Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

881–886 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#881

Earlier quoted context omitted.

There has been plenty of material to reference but all those topics do not benefit space karen so he does not bring them up. [1]: https://en.wikipedia.org/wiki/Anti-Defamation_League#Recepti...

Thanks for clarifying. I'm not familiar enough with this organization to either stake a position for or against, but one passing observation based on that wiki page : > Right-wing groups and pundits, including right-wing Jewish groups, have criticized ADL as having moved too far to the left under Jonathan Greenblatt, labeling it a "Democratic Party auxiliary" > In August 2020, a coalition of progressive organizations…

To me, the ADL doesn't seem right or left within the US. The evident goal of their org today is to silence criticism of US-Israel relations and run PR for Israel in general, which makes sense given its founding org. That's its own thing, in fact it'd be counterproductive to do it in a partisan way.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#882
post #531

Earlier quoted context omitted.

> I would argue that iMessage is way to problematic to be used safely, at all. Maybe I'm missing something but every single time the only part of iMessage (actually Messages.app) that is insecure is the bit that automatically unfurls attachments and the payload is exploiting a vulnerability elsewhere. So any other app unfurling the attachment thus triggering the payload would be equally vulnerable. Imagine ping had a…

> So any other app unfurling the attachment thus triggering the payload would be equally vulnerable. What you're missing is that iPhone's app sandboxing applies to other apps, not to iMessage. Sure, imessage does have blastdoor and some sandboxing, but it also still has imagent: https://googleprojectzero.blogspot.com/2021/01/a-look-at-ime... imagent runs as root and processes incoming messages. whatsapp or signal or…

Why would they give that specific process (imagent) that much privilege? Can nefarious motives be inferred from such a choice? It seems pretty damning to me that a glorified GIF processing helper is given root access to the entire system. It just doesn't add up that this is all accidental.

What are the odds that something like the NSO just happens to luck into being able to remotely initiate and sustain the building of an entire Turing-complete internal and unauthorized computer internally that also happens to be able to override all hardened protections to the contrary? It just seems so unlikely that there was not a hand in facillitating this internally at Apple. That's what happened with the GreyKey guy...

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#883
post #649
post #436

Earlier quoted context omitted.

Curious why no fix is out for iOS 15 yet. Is iOS 15 not vulnerable to this attack? Or is there often a delay in backporting security fixes that I'm not aware of? And if so, should I be implementing a workaround if I wanted to protect against these exploits?

Active support ended a year ago (12 Sep 2022), but somehow it still saw a security release on 24 Jul 2023. Perhaps we will see one more?

They've been supporting iOS 15 with security updates for devices that can't update to iOS 16. Not sure how long they'll continue doing it but I imagine it'll be for a good while.

Looks like they just released an update that fixes CVE-2023-41064 at least: https://support.apple.com/en-au/HT213913

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#884

Wow, so much discussion of Apple and their software, and so little of NSO group and why they're even a thing. I just want to add this: these people operate pretty much in the open. They're not ashamed of it either, or else they wouldn't put it on their CV: https://www.linkedin.com/company/nso-group/people/ That right there tells me that we as "the tech community" are way too okay with this sort of application of the…

Security holes will be hunted down and exploited in whatever is popular.

That is a law of nature and no amount of shaming will change it.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#885
post #865

Earlier quoted context omitted.

> unless you've personally vetted the code I don't see how it can be trusted. As opposed to proprietary Google code that cannot be vetted?

What about the proprietary binary blobs that Graphene is reliant on? Who vetted those?

I think that we both can agree that less = better, so I don't see your point.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#886
post #587

Earlier quoted context omitted.

You don't have to use iCloud Backup.

It's on by default, which means everyone you iMessage with is escrowing the keys that allow Apple to decrypt all of the messages. Turning it off on only one end of the conversation has no meaningful effect.

Fair point.
Post reply on HN