Live data from Hacker News

NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

citizenlab.org

81–90 of 255 posts

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#82

This is a REALLY, REALLY good reason why "activists" of any variety should be trained in how to acquire an old Thinkpad and install Debian on it (plus a reasonably xorg/XFCE4 desktop environment). If you're dealing with authoritarian regimes you can do a lot to reduce your attack surface. However at the end it all comes down to rubber hose cryptography. If your government, for example Bahrain decides to detain and to…

Debian? If it's anyone that's even 1/10 as targeted as Mansoor was, then they shouldn't use anything less than Qubes, Subgraph, or TAILS.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#83
post #3

Vice has a nice writeup on the exploits as well: https://motherboard.vice.com/read/government-hackers-iphone-...

FTA: It appears that the company that provided the spyware and the zero-day exploits to the hackers targeting Mansoor is a little-known Israeli surveillance vendor called NSO, which Lookout’s vice president of research Mike Murray labeled as “basically a cyber arms dealer.” Phineas Fisher, we need you now.

This is just speculation. They'd have no reason to "target Mansoor" even if they had the capability.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#84
post #60

The UAE really hates on activists, and appears to be hiring a bunch of people specifically to suppress activists/dissidents within the country. [1] Unfortunately, due to the amount of wealth the country has, it won't stop almost anybody from dealing with them unless Western sanctions are placed on the country, which are unlikely given the current geopolitical situation. https://www.evilsocket.net/2016/07/27/How-The-U…

This is the problem with surveillance technologies: they frequently end up being used not just against enemies, but anyone who disagrees with the government or threatens the status quo. Sadly, this happens even in democratic "free" countries.

> not just against enemies, but anyone who disagrees with the government or threatens the status quo.

Those are enemies of the state. What you consider enemies are not who everybody regards as enemies. That is why there is no such thing as allowing 'good guys' using these tools for good and preventing 'bad guys' using them for bad.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#85

Make sure to update to 9.3.5 on all of your iOS devices ASAP!

"iOS 9.3.5 provides an important security update for your iPhone and is recommended for all users" I can't help but think at this point we've totally lost control of our devices..

I don't get the point you're trying to make here. We've lost control because there's a serious vulnerability? We've lost control because Apple can patch the OS?

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#86
post #26

Earlier quoted context omitted.

And quite the heads up move by Ahmed Mansoor to recognize the suspicious text for what it was and send it to the research team instead of clicking the link. If this thing really has been going since iOS 7 that means he is the outlier in taking precautions.

FTA: He had been targeted previously by FinFisher AND Hacking Team's malware. Avoiding malware is nothing new to this guy, something this NSO Group should have taken into account when they came up with their spear-phishing attack.

Sure but how is that responsive to parent's point about Mansoor being an "outlier in taking precautions"? The reason he found out about the previous attacks was likely because he took similar precautions:

"When Ahmed Mansoor opened the document, his suspicions were aroused due to garbled text displayed. His email account was later accessed from the following suspicious IPs.."

https://citizenlab.org/2012/10/backdoors-are-forever-hacking...

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#87
post #68

Earlier quoted context omitted.

I had the same thought as hackuser when reading the article, and then it was quickly followed by your point. I think an important first step would be to get certain things classified as arms. Once that's done, normal options may be able to handle them appropriately, such as not allowing the purchase or sale of certain types of arms within or over borders, etc. This would of course open up a whole new can of worms in…

Would it then be illegal for Google Project Zero to publish a blog post about a vulnerability that a vendor refuses to fix?

I was thinking less of the knowledge being considered an armament, and more that an actual program that takes advantage of it being one. I don't consider the the scientific knowledge required to create a gun as an armament, nor even specific schematics, but governments may view it differently (indeed, they weren't happy about the 3D printable gun).

Also, I don't think this concept is limited specifically to exploiting bugs. I think a program that was meant to access and catalog social media accounts for a person while hiding it's accesses as much as possible, but run from a third party's location, might be considered an armament. Same with something designed to DoS a service.If the purpose is to cause harm, it might be an armament. I am aware there's probably a fine line here, and one that would inevitably be abused. I'm not sure how to deal with that, and whether the negatives there outweigh the possible positives overall.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#88

Make sure to update to 9.3.5 on all of your iOS devices ASAP!

Sad face. Right now, on my iPhone: "iOS 9.3.5 provides an important security update for your iPhone" 40.5 MB. Great! Tapped "Download and install". It's greyed out. Huh? Oh, "this important security update requires a Wi-Fi network connection to download". Really? It's only 40.5 MB. Let me decide, please, how I use my data. Am I missing a setting that allows me to install an important security update on a network of m…

Go to https://bugreport.apple.com and request that. The more duplicates they get, the more likely something is to get fixed.

Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender

#89

Earlier quoted context omitted.

My Android has an unlockable bootloader but you need to actually request the key from the manufacturer. Malware can't unlock it against my will without a jailbreak. Seems like a decent arrangement to me- safe by default, but if I want to root my phone I can.

"safe by default" except for the huge amount of userland vulns that Android has.

Yeah, but that's life with a complex bundle of software. It's not as though Apple's attempt at making a walled garden makes them magically better at not writing exploitable bugs in the userland. Mostly where they're better is at making it harder for normal users to intentionally install something that turns out to be malware, which isn't nothing, but a with exploits like Trident, that makes absolutely no difference.
Post reply on HN