5 ms·
I realize it's a really sexy headline, but I'd like for there to be more than 0 proof that this is a real thing. Especially if they claim a vulnerability that's
by mont 8y ago
I realize it's a really sexy headline, but I'd like for there to be more than 0 proof that this is a real thing. Especially if they claim a vulnerability that's exploitable by only sending a text.
- qaq 8y agoI would imagine details of such an exploit are worth more than A million so doubt people would be eager to share
- swebs 8y agoThis article doesn't cite sources, but the other one cites Lori Stroud, a former developer of the application. https://www.reuters.com/investigates/special-report/usa-spying-raven/ https://www.reuters.com/investigates/special-report/usa-spyi...
- bkdbkd 8y agoA much more technical description of the program. Thank you.
- ganoushoreilly 8y agoLauri did not develop the program. She was an solely an intelligence analyst.
- kuuspa 8y agoI am 100% sure this is an exploit related to PDU mode SMS messages. Tons of phones of different brands are probably vulnerable to variations of this attack.
- newaccoutnas 8y agoI think the asertion that it's on the baseband is correct, for sure
- zozbot123 8y agoThere have been similar vulnerabilities in iOS before, such as the crashing bug that could be exploited by sending a single malformed ligature/combined character in some incredibly obscure Indian script.
- lawnchair_larry 8y agoThere is no reason to doubt this. It wouldn’t be the first time such a vulnerability was found.
- shittyadmin 8y agoThere've been similar issues in both iOS and Android before - iOS had one recently where a text would cause repeated app crashes. Back in 2009 there was a full exploit via SMS on iOS, and just a few years back the Android stagefright exploit was barely spared from turning into a giant worm due to exploit mitigations and the diversity of devices. It's quite possible to see these attacks come to light in a much scarier way. That exploit is solid gold and they probably paid a small fortune for it.
- alasdair_ 8y ago>Especially if they claim a vulnerability that's exploitable by only sending a text. For some time, it was possible to crash some iPhones by texting them a Taiwanese flag emoji (which was censored by mainland China). https://www.cultofmac.com/561635/apples-taiwanese-flag-ban-leads-to-iphone-crashes/ https://www.cultofmac.com/561635/apples-taiwanese-flag-ban-l... I don't know offhand if this was a buffer overflow or something else, but if you can crash the OS with a text, you . could likely exploit it instead.
- brisance 8y agoThe description of the hack fits StageFright perfectly[1], which was exactly what it did. The sources may have just changed the affected platform to iOS to gain some traction. [1] https://en.wikipedia.org/wiki/Stagefright_(bug) https://en.wikipedia.org/wiki/Stagefright_(bug)