Live data from Hacker News

Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

citizenlab.ca

291–300 of 314 posts

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#291
post #175

Earlier quoted context omitted.

Both due to Trump, not AIPAC. Biden is likely to restore the Iran deal, at least in form. US pushing mideast peace is longstanding American policy.

You don't think Trump was influenced by powerful zionists including AIPAC and his son-in-law? Why else would he care?

Why would Trump care to withdraw from the Paris climate accord or the Cuba normalization agreement?

I'm not arguing Nethanyahu played no role, he did deploy whatever influence and persuasion he could muster, and that helped overpower the influence of those who supported the deal, like French President Macron. But ultimately it was Trump's decision, and Nethanyahu would have had to live with it had Trump made a different call.

Aside, note that nobody even thinks of easing up US sanctions on Cuba again or rejoining that agreement with Cuba. The Democratic party got such a signal from Hispanics last elections it's not even on the agenda.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#292

Earlier quoted context omitted.

I doubt it's macOS only, if you remember EternalBlue, that was called that way because it kept bluescreening on machines the NSA tested it on ...

The name came from a previous exploit called BlueKeep, which wasn't related to BSOD. In fact: "On 6 September 2019, an exploit of the wormable BlueKeep security vulnerability was announced to have been released into the public realm.[4] The initial version of this exploit was, however, unreliable, being known to cause "blue screen of death" (BSOD) errors. A fix was later announced, removing the cause of the BSOD erro…

EternalBlue is probably ancient and additionally was leaked to the public 2 years prior to BlueKeep.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#293
post #277
post #228

Earlier quoted context omitted.

They should’ve sent the phones to Apple to investigate.

Why would Apple investigate? This costs thousands of dollars and Apple isn’t a forensics service provider.

News like "zero-click iMessage to root exploit" costs Apple millions of dollars as it's a PR nightmare and erodes the trust they spent years (+tens of millions of dollars) building. Those "thousands of dollars" they would spend on forensics would be their least concern.

Imagine The Guardian, The New York Times and several other top journals covered this story with a sensational title like "Our Journalists' iPhones are hacked remotely". There's no going back from that.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#294
post #176

How come when we hear about this stuff it is always Israeli companies involved? Is ethics not taught in Israeli Computer Science curricula? Those who wrote this exploit are clearly "brilliant" and at least some of them are bound to be reading Hacker News. Is other countries' spyware firms just better at hiding their malware than Israel's is?

Israel has a large security industry with deep ties to their military. More so than other countries.

Specifically, Israel has a huge cybersecurity software business around selling oppressive regimes NSA-style tools of mass surveillance and spyware kits. This is a government-sanctioned industry (US intelligence is in this too), and doesn't seem to have any ethics. Here are some stories:

https://www.timesofisrael.com/israeli-government-okayed-sale...

https://www.reuters.com/article/us-usa-cyber-nso-exclusive/e...

https://en.wikipedia.org/wiki/Pegasus_(spyware)

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#295
post #204

Apple needs to do a serious architecture of how its own apps work. Its clearly unacceptable that their own apps are not sandboxed to the same level as everything else. If its not possible to implement all of imessage with the public APIs then they need to find a way to expose those private APIs publicly in a safe way. imessage and facetime have been a constant source of exploits.

iOS and macOS don’t allow to delete many of their apps. Why on earth I have to have iMessage if I don’t use it?

It is hard to read and impossible to send an SMS on iPad without activating iMessage. I don't understand why this hasn't been considered anti-competitive behavior already. It is completely normal to send and receive SMS messages on Android tablets...

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#296

Earlier quoted context omitted.

>human rights activists will die Most Israelis I talked to (about this specific subject; including the ones, working for NSO Group) do not understand the concept of human rights. First two questions I get are "How gives these rights?" and "Where does the list written?" in this order with the same intonation. My guess it is result of some kind of indoctrination during high school and army service. P.S. I'm israeli

Utter crap. The overwhelming majority of NSO's hiring pool -- i.e. army tech "graduates" -- are firmly against them. Another chunk doesn't care and is swayed by their 2-4x salaries, luxurious company vacations, gifts, all things to "make it up for" what you do. They're known to be "the bad guys". The tech courses we took in the army had plenty of emphasis on ethics, both the moral kind and conflict-of-interest kind.…

>tech courses we took in the army had plenty of emphasis on ethics, both the moral kind and conflict-of-interest kind

All the things done to all citizens of Israel (for example, indiscriminate movement and contact tracing) and residents of occupied territories are made possible by graduates of these courses.

Main emphasis of "emphasis on ethics" is explanation to soldiers how each choice made during a chain of events resulting in underage kid, teenager or old woman in her sixties being shot point-blank is correct and no other choice is possible.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#297

Earlier quoted context omitted.

> Is ethics not taught in Israeli Computer Science curricula? ...Is ethis taught in any CS curriculum? It sure wasn't in mine (but to be fair, that was in Switzerland).

It's no longer commonly taught, I think it was 10 years ago. It may have something to do with degree accreditation bodies but I'm not sure. Knowing Ethics doesn't really mean much, given ethicists aren't more ethical than normal people [0]. As an aside, another consideration is this isn't some private corporation, it's every government, you've got to consider the number of people before someone like Snowden popped th…

In order to understand that ethicists aren't more ethical than normal people you need a course in ontology. We sadly lack courses in ontology in most curriculum.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#298
post #192

As someone that isn't a developer, I wonder how many zero days come from people inside the software team. To simply have knowledge of a difficult bug that hasn't been resolved would seem to be valuable commodity in a closed source system.

I don't think this is a thing for two reasons : * firstly, not many people outside the security world knows that bugs are a valuable commodity for attackers. Same thing with internal orgs diagrams which are something you can sell to economic intelligence firms. * secondly, top-tier orgs like FAANG usually peppers a lot of telemetry around known bugs in production code in order to see if someone isn't exploiting them…

I struggle to understand that logic

> firstly, not many people outside the security world knows that bugs are a valuable commodity for attackers. Same thing with internal orgs diagrams which are something you can sell to economic intelligence firms.

All you need to realize its value is read some security related news for a week.

Also you can have security_interested people apply to FAANG and then cause harm.

>secondly, top-tier orgs like FAANG usually peppers a lot of telemetry around known bugs in production code in order to see if someone isn't exploiting them (or simply to better track down the root cause).

As you said - around known bugs, so it's irrelevant here

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#299
post #285

Earlier quoted context omitted.

No. It’s because they’re totally different products, and cellebrite, a forensics company, doesn’t make a version that you are describing. They make forensics products, not monitoring tools. They have nothing to do with NSO.

This certainly sounds like something that breaks into a phone to me. https://www.cellebrite.com/en/ufed/ They don’t have to have anything to do with NSO to have phone exploits that they use to gain access to the device without the owners permission.

It isn’t a backdoor or spy tool. It cannot be used for surveillance.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#300

Earlier quoted context omitted.

No, that isn’t what happened. Why are you pretending that they knew they were journalists instead of acknowledging that this incident was a tragic mistake?

Nothing in my post pretends that, and "how should we know the media card carrying unarmed civilians we shot were journalists" doesn't help their case as much as you think.

It helps it exactly as much as I think. Obviously the only one who said anything like that is you though. And now you’re falsely claiming that they intentionally targeted unarmed civilians.
Post reply on HN