14 ms·
NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
- micaksica 10y agoThe UAE really hates on activists, and appears to be hiring a bunch of people specifically to suppress activists/dissidents within the country. [1] Unfortunately, due to the amount of wealth the country has, it won't stop almost anybody from dealing with them unless Western sanctions are placed on the country, which are unlikely given the current geopolitical situation. https://www.evilsocket.net/2016/07/27/How-The-United-Arab-Emirates-Intelligence-Tried-to-Hire-me-to-Spy-on-its-People/ https://www.evilsocket.net/2016/07/27/How-The-United-Arab-Em...
- 0x0 10y agoDon't forget the time they pushed an "update" for blackberries: http://news.bbc.co.uk/2/hi/8161190.stm http://news.bbc.co.uk/2/hi/8161190.stm
- walrus01 10y agoDon't forget that Etisalat is now the majority shareholder and pretty much runs PTCL, the incumbent/largest telephone and telecom company in Pakistan, either... PTCL is to Pakistan as Verizon, Frontier or Centurylink are to various regions of the US. It's the ILEC. Etisalat is not your friend. Etisalat has great marketing and is building GSM-based (LTE, etc) networks in many developing nations but it is no friend of an open internet or democratic institutions. Etisalat is the reason why in some places in the world if you try to run a VoIP to Phone system gateway, armed men with carbines will show up and ransack your offices and home. They will use their influence with whatever local government exists to "deal with" threats to their revenue and/or tax base. This has happened in Pakistan and the UAE.
- micaksica 10y ago> armed men with carbines will show up and ransack your offices and home This is a solid reminder that in the end, your ability to use defensive technology does not actually decide who calls the shots. Power is still ultimately controlled by violence.
- deleted 10y ago[deleted]
- Esau 10y agoThis is the problem with surveillance technologies: they frequently end up being used not just against enemies, but anyone who disagrees with the government or threatens the status quo. Sadly, this happens even in democratic "free" countries.
- mhurron 10y ago> not just against enemies, but anyone who disagrees with the government or threatens the status quo. Those are enemies of the state. What you consider enemies are not who everybody regards as enemies. That is why there is no such thing as allowing 'good guys' using these tools for good and preventing 'bad guys' using them for bad.
- deleted 10y ago[deleted]
- S_Daedalus 10y agoIt's just sealing their fate somewhere down the line really, in a part of the world where people have famously good memories for wrongs committed against them. Like the Saudi's, they're fine while the world desperately needs them, and the day after they don't, they'll all be dead.
- scosman 10y agoDoes anyone know if the iOS 10 developer beta 7 (public beta 6) got this patch, or are we vulnerable?
- dropalltables 10y agoWe currently believe not exploitable due to increased hardening, but still more research to be done here...
- imwally 10y agoAccording to Ars the bugs have already been fixed in iOS10: http://arstechnica.com/apple/2016/08/apple-releases-ios-9-3-5-with-an-important-security-update/ http://arstechnica.com/apple/2016/08/apple-releases-ios-9-3-...
- sigzero 10y agoApple told Ars: "Apple also tells us that these bugs were fixed in the latest versions of the iOS 10 public and developer betas, which were released last week."
- jtchang 10y agoThe article mentions how this may have been use all the way back in iOS 7 which is crazy. If you are being targeted for surveillance smartphones are a very bad idea depending on your adversary. A cheap phone that is refreshed regularly will probably be your best bet.
- S_Daedalus 10y agoI'm not sure how much I believe in any counter-surveillance methods anymore that involve a phone. Then again, I'm happy that my life doesn't include the need for that level of secrecy.
- jonknee 10y agoOn the other hand, smartphones are invaluable to most activists because they allow you to provide documentation of abuses through its various sensors (audio, video, photos, etc).
- contingencies 10y agoA cheap phone that is refreshed regularly will probably be your best bet. Don't buy it traceably or in the same place, use the same model, use the same SIM, turn it on in the same geographic location, or call the same people!
