3 ms·
Honestly, whoever the NSO Group hires must be absolute wizards with some of these hacks. I've read the in-dept writeups on some of the previous ones and they a
by EMM_386 3y ago
Honestly, whoever the NSO Group hires must be absolute wizards with some of these hacks.
I've read the in-dept writeups on some of the previous ones and they are insane. Combining 5+ seperate problems to finally achieve the goal.
I can't imagine what that interview is like.
Not that I condone any of this stuff, quite the opposite. But from a programming perspective, it's pretty incredible.
- Hortinstein 3y agoThe one where they altered a gif to invoke legacy pdf compatibility libraries that was somehow turing complete and used it to bootstrap a VM that performed memory analysis to escape a sandbox was likely the most impressive feat of engineering I have read...ever. I would love to read an entire book about how this was discovered, productized and deployed. https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-into-nso-zero-click.html?m=1 https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...
- EMM_386 3y agoYep, that one was insane. These have to be ex-employees of national security groups like the NSA, etc. who are already familiar with this type of stuff. The Stuxnet-type employees who understand everything at the deepest levels and can (and will) do anything to make it happen. Top-tier engineering. Just used for nerfarious purposes, despite the PR spin. I'm actually surprised they have a PR person. "Um, nothing to see here!" would be my standard response.