Live data from Hacker News

NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

citizenlab.org

31–40 of 255 posts

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#32
post #27
post #4

An untethered stealth jailbreak that installs without user interaction from a webview, that's almost as bad as it gets. And for iOS 7.0.0 - 9.3.4 inclusive. And with exfiltration of audio, video, whatsapp, viber, etc etc. So thorough and so bad :-/

> An untethered stealth jailbreak that installs without user interaction from a webview, that's almost as bad as it gets. And for iOS 7.0.0 - 9.3.4 inclusive. And with exfiltration of audio, video, whatsapp, viber, etc etc. So thorough and so bad :-/ Short of being triggered completely in the background by an UDP packet, what's worse than this?

Chaining this with some form of SMS/MMS bug (a la Stagefright) would make this unbelievably powerful. That's essentially the worst case scenario I can imagine for mobile security.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#33

Make sure to update to 9.3.5 on all of your iOS devices ASAP!

"iOS 9.3.5 provides an important security update for your iPhone and is recommended for all users"

I can't help but think at this point we've totally lost control of our devices..

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#34

The UAE really hates on activists, and appears to be hiring a bunch of people specifically to suppress activists/dissidents within the country. [1] Unfortunately, due to the amount of wealth the country has, it won't stop almost anybody from dealing with them unless Western sanctions are placed on the country, which are unlikely given the current geopolitical situation. https://www.evilsocket.net/2016/07/27/How-The-U…

[deleted]

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#35

Amazing work by Lookout and Citizen Lab. Until this point I was not aware that Lookout provided any value-add for mobile devices. I was under the impression it was the McAfee of mobile. It sounds mean but this is the first reference to actual vulnerability discovery done by themselves on their blog, which usually reports on security updates that Google's Android security team discovered. Previous entries include such…

Direct links to other resources:

Technical analysis: https://info.lookout.com/rs/051-ESQ-475/images/lookout-pegas...

CitizenLab analysis of the nation-state side of things: https://citizenlab.org/2016/08/million-dollar-dissident-ipho...

Apple update: https://support.apple.com/en-us/HT207107

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#36
post #15

Earlier quoted context omitted.

FTA: It appears that the company that provided the spyware and the zero-day exploits to the hackers targeting Mansoor is a little-known Israeli surveillance vendor called NSO, which Lookout’s vice president of research Mike Murray labeled as “basically a cyber arms dealer.” Phineas Fisher, we need you now.

So we have cyber arms dealers now. I continue to be amazed at the prophecies of William Gibson. Makes me wonder if there's anything to "remote viewing." Did he just look forward into the 21st century and write down what he saw? :) BRB, gonna go slot me an icebreaker...

> "So we have cyber arms dealers now."

Yep. And even middle men who will clear 7 figures taking a 15% fee. A dated article, but it has a "price list" of sorts, which is interesting: http://www.forbes.com/sites/andygreenberg/2012/03/23/shoppin...

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#37
post #28
post #15

Earlier quoted context omitted.

So we have cyber arms dealers now. I continue to be amazed at the prophecies of William Gibson. Makes me wonder if there's anything to "remote viewing." Did he just look forward into the 21st century and write down what he saw? :) BRB, gonna go slot me an icebreaker...

> So we have cyber arms dealers now. See https://www.zerodium.com/program.html Someone who discovers/developers a remote Jailbreak like this can apparently sell it for a cool half-million.

For iOS, $500k was quoted in HN-featured media recently. However, $750k was quoted on HN in response to a query perhaps two years ago.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#38
post #11

The article mentions how this may have been use all the way back in iOS 7 which is crazy. If you are being targeted for surveillance smartphones are a very bad idea depending on your adversary. A cheap phone that is refreshed regularly will probably be your best bet.

A cheap phone that is refreshed regularly will probably be your best bet.

Don't buy it traceably or in the same place, use the same model, use the same SIM, turn it on in the same geographic location, or call the same people!

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#40

Amazing work by Lookout and Citizen Lab. Until this point I was not aware that Lookout provided any value-add for mobile devices. I was under the impression it was the McAfee of mobile. It sounds mean but this is the first reference to actual vulnerability discovery done by themselves on their blog, which usually reports on security updates that Google's Android security team discovered. Previous entries include such…

Yep -- This is legit security research. Excellent research.
Post reply on HN