- firloop 10y agoApple made its bug bounty program public a few weeks ago and the past few iOS updates have all been patching security vulns. It could be a coincidence, but from an outsider's point of view, it looks like the program is working.
- deleted 10y ago[deleted]
- okket 10y agohttps://citizenlab.org/2016/08/million-dollar-dissident-iphone-zero-day-nso-group-uae/ https://citizenlab.org/2016/08/million-dollar-dissident-ipho... > Alarmingly, some of the names suggested a willingness on > the part of the operators to impersonate governments and > international organizations. For example, we found two > domain names that appear intended to masquerade as an > official site of the International Committee of the Red > Cross (ICRC): icrcworld.com and redcrossworld.com.
- bgentry 10y agoThis is a much more informative source. Moderators may want to merge everything into this story: https://news.ycombinator.com/item?id=12360714 https://news.ycombinator.com/item?id=12360714 Edit: that story is now flagged as dupe, can we at least get the URL changed to this much more in-depth article? https://citizenlab.org/2016/08/million-dollar-dissident-iphone-zero-day-nso-group-uae/ https://citizenlab.org/2016/08/million-dollar-dissident-ipho...
- okket 10y agoRelated: > That a country would expend millions of dollars, and > contract with one of the world’s most sophisticated cyber > warfare units, to get inside the device of a single human > rights defender is a shocking illustration of the serious > nature of the problems affecting civil society in > cyberspace. This report should serve as a wake-up call > that the silent epidemic of targeted digital attacks > against civil society is a very real and escalating > crisis of democracy and human rights. https://deibert.citizenlab.org/2016/08/disarming-a-cyber-mercenary-patching-apple-zero-days/ https://deibert.citizenlab.org/2016/08/disarming-a-cyber-mer...
- dropalltables 10y agoMake sure to update to 9.3.5 on all of your iOS devices ASAP!
- acomjean 10y ago"iOS 9.3.5 provides an important security update for your iPhone and is recommended for all users" I can't help but think at this point we've totally lost control of our devices..
- lostlogin 10y agoOne upside of this is that a large percentage of devices are up to date. It's quite a contrast to other platforms (mobile or otherwise). Just how benign is big brother though?
- wutbrodo 10y agoThis happened the moment you bought an iPhone. Not that Android is much better: Apple (and to a certain extent, previous feature phone manufacturers) set the stage for treating consumers as too dumb to use their phones as they like, and the rest of the smartphone arena happily followed suit. There's never been a point in time where I was satisfied with the heavy constraints placed on users by smartphone OS makers. And I'm not approaching this from a Stallmanesque, philosophical perspective, but a plain old ease-of-use one.
- snowwrestler 10y agoI don't get the point you're trying to make here. We've lost control because there's a serious vulnerability? We've lost control because Apple can patch the OS?
- acomjean 10y agoWell its sort of a general thing. We can't even control what runs on our devices and they run so fast you might not even notice something new running. Also stopping hacker from getting in remotely is hard for 24/7 connected devices. Even on desktop machines (Linux or Mac for me), there are processes running that I don't really know what they are doing. The OS is actually very complex and you could insert another process and it can go and send stuff out and it would be hard to notice. I was also thinking in context of Windows 10 sending out who knows what all the time ( I don't use windows, but I think they called telemetry..). In the past when everything wasn't connected together and the connections were slower this wasn't as much of an issue. Although that does allow us to patch quickly and easily. Apple sees to it you'll be hounded till you update.. Its doesn't seem easy to fix. Maybe safer languages will lead to less hackable code.
- bkmintie 10y agoVice has a nice writeup on the exploits as well: https://motherboard.vice.com/read/government-hackers-iphone-hacking-jailbreak-nso-group https://motherboard.vice.com/read/government-hackers-iphone-...
