The story is great but I really doubt this. I'm wondering what made him suspect the link? Does he send all the links he receives to Citizen Lab?
Yes, who doesn't click on random links received from unknown numbers over (get this) SMS? Some people.
NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
241–250 of 255 posts
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#2421. never click on links in e-mails. 2. if you're targeted by a nation state, you're screwed. 3. everybody is vulnerable to rubber-hose cryptography.
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#243Earlier quoted context omitted.
And fundamentally it's the knowledge that matters. Programmers are "expensive" but not that expensive. Give any decent off-the-shelf code monkey the specifics of a vulnerability and he can give you exploit code. Which means restricting the exploit code is quite useless. But restricting the knowledge itself doesn't work because the same knowledge is necessary to mitigate the vulnerability and to test that the mitigati…
These days, exploiting vulnerabilities in most interesting code actually seems to be quite fiddly thanks to all the mitigation techniques and requires a bunch of specialist knowledge and tools that isn't exactly trivial to come by. The knowledge is already restricted, just for commercial rather than legal reasons.
Eh, specialist knowledge yes. Restricted, no. Getting documents on how chips and software has always been somewhat restricted, just be a linux person and try to get documentation from Broadcom on how their wifi/lan chips work, for example.
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#244Earlier quoted context omitted.
> Are the other similar situations, where perpetrators are so hard to catch and you have to ban the means? The nearest thing is clearly DMCA 1201. The problem of course being that DMCA 1201 is an epic failure. DRM circumvention tools are widely available to pirates, meanwhile it regularly subjects honest people to a choice between breaking the law and having it interfere with their legitimate activities. > Also, colo…
> Smallpox is inherently dangerous. I think the equivalent (or much worse, actually) for exploits is something that is self replicating and disruptive. For example, a bug in the BGP routing protocol (or a certain percentage of the common implementations) that propagates bogus routes and disrupts some or all traffic for affected systems and spreads. Something that disrupted a large enough chunk of global traffic would…
If you have the tooling to keep smallpox and not kill yourself you can also keep ebola around too, if you go to the effort to go find it. Really dangerous stuff and is going to be costly.
The problem here is I can make and keep 'digital smallpox' on my home PC, and for many pieces of equipment it is surprisingly easy to find exploits for them. Are you planning on watching every computer? Every person in the world?
Take a lesson from the failed war on drugs, where there is significant profit motivation people will do what is necessary to make massive amounts of money. There are massive amounts of money in blackhat work.
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#245Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#246Earlier quoted context omitted.
I look at it the other way: as exploits become more and more underground, I feel safer: I know those exploits are more likely to be used by state actors against activists and other people who are doing illegal stuff, and less likely to be used against me and millions of other users to install malware on our phones (to make them send spam, to make them send expensive texts...) So yes I feel safer now.
Perhaps you feel that way because you have the luxury of living in a place where human rights are respected. That these exploits are being used by regimes to shut down opposition is terrible in its own right. Edit: As for net effect on global society, I think having my phone be part of a botnet that sends spam is less impactful than disrupting democratic progress.
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#247Earlier quoted context omitted.
As consumers we don't face very good choices right now. When you buy an iPhone, you don't own it. You are a sharecropper on Apple's OS license. If you buy an Android with an unlockable bootloader, you own it. But if attacked, the adversary owns the device. It's a shitty situation but it's hard not to recommend iOS to most users.
I guess ambiguity / assumed apple fanboyism is why you're downvoted, but if I'm understanding you correctly, then I feel largely the same way. Apple's walled garden and "moral" approach to guarding their garden is incredibly frustrating, but the sheer number of vulnerabilities affecting different levels of the Android stack is so disheartening. This is true of my PC/Mac as well, all it takes is someone to plug in a m…
But empirically the iOS ecosystem is demonstrating that there is a close source ecosystem with better security properties than the open source one. Security advances the same virtues of user self determination as open source does.
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#248Earlier quoted context omitted.
> Are the other similar situations, where perpetrators are so hard to catch and you have to ban the means? The nearest thing is clearly DMCA 1201. The problem of course being that DMCA 1201 is an epic failure. DRM circumvention tools are widely available to pirates, meanwhile it regularly subjects honest people to a choice between breaking the law and having it interfere with their legitimate activities. > Also, colo…
> Smallpox is inherently dangerous. I think the equivalent (or much worse, actually) for exploits is something that is self replicating and disruptive. For example, a bug in the BGP routing protocol (or a certain percentage of the common implementations) that propagates bogus routes and disrupts some or all traffic for affected systems and spreads. Something that disrupted a large enough chunk of global traffic would…
Fixing it is hard because it requires a lot of independent parties to agree on what to do and update their routers. In theory this is the sort of thing a government could help with by providing funding, to fund research into solutions and/or provide cash incentives to early adopters.
But the market also solves these things eventually, since successful attacks are bad for business. It just takes for the attacks to actually happen first in that case.
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#249Unless you are a high-value target, Apple's security seems fairly sufficient for normal use (I have Android ;)). Companies like NSO Group that state that they play both sides without any moral compass seem like a great target for Anonymous or others. Imagine the client list, and banking information as a trail to blaze!
This guy seems to be quite the high-value target to warrant 3 zero-days, on ios no less. edit: What platform would be recommended, if you happen to be a high value target though. Using iOS at least seems to raise the cost of infiltration significantly judging by this http://www.forbes.com/sites/andygreenberg/2012/03/23/shoppin... .
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#250Earlier quoted context omitted.
You say Apple's security isn't sufficient. It certainly appears that as time goes on Apple's security is pretty sufficient for most users. We're talking about exploits worth 1+ million dollars being used in a targeted attack against a single individual (or, more likely, a relatively small number of targeted individuals over time). This isn't something that the overwhelming majority of users need to be concerned about…
I think its a bit naive to believe that a 1+ million worth exploit will remain a secret until the patch is shipped, at which point it is worth exactly nothing. There are so many way that the exploit will trickle down to more people until reach mass use. To mention a few ways: The buyer might want to recover the purchasing price by reselling. If its a government agency, they might want to establish credential with fut…