Apple made its bug bounty program public a few weeks ago and the past few iOS updates have all been patching security vulns. It could be a coincidence, but from an outsider's point of view, it looks like the program is working.
NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
81–90 of 255 posts
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#82This is a REALLY, REALLY good reason why "activists" of any variety should be trained in how to acquire an old Thinkpad and install Debian on it (plus a reasonably xorg/XFCE4 desktop environment). If you're dealing with authoritarian regimes you can do a lot to reduce your attack surface. However at the end it all comes down to rubber hose cryptography. If your government, for example Bahrain decides to detain and to…
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#83Vice has a nice writeup on the exploits as well: https://motherboard.vice.com/read/government-hackers-iphone-...
FTA: It appears that the company that provided the spyware and the zero-day exploits to the hackers targeting Mansoor is a little-known Israeli surveillance vendor called NSO, which Lookout’s vice president of research Mike Murray labeled as “basically a cyber arms dealer.” Phineas Fisher, we need you now.
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#84The UAE really hates on activists, and appears to be hiring a bunch of people specifically to suppress activists/dissidents within the country. [1] Unfortunately, due to the amount of wealth the country has, it won't stop almost anybody from dealing with them unless Western sanctions are placed on the country, which are unlikely given the current geopolitical situation. https://www.evilsocket.net/2016/07/27/How-The-U…
This is the problem with surveillance technologies: they frequently end up being used not just against enemies, but anyone who disagrees with the government or threatens the status quo. Sadly, this happens even in democratic "free" countries.
Those are enemies of the state. What you consider enemies are not who everybody regards as enemies. That is why there is no such thing as allowing 'good guys' using these tools for good and preventing 'bad guys' using them for bad.
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#85Make sure to update to 9.3.5 on all of your iOS devices ASAP!
"iOS 9.3.5 provides an important security update for your iPhone and is recommended for all users" I can't help but think at this point we've totally lost control of our devices..
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#86Earlier quoted context omitted.
And quite the heads up move by Ahmed Mansoor to recognize the suspicious text for what it was and send it to the research team instead of clicking the link. If this thing really has been going since iOS 7 that means he is the outlier in taking precautions.
FTA: He had been targeted previously by FinFisher AND Hacking Team's malware. Avoiding malware is nothing new to this guy, something this NSO Group should have taken into account when they came up with their spear-phishing attack.
"When Ahmed Mansoor opened the document, his suspicions were aroused due to garbled text displayed. His email account was later accessed from the following suspicious IPs.."
https://citizenlab.org/2012/10/backdoors-are-forever-hacking...
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#87Earlier quoted context omitted.
I had the same thought as hackuser when reading the article, and then it was quickly followed by your point. I think an important first step would be to get certain things classified as arms. Once that's done, normal options may be able to handle them appropriately, such as not allowing the purchase or sale of certain types of arms within or over borders, etc. This would of course open up a whole new can of worms in…
Would it then be illegal for Google Project Zero to publish a blog post about a vulnerability that a vendor refuses to fix?
Also, I don't think this concept is limited specifically to exploiting bugs. I think a program that was meant to access and catalog social media accounts for a person while hiding it's accesses as much as possible, but run from a third party's location, might be considered an armament. Same with something designed to DoS a service.If the purpose is to cause harm, it might be an armament. I am aware there's probably a fine line here, and one that would inevitably be abused. I'm not sure how to deal with that, and whether the negatives there outweigh the possible positives overall.
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#88Make sure to update to 9.3.5 on all of your iOS devices ASAP!
Sad face. Right now, on my iPhone: "iOS 9.3.5 provides an important security update for your iPhone" 40.5 MB. Great! Tapped "Download and install". It's greyed out. Huh? Oh, "this important security update requires a Wi-Fi network connection to download". Really? It's only 40.5 MB. Let me decide, please, how I use my data. Am I missing a setting that allows me to install an important security update on a network of m…
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#89Earlier quoted context omitted.
My Android has an unlockable bootloader but you need to actually request the key from the manufacturer. Malware can't unlock it against my will without a jailbreak. Seems like a decent arrangement to me- safe by default, but if I want to root my phone I can.
"safe by default" except for the huge amount of userland vulns that Android has.
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#90Just kidding. The difference here is that a government doesn't want to do such as provide reasonable suspicion or go publicly in front of a judge.