- explorigin 10y agoFTA: It appears that the company that provided the spyware and the zero-day exploits to the hackers targeting Mansoor is a little-known Israeli surveillance vendor called NSO, which Lookout’s vice president of research Mike Murray labeled as “basically a cyber arms dealer.” Phineas Fisher, we need you now.
- api 10y agoSo we have cyber arms dealers now. I continue to be amazed at the prophecies of William Gibson. Makes me wonder if there's anything to "remote viewing." Did he just look forward into the 21st century and write down what he saw? :) BRB, gonna go slot me an icebreaker...
- imron 10y ago> So we have cyber arms dealers now. See https://www.zerodium.com/program.html https://www.zerodium.com/program.html Someone who discovers/developers a remote Jailbreak like this can apparently sell it for a cool half-million.
- contingencies 10y agoFor iOS, $500k was quoted in HN-featured media recently. However, $750k was quoted on HN in response to a query perhaps two years ago.
- imron 10y agoThe same company I linked above issued a $1 million bounty for an iOS remote jailbreak vuln late last year (for a maximum of 3 different winners). By the time the bounty expired only 1 team had won. https://www.zerodium.com/ios9.html https://www.zerodium.com/ios9.html So pricing has some fluidity, but you're looking at at least 500k.
- 0x0 10y agoAn untethered stealth jailbreak that installs without user interaction from a webview, that's almost as bad as it gets. And for iOS 7.0.0 - 9.3.4 inclusive. And with exfiltration of audio, video, whatsapp, viber, etc etc. So thorough and so bad :-/
- api 10y agoI wonder if you can hit this via 4G/LTE networks? I also wonder if it works over VPNs? Or is hardware L2 adjacency (WiFi) required?
- 0x0 10y agoIt would affect anything capable of rendering html.
- drewbug 10y agoReminds me of https://en.wikipedia.org/wiki/JailbreakMe https://en.wikipedia.org/wiki/JailbreakMe
- mi100hael 10y agoI remember going into the Apple store and every iPhone on the display tables being jailbroken due to that site.
- koolba 10y ago> An untethered stealth jailbreak that installs without user interaction from a webview, that's almost as bad as it gets. And for iOS 7.0.0 - 9.3.4 inclusive. And with exfiltration of audio, video, whatsapp, viber, etc etc. So thorough and so bad :-/ Short of being triggered completely in the background by an UDP packet, what's worse than this?
- daeken 10y agoChaining this with some form of SMS/MMS bug (a la Stagefright) would make this unbelievably powerful. That's essentially the worst case scenario I can imagine for mobile security.
- Miner49er 10y agoThis vulnerability sounds like this: https://www.zerodium.com/ios9.html https://www.zerodium.com/ios9.html It was claimed November of last year. I wouldn't be surprised if this "Trident" was sold by Zerodium. Glad it's patched. Edit: I just saw the Citizen Lab article on this: https://citizenlab.org/2016/08/million-dollar-dissident-iphone-zero-day-nso-group-uae/ https://citizenlab.org/2016/08/million-dollar-dissident-ipho... They mention the Zerodium bounty as well.
- envy2 10y agoArticle mentions that there are indications this was in the wild as far back as iOS 7, suggesting this isn't directly linked to that Zerodium bounty.
- Miner49er 10y agoYou're right, missed that. Still possible the Zerodium exploit uses the same vulnerabilities.
- dogma1138 10y agoThe Article mentions that the exploit has kernel mappings going as far as iOS7. This doesn't mean this predates the bounty at all, the bug that received the bounty payout for all we know might have been simply functional on iOS 7-9 or even earlier (and who ever made the final commercial product just didn't bother). iOS7/8 is most likely still used since older iPhones stop receiving updates at some point and older iPhones are the ones you might actually find in emerging markets and developing countries. While rare you can still see people even in "developed" countries running Iphone 4's, if you go to the middle east, africa, or asia you probably see considerably more of them through being sold on the secondary markets.
