Live data from Hacker News

NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

citizenlab.org

51–60 of 255 posts

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#51
Should exploits like this be treated as munitions, with sale to foreign governments restricted? Or any sale at all restricted? Some thoughts:

* The only uses for the exploits are either illegal or by government security organizations

* I don't think you can just make an explosive and sell it to a foreign government; I think there are strict export controls (though I know very few details, I only read about companies applying, getting approval, etc.).

* In the 1990s, strong encryption was called a 'munition' and export was restricted. That turned out to be impractical (it was available in many countries and the Internet has no borders), morally questionable (restricting private citizen's privacy), and it fell apart.

While I believe in liberty and freedom-to-tinker, as I said, this stuff has no legitimate use.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#52

Should exploits like this be treated as munitions, with sale to foreign governments restricted? Or any sale at all restricted? Some thoughts: * The only uses for the exploits are either illegal or by government security organizations * I don't think you can just make an explosive and sell it to a foreign government; I think there are strict export controls (though I know very few details, I only read about companies…

And to extend your thought further, should US based VC's be backing this? NSO is backed by San Fransisco based Fransisco Partners [1].

[1] http://www.reuters.com/article/us-nsogroup-m-a-idUSKCN0SR2JF...

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#53
post #48
post #45

There is a frustration, as a user, that as the value of the iOS exploits increase, they become more and more 'underground'. The time between OS release and public jailbreak is continually growing - and it doesn't seem to only be due to the hardening of the OS. People are selling their exploits rather than releasing them publicly. And the further underground they go, the more likely they will be utilized for nefarious…

As consumers we don't face very good choices right now. When you buy an iPhone, you don't own it. You are a sharecropper on Apple's OS license. If you buy an Android with an unlockable bootloader, you own it. But if attacked, the adversary owns the device. It's a shitty situation but it's hard not to recommend iOS to most users.

And if an iPhone is attacked the attacker...doesn't own the device? I don't follow your reasoning.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#54
post #48
post #45

There is a frustration, as a user, that as the value of the iOS exploits increase, they become more and more 'underground'. The time between OS release and public jailbreak is continually growing - and it doesn't seem to only be due to the hardening of the OS. People are selling their exploits rather than releasing them publicly. And the further underground they go, the more likely they will be utilized for nefarious…

As consumers we don't face very good choices right now. When you buy an iPhone, you don't own it. You are a sharecropper on Apple's OS license. If you buy an Android with an unlockable bootloader, you own it. But if attacked, the adversary owns the device. It's a shitty situation but it's hard not to recommend iOS to most users.

What do you mean? In this attack, the attackers leveraged a root privilege escalation exploit. So iPhones are just as owned.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#55
post #26

Amazing work by Lookout and Citizen Lab. Until this point I was not aware that Lookout provided any value-add for mobile devices. I was under the impression it was the McAfee of mobile. It sounds mean but this is the first reference to actual vulnerability discovery done by themselves on their blog, which usually reports on security updates that Google's Android security team discovered. Previous entries include such…

And quite the heads up move by Ahmed Mansoor to recognize the suspicious text for what it was and send it to the research team instead of clicking the link. If this thing really has been going since iOS 7 that means he is the outlier in taking precautions.

FTA: He had been targeted previously by FinFisher AND Hacking Team's malware. Avoiding malware is nothing new to this guy, something this NSO Group should have taken into account when they came up with their spear-phishing attack.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#56

Should exploits like this be treated as munitions, with sale to foreign governments restricted? Or any sale at all restricted? Some thoughts: * The only uses for the exploits are either illegal or by government security organizations * I don't think you can just make an explosive and sell it to a foreign government; I think there are strict export controls (though I know very few details, I only read about companies…

Which foreign governments though? Not all security researchers are from your country (whichever one that may be).

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#57
post #4

An untethered stealth jailbreak that installs without user interaction from a webview, that's almost as bad as it gets. And for iOS 7.0.0 - 9.3.4 inclusive. And with exfiltration of audio, video, whatsapp, viber, etc etc. So thorough and so bad :-/

>We recognized the links as belonging to an exploit infrastructure connected to NSO Group

So they were re-using $3 domains to send out a million dollar exploit? Am I reading this right?!

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#58
post #15

Earlier quoted context omitted.

FTA: It appears that the company that provided the spyware and the zero-day exploits to the hackers targeting Mansoor is a little-known Israeli surveillance vendor called NSO, which Lookout’s vice president of research Mike Murray labeled as “basically a cyber arms dealer.” Phineas Fisher, we need you now.

So we have cyber arms dealers now. I continue to be amazed at the prophecies of William Gibson. Makes me wonder if there's anything to "remote viewing." Did he just look forward into the 21st century and write down what he saw? :) BRB, gonna go slot me an icebreaker...

There are many private firms in the US doing the exact same thing, and have for years, except they sell exclusively to the US government/NSA. Not sure if it's more or less profitable than being a freelance "cyber arms trafficker".

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#59

Make sure to update to 9.3.5 on all of your iOS devices ASAP!

"iOS 9.3.5 provides an important security update for your iPhone and is recommended for all users" I can't help but think at this point we've totally lost control of our devices..

One upside of this is that a large percentage of devices are up to date. It's quite a contrast to other platforms (mobile or otherwise). Just how benign is big brother though?

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#60

The UAE really hates on activists, and appears to be hiring a bunch of people specifically to suppress activists/dissidents within the country. [1] Unfortunately, due to the amount of wealth the country has, it won't stop almost anybody from dealing with them unless Western sanctions are placed on the country, which are unlikely given the current geopolitical situation. https://www.evilsocket.net/2016/07/27/How-The-U…

This is the problem with surveillance technologies: they frequently end up being used not just against enemies, but anyone who disagrees with the government or threatens the status quo. Sadly, this happens even in democratic "free" countries.
Post reply on HN