Live data from Hacker News

A 0-click exploit chain for the Pixel 10

projectzero.google

231–240 of 255 posts

Re: A 0-click exploit chain for the Pixel 10

#231
post #220

Earlier quoted context omitted.

I don't necessarily disagree but a lot of chains will bail out if they find like the Norton Antivirus app on your phone so

In this case the body of evidence is still quite powerful though, given that not only do we not have any forensic evidence of compromise from a phone with Lockdown Mode, but in all public cases where chains were RE'd back out of the forensic evidence, they don't work when tested on Lockdown Mode! So, there's even signal that the lack of forensics indicating Lockdown Mode compromises is not due to artificial targeting…

That is a total strawman. The standard of “effective” being used by the person I was responding to and Apple themselves is “protects against state actors targeting you”, not “has any benefit whatsoever” or even “has a material benefit”.

Protecting against state actors is not a instantaneous property of the present. It demands durable protection against compromise by state actors who can easily spend tens to hundreds of millions of dollars on teams of hundreds for multiple years to develop novel, durable exploits known only to them. To the extent that compromises exist, they would require expected resource expenditure in excess of what state actors can deploy or are in excess of the value derivable by state actors which is going to be in the hundreds of millions to billions of dollar range to constitute as being "effective against state actors targeting you".

Protecting against state actors means secure against Iran, Saudi Arabia, China, and the NSA. That is the unsupported marketing bullshit I am calling out.

Re: A 0-click exploit chain for the Pixel 10

#232

Earlier quoted context omitted.

I don't know if that is the right lesson. It's kind of like "don't click on links"... Err, no. You should be able to click any link without getting hacked.

I have always found the whole "Don't trust links" a faux-pax when it comes to user training. As it just means that the failure to secure systems in the first place has already failed.....

It's worse, often the saying goes "don't click on suspicious links"/"don't open suspicious attachments". If I (target of such hint) knew the link was "suspicious" I wouldn't click it! Users are not opening suspicious attachments, they open (what they think is) important invoice or message from their boss.

Re: A 0-click exploit chain for the Pixel 10

#233
post #145

I hope the average person will soon understand the importance of security and will be OK with making the necessary sacrifices to achieve it. Almost everyone has something to protect, be it personal information or property (money, IP). People love new technologies and features that make their lives easier, but so far only a small subset of these people have made a conscious decision to limit their exposure to risk by…

[dead]

Re: A 0-click exploit chain for the Pixel 10

#234
post #117

Earlier quoted context omitted.

> What is the purported lesson we should have learned? Not to automatically execute things within data that we have been sent.

I think it's "don't use parsers written in unsafe languages".

All languages are unsafe. Some just make it less obvious.

Re: A 0-click exploit chain for the Pixel 10

#235

Earlier quoted context omitted.

You said removing features. This link is talking about making certain feautures optional and disabled by default, not removing them.

Disabled, is removed... Removed from operation

Don't be ridiculous.

Re: A 0-click exploit chain for the Pixel 10

#236

Earlier quoted context omitted.

I should have said “a well crafted malicious email” or SMS etc.

Phishing is big business and ways to combat are not fool proof. Education helps. Spam detection helps.

Education helps, but it puts the burden on the user. The real fix is shutting down the phishing source, not just filtering the symptom.

Re: A 0-click exploit chain for the Pixel 10

#237
post #66

I followed the link to the Pixel 9 bug/exploit and saw this: "Over the past few years, several AI-powered features have been added to mobile phones that allow users to better search and understand their messages. One effect of this change is increased 0-click attack surface, as efficient analysis often requires message media to be decoded before the message is opened by the user" Haven't we learned our lesson on this…

> Haven't we learned our lesson on this? What is the purported lesson we should have learned? Users choose phones with rich messaging features. This was a major selling point for iPhone, first, with iMessage, and later with Android until iOS caught up with RCS.

Who are these people that are buying phones based on their 1st party SMS features?

There's a plethora of 3rd party messaging apps, namely WhatsApp or WeChat -- I haven't felt that messaging has sucked since then BBM days.

Re: A 0-click exploit chain for the Pixel 10

#238
post #94
post #62

Earlier quoted context omitted.

This makes sense if you’re a human-rights journalist working in a dangerous country, with the threat of state-level actors looking to compromise you. If you’re not then this seems quite paranoid, bordering on LARPing.

LARPing is imagining that Lockdown mode protects you from state-level actors. It is frankly baffling why a industry that has been laughing for literal decades at even the possibility of stopping state-level actors just turns around and uncritically believes Apple's marketing team with literally zero support, evidence or proof except for a long track record of failure. You would think that extraordinary claims would d…

No root and no way to firewall them. "Lockdown" mode - a lot of inconveniences.

Re: A 0-click exploit chain for the Pixel 10

#239
post #123

Earlier quoted context omitted.

I think it's simpler: don't touch untrusted content unless/until you need to.

But that just moves it from 0-touch, to 1-touch (which is of course better). But users are morons. We STILL NOW, have people getting phished and pwning their employers.

Let's think about why that happens though

We all go through that stupid phishing training. They give us a list of red flags to help determine if an email is legit.

Then the next day, the CTO sends out an email that says IMPORTANT and the only text body says PLEASE READ THE ATTACHED .DOCX FILE. This is exactly what we were just trained not to open, but its from some exempt C-level who didn't have time to take the training, and all he is now doing is training the employees to open mails that look like phishing.

Re: A 0-click exploit chain for the Pixel 10

#240

Earlier quoted context omitted.

The thing is, nobody's happy just previewing jpegs and pngs. Before you know it, people want to preview SVGs, PDFs, video, HTML and so on. And to do that properly means you've got to support obscure formats like JBIG2 and CCITT Fax. Malicious vector images with a billion elements to render. XML that lets one file embed another. And good luck getting the budget to re-implement them all from scratch in a better languag…

Perfection is the enemy of the perfectly good. And let's be honest, you'll have what, 0.0001% of users who want to preview CCITT in 2026? Less? Probably less.

It's a part of PDF, so if there's a PDF renderer which makes preview, it supports G4 and JBIG2.
Post reply on HN