- nogbit 10y agoOlder iPhones become the "kids" phone when daddy buys the new one. There are more of them out there then you think.
- landr0id 10y agoThis is off-topic but at first I thought I was on a Spotify blog page. Lookout has very similar branding.
- landr0id 10y agolol downvotes, ok hn. My initial reaction was "this is crazy Spotify found something like this", which was why I commented.
- joecool1029 10y agoIt's ok. I thought the same thing. You're not the only one.
- linkregister 10y agoAmazing work by Lookout and Citizen Lab. Until this point I was not aware that Lookout provided any value-add for mobile devices. I was under the impression it was the McAfee of mobile. It sounds mean but this is the first reference to actual vulnerability discovery done by themselves on their blog, which usually reports on security updates that Google's Android security team discovered. Previous entries include such gems as "Now available: The Practical Guide to Enterprise Mobile Security" and "Insights from Gartner: When and How to Go Beyond EMM to Ensure Secure Enterprise Mobility." I can't wait to see more great work. Lookout is now on my radar.
- jonknee 10y agoAnd quite the heads up move by Ahmed Mansoor to recognize the suspicious text for what it was and send it to the research team instead of clicking the link. If this thing really has been going since iOS 7 that means he is the outlier in taking precautions.
- redwards510 10y agoFTA: He had been targeted previously by FinFisher AND Hacking Team's malware. Avoiding malware is nothing new to this guy, something this NSO Group should have taken into account when they came up with their spear-phishing attack.
- runesoerensen 10y agoSure but how is that responsive to parent's point about Mansoor being an "outlier in taking precautions"? The reason he found out about the previous attacks was likely because he took similar precautions: "When Ahmed Mansoor opened the document, his suspicions were aroused due to garbled text displayed. His email account was later accessed from the following suspicious IPs.." https://citizenlab.org/2012/10/backdoors-are-forever-hacking-team-and-the-targeting-of-dissent/ https://citizenlab.org/2012/10/backdoors-are-forever-hacking...
- 10y ago
- epistasis 10y agoNot having heard about NSO Group before, they've been claiming to have this ability since 2014: http://blogs.wsj.com/digits/2014/08/01/can-this-israeli-startup-hack-your-phone/ http://blogs.wsj.com/digits/2014/08/01/can-this-israeli-star... What other 0-days do they have in their pockets?
- artursapek 10y agoWill 9.3.5 disable/remove the spyware on infected phones? Or does it just prevent one from becoming infected?
- biot 10y agoFrom the article: "The kit appears to persist even when the device software is updated and can update itself to easily replace exploits if they become obsolete."
- nogbit 10y agoAnd, even if your phone is updating it may be doing a fake update and then show you that you did update to whatever version Apple says is "safe" for this exploit but in fact Pegasus was in control the entire time. Get a new phone ASAP.
- nacs 10y ago... or you could just hook it up to iTunes and let iTunes flash the whole phone with the latest iOS from scratch (9.3.5 fixes these exploits) instead of letting the on-device updater do it. No need for a whole new phone.
- tannedNerd 10y agoI guess I've never dug deep into how a iPhone restore to default from iTunes works, but does it actually zero out the whole disk or is it possible for this exploit to survive that.
- nacs 10y agoThere are 2 ways. It can do a quick reinstall or it can do a full flash that wipes out everything (you can force it to do that by holding shift or the Apple key or something when clicking the restore button).
- 10y ago
- gergles 10y agoHere are the full technical details: https://info.lookout.com/rs/051-ESQ-475/images/lookout-pegasus-technical-analysis.pdf https://info.lookout.com/rs/051-ESQ-475/images/lookout-pegas...
