24 ms·
Hackers used zerodays to infect Windows, iOS, and Android users
- rany_ 6y agoWhy is "expert" in quotes? Aren't 11 zerodays impressive?
- sdflhasjd 6y agoIt's in quotes because it's a quote from Maddie Stone as opposed to a judgement made by the author.
- tiddles 6y agoTotally off topic, but I'm often tripped up by these multiple uses of quotes like this. Why do we use the same symbols out of a huge space for both quoting and sarcasm ?
- Bancakes 6y agoSarcasm should be put in single quotes.
- corty 6y agoThere are separate symbols for sarcasm, but in "serious" writing emoji aren't considered appropriate. And sites/software likes to restrict them, like e.g. HN, which is why the sarcasm above is marked by quotes instead of the appropriate emoji. Some earlier internet cultures used :> But I fear that is understood less widely nowadays.
- codetrotter 6y agoOn Reddit people sometimes put /s at the end of a sentence to indicate sarcasm. And then there is also the irony punctuation which looks like this: ⸮ https://en.wikipedia.org/wiki/Irony_punctuation https://en.wikipedia.org/wiki/Irony_punctuation But I have never seen anyone actually ever use it. In fact I only ever heard about it so rarely that I almost miswrote and was about to say that interrobang is sometimes used for indicating sarcasm. But when I looked it up I read that interrobang is for showing surprise of course! As for your :> there was a guy that used to use it on an IRC channel that I was on. But I never understood quite what he meant by that kind of smiley. And later I looked it up and in his case I think the description I saw on Urban Dictionary fit pretty well, which said it was like a mischievous or devious smile. And I guess that also fits good for when you are sarcastic. Ever since I read that definition of :> it makes me think of this cartoon grinch smile https://meme.fandom.com/wiki/The_Grinch_Smile https://meme.fandom.com/wiki/The_Grinch_Smile
- smolder 6y agoNot a linguist or anything, but I'd say there's really just two categories: direct quotes (usually with a source), and then scare quotes which are used to communicate that you don't endorse the usage of the contained word(s).
- rzzzt 6y agoBBC articles tend to use it a lot, it's probably part of their style guide. I snicker quietly at each title that "is worded" like "this", imagining a Dr. Evil air quoting each segment dutifully.
- deleted 6y ago[deleted]
- deleted 6y ago[deleted]
- cyberpunk 6y agoIt looks like the chain here was 'visit some site via browser' -> 'kernel exploit' on ios, windows and android. I'd call whoever is responsible for such a valuable amount of 0days expert/nation state level for sure.
- pacificmint 6y agoIf a PC is infected I can (and should) reinstall everything from scratch. That should remove the malware, barring some super resistant malware that hides in the BIOS or something like that. What do you do on an iOS device? Does a full device reset reinstall the OS, or does it simply remove all user settings? I feel like the locked down nature of iOS makes it harder to attack, but if an attack goes thru it would also make it harder to clean up the attack?
- jsty 6y agoIf you're going against an adversary capable and willing to drop multiple zero days to breach you, let alone 11, I wouldn't wager much on a simple system wipe getting you back to a good state (iOS or not). Given the price of iOS devices vs good security consultant hourlies, the easiest and most effective clean-up for a few devices is likely just starting over.
- corty 6y agoReinstalling everything from scratch is a good start, but persistence of an exploit can easily be achieved through most data backups. Nobody wants to part with their important Word and Excel files, so those will get restored onto the fresh machine, carrying all the usual embedded macro nasties that an attacker planted there. Of course you can try to be diligent and skip everything that is potentially a problem, but it is even harder than reinstalling and the data you are dropping is usually more valuable than the OS installation.
- saagarjha 6y ago> persistence of an exploit can easily be achieved through most data backups Not on iOS.
- pabs3 6y agoThere is a bootrom exploit called checkm8 (and corresponding jailbreak called checkra1n) for some iOS devices, you could exploit that, which lets you run code before any possible malware, then use that code to wipe the device and reinstall iOS, although I expect it would be hard to obtain a pristine copy of all the firmware in all the parts of the SoC. https://checkra.in/ https://checkra.in/
- cyberpunk 6y agoMaybe a better link: https://googleprojectzero.blogspot.com/2021/03/in-wild-series-october-2020-0-day.html https://googleprojectzero.blogspot.com/2021/03/in-wild-serie...
- strogonoff 6y agoIt seems that a watering hole attack by definition targets users of a particular organization, but articles on this event make no mention of which organizations would that be, sounding like it affects general public. Wondering who should be worried. Related: can community recommend some forums, periodic publications or other sources that aggregate information security news?
