5 ms·
How do all these people hack into phones all the time? Is there just a cache of 0Days that they have access to or do they just get really clever with phishing
by ragnot 5y ago
How do all these people hack into phones all the time? Is there just a cache of 0Days that they have access to or do they just get really clever with phishing attacks?
- sleibrock 5y agoAccording to the article, it seems like it was heavily based off of Apple iMessage zero-click exploits built into some platform. And even a bit of social engineering. Past that, who knows where they get exploits from? I imagine if they're renting servers with Bitcoins to perform computer attacks, these operatives are probably familiar with darknet sites for trading secrets as well.
- gonzo41 5y agoPretty much, that also have 0 days on components, so it's a matter of putting together an exploit chain that gets them what they need.
- AgentME 5y agoIf software developers were ever held responsible for defects in their software that lead to breaches of privacy and harm caused through those breaches, I wonder how quickly software development practices would change. Memory unsafe languages like C would probably disappear as a choice for new projects in a heartbeat due to the liability.
- mike_d 5y agoMoney. The going rate for iOS full chain (iMessage, Safari, or BT/WiFi exploit + sandbox escape, protection bypass, and persistence) is over two million dollars. The brokers then sell them for 2x-5x that amount. Reporting that same vulnerability to Apple can net you up to a million.
- SilverRed 5y agoIt seems pretty clear that just about every government has a large bank of exploits on just about every single system. We only hear about the ones that get exposed and fixed and not the 30 others in storage or active use.
- toomanyrichies 5y ago> The brokers then sell them for 2x-5x that amount. Reporting that same vulnerability to Apple can net you up to a million. If this is true, I'm super-curious about the economic incentives involved. According to Apple's Sept. 2020 balance sheet, they had over $143 billion in current assets on their books. They have deeper pockets than basically anyone else on Earth, including many state actors. They could 10x their current bounty and it would still basically be couch money for them. So why are 0-day brokers and their customers able to outbid them? I would think that Apple has much more skin in the game than attackers do, and much more to lose from being the #2 bidder. But judging by the going rates you mentioned, that doesn't seem to be the case. The only thing I can think of is that the small minority of parties with both the means and motive to outbid Apple (the respective governments of the US, China, Russia, etc) are in fact the ones doing so.
- spaetzleesser 5y ago“I would think that Apple has much more skin in the game than attackers do” What skin in the game do they have? As long as they aren’t viewed as way more insecure than Android vulnerabilities don’t really cost them anything.
- tptacek 5y agoJust your periodic reminder that the dollar figures here aren't apples-apples. Apple will pay you X for a vulnerability, and a broker might pay nX. But n is complicated. The ordinary way it works is that payments are tranched; you're paid in chunks, up to some cap, until the vulnerability is burnt. Once that happens, you stop getting paid, so n can be less than 1. It's also always worth pointing out, even though it's not relevant to this thread, that the vulnerabilities we're talking about all fit into a similar mold; they're all generally some form of drive-by or click-by clientside RCE (they're some of the harder vulnerabilities to find and weaponize, and, from what we can see in reporting, they're not the kinds of vulnerabilities we see lots of disputes about with vendors, though I'm happy to be corrected). And, as always, I want to point out that even at these eye-watering figures, vulnerabilities are cheap. The market competition to RCE vulnerabilities and implant kits is human intelligence. You will pay more just in health insurance and benefits overhead to run a single human intelligence program against a target. Every government in the world, from Germany to the Seychelles, can afford what the IC pays for vulnerabilities, and there's probably no figure we can realistically drive vulnerabilities to in the near future that will change that --- Iran can pull this kind of money out from under its couch cushions, and NATO and China's couch cushions are stuffed with it.
- mike_d 5y ago> The ordinary way it works is that payments are tranched; you're paid in chunks, up to some cap, until the vulnerability is burnt. Eh, it is very complicated. On one end of the spectrum you can take a cash payout up front for less money, on the other end you are under contract to keep an arsenal with specific coverage at a minimum fixed size. Brokers exist to trade risk for upside and shield parties from each other. I think we are in alignment on your second point. Oil rich companies lack domestic talent but have massive war chests of money. I have some insights into the numbers they are throwing around to skilled foreign workers and while it is clear the numbers are stupid big, it is nothing in comparison to running a HUMINT asset or buying a drone.
- Maven911 5y agoHow much would they pay for foreign skilled workers?
- diebeforei485 5y agoMore likely, Apple will lead you on for months and then pay you nothing.
- sumedh 5y ago> Reporting that same vulnerability to Apple can net you up to a million. I think there was a post on HN awhile back where the guy just got 100K for a a very major bug. So you will definitely get more money if you go rouge
- causasui 5y ago95% social engineering/phishing, maybe 5% exploits. Using exploits is complicated, expensive, and risky. In most cases - to quote XKCD - it's cheaper and easier to just hit the victim on the head w/ a proverbial $5 wrench until they cough up their password, e.g.: have them download your "secure messaging app" which is actually just your implant. From the article: > To get close to Donaghy, a Raven operative should attempt to “ingratiate himself to the target by espousing similar beliefs,” the cyber-mercenaries wrote. Donaghy would be “unable to resist an overture of this nature,” they believed. Posing as a single human rights activist, Raven operatives emailed Donaghy asking for his help to “bring hope to those who are long suffering,” the email message said. The operative convinced Donaghy to download software he claimed would make messages “difficult to trace.” In reality, the malware allowed the Emiratis to continuously monitor Donaghy’s email account and Internet browsing.
- PoignardAzur 5y agoHe fell for that? They were warning you about that trick in the 2000s!
- emkoemko 5y agothey have lots of funds to buy 0days on dark web and to hire the best.