- deleted 10y ago[deleted]
- guelo 10y agoNSO sells tools that when used violate the CFAA act. It is an Israeli company but a majority share was bought by a San Francisco based VC [0]. It doesn't seem like it should be legally allowed to exist as an American owned company. Maybe Ahmed Mansoor could sue the VC in American courts. [0] http://jewishbusinessnews.com/2014/03/19/francisco-partners-acuires-israeli-intelligence-cyber-tracking-developer-start-up-nso-for-120-million/ http://jewishbusinessnews.com/2014/03/19/francisco-partners-...
- lostlogin 10y agoA little off topic, but that link has such an obnoxious share-tab-nubbin-thingy on the side of the page.
- cloudjacker 10y agoa) Selling tools itself doesn't violate the CFAA act. A separate entity uses the tools and assumes that liability, which as we see is mitigated by sovereign immunity. b) And even if selling tools began to violate CFAA, then NSO itself would be sued. As it is a separate entity than the investors, which is the whole point of limited liability....
- darkarmani 10y agoIf you can tie the tool to any circumvention of copyright protections -- pretty broad argument (DMCA), you can be sued or arrested.
- cloudjacker 10y agoand then you lean on USC Title 17 Chapter 12 § 1201 (f) : the interoperability with other software defense, broad argument.
- guelo 10y agoThat makes more sense then my idea. But it would have to be Apple that brought the suit.
- toufka 10y agoThere is a frustration, as a user, that as the value of the iOS exploits increase, they become more and more 'underground'. The time between OS release and public jailbreak is continually growing - and it doesn't seem to only be due to the hardening of the OS. People are selling their exploits rather than releasing them publicly. And the further underground they go, the more likely they will be utilized for nefarious purposes rather than allowing me to edit my own HOSTS file. The most recent iOS jailbreak (to be able to gain root access to my iPhone) lasted less than a month before Apple stopped signing the old OS. Yet its clear this (new) quick action on Apple's part does not (yet?) stop persistent state-sponsored adversaries. It is more and more clear that to accept Apple's security (which seems to be getting better, but obviously still insufficient) I must also accept Apple's commercial limitations to the use of a device I own. And I suppose that the dividing line between the ability to exploit a vulnerability and to 'have control' is a sliding scale for every user: one man's 'obvious' kernel exploit is another man's 'obvious' phishing scam. It is not a new tension, but it does seem the stakes on both sides seem to be getting higher and higher - total submission to an onerous EULA vs total exploitable knowledge about me and my device. Both sides seem to have forced each other to introduce the concept of 'total' to those stakes, and that is frustrating. More-so when it's not yet clear which threat is greater.
- zmanian 10y agoAs consumers we don't face very good choices right now. When you buy an iPhone, you don't own it. You are a sharecropper on Apple's OS license. If you buy an Android with an unlockable bootloader, you own it. But if attacked, the adversary owns the device. It's a shitty situation but it's hard not to recommend iOS to most users.
- hackuser 10y agoShould exploits like this be treated as munitions, with sale to foreign governments restricted? Or any sale at all restricted? Some thoughts: * The only uses for the exploits are either illegal or by government security organizations * I don't think you can just make an explosive and sell it to a foreign government; I think there are strict export controls (though I know very few details, I only read about companies applying, getting approval, etc.). * In the 1990s, strong encryption was called a 'munition' and export was restricted. That turned out to be impractical (it was available in many countries and the Internet has no borders), morally questionable (restricting private citizen's privacy), and it fell apart. While I believe in liberty and freedom-to-tinker, as I said, this stuff has no legitimate use.
- AgalmicVentures 10y agoAnd to extend your thought further, should US based VC's be backing this? NSO is backed by San Fransisco based Fransisco Partners [1]. [1] http://www.reuters.com/article/us-nsogroup-m-a-idUSKCN0SR2JF20151103 http://www.reuters.com/article/us-nsogroup-m-a-idUSKCN0SR2JF...
- jacquesm 10y agoWhich foreign governments though? Not all security researchers are from your country (whichever one that may be).