- gerdesj 6y ago"can community recommend some forums" Keep an eye on r/sysadmin in Reddit.
- strogonoff 6y agoThanks!
- deleted 6y ago[deleted]
- molsongolden 6y agoRisky.biz podcast r/netsec
- strogonoff 6y agoNice, didn’t know about Risky.biz!
- donatj 6y agoThe scare quotes in the title read as sarcasm but they clearly didn’t intend them as such. An odd choice as I almost overlooked the article assuming it was a tale of some failed hackers.
- ChrisSD 6y agoThe author uses quotes as actual quotes instead of as scare quotes. I'm not a fan of "scare" quotes so I'd be very pleased if other journalists did the same even if it takes some getting used to.
- egeozcan 6y agoI use "(!)" when I mean sarcasm: > Expert (!) hackers used... I hope then it's clear they are not experts really and when I say "experts" it's clear that I'm just quoting.
- justusthane 6y agoI would not understand that you were using that to indicate sarcasm—I would think you were emphasizing the fact that they're experts. I also don't think that usage is in any style guide, so you're not going to see journalists doing it. On the other hand, using quotation marks to indicate sarcasm or irony is normal use and is in style guides. You just have to rely on context to differentiate. The headline of the linked article is pretty ambiguous and like GP I read them as sarcasm. I think it was a poor choice to include them at all in this case—they don't add anything to the headline.
- egeozcan 6y agoI don't know why started using it but it's in wiktionary so everyone should (!) understand it: https://en.wiktionary.org/wiki/ https://en.wiktionary.org/wiki/(!) I don't know why started using it but it's in wiktionary so "everyone should" understand it: https://en.wiktionary.org/wiki/ https://en.wiktionary.org/wiki/(!) I guess, as you also mentioned, without enough context around it, both are hard to understand.
- sneak 6y agoHow long until we realize that JIT was a mistake and that we should offer orders of magnitude slower JS in browsers that is actually safe (or start building webpages without JS at all again, which will probably never happen) lest we give every website the ability to take over our device? I'd pay real money for a browser with a slow, safe JS interpreter.
- high_byte 6y agowhy do you assume an interpreter is any safer than JIT? kinda like saying arrays are better than matrices.
- throwaway33432 6y agoA JIT will write to memory and then turn the executable bit on. https://en.wikipedia.org/wiki/W%5EX https://en.wikipedia.org/wiki/W%5EX
- high_byte 6y agoyou are implying this is the underlying cause for code execution exploit, it is not.
- Randor 6y agoActually with the font exploits an interpreter would be quite a bit safer. Many of the font exploit chains work by creating line vectors that result in an infinity or NaN throwing a floating point error (with the SeH handler already being overwritten). When running this by JIT... all of this is occurring on the physical CPU. If the floating point calculations were occurring inside an interpreter then the SEH chain can be protected by SEHOP/SAFESEH and the interpreter could implement bounds checks and while retaining the NX bit on everything executing.
- high_byte 6y agoa. closing one attack vector does not justify slowing down the entire world. b. you can have the jit compile with any bound checks as you suggested, so still not justifying an interpreter. the only reason for an interpreter is simplicity, once you have a jit there's no logical reason to go back. also when you say NX bit, you do know the interpreter is running code still. it's just doesn't have to be RW (actually jit don't either) which still allows for ROP. there has to be some very specific exploit for these things to have a dramatic effect (ie. can be vs. cannot be exploited) many times there will be several methods to exploit a vuln.
- swebs 6y ago>The importance of keeping apps and OSes up to date and avoiding suspicious websites still stands. Unfortunately, neither of those things would have helped the victims hacked by this unknown group. Disabling Javascript would have helped. You can even use tools like uMatrix to set exceptions per site so you're not exposing yourself to every single site on the internet by default. Though you won't see online news sites suggest this since their revenue is so tied to Javascript being enabled.
- Jonnax 6y agoThe reason why general computing sites don't recommend it is because users won't be happy when they can't sign into their bank or use other websites they wish to use. The average user doesn't know anything about how sites are constructed. Telling them to use uMatrix is non sensical. Though that's not to say there's good advice on these kinds of sites. I've seen a "Windows 10 tips" list from a very popular site telling users that "they don't like being patronised about their own computer" and recommends turning off UAC (Essentially running their account as root) Or even saying that updating your OS is frustrating so here's how to disable it. Absolutely dangerous advice but that's the level of general computer sites.
- cute_boi 6y agoYep Regarding Update/UAC Please blame microsoft. I don't want forced updates when I am working. And many time I have encountered issues like computer not booting. After updates they prompts "Please install our cool new software called edge". I want security update not the marketing update. So I make a compromise and disable update all together. Why not give linux style update where I can review each and every package.
