open a link in a web browser instance, eliminating the need for a user to click on the link to become infected. It goes on to say that mess…

Wow this WAP Push SL thing seems egregious. It's understandable that somebody thought it would be useful, for like five minutes. But how could a standards body or any of the several different OS companies who have implemented it not have realized how monumentally unwise it is to just automatically run shit that randomly gets sent to a phone?

This stuff was all designed by European mobile operators (many of them monopolies) in the mid-90's. Not exactly a peak period for security thinking.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#240

Earlier quoted context omitted.

When your service provider is owned by the state, all you can rely on is the OS provider. Maybe we should all just go back to carrying dumbphones.

That's presuming you have more faith in your desktop/other computing systems to be safe in the long run. Personally, I'd take iOS over any alternative, if security was my biggest concern.

I can recommend you to try qubes OS.
Post reply on HN