- kbenson 10y agoI had the same thought as hackuser when reading the article, and then it was quickly followed by your point. I think an important first step would be to get certain things classified as arms. Once that's done, normal options may be able to handle them appropriately, such as not allowing the purchase or sale of certain types of arms within or over borders, etc. This would of course open up a whole new can of worms in the US, as we are constitutionally guaranteed the right to bear arms, but that's just makes it hard, not impossible (and could possibly even serve to provide some much needed nuance to that discussion in the US). That said, I haven't put a lot of thought into this, so a well reasoned criticism could completely change my stance.
- metafunctor 10y agoIs there any way to check if an iOS device has Pegasus installed, without installing and registering for the Lookout app?
- e28eta 10y agoSounds like an exploited device should be jailbroken, you could try running an unsigned binary (if it's easy to find & install one - I'm not sure). I believe the article also says it disables the auto-update mechanism. So if you've seen an auto-update prompt recently, your odds are better. The background audio recording must be terrible for battery life.
- startling 10y ago(From the lookout paper): "In order to maintain its ability to run, communicate, and monitor its own status, the software disable's the phone's 'Deep Sleep' functionality."
- TechNewb 10y agoI'm curious about this to. Does anyone know if there are steps that one could use with Xcode to see if any of these files exist?
- abecedarius 10y agoI have an iPad 1 which long ago was left behind by upgrades. It'd be nice to know when the vulnerabilities were introduced too. Should I stop doing anything networked with it?
- mikeash 10y agoI would definitely not trust it, at the very least. Even if this particular vulnerability didn't exist for it, there are bound to be many others that did.
- e28eta 10y agoI thought it was interesting that they're using Cydia Substrate to hook into specific third-party apps for monitoring. I wonder if we'll ever see privacy conscious apps using some sort of obfuscation. So that every time you update your app, the attacker will have to reverse-engineer the symbol names again. It seems like a compile or link time tool could find method call & selector references. As long as your app isn't calling methods using strings, or doing something else tricky, I think it could work. Or you could just write the app in swift. It's the Objective-C runtime that makes it so easy to intercept method calls.
- SXX 10y ago> I wonder if we'll ever see privacy conscious apps using some sort of obfuscation. Actually Apple can do that already since they have bitcode for many applications. For now it's only required for watchOS and tvOS apps, but might become requirement for every app in future. I suppose it's close to LLVM-bytecode so perfect for obfuscation.
- wepple 10y agoThe attacker could find a way to be in the kernel, or insert a shim between the app and OS if everything was sufficiently obfuscated.
- mikeash 10y agoThe trouble is that nearly every app does "something tricky" because it's so baked into Apple's frameworks. Every UI control calls methods using strings when you interact with it. Key-value coding and observing works extract method names from strings. Core Data uses method names to look stuff up in the underlying storage. And these things are so easy to do that it's pretty common for third-party code to do similar stuff. Reliably figuring out which methods were safe to change would be really tough.
- walrus01 10y agoThis is a REALLY, REALLY good reason why "activists" of any variety should be trained in how to acquire an old Thinkpad and install Debian on it (plus a reasonably xorg/XFCE4 desktop environment). If you're dealing with authoritarian regimes you can do a lot to reduce your attack surface. However at the end it all comes down to rubber hose cryptography. If your government, for example Bahrain decides to detain and torture you, you're pretty much fucked.
- mtgx 10y agoDebian? If it's anyone that's even 1/10 as targeted as Mansoor was, then they shouldn't use anything less than Qubes, Subgraph, or TAILS.
- walrus01 10y agoyou realize TAILS is just debian with TOR, and non persistent storage? I'm sure you can find a way to spear phish somebody and send them a Linux ELF binary that they will then execute, but accomplishing that is considerably harder than on Windows/OSX/Android/iOS.
