Live data from Hacker News

NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

citizenlab.org

61–70 of 255 posts

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#61
post #42

NSO sells tools that when used violate the CFAA act. It is an Israeli company but a majority share was bought by a San Francisco based VC [0]. It doesn't seem like it should be legally allowed to exist as an American owned company. Maybe Ahmed Mansoor could sue the VC in American courts. [0] http://jewishbusinessnews.com/2014/03/19/francisco-partners-...

A little off topic, but that link has such an obnoxious share-tab-nubbin-thingy on the side of the page.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#62
post #5
post #4

An untethered stealth jailbreak that installs without user interaction from a webview, that's almost as bad as it gets. And for iOS 7.0.0 - 9.3.4 inclusive. And with exfiltration of audio, video, whatsapp, viber, etc etc. So thorough and so bad :-/

Reminds me of https://en.wikipedia.org/wiki/JailbreakMe

I remember going into the Apple store and every iPhone on the display tables being jailbroken due to that site.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#63

Should exploits like this be treated as munitions, with sale to foreign governments restricted? Or any sale at all restricted? Some thoughts: * The only uses for the exploits are either illegal or by government security organizations * I don't think you can just make an explosive and sell it to a foreign government; I think there are strict export controls (though I know very few details, I only read about companies…

No, exploits are more widely used in industry (for testing and red-teaming) than they are by governments, simply because there are more red teams than there are government-sponsored intelligence and police agencies.

It's hard to imagine a scheme under which exploits could be regulated in the US that wouldn't set precedents for whether code was protected speech. I think very few people on HN would be comfortable with those precedents.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#64
post #3

Vice has a nice writeup on the exploits as well: https://motherboard.vice.com/read/government-hackers-iphone-...

FTA: It appears that the company that provided the spyware and the zero-day exploits to the hackers targeting Mansoor is a little-known Israeli surveillance vendor called NSO, which Lookout’s vice president of research Mike Murray labeled as “basically a cyber arms dealer.” Phineas Fisher, we need you now.

[deleted]

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#65
post #48
post #45

There is a frustration, as a user, that as the value of the iOS exploits increase, they become more and more 'underground'. The time between OS release and public jailbreak is continually growing - and it doesn't seem to only be due to the hardening of the OS. People are selling their exploits rather than releasing them publicly. And the further underground they go, the more likely they will be utilized for nefarious…

As consumers we don't face very good choices right now. When you buy an iPhone, you don't own it. You are a sharecropper on Apple's OS license. If you buy an Android with an unlockable bootloader, you own it. But if attacked, the adversary owns the device. It's a shitty situation but it's hard not to recommend iOS to most users.

My Android has an unlockable bootloader but you need to actually request the key from the manufacturer. Malware can't unlock it against my will without a jailbreak. Seems like a decent arrangement to me- safe by default, but if I want to root my phone I can.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#68

Should exploits like this be treated as munitions, with sale to foreign governments restricted? Or any sale at all restricted? Some thoughts: * The only uses for the exploits are either illegal or by government security organizations * I don't think you can just make an explosive and sell it to a foreign government; I think there are strict export controls (though I know very few details, I only read about companies…

Which foreign governments though? Not all security researchers are from your country (whichever one that may be).

I had the same thought as hackuser when reading the article, and then it was quickly followed by your point. I think an important first step would be to get certain things classified as arms. Once that's done, normal options may be able to handle them appropriately, such as not allowing the purchase or sale of certain types of arms within or over borders, etc.

This would of course open up a whole new can of worms in the US, as we are constitutionally guaranteed the right to bear arms, but that's just makes it hard, not impossible (and could possibly even serve to provide some much needed nuance to that discussion in the US).

That said, I haven't put a lot of thought into this, so a well reasoned criticism could completely change my stance.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#69

Should exploits like this be treated as munitions, with sale to foreign governments restricted? Or any sale at all restricted? Some thoughts: * The only uses for the exploits are either illegal or by government security organizations * I don't think you can just make an explosive and sell it to a foreign government; I think there are strict export controls (though I know very few details, I only read about companies…

> * In the 1990s, strong encryption was called a 'munition' and export was restricted. That turned out to be impractical (it was available in many countries and the Internet has no borders), morally questionable (restricting private citizen's privacy), and it fell apart.

IIRC, thats still on the books. Its just one of those sleeping paragraphs since the PGP release.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#70

Should exploits like this be treated as munitions, with sale to foreign governments restricted? Or any sale at all restricted? Some thoughts: * The only uses for the exploits are either illegal or by government security organizations * I don't think you can just make an explosive and sell it to a foreign government; I think there are strict export controls (though I know very few details, I only read about companies…

The only legitimate use of this is a jailbreak tool. Obviously 'this' being the root exploit and not the malware/data capturing portion. I agree malware like that should be treated as munitions.
Post reply on HN