Live data from Hacker News

0-days exploited by commercial surveillance vendor in Egypt

blog.google

251–254 of 254 posts

Re: 0-days exploited by commercial surveillance vendor in Egypt

#251
post #249

Earlier quoted context omitted.

This thread keeps trying to escape down little rabbitholes of abstraction. I'll be clear: if Apple wanted to ship an EAL5 product, the very first product decision they would need to make in service of that would be to stop rendering HTML. No browsers. No rich media. No installable apps that could do any kind of IPC. This is what we mean when we say an EAL5+ product is a different kind of thing. It's why this whole CC…

I am blaming them for selling products that are inadequate for the threat environment they are expected to operate in and lying and/or insinuating that they are adequate for that threat environment, especially when they know for certain that they are not and certify as such. If the customers truly want those products and features, security be damned, like you say then they will do that even if the companies are compl…

> I am blaming them for selling products that are inadequate for the threat environment they are expected to operate in and lying and/or insinuating that they are adequate

You lost me here. Where has Apple "insinuated" anything else but "secure enough for consumers"? Really, I want to know where they promote their products as the choice to protect oneself from nation-state adversaries, because so far, the only security offers they have for iPhone users are threat notifications [0] and lockdown mode [1], and they make no guarantees on either of them.

Samsung [2] and Google [3] make similar assertions.

I believe you are targeting a strawman here, especially given the fact that there are zero consumer grade phones out there that are CC certified to a level that you may consider adequate.

> In addition, the lies suck all of the air out of the room for actual secure products because why go through the extremely hard work of actually making something secure when you can just lie about it.

This is blatantly false.

There aren't consumer ready operating systems that may replace Apple's, and are EAL5+ certified.

Unless your point is that some day you may be able to install System Z in your laptop, that is.

[0] https://support.apple.com/en-us/102174

[1] https://support.apple.com/en-us/HT212650

[2] https://www.samsungknox.com/en

[3] https://landing.google.com/advancedprotection/

Re: 0-days exploited by commercial surveillance vendor in Egypt

#252

Earlier quoted context omitted.

Would amount of critical vulnerabilities be lower if we sacrifice some performance? 10-20%?

Yes, this has been a trend for a little while now. For example this gist[1] gives linux boot parameters to make linux significantly faster and all it does is basically turn off all default security mitigations. I would make the distinction between vulnerabilities and "exploitable" vulnerabilities though. Mitigations usually give a runtime performance hit but don't remove the underlying flaws, it can just make it hard…

thanks

Re: 0-days exploited by commercial surveillance vendor in Egypt

#253
post #141

Earlier quoted context omitted.

it's http interception so no, I doubt javascript matters at all

Without knowing more, that's a bit of an assumption. The vulnerability could be in image decoding, in which case an tag is enough and no scripting is needed, but it could also very well require doing something funky with JavaScript.

if it required javascript then it was already an exploit without the mitm
Post reply on HN