- thingexplainer 10y ago> I'm sure you can find a way to spear phish somebody and send them a Linux ELF binary that they will then execute, but accomplishing that is considerably harder than on Windows/OSX/Android/iOS. I'm afraid people are just as foolable and code just as executable on Debian as on any other platform. Additionally, vulnerabilities on Android are likely exploitable on Debian. You will not survive an attack from a state adversary because you used Qubes, or OpenBSD, and certainly not TAILS (which is not particularly secure, just well integrated with Tor). You will survive because you are familiar with your tools of choice and you know how to secure them. As a final note, if you're being targeted by a nation state, getting an pre-owned ThinkPad will probably result in getting a pre-0wn3d ThinkPad.
- walrus01 10y ago
- matt_wulfeck 10y agoHe wasn't hacked, he was being "lawfully intercepted"! Just kidding. The difference here is that a government doesn't want to do such as provide reasonable suspicion or go publicly in front of a judge.
- timeal 10y agoYou can be sure that this vulnerability was probably discovered by some researcher, then sold to grey markets like https://www.zerodium.com https://www.zerodium.com or https://www.exodusintel.com/ https://www.exodusintel.com/ (they pay up to $1 million for a highprofile iOS exploit), who then resold it to some government who is now trying to exploit this dude's phone...
- dboreham 10y ago"we did not have an iPhone 6 available for testing" Big budget operation!
- ceejayoz 10y agoIt's a human rights lab at an academic institution. Small budget is hardly a shock. Somewhat hilariously, they appear to be funded in part by donations from Palantir.
- Osmium 10y agoAside, but does anybody else find the switch from right-to-left to left-to-right really jarring in this screenshot? https://citizenlab.org/wp-content/uploads/2016/08/image13-768x706.jpg https://citizenlab.org/wp-content/uploads/2016/08/image13-76... It has the effect of introducing a line-break into the middle of a line, rather than at either end. I've never encountered this before and it took my brain a few seconds to catch on. I'd be really curious how native bilingual readers of both a right-to-left and left-to-right language would read that. Does it look natural? Where do your eyes go first?
- itayperl 10y agoBiDi sucks, and as an RTL language speaker you learn to live with it. My native language is Hebrew, and we don't bother translating most technical terms to Hebrew. You end up with technical documents looking something like this: ".yadot patch a desaeler Apple .iOS 9.3 ni ytilibarenluv privilege-escalation a dnuof srehcraeser ehT" In newspapers, where lines are typically short, you get the effect in the screenshot in question. E.g.: "Everyone gets a day .ni tnew eH .dias eh ",off tomorrow You can't really get used to that. You actually have to read the second line sideways from the middle! By the way, typing mixed text is even worse than reading it. You have to press alt+shift every 2-3 words to switch layout. If that's not bad enough, Office 2007 (if I'm not mistaken) introduced a 0.5-1sec lag after each keyboard layout switch. Imagine typing out an entire document like that. I lost my nerve a couple of times. In many cases we avoid this issue by simply writing technical documents in English, but sometimes that's not an option.
- Osmium 10y agoThanks for this – I really appreciate the insight. That changing-input lag sounds like an absolute nightmare. Since I left my previous comment, I came across some Apple presentations on new work they've been doing in iOS 9 and iOS 10 on internationalisation including RTL and mixed-content support. It sounds like there's a lot of work still to do, but I was pleased to see they've at least started multilingual input sources now (in iOS 10, autocorrect can work with multiple languages without having to switch keyboards, though I'm guessing this only works with Latin alphabet languages for now?).
- themihai 10y ago<< Instead of clicking, Mansoor sent the messages to Citizen Lab researchers. The story is great but I really doubt this. I'm wondering what made him suspect the link? Does he send all the links he receives to Citizen Lab?
- revelation 10y agoYes, who doesn't click on random links received from unknown numbers over (get this) SMS? Some people.
