Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

281–290 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#281

Earlier quoted context omitted.

At the risk of being boring: software liability would go a long way towards getting companies to do this work themselves. Even though Apple is the largest company on the planet an entity that has a small fraction of the budget is apparently able to do a better job. I don't see why Apple couldn't make those people an offer they can't refuse. That takes them off the market and has them doing something productive.

> Even though Apple is the largest company on the planet an entity that has a small fraction of the budget is apparently able to do a better job. NSO Group is Israeli and (most likely) filled to the brim with former Unit 8200 staff. About the best of the best what the IDF has to offer - they've been said to match the NSA in quality. > I don't see why Apple couldn't make those people an offer they can't refuse. For al…

NSO seems more like a business. If Israel wanted to, they could pay NSO to keep their software internal/private, no?

The more devices that get exploited, the more exploits that get closed. That's how you lose your edge against your enemies.

Unless they're so confident in their stream of exploits that it's worth burning a few. Or these nation states are buying the devices to operate these exploits and operating them in their security labs...hrmmmmm...

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#282

We're all very lucky that CitizenLab exists as they are often the first discovery point of numerous similar exploits. They proactively scan the phones of internationally sensitive people and publish their findings. I'm not aware of any other public service that has had this much success exposing mobile device attacks. Attacks which have completely and utterly compromised the entire device that someone keeps with them…

[dead]

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#283

Earlier quoted context omitted.

Apple isn’t going to have internal bounties that can compete with nation state budgets.

Apple is a nation state.

Snap of Xi’s finger and they mostly disappear.

https://www.mediaite.com/tv/tim-cook-silent-fox-reporter-con...

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#284

The only thing preventing this would be grsec for iOS.

Grsecurity generally focuses on the kernel side of things, although it does include a number of userspace mitigations as well. Still, when you have such ripe primitives not even Grsecurity can protect you.

What we really need is to just have radically lower bug density. Buffer overflows need to die. UAFs need to be made far less common. The "distance" between vulns needs to be greatly increased. Having design and validation issues sitting smushed between a dozen memory safety issues is just not something you can deal with through software mitigation techniques.

An app like iMessage is just too sensitive (ie: unauthenticated communication with many image parsers) to be built the way that it is. Fundamentally it just can't be safe without core components being rewritten with memory safety in mind. Grsecurity and other mitigations would be an awesome defense in depth and would be particularly helpful to avoid subsequent privescs, but I'm far more concerned with "anyone can text me an image and own me thanks to 1990s style bugs".

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#286
post #122

Earlier quoted context omitted.

What is frustrating is the NSO group continues to exist despite all the bad they do. How many people are they responsible for being on the receiving end of a bone saw?

At the risk of being boring: software liability would go a long way towards getting companies to do this work themselves. Even though Apple is the largest company on the planet an entity that has a small fraction of the budget is apparently able to do a better job. I don't see why Apple couldn't make those people an offer they can't refuse. That takes them off the market and has them doing something productive.

NSO Group is just one vendor; there are many more: Variston, Dataflow, Azimuth, Cytrox, …

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#287

Earlier quoted context omitted.

> Even though Apple is the largest company on the planet an entity that has a small fraction of the budget is apparently able to do a better job. NSO Group is Israeli and (most likely) filled to the brim with former Unit 8200 staff. About the best of the best what the IDF has to offer - they've been said to match the NSA in quality. > I don't see why Apple couldn't make those people an offer they can't refuse. For al…

NSO seems more like a business. If Israel wanted to, they could pay NSO to keep their software internal/private, no? The more devices that get exploited, the more exploits that get closed. That's how you lose your edge against your enemies. Unless they're so confident in their stream of exploits that it's worth burning a few. Or these nation states are buying the devices to operate these exploits and operating them i…

The business of these companies is to develop a continual stream of exploits to counteract them being eventually patched, yes.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#288
post #23

Here we go again... NSO Group has a long history of 0-click, 0-days against iMessage, and just a few months ago Kaspersky caught a different zero day iMessage exploit targeting their staff. If Apple repeatedly fails at securing their devices from an attack vector that has been demonstrated over, and over, and over... no wonder China is banning government officials from using their devices.

>no wonder China is banning government officials from using their devices. Do you actually think security is the reason they are being banned? I think the reasons are far more political than technical.

The two issues are intertwined, and from their perspective the real risk is likely relying on a US company during a time when US/China relations are quite tense. But Apple repeatedly having 0-click 0-day iMessage exploits being used in the wild certainly doesn't help. At a minimum it's a very good justification for them to move to a domestic solution like Huawei and HarmonyOS.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#289

Earlier quoted context omitted.

Apples revenue isn’t much lower than Israel’s GDP and NSO isn’t really a nation state actor.

NSO is reported to consist of mostly Unit 8200 staff. No way they're not deeply connected with the Israeli government.

Unit 8200 is single largest Israeli military unit, their entire tech industry is filled with 82xx, 81xx and 99xx alumni.

This is what happens when you have universal conscription and the intelligence corps get their pick of the brightest conscripts.

It still doesn’t make them a state actor anymore than the dozen or so European malware vendors and the probably far more numerous US ones and that is before looking into the defense sector proper.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#290
post #109

Earlier quoted context omitted.

This is the frustrating part: that is cool from a technical perspective but terrifying when you think about this stuff being used to target journalists, activists, etc. Maybe not everyone gets the bone saw but some will - and from the sounds of it it’s people standing up to abusive people: > Last week, while checking the device of an individual employed by a Washington DC-based civil society organization with interna…

Honestly I find it a little reassuring that these are the lenghts you have to go to find a reproducible exploit. Granted the failure mode is not great…

Yeah, it’s been too slow but we have come a long way from when any motivated person could find an exploit in a binary file decoder with a day or two of work.
Post reply on HN