- httpsterio 6y agoBecause you most likely didn't buy the product called Windows 10. Rather, you're using the service and you are in fact the product. W10 education and enterprise licenses allows you to manage the updates yourself.
- 6y ago
- dave_sullivan 6y agoBeen playing with tools like angr lately and learning more about binary analysis. It seems to me that "automatic exploit generation" is improving quite a bit where the infrastructure for analysis is a little tricky to set up, but then you can direct that infrastructure to analyze the code for you. The bad guys and good guys are in a race to find new exploits faster (they always have been) but I've been pretty amazed by the direction I see things going with automation. I might just go back to pen and paper at this point.
- ancarda 6y ago>I might just go back to pen and paper at this point. Maybe you kid, but... I've been using a physical calendar on the wall this year. I also replaced my Apple Watch with a Casio F-91W some time ago. You know what's really great? My calendar or watch never gets hacked and it's never unavailable because some overnight software update broke it! Sure, the F-91W technically runs software, but it has no connectivity. That's the important part. Now if I could just figure out what to do with my phone... I don't think dumb phones are particularly secure, so maybe it makes sense to keep using Android? Or eventually switch to Linux on my phone?
- sausage_dog 6y agoI suppose this year is different but what about when you're outside and you want to check your calendar? Do you copy everything to a pocket calendar and risk them going out of sync?
- ancarda 6y agoSo far that hasn't really come up. How often do you need to check your calendar outside? Maybe I don't need to very much because I work from home. Here's some possible scenarios though: * If I need to remember when something is going to happen, such as "I'm leaving my house to meet a friend at 4 PM", I can just commit to memory what time it was suppose to be. * If there's a lot of stuff happening, then I'd make a note on my phone. If the times of events change while I'm out, it doesn't really matter if my calendar at home is out of sync. I'm just going to cross the day off when I get back. * If I find out a later date will change ("the user group has been moved to Thursdays"), then I'll leave myself a reminder on my phone. Most of the things on my calendar are actually little post-it notes, so I can move things around. I only write things in ink when they will never change, like national holidays that are already scheduled/set in stone. So far, I haven't really run into any pain points. The drawbacks of paper calendars just aren't enough to overcome the drawbacks of electronic calendars.
- headmelted 6y agoProbably a stupid question to ask, and I realise the bigger picture here is that there are sophisticated groups searching for complicated exploits all the time, but are these specific exploits addressed already in the latest software updates for the affected platforms? Wasn’t clear to me from the article, although I may just have missed it being the idiot that I am.
- iSnow 6y agoUsually, security researchers communicate exploits to the companies that build platforms before publishing so they get a chance to plug the holes. Of course it happens that those companies just don't react but with such a high-profile zoo of exploits, their security guys would be scrambling.
- deleted 6y ago[deleted]
- choeger 6y agoI said this once and I'll say it again: To counter such threats we need a healthy heterogeneous ecosystem. According to the article, the attack would have been prevented by using Firefox, (because it relied on a Chrome CVE). It also did not work on Linux and presumably not on Apple's ARM CPUs. But unfortunately we don't get exponential security. Normally, one would expect that n variables (Browser, OS, CPU architecture) with three choices each should give you 3^n required exploits to cover all combinations. But unfortunately, n is rather small nowadays, the number of choices shrinks every year, and -even more worrying- the attack vectors compose extremely well so you actually just need 3n exploits. So I am a little bit at a loss here how we can make such attacks non-economical again.
- arnaudsm 6y agoExactly how biodiversity protects us from diseases.
- foolmeonce 6y agoBut this is reversed for a watering hole bug against an organization. They only needed to get into one stack one member of the org uses and stay. Their reason for releasing multiple chains of attack at once instead of whenever their current attack is patched is unclear unless they want to get into multiple organizations where some avoid a diversity of exploitable software.
- enkid 6y agoBut these are attacks that worked across multiple systems. Heterogeneity is going to lead to more systems with less overall security work being done per system. Sure, using Firefox would have prevented the attacks we know about, but who's to say Google found all of the attacks. They exploit Chrome, Samsung browser, Windows, Android, iOS, and Safari. It seems silly to say "if we had one more, it would have stopped them."
- caslon 6y ago> They exploit Chrome, Samsung browser, Windows, Android, iOS, and Safari. It seems silly to say "if we had one more, it would have stopped them." Samsung's browser and Chrome share 100% of attack surface; Safari and Chrome share likely near 70%. Windows and Android have Chrome built-in at the OS layer, iOS has Safari built in at the OS layer. In this case, something like Firefox which shares much less attack surface would in fact solve the problem, because the problem is that other things have Chrome at the OS-level.