- jessaustin 10y agoYeah that's almost dumb enough to indicate that this whole thing has been a cat's paw. Burn an old vuln, get everybody riled up about it, but distract them from looking for the sophisticated things you're doing when you actually want to spy on a troublesome subject.
- themihai 10y agoGiven his job I assumed he gets a lot of requests/messages from unknown people.
- cwkoss 10y agoSounds like he has been targeted by state-level actors before. He's probably suspicious of any unsolicited information sent to him.
- SanPilot 10y agoI'm a beginner when it comes to software development (mostly web development), but it seems to me that the majority of complex exploits like this involve some type of memory overflow and subsequent code execution. Shouldn't there be methods for detecting these kinds of things in source code or more priority given to preventing it in the C/low-level community?
- startling 10y agoThere are. "(Kernel) address space layout randomization" is one of them. It was circumvented here; that's part of why this is impressive.
- SanPilot 10y agoHow is it possible to put the malicious code in the correct memory spaces? Unless the attacker had a full image of the memory, I don't see how this can be accomplished.
- startling 10y agoThe second bit of the exploit chain, CVE-2016-4655, leads to disclosure of kernel memory addresses. Once a single memory address is known, you can calculate the random offset of the kernel, and then exploit the third part to overwrite the return address and return into specific chunks of kernel code ("Return Oriented Programming"), whose addresses you computed from the offset + a fixed code location. These can let you e.g. install your payload.
- Jerry2 10y agoHow does one monitor the infection of an iOS device and how do you capture and store all the stages of an infection? I've never done any reverse engineering so I'm not sure how you'd go about recording what an infection like this does to your device...
- FunctionalGuy 10y agoThe "NSO Group" is just speculation.
- eggy 10y agoUnless you are a high-value target, Apple's security seems fairly sufficient for normal use (I have Android ;)). Companies like NSO Group that state that they play both sides without any moral compass seem like a great target for Anonymous or others. Imagine the client list, and banking information as a trail to blaze!
- _nedR 10y agoThis guy seems to be quite the high-value target to warrant 3 zero-days, on ios no less. edit: What platform would be recommended, if you happen to be a high value target though. Using iOS at least seems to raise the cost of infiltration significantly judging by this http://www.forbes.com/sites/andygreenberg/2012/03/23/shopping-for-zero-days-an-price-list-for-hackers-secret-software-exploits/ http://www.forbes.com/sites/andygreenberg/2012/03/23/shoppin....
- eggy 10y agoI agree with you on iOS being the better choice, which is why there's a wink to my owning Android. I am obviously not a high-valued target. FWIW - I only journal with ink and paper. I never trust digital files, and I sometimes forget how many backups I have of the same photo or other file.
- namero999 10y agoThe other dimension to keep in mind is time. Governments can just cash out whatever {Vupen|Zerodium|rogue researcher} ask for, and get a 0-day for any major platform waiting there to be sold. Any obscure, probably less-secure platform has surely gone through less research and time becomes key: probably there will be no time to develop an exploit within your operational window.
- driverdan 10y agoTo people who work for companies that sell / invest in products that are used in unethical ways (Francisco Partners, NSO, Cisco, etc), how do you justify it to yourself?
- keyme 10y agoHow do the people working for Citizen Lab / lookout justify to themselves blowing active operations by countless police forces around the world? Ops like Mexico vs Cartels? Also, since when is selling weapons to governments unethical?
- Robin_Message 10y agoWhen the governments are oppressing their people, that's a good clue.
- chenster 10y agoI think NSA is trying to acquire them.
- Tepix 10y agoIt's curious that Signal was missing in their list of apps that can be intercepted. Are the targets not using it? Or was it just not mentioned?
- maglavaitss 10y agoSo, basically three things to notice: 1. never click on links in e-mails. 2. if you're targeted by a nation state, you're screwed. 3. everybody is vulnerable to rubber-hose cryptography.
- deleted 10y ago[deleted]