Live data from Hacker News

Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

citizenlab.ca

251–260 of 314 posts

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#251

How come when we hear about this stuff it is always Israeli companies involved? Is ethics not taught in Israeli Computer Science curricula? Those who wrote this exploit are clearly "brilliant" and at least some of them are bound to be reading Hacker News. Is other countries' spyware firms just better at hiding their malware than Israel's is?

If I had to guess.... as a person who once did a fair amount of business in the middle east, but Egypt and not Israel...

I had a former customer there _go out of business_ when the Barack Hussein Obama (mmm mmm mmm!) administration supportd an attempted putsch by (in my customer's words) "The Retarded F___ing Nazis who killed Sadat for making peace with the Jews."

Israel and the non-Brotherhood Arab countries face the burdensome situation that their most reliable "ally" is a country that depending on the politics is going to support the Brotherhood _and_ the large wannabe-hegemonic Russian satellite state trying to develop nuclear weapons. (Oh, and funded said state's reconquest of Syria in the process). Said schizophrenic state also has a massive surveillance system of its own.

My guess: they all don't look at this as a violation of civil rights or ethics, they look at this as a means for the little countries like them to get a leg up on some of the insane intelligence agencies of the large countries that are funding enemies both domestic and foreign.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#252
post #232

Earlier quoted context omitted.

> Is ethics not taught in Israeli Computer Science curricula? ...Is ethis taught in any CS curriculum? It sure wasn't in mine (but to be fair, that was in Switzerland).

It was a requirement for my Software Engineering degree (my university was in the US). When discussing with my coworkers in the past, I don't think many of them were required to take any ethics courses, unfortunately. Ethics in software is something we should all probably talk about a little more often.

My alma mater treated CS more like "Applied Math", to the degree that I don't think that anyone in the department viewed Software Engineering as a major source of employment after the (Master's) degree.

Viewed from the lens of "CS is a researcher/PhD candidate mill", a lack of focus on ethics makes some sense to the cynic in me.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#253

> We were unable to retrieve these binaries from flash memory, as we did not have access to a jailbreak for iPhone 11 running iOS 13.5.1. It’s ironic that the exploit is able to plant arbitrary code on an up-to-date device and yet the owner of the phone can’t introspect their phone to see it themselves because they don’t know how to bypass the protections :/

These attacks would be a lot less dangerous if they couldn't get on-disk persistence. Just reboot your phone, and you're good to go. Only creeps like NSO who spy on normal people need that degree of persistence. Everyone else can just hang out in ram on some always-on server. Vendors need to make it easier to verify the integrity of persistent firmware, in an offline fashion. It will dramatically increase the cost of…

>“Just reboot your phone, and you're good to go”

Doesn’t really work like that. First of all, when would you reboot your phone? Once per day? Once per hour? Every five minutes? Regardless, these attacks are incredibly advanced, remember they require zero interaction from the user.

Even if you rebooted constantly and the exploit lacked a persistence vector, they would still be able to exploit you whenever they want. There are literally no good defense mechanisms against zero-click attacks. The only effective one being turning off your phone forever.

Something like these exploits takes 1-2 minutes maximum to achieve full data exfiltration. This means you’re not safe even if you reboot every five minutes.

So preventing persistence vectors is not really useful against these types of attacks. Persistence is more of a “comfort feature” for attackers, is not really something essential.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#254
post #22

NSO Group will lose a lot of business when authoritarian countries wake up and realize they can simply force Apple to migrate user data into servers they own in exchange for market access.

> when authoritarian countries wake up and realize they can simply force Apple to migrate user data into servers they own in exchange for market access China is the only authoritarian country with enough leverage over Apple to force them to do that sort of thing. There it's not just an enormous market, but also an utterly critical part of Apple's supply chains. Every other authoritarian country is small fry in compar…

Saying "the only privacy threat you have to worry about is the 1.5 billion person country that makes _everything_ with a chip in it" is like saying "Take your daily arsenic and you won't have to worry about the the cancer."

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#255
post #134

Earlier quoted context omitted.

When HackingTeam was exposed, no one was asking to sanction Italy. Hating on Israel specifically is a very cool and woke thing to do. Has been for decades.

> Hating on Israel specifically is a very cool and woke thing to do. Has been for decades. Well Israeli has been treating palestinians pretty badly so it's not like it isn't justified. At least critising Israel for genuine reasons isn't deemed anti-semitic in the latest international standard of the definition, oh wait!

