Earlier quoted context omitted.
What is frustrating is the NSO group continues to exist despite all the bad they do. How many people are they responsible for being on the receiving end of a bone saw?
At the risk of being boring: software liability would go a long way towards getting companies to do this work themselves. Even though Apple is the largest company on the planet an entity that has a small fraction of the budget is apparently able to do a better job. I don't see why Apple couldn't make those people an offer they can't refuse. That takes them off the market and has them doing something productive.
NSO group iPhone zero-click, zero-day exploit captured in the wild
351–360 of 886 posts
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#352Earlier quoted context omitted.
Some of the problems with iMessage have to do with the fact that it's integrated with the system SMS app. It seems that there are a large number of legacy requirements in the GSM spec that require the Messages app to be privileged in some way, especially with regards to automatic processing of data received. There have been plenty of iMessage or Messages related vulnerabilities. I do wish there was a way to turn off…
One can't even mark all messages as read in iMessage, which seems to me like the most basic functionality. Something is really messed up in how this thing has to run if you can't do that
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#353Earlier quoted context omitted.
>Please... Androids no better. The Pixel is. >At least Apple will have it patched within the year of discovery. Can't say the same for other Android vendors. And the Pixel would have the patch released quicker.
The pixel is decent if using graphene is . Not sure if any system is good by default. Apple fans think their defaults are somehow more private or secure, mostly due to marketing.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#354Earlier quoted context omitted.
At the risk of being boring: software liability would go a long way towards getting companies to do this work themselves. Even though Apple is the largest company on the planet an entity that has a small fraction of the budget is apparently able to do a better job. I don't see why Apple couldn't make those people an offer they can't refuse. That takes them off the market and has them doing something productive.
Software liability would effectively crush smaller companies, unable to keep up with the lawsuits, because they don't have billions in the bank.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#355Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#356Earlier quoted context omitted.
If it makes you feel better the click was actually unnecessary theater.
Yeah, the whole way that the jailbreaks installed was scary enough for me to never want to go near them.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#357Earlier quoted context omitted.
I think you’re misunderstanding. Mossad likely wouldn’t let anyone pay enough. Or let NSO accept. Unless they were already friends enough to not need to worry much about cost.
I understood but am skeptical of that - they'd block sale of the entire company but I think it'd be a surprise if they prevented a bunch of Israeli nationals from accepting prestigious jobs with an American company.
2) any company doing that would have to be insanely naive or reckless.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#358Earlier quoted context omitted.
Almost all people don't want to or aren't capable of implementing image codecs, the safer languages aren't fast enough to do it in, and the people who are capable of it don't want to learn them.
All good points, but hopefully Google would be able to find the resources to overcome these?
Of course as the blog post says, just because memory safety bugs are overcome doesn't mean vulnerabilities have stopped; people find other kinds of vulnerability now.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#359Earlier quoted context omitted.
If Apple buys NSO Group and shuts it down, other firms are incentivized to enter the market especially because of the prospect of a nice payday if Apple buys the new firm, too.
Companies don't do things. People do. Shut down NSO and its skilled people will go elsewhere.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#360Earlier quoted context omitted.
At the risk of being boring: software liability would go a long way towards getting companies to do this work themselves. Even though Apple is the largest company on the planet an entity that has a small fraction of the budget is apparently able to do a better job. I don't see why Apple couldn't make those people an offer they can't refuse. That takes them off the market and has them doing something productive.
[flagged]