4 ms·
Protecting against these vulnerabilities involves a lot more than just the OS. On this topic, see this incredible multi-step exploit from Google's Project Zero
by thamer 3y ago
Protecting against these vulnerabilities involves a lot more than just the OS. On this topic, see this incredible multi-step exploit from Google's Project Zero team, which goes from exploiting the Wi-Fi firmware to eventually gaining read-write access to the entire memory: https://googleprojectzero.blogspot.com/2017/10/over-air-vol-2-pt-3-exploiting-wi-fi.html https://googleprojectzero.blogspot.com/2017/10/over-air-vol-...
> During our research, we explored several components, including Broadcom’s Wi-Fi firmware, the DART IOMMU, and Apple’s Wi-Fi drivers […] We’ve also seen how the iPhone utilises hardware security mechanisms, such as DART, in order to provide isolation between the host and potentially malicious components.
Companies like NSO Group are certainly capable of developing exploits of this complexity, as Google's team has shown. Their analysis of NSO's FORCEDENTRY exploit showed NSO building a mini-VM from scratch within a little-known image codec used by the iMessage PDF engine: https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-into-nso-zero-click.html https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...
It is extremely difficult to defend against teams that have this amount of skill and dedication.
- mrguyorama 3y ago>this amount of skill and dedication. Time and money. These groups are funded 8 hours a day, 40 hours a week, per person, to dig into your code and find problems to exploit. Unless your place of work has an even bigger security team, you have no chance.
- mptest 3y agoReading Pegasus[0] was terrifying, and yet that second exploit link is so exciting and awe inspiring I fluctuate between admiration and terror. IIRC governments like the Saudi's offered Ronaldo levels of money to some of NSO's engineers. Extremely difficult to defend against them indeed... Very happy that book on NSO has made the waves it has in my political circles. Everyone needs to be aware of the security/safety climate journalists, and anyone who wants to challenge governments/capital in any meaningful way are facing. Any more links like those? Fantastic stuff. Should I just be reading Google Project Zero's blog? I've recently found offensiveCon thanks to hackernews. [0] https://www.goodreads.com/book/show/59808055-pegasus https://www.goodreads.com/book/show/59808055-pegasus