Live data from Hacker News

NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

citizenlab.org

71–80 of 255 posts

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#71
I thought it was interesting that they're using Cydia Substrate to hook into specific third-party apps for monitoring.

I wonder if we'll ever see privacy conscious apps using some sort of obfuscation. So that every time you update your app, the attacker will have to reverse-engineer the symbol names again.

It seems like a compile or link time tool could find method call & selector references. As long as your app isn't calling methods using strings, or doing something else tricky, I think it could work.

Or you could just write the app in swift. It's the Objective-C runtime that makes it so easy to intercept method calls.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#72
post #48

Earlier quoted context omitted.

As consumers we don't face very good choices right now. When you buy an iPhone, you don't own it. You are a sharecropper on Apple's OS license. If you buy an Android with an unlockable bootloader, you own it. But if attacked, the adversary owns the device. It's a shitty situation but it's hard not to recommend iOS to most users.

My Android has an unlockable bootloader but you need to actually request the key from the manufacturer. Malware can't unlock it against my will without a jailbreak. Seems like a decent arrangement to me- safe by default, but if I want to root my phone I can.

What i would love to see is a bootlader where i can load my own signatures. Preferably done via USB only, and by putting the device into a mode that require certain button inputs during power up.

Signed boot has uses, but we need to be sure that the user does the signing.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#73
post #48

Earlier quoted context omitted.

As consumers we don't face very good choices right now. When you buy an iPhone, you don't own it. You are a sharecropper on Apple's OS license. If you buy an Android with an unlockable bootloader, you own it. But if attacked, the adversary owns the device. It's a shitty situation but it's hard not to recommend iOS to most users.

My Android has an unlockable bootloader but you need to actually request the key from the manufacturer. Malware can't unlock it against my will without a jailbreak. Seems like a decent arrangement to me- safe by default, but if I want to root my phone I can.

"safe by default" except for the huge amount of userland vulns that Android has.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#74
post #15

Earlier quoted context omitted.

FTA: It appears that the company that provided the spyware and the zero-day exploits to the hackers targeting Mansoor is a little-known Israeli surveillance vendor called NSO, which Lookout’s vice president of research Mike Murray labeled as “basically a cyber arms dealer.” Phineas Fisher, we need you now.

So we have cyber arms dealers now. I continue to be amazed at the prophecies of William Gibson. Makes me wonder if there's anything to "remote viewing." Did he just look forward into the 21st century and write down what he saw? :) BRB, gonna go slot me an icebreaker...

I think Gibson's explanation is that the future is here, it's just not evenly distributed yet.

Others like Doctorow and Stross has voiced similar views. In Stross' case, he apparently shelved the third part of a trilogy because the NSA was outpacing him.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#75
This is a REALLY, REALLY good reason why "activists" of any variety should be trained in how to acquire an old Thinkpad and install Debian on it (plus a reasonably xorg/XFCE4 desktop environment). If you're dealing with authoritarian regimes you can do a lot to reduce your attack surface. However at the end it all comes down to rubber hose cryptography. If your government, for example Bahrain decides to detain and torture you, you're pretty much fucked.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#76
post #68

Earlier quoted context omitted.

Which foreign governments though? Not all security researchers are from your country (whichever one that may be).

I had the same thought as hackuser when reading the article, and then it was quickly followed by your point. I think an important first step would be to get certain things classified as arms. Once that's done, normal options may be able to handle them appropriately, such as not allowing the purchase or sale of certain types of arms within or over borders, etc. This would of course open up a whole new can of worms in…

Would it then be illegal for Google Project Zero to publish a blog post about a vulnerability that a vendor refuses to fix?

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#77

Should exploits like this be treated as munitions, with sale to foreign governments restricted? Or any sale at all restricted? Some thoughts: * The only uses for the exploits are either illegal or by government security organizations * I don't think you can just make an explosive and sell it to a foreign government; I think there are strict export controls (though I know very few details, I only read about companies…

> * In the 1990s, strong encryption was called a 'munition' and export was restricted. That turned out to be impractical (it was available in many countries and the Internet has no borders), morally questionable (restricting private citizen's privacy), and it fell apart. IIRC, thats still on the books. Its just one of those sleeping paragraphs since the PGP release.

The book in question: https://www.bis.doc.gov/index.php/policy-guidance/encryption

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#78

Should exploits like this be treated as munitions, with sale to foreign governments restricted? Or any sale at all restricted? Some thoughts: * The only uses for the exploits are either illegal or by government security organizations * I don't think you can just make an explosive and sell it to a foreign government; I think there are strict export controls (though I know very few details, I only read about companies…

> * In the 1990s, strong encryption was called a 'munition' and export was restricted. That turned out to be impractical (it was available in many countries and the Internet has no borders), morally questionable (restricting private citizen's privacy), and it fell apart. IIRC, thats still on the books. Its just one of those sleeping paragraphs since the PGP release.

Debian documents mention that "BXA revised the provisions of the EAR governing cryptographic software" in October 2000. Debian no longer has separate non-us repositories for crypto because of that.

https://www.debian.org/legal/cryptoinmain

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#79

Is there any way to check if an iOS device has Pegasus installed, without installing and registering for the Lookout app?

Sounds like an exploited device should be jailbroken, you could try running an unsigned binary (if it's easy to find & install one - I'm not sure).

I believe the article also says it disables the auto-update mechanism. So if you've seen an auto-update prompt recently, your odds are better.

The background audio recording must be terrible for battery life.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#80

Make sure to update to 9.3.5 on all of your iOS devices ASAP!

"iOS 9.3.5 provides an important security update for your iPhone and is recommended for all users" I can't help but think at this point we've totally lost control of our devices..

This happened the moment you bought an iPhone. Not that Android is much better: Apple (and to a certain extent, previous feature phone manufacturers) set the stage for treating consumers as too dumb to use their phones as they like, and the rest of the smartphone arena happily followed suit. There's never been a point in time where I was satisfied with the heavy constraints placed on users by smartphone OS makers. And I'm not approaching this from a Stallmanesque, philosophical perspective, but a plain old ease-of-use one.
Post reply on HN