3 ms·
Nowadays, technology firms are going to the extremes like implementing virtual machines with a custom instruction set inside of PDF files [1], so they can sell
by LaputanMachine 4y ago
Nowadays, technology firms are going to the extremes like implementing virtual machines with a custom instruction set inside of PDF files [1], so they can sell exploits to governments who use them to spy on their enemies.
I think not much has changed. Highly sophisticated spying activities are still happening in today's world. The advanced techniques required are very valuable, and are thus only used in cases where the desired info is valuable enough, and cannot be obtained through simpler means.
Users voluntarily sharing "a ridiculous amount of information" are not the target group of today's sophisticated hacks, and were not the target group of the Selentric bug either.
[1]: https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-into-nso-zero-click.html https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...
- stavros 4y agoUsers sharing "a ridiculous amount of information" are definitely not the target group, but it sure as hell is easier when your target is in that group. Nowadays you don't need to bug a Selectric, you just need to pay some ops person half a world away a few thousand to send you all the info you need.
- peter_d_sherman 4y agoFirst of all, excellent link! Virtual machines with custom instruction sets -- seem to be a broader problem -- that they can apparently exist within a PDF file is one specific instance of this broader problem... A selected quote from the article linked: >"Short of not using a device, there is no way to prevent exploitation by a zero-click exploit; it's a weapon against which there is no defense." To the author of that article: Well, "short of not using it", that is! <g>