Should exploits like this be treated as munitions, with sale to foreign governments restricted? Or any sale at all restricted? Some thoughts: * The only uses for the exploits are either illegal or by government security organizations * I don't think you can just make an explosive and sell it to a foreign government; I think there are strict export controls (though I know very few details, I only read about companies…
No, exploits are more widely used in industry (for testing and red-teaming) than they are by governments, simply because there are more red teams than there are government-sponsored intelligence and police agencies. It's hard to imagine a scheme under which exploits could be regulated in the US that wouldn't set precedents for whether code was protected speech. I think very few people on HN would be comfortable with…
NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
91–100 of 255 posts
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#92Earlier quoted context omitted.
"iOS 9.3.5 provides an important security update for your iPhone and is recommended for all users" I can't help but think at this point we've totally lost control of our devices..
I don't get the point you're trying to make here. We've lost control because there's a serious vulnerability? We've lost control because Apple can patch the OS?
Even on desktop machines (Linux or Mac for me), there are processes running that I don't really know what they are doing. The OS is actually very complex and you could insert another process and it can go and send stuff out and it would be hard to notice. I was also thinking in context of Windows 10 sending out who knows what all the time ( I don't use windows, but I think they called telemetry..).
In the past when everything wasn't connected together and the connections were slower this wasn't as much of an issue. Although that does allow us to patch quickly and easily. Apple sees to it you'll be hounded till you update..
Its doesn't seem easy to fix. Maybe safer languages will lead to less hackable code.
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#93Earlier quoted context omitted.
As consumers we don't face very good choices right now. When you buy an iPhone, you don't own it. You are a sharecropper on Apple's OS license. If you buy an Android with an unlockable bootloader, you own it. But if attacked, the adversary owns the device. It's a shitty situation but it's hard not to recommend iOS to most users.
My Android has an unlockable bootloader but you need to actually request the key from the manufacturer. Malware can't unlock it against my will without a jailbreak. Seems like a decent arrangement to me- safe by default, but if I want to root my phone I can.
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#94Earlier quoted context omitted.
Chaining this with some form of SMS/MMS bug (a la Stagefright) would make this unbelievably powerful. That's essentially the worst case scenario I can imagine for mobile security.
Or this, from the detailed writeup linked elsewhere on this page: > To use NSO Group’s zero-click vector, an operator instead sends the same link via a special type of SMS message, like a WAP Push Service Loading (SL) message. A WAP Push SL message causes a phone to automatically open a link in a web browser instance, eliminating the need for a user to click on the link to become infected. It goes on to say that mess…
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#95Earlier quoted context omitted.
No, exploits are more widely used in industry (for testing and red-teaming) than they are by governments, simply because there are more red teams than there are government-sponsored intelligence and police agencies. It's hard to imagine a scheme under which exploits could be regulated in the US that wouldn't set precedents for whether code was protected speech. I think very few people on HN would be comfortable with…
Isn't cryptography a controlled export?
Most people don't know about it though. I think everyone thinks we won that "war" completely. Even talking to someone like Phil Zimmermann, he was wasn't aware about it.
Granted it is more about exporting to "rogue states" and more of a registration requirement. But it is something, companies (especially startups) probably forget to do. And I don't know of anyone personally who got in trouble over it.
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#96I thought it was interesting that they're using Cydia Substrate to hook into specific third-party apps for monitoring. I wonder if we'll ever see privacy conscious apps using some sort of obfuscation. So that every time you update your app, the attacker will have to reverse-engineer the symbol names again. It seems like a compile or link time tool could find method call & selector references. As long as your app isn'…
> I wonder if we'll ever see privacy conscious apps using some sort of obfuscation.
Actually Apple can do that already since they have bitcode for many applications. For now it's only required for watchOS and tvOS apps, but might become requirement for every app in future.I suppose it's close to LLVM-bytecode so perfect for obfuscation.
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#97Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#98Big budget operation!
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#99This is off-topic but at first I thought I was on a Spotify blog page. Lookout has very similar branding.
Re: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
#100https://citizenlab.org/2016/08/million-dollar-dissident-ipho... > Alarmingly, some of the names suggested a willingness on > the part of the operators to impersonate governments and > international organizations. For example, we found two > domain names that appear intended to masquerade as an > official site of the International Committee of the Red > Cross (ICRC): icrcworld.com and redcrossworld.com.
> That a country would expend millions of dollars, and
> contract with one of the world’s most sophisticated cyber
> warfare units, to get inside the device of a single human
> rights defender is a shocking illustration of the serious
> nature of the problems affecting civil society in
> cyberspace. This report should serve as a wake-up call
> that the silent epidemic of targeted digital attacks
> against civil society is a very real and escalating
> crisis of democracy and human rights.
https://deibert.citizenlab.org/2016/08/disarming-a-cyber-mer...