Depending on when your justifiability timeline begins, Palestine is occupying the area illegally.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#256
"Alexa, hack into all journalist's computers, tablets, cell phones, and while you're at it, hack into all big banks, financial institutions, stock exchanges, voting machines, military installations, CIA, FBI, NSA, DHS, government computers, foreign government computers, corporations (USA, China, heck, every foreign corporation), every database, all of hollywood, silicon valley, the justice system, state governments, democrats, republicans, russians -- in fact, just hack EVERYBODY..."

Alexa: "OK, Done! Will there be anything else?"

You: "Yes! Alexa, cross correlate the results of all that data and tell me JUST WHAT IS GOING WRONG IN THE WORLD TODAY?"

Alexa: "Done! Here are the results in URL format:"

Alexa: "

https://en.wikipedia.org/wiki/Fruit_of_the_poisonous_tree

https://en.wikipedia.org/wiki/Pre-crime

https://en.wikipedia.org/wiki/Minority_Report_(film) "

You: "Damn, Alexa, you sure are smart!

"Hey, would you mix me up a drink, like a whiskey sour, or a mojito or a bourbon or something like that?"

Alexa: "I'm sorry Dave... I can't do that... I'm not connected to a drink mixing machine..."

(Oh yeah, and watch out for this guy too:

https://en.wikipedia.org/wiki/HAL_9000 )

Disclaimer: All of the above is fiction and written for comedy purposes only!

Any and all similarities between the fiction above and anything in the real world -- is purely coincidental! )

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#257

How come when we hear about this stuff it is always Israeli companies involved? Is ethics not taught in Israeli Computer Science curricula? Those who wrote this exploit are clearly "brilliant" and at least some of them are bound to be reading Hacker News. Is other countries' spyware firms just better at hiding their malware than Israel's is?

> Is ethics not taught in Israeli Computer Science curricula? ...Is ethis taught in any CS curriculum? It sure wasn't in mine (but to be fair, that was in Switzerland).

It was a required in my program. State school, USA.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#258

How come when we hear about this stuff it is always Israeli companies involved? Is ethics not taught in Israeli Computer Science curricula? Those who wrote this exploit are clearly "brilliant" and at least some of them are bound to be reading Hacker News. Is other countries' spyware firms just better at hiding their malware than Israel's is?

It’s called selection bias. It’s fun and always acceptable to hate on Israel. It’s also more memorable due to the sensationalization of it. A few years ago bluecoat systems was caught providing deep packet inspection gear to the Syrian government. But that wasn’t Israel so no biggie and you either never heard about it or didn’t pay much attention because it wasn’t Israel. American and European companies do this all t…

You know what's even more acceptable? Dismissing any criticism of Israel as "anti-semitism", absolving them of any wrongdoing whatsoever. This happens every time like clockwork when talking about the Israeli defense industry and the horrible things they do.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#259

As someone that isn't a developer, I wonder how many zero days come from people inside the software team. To simply have knowledge of a difficult bug that hasn't been resolved would seem to be valuable commodity in a closed source system.

I didn't think this was true until I read Permanent Record, where Snowden talks about how the agencies could get stuff done through bribes or planted employees. Since knowing that, I've become a lot less certain.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#260

So, iiuc, this "zero-click" hack involved iMessage and payloads apparently injected via Apple's domains and the exfiltration of data through a tor-like network eventually reaching malicious servers. Is anyone aware of any (FOSS) software (presumably intrusion detectors or indicators of compromise) for mobile phones that might help flag or even prevent such attacks? TinyCheck [0] comes to mind, but it isn't truly mobi…

> Is anyone aware of any (FOSS) software (presumably intrusion detectors or indicators of compromise) for mobile phones that might help flag or even prevent such attacks? Assuming such applications existed, how would you install them on the "suspect" iPhone? Assuming you were able to install such applications, you'd still not have any access to or control over the baseband (which I strongly suspect has plenty of issu…

>> what would be the most secure way to keep and use a mobile phone?

My opinion: there is no secure way. My initial solution: build a home phone based on a Raspberry Pi 3B+ (with touch screen).

I already built this home phone for myself. It does only voice and SMS/MMS. It only works over Ethernet or Wi-Fi.It uses mains electricity. I wrote the software -it's Python3 and C.

I've been using this phone as my daily driver for the last year. It is very reliable.

I plan to start making it available in Jan 2021. Look for more posts here.

Post reply on HN