Live data from Hacker News

NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

citizenlab.org

41–50 of 255 posts

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#41

Make sure to update to 9.3.5 on all of your iOS devices ASAP!

Sad face. Right now, on my iPhone:

"iOS 9.3.5 provides an important security update for your iPhone"

40.5 MB. Great! Tapped "Download and install". It's greyed out. Huh?

Oh, "this important security update requires a Wi-Fi network connection to download". Really? It's only 40.5 MB. Let me decide, please, how I use my data.

Am I missing a setting that allows me to install an important security update on a network of my choosing?

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#42
NSO sells tools that when used violate the CFAA act. It is an Israeli company but a majority share was bought by a San Francisco based VC [0]. It doesn't seem like it should be legally allowed to exist as an American owned company. Maybe Ahmed Mansoor could sue the VC in American courts.

[0] http://jewishbusinessnews.com/2014/03/19/francisco-partners-...

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#43
post #32
post #27

Earlier quoted context omitted.

> An untethered stealth jailbreak that installs without user interaction from a webview, that's almost as bad as it gets. And for iOS 7.0.0 - 9.3.4 inclusive. And with exfiltration of audio, video, whatsapp, viber, etc etc. So thorough and so bad :-/ Short of being triggered completely in the background by an UDP packet, what's worse than this?

Chaining this with some form of SMS/MMS bug (a la Stagefright) would make this unbelievably powerful. That's essentially the worst case scenario I can imagine for mobile security.

Or this, from the detailed writeup linked elsewhere on this page:

> To use NSO Group’s zero-click vector, an operator instead sends the same link via a special type of SMS message, like a WAP Push Service Loading (SL) message. A WAP Push SL message causes a phone to automatically open a link in a web browser instance, eliminating the need for a user to click on the link to become infected.

It goes on to say that messages of this type are increasingly restricted by service providers and newer phone OSes, but that's still pretty horrifying to read.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#44
post #4

An untethered stealth jailbreak that installs without user interaction from a webview, that's almost as bad as it gets. And for iOS 7.0.0 - 9.3.4 inclusive. And with exfiltration of audio, video, whatsapp, viber, etc etc. So thorough and so bad :-/

Not really without user interaction. The target in this case would have had to visit the exploit site.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#45
There is a frustration, as a user, that as the value of the iOS exploits increase, they become more and more 'underground'. The time between OS release and public jailbreak is continually growing - and it doesn't seem to only be due to the hardening of the OS. People are selling their exploits rather than releasing them publicly. And the further underground they go, the more likely they will be utilized for nefarious purposes rather than allowing me to edit my own HOSTS file. The most recent iOS jailbreak (to be able to gain root access to my iPhone) lasted less than a month before Apple stopped signing the old OS. Yet its clear this (new) quick action on Apple's part does not (yet?) stop persistent state-sponsored adversaries.

It is more and more clear that to accept Apple's security (which seems to be getting better, but obviously still insufficient) I must also accept Apple's commercial limitations to the use of a device I own. And I suppose that the dividing line between the ability to exploit a vulnerability and to 'have control' is a sliding scale for every user: one man's 'obvious' kernel exploit is another man's 'obvious' phishing scam.

It is not a new tension, but it does seem the stakes on both sides seem to be getting higher and higher - total submission to an onerous EULA vs total exploitable knowledge about me and my device. Both sides seem to have forced each other to introduce the concept of 'total' to those stakes, and that is frustrating. More-so when it's not yet clear which threat is greater.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#46

Will 9.3.5 disable/remove the spyware on infected phones? Or does it just prevent one from becoming infected?

From the article:

  "The kit appears to persist even when the device
   software is updated and can update itself to easily
   replace exploits if they become obsolete."

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#47

Will 9.3.5 disable/remove the spyware on infected phones? Or does it just prevent one from becoming infected?

A Lookout page describes a post-update process involving opening the Lookout app and using it to check for an existing compromise, so it seems unlikely that the software update alone will suffice to uninfect a phone.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#48
post #45

There is a frustration, as a user, that as the value of the iOS exploits increase, they become more and more 'underground'. The time between OS release and public jailbreak is continually growing - and it doesn't seem to only be due to the hardening of the OS. People are selling their exploits rather than releasing them publicly. And the further underground they go, the more likely they will be utilized for nefarious…

As consumers we don't face very good choices right now.

When you buy an iPhone, you don't own it. You are a sharecropper on Apple's OS license.

If you buy an Android with an unlockable bootloader, you own it. But if attacked, the adversary owns the device.

It's a shitty situation but it's hard not to recommend iOS to most users.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#49
post #18
post #14

https://citizenlab.org/2016/08/million-dollar-dissident-ipho... > Alarmingly, some of the names suggested a willingness on > the part of the operators to impersonate governments and > international organizations. For example, we found two > domain names that appear intended to masquerade as an > official site of the International Committee of the Red > Cross (ICRC): icrcworld.com and redcrossworld.com.

This is a much more informative source. Moderators may want to merge everything into this story: https://news.ycombinator.com/item?id=12360714 Edit: that story is now flagged as dupe, can we at least get the URL changed to this much more in-depth article? https://citizenlab.org/2016/08/million-dollar-dissident-ipho...

That is a MUCH more detailed article. Thanks for sharing.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#50

Make sure to update to 9.3.5 on all of your iOS devices ASAP!

Sad face. Right now, on my iPhone: "iOS 9.3.5 provides an important security update for your iPhone" 40.5 MB. Great! Tapped "Download and install". It's greyed out. Huh? Oh, "this important security update requires a Wi-Fi network connection to download". Really? It's only 40.5 MB. Let me decide, please, how I use my data. Am I missing a setting that allows me to install an important security update on a network of m…

Yeah, apple needs to fix this. They have been bumping the max app size for non-wifi downloads throughout the years from 10mb to 100mb, but they haven't kept up for the actual security updates.

For extra hilarity, if you have two iphones available, you can use the personal hotspot feature between them and install the updates even though it's all 3g/4g anyways.

Post reply on HN