Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

321–330 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#322
post #9

These fixes came out today, apparently timed with the announcement, make sure updates are applied for you and yours. https://support.apple.com/en-us/HT201222

Interestingly, no kernel vulnerability or anything is mentioned. As far as I know, any parsing code for iMessages should run within the BlastDoor sandbox – is there another vulnerability in the chain that is not reported here?

It may be the case that either the kernel vulnerability hasn't been analyzed or fixed yet, or that they were not able to capture it. Many of these exploits have multiple stages and grabbing the later ones is difficult.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#323
post #293

Earlier quoted context omitted.

Software liability would effectively crush smaller companies, unable to keep up with the lawsuits, because they don't have billions in the bank.

Or you’d have separate rules, similar to how you can make kit cars or ultralight airplanes without being held to the same scrutiny as Boeing or GM.

...implying the scrutiny Boeing is held to does anything beneficial.

The regulatory capture resulted in a pathological operating module that put over 346 in an early grave because they couldn't be arsed to not cut corners; then on top of ot all, there's no substantive finding of liability or wrongdoing.

Laws that are ultimately unenforced due to 2B2F might as well not exist at all.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#325
post #38
post #23

Here we go again... NSO Group has a long history of 0-click, 0-days against iMessage, and just a few months ago Kaspersky caught a different zero day iMessage exploit targeting their staff. If Apple repeatedly fails at securing their devices from an attack vector that has been demonstrated over, and over, and over... no wonder China is banning government officials from using their devices.

Please... Androids no better. At least Apple will have it patched within the year of discovery. Can't say the same for other Android vendors.

You can just avoid crappy Android vendors. 1 year is low bar.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#326

Earlier quoted context omitted.

And a much older bug with TIF rendering in iOS 4 used by jailbreakme.com back in the day. It was wonderful pressing a button in Safari and suddenly seeing my iPod touch reboot with Cydia installed.

Huh? I could've sworn the TIFF bug was during the iPhoneOS 1.x days. I recall jailbreakme's exploit using corrupted fonts in a PDF, not TIFF images. A quick Google search led me to this https://appleinsider.com/articles/10/08/03/browser_based_ios...

You're right, iOS 4 jailbreakme was PDF. But jailbreakme also existed for 1.x, using TIFF. https://en.wikipedia.org/wiki/JailbreakMe

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#327
post #215

Earlier quoted context omitted.

I guess you've never had sudo before.

I don’t see the analogy. If I could visit a website and it runs sudo commands on my machine without my input then I would be scared.

Or non-sudo commands for that matter

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#328

Earlier quoted context omitted.

I would describe a one click rootkit as terrifying as opposed to wonderful.

It was a different time. There was nothing on my iPod touch that mattered enough.

(And I could even patch the vulnerability via jailbreaking, haha)

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#329

I find it interesting that most comments here are blaming the victim (Apple’s iMessage and by transitivity its users) rather than the aggressor (NSO and its users). How come NSO isn’t yet designated as a (cyber-)terrorist group worth hunting down and extinguishing?

Apple makes security claims in a world where these types of attacks are known about and expected. They are responsible for fulfilling their own claims.

If an air bag fails, you fault the manufacturer. They don’t escape responsibility by saying it’s the other drivers fault.

I’ll also add that Apple is not the victim here, the targeted end users are.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#330
post #85
post #13

Earlier quoted context omitted.

They're slowly rewriting the whole thing in Swift which should eventually eliminate most of the non architectural attack vectors. Most of them were mitigated in iOS 14 where they did some rather large architectural changes. Edit: Further info: https://googleprojectzero.blogspot.com/2021/01/a-look-at-ime...

When I look at an initiative like BlastDoor, I'm struck by how unlikely it is that every other messaging app makes a similar investment on every platform. Does WhatsApp have a similar architecture? Has the Gmail app rewritten all its image parsers in a similar manner? Has Tinder? And sure, if you compromise WhatsApp you only get access to its internal memory and may not be able to escalate to other apps or OS storage…

They cannot, because Apple does not allow third party apps to create sandboxed subprocesses.
Post reply on HN