- ddtaylor 6y agoWhat sites were targeted?
- jokoon 6y agoI really don't understand why people decide to work in computer security, today it's really an arms race. I see how it's like games of lockpicking, but honestly I don't understand the value of it. It's like being in the arms trade: what matters is who you decide to trade with. Honestly, I'd rather see myself as anti-cyber-war at this point, like anti-war protests, meaning telling people to use computers for less critical tasks, and disengaging from certain areas.
- kube-system 6y agoIf you don't want it to happen, then why not become one of the people trying to prevent attacks from being successful? The best way to stop future attacks is to make current attacks unsuccessful.
- jokoon 6y agoIt's more interesting to understand the motives of attacks. Often, attacks have a geopolitical or political motive. So the whole point of security, digital or physical, is power. For now, I really don't see the point of working in security for a single reason: there is NO REGULATION on measures of security when writing software. You can find millions of regulations for making physical products, but very few for software when it comes to security. Of course, governments have higher standards, but law should mandate that insurance companies be able to evaluate cyber risks, so there should be regulations regarding computer security.
- qw3rty01 6y agoUnlike lockpicking or actual arms races, it is possible to write software such that the only weak point is the people using it. Ideally all software would be formally verified, but that's a bit too cost/time expensive to be practical for everything, so instead computer security focuses a lot on minimizing attack surface and getting as close as possible to that "humans are the weak point" goal. Even if a 0day exists for particular software, if there's no way to reach it, then it's as good as being nonexistent.
- cutemonster 6y ago
- upofadown 6y agoThe actual exploited bugs were mostly found in the OS but this is really about browsers. A contemporary browser pretty much exposes your entire OS to remote attacks. You want to exploit font interpretation? No problem, the browser will happily download your malicious font. There has to be a better way. This isn't working...
- ancarda 6y agoThe only thing that comes to mind is having most websites be sites and not apps. Most sites don't need custom fonts, JavaScript, and CSS. If Firefox & Chrome had support for something lightweight like Gemini (https://gemini.circumlunar.space/ https://gemini.circumlunar.space/) then most sites could just use that. With that sort of setup, restrictions on the web like uMatrix would be a lot less painful because most sites wouldn't ever need to be whitelisted.
- sodality2 6y ago>If Firefox & Chrome had support for something lightweight like Gemini (https://gemini.circumlunar.space/ https://gemini.circumlunar.space/) then most sites could just use that. But they wouldn't, because they couldn't track people.
- ipaddr 6y agoWhy do you think firefox is tracking you?
- sodality2 6y agoIt was a response to >most sites could just use that They wouldn't use it (or the VAST majority wouldn't) because it means losing tracking.
- Delk 6y agoI guess in an ideal world, the default might be something simple enough (akin to Gemini), and using a more flexible and complex technology that comes with all the security and privacy implications would be distinguishable from the simpler sites and using them would require and allow user discretion. That might place web apps somewhere between plain websites and applications installed on the computer (or phone or whatever). If implementing your site as an app rather than using something like Gemini came at the price of making people think twice, in theory there might be an incentive to only do web apps when it's actually needed. But of course not that many people would use that kind of discretion, not to mention "ooh, shiny!" And it's hard to put the genie back in the bottle anyway.
- boringg 6y agoCurious why there isn't more specificity in the article? Is it to protect the sites and allow them time to fix? I'm not asking in a derogatory fashion, more trying to figure out the level of potential exposure I have myself. Tough to determine from the article.
- GartzenDeHaes 6y agoHackers ARE using zerodays to infect EVERYTHING. I really can't understand why people continue to just assume that their endpoints and networks are clean. Worse, they then use the lack of security events to justify not buying the tools and expertise that are necessary to identify compromises. EDIT: not just zerodays. Many organizations have patch schedules that are too slow.
- Taylor_OD 6y agoI think the average person doesn't know how to prevent it and believes that learning out would be beyond their abilities.
- jbverschoor 6y agoNo, they just really don’t care. If they did, there would be more effort and knowledge about the subject
- saagarjha 6y agoThere is very little the average person can do to protect themselves, other than just avoiding using the internet altogether.
- sloshnmosh 6y agoMy guess is that the watering hole websites were probably browsed by minorities frowned upon by the Chinese state. The Volexity blog covers some of the earlier watering hole attacks in more detail.
- trepatudo 6y agoEven if it this worked on Linux, would a chrome running in flatpak sandbox be able to escalate privileges?
- brundolf 6y agoIt hints but doesn't outright say that these attacks were highly targeted to specific people, and not the general public; is that known?