Live data from Hacker News

A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

googleprojectzero.blogspot.com

71–80 of 360 posts

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#71

> further demonstrating that the capabilities NSO provides rival those previously thought to be accessible to only a handful of nation states I mean the whole “nation state” or “nation state backed” hackers thing was always a liiiiitle (very) ambiguous right? Does the evidence really even move the goal post or mitigate the convenient scapegoating? Politicians and CEOs and certified IT professionals are all incentiviz…

Blaming entire nations gives domestic justification for retaliation. No point giving up a card when it's handed to you. It is in a government's best interest to exploit every opportunity handed to them -- it's less effort than fabricating a reason when you need it later.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#72
post #44

Earlier quoted context omitted.

Then you can "Enhance". https://www.youtube.com/watch?v=Vxq9yj2pVWk Joking aside, this does illustrate the "magical" properties of technology to the layperson. As a corollary, failure modes end up quite suprising and hard to reason about without a certain amount of proficiency in these technologies.

Enhancing works with trained AI these days Maybe not for evidence collection, but for pleasing a human being to go follow a lead sure

>Maybe not for evidence collection,

Kyle Rittenhouse was possibly almost convicted due to "enhance with AI".

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#73

I see "...a small computer architecture..." in the article and my instinct is to ask "Yeah-- but can it run DOOM?"

And since you already have graphical output, because it is a GIF displayed in iMessage, and you have access to gestures, since you exploited OS and can get access to any input, you should be able to have fully playable DooM in iMessage! You can even share that game with friends (who run unpatched iOS)!

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#74
post #3

This is mind boggling. NSO used a compression format's instructions to create logic gates and then from there "a small computer architecture with features such as registers and a full 64-bit adder and comparator which they use to search memory and perform arithmetic operations", all within a single pass of decompression. Combine this with a buffer overflow and you've got your sploit.

Its amazing how they took a buffer overflow and ran with it to create a whole turing complete machine. Its mind boggling how complex these exploits can be, no wonder they sell for millions

It also demonstrates how much more work there is after “buffer overflow” until you get to RCE.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#75
post #45

Since NSO is able to do these 0 click exploits on iphones does this mean they have have hacked apple engs as well and have copies of iOS lying around?

No, it just means that they've found vulnerabilities that can be triggered without user interaction. This is entirely doable by just fuzzing or reverse engineering the released iOS binaries.

go ahead, fuzz your own iOS exploit. you make it sound like someone just cranks one out before lunch.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#76
post #66

And NSO is the value option. Now imagine what nation states with an actual budget have at their disposal.

It's still pretty expensive! NSO charged a flat $500,000 fee for installing Pegasus. It charged government agencies $650,000 to spy on 10 iPhones; $650,000 for 10 Android users; $500,000 for five BlackBerry users; or $300,000 for five Symbian users.

Feels weird that a private company can target individuals for a price. How was this legal? Isn’t it illegal to hack the phone of a private individual? Or do they simply say here’s the tool, here’s the manual, do what you want just don’t tell us?

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#77
post #45

Since NSO is able to do these 0 click exploits on iphones does this mean they have have hacked apple engs as well and have copies of iOS lying around?

No, it just means that they've found vulnerabilities that can be triggered without user interaction. This is entirely doable by just fuzzing or reverse engineering the released iOS binaries.

I mean, you’re not going to fuzz your way to bit twiddling together a small virtual computer inside of a compression stream.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#78

Earlier quoted context omitted.

Signal lets you embed animated images but they still won't let you send native resolution images from your phone to someone else. Signal drastically recompresses any image sent. The only end to end encrypted software I know of that allows that is iMessage.

How could Signal recompress images while retaining end-to-end encryption? Wouldn't any "recompression" happen entirely on the client-side, and therefore be fair game for hackers to bypass with their own payloads?

they definitely don’t do this, but in principle they could use homomorphic encryption to do the compression server-side with zero knowledge

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#79

Amazing apple let this slip past. Seems pretty obvious why this is bad design, easy to exploit, etc. so maybe it was intentional and already being used by us when the NSO group caught wind through “back channels” and hopped on the gravy train.

"iMessage's .gif handling was a bit sloppy" is a believable problem; the idea that it was done deliberately to facilitate access to what amounts to a VM running in an old image compression format is a big stretch.

This isn't like goto fail, and even that one could be explained by developer oversight.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#80
post #72

Earlier quoted context omitted.

Enhancing works with trained AI these days Maybe not for evidence collection, but for pleasing a human being to go follow a lead sure

>Maybe not for evidence collection, Kyle Rittenhouse was possibly almost convicted due to "enhance with AI".

Bring it up with the appeals court in the event it occurs, unless you run out of money. Dont run out of money.
Post reply on HN