NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
citizenlab.org
citizenlab.org
Until this point I was not aware that Lookout provided any value-add for mobile devices. I was under the impression it was the McAfee of mobile.
It sounds mean but this is the first reference to actual vulnerability discovery done by themselves on their blog, which usually reports on security updates that Google's Android security team discovered. Previous entries include such gems as "Now available: The Practical Guide to Enterprise Mobile Security" and "Insights from Gartner: When and How to Go Beyond EMM to Ensure Secure Enterprise Mobility."
I can't wait to see more great work. Lookout is now on my radar.
"When Ahmed Mansoor opened the document, his suspicions were aroused due to garbled text displayed. His email account was later accessed from the following suspicious IPs.."
https://citizenlab.org/2012/10/backdoors-are-forever-hacking...
Agree strongly, just a small note: UAE is quite wealthy. Higher PPP-adjusted per capita income than Sweden.
Technical analysis: https://info.lookout.com/rs/051-ESQ-475/images/lookout-pegas...
CitizenLab analysis of the nation-state side of things: https://citizenlab.org/2016/08/million-dollar-dissident-ipho...
Apple update: https://support.apple.com/en-us/HT207107
If Apple, Google, MS, Linux distribution does the following:
* Create sha1, sha256, sha256 chksums of every system, app files and store them in a secure database somewhere.
* Check and audit the system files from time to time and notify the user when change happen.
Would it prevent these type attack or at lease notify the user that system security has be compromised?
You need to run 'tripwire --update' every time you run 'apt-get update' or 'pip install foo' or 'npm install bah' or whatever - then you wont get that storm of false positives.
I've been in the previous boat: of having it running on a system I've inherited, and given up because it seemed too much hassle.
Those three timely notifications of real breaches have made 20+ years worth of occasional false positives 100% worth it.
Also, putting code signing in the processor wouldn't fix the problem: code signing already happens in higher levels (ie higher than userland), so moving the verification a level up would likely take the exploitable bugs with it. The problem remains.
Realistically, this is also something virtualization can help guard against. If your OS is initialized from a known good version external to the VM, every time the VM starts, you greatly increase the difficulty for an attacker to get persistant root.
KPP: https://en.m.wikipedia.org/wiki/Kernel_Patch_Protection
SIP: https://en.m.wikipedia.org/wiki/System_Integrity_Protection
Hopefully Apple "made it rain" on these guys (with cash).
It is more and more clear that to accept Apple's security (which seems to be getting better, but obviously still insufficient) I must also accept Apple's commercial limitations to the use of a device I own. And I suppose that the dividing line between the ability to exploit a vulnerability and to 'have control' is a sliding scale for every user: one man's 'obvious' kernel exploit is another man's 'obvious' phishing scam.
It is not a new tension, but it does seem the stakes on both sides seem to be getting higher and higher - total submission to an onerous EULA vs total exploitable knowledge about me and my device. Both sides seem to have forced each other to introduce the concept of 'total' to those stakes, and that is frustrating. More-so when it's not yet clear which threat is greater.
When you buy an iPhone, you don't own it. You are a sharecropper on Apple's OS license.
If you buy an Android with an unlockable bootloader, you own it. But if attacked, the adversary owns the device.
It's a shitty situation but it's hard not to recommend iOS to most users.
On iPhone, user-mode exploits may remain sandboxed, unless they break from sandbox too. On jailbroken iPhones, that last step may be pre-made for them.
On Android, user-mode exploits may remain sandboxed too, unless they break from the sandbox - same as iPhone. On rooted Android devices, the last step may be pre-made for them.
You can not compare stock iPhone and rooted Androids - just like you can not compare jailbroken iPhone and stock Android.
Signed boot has uses, but we need to be sure that the user does the signing.
Turns out, in Android 6, there's a Developer Option called "Allow OEM Unlock" which does enable the ability to unlock the bootloader through fastboot.
While I can't sign my own bootloader, having a developer option to enable the unlock that can only be triggered from inside the OS is an interesting trade off.
By jailbreak, you really mean "vulnerability" and unfortunately those are quite common in the Android hardware/software/bootloader realms.
Apple's walled garden and "moral" approach to guarding their garden is incredibly frustrating, but the sheer number of vulnerabilities affecting different levels of the Android stack is so disheartening. This is true of my PC/Mac as well, all it takes is someone to plug in a malicious USB stick and it'll infect the firmware on the USB host, and that's it, game over. Can spread from there to disk firmware, also growing increasingly complicated and opaque, and who knows where else.
It's reaching a point where I trust my iOS device more than any other, depressingly because of the walled garden. I can't build suitable fences around my kit myself to protect myself against every new vuln (now even monitors can have their firmware exploited and screenloggers installed), giving up trying and sacrificing some freedom for that sense of security is terrible, but feels like the only logical course of action at this point.
But empirically the iOS ecosystem is demonstrating that there is a close source ecosystem with better security properties than the open source one. Security advances the same virtues of user self determination as open source does.
- $1M Cash
- skilled working knowledge of Apple's software and hardware
- fast reflexes to quickly react and apply a newly-public exploit derived from any of the above
Together, the number of world-wide actors who fall into one of those categories is actually fairly large. Those all have the capability to have total 'access' to my device. Given the value (to me) and the amount of data on that device, that's a huge hole, even for the majority of people. Further, with these networked exploits, the distinction between having one individual targeted, and all individuals running that OS is actually fairly slight. It wouldn't take that much more work to spam a well-designed exploit against an entire class of (normal) users.
- a single person or committee with the authority to sign off on $1 million for this sort of thing.
- a willingness to risk the legal and PR consequences of being discovered.
Which cuts out a lot of potential corporate espionage
To mention a few ways: The buyer might want to recover the purchasing price by reselling. If its a government agency, they might want to establish credential with future sellers. Reverse engineers have a 1+ million dollars incentive, and they have a much smaller window to sell it before it becomes worthless.
Its like piracy. First its the group with so called FTP access. During that period of time, maybe a release is worth X amount of dollars, but whats the chance that it remains there and never reach a mass audience?
So yes I feel safer now.
Edit: As for net effect on global society, I think having my phone be part of a botnet that sends spam is less impactful than disrupting democratic progress.
State actors usually have their own opinions about what's legal and what's not, and they tend to give themselves the benefit of the doubt because... the mission must succeed! So no, this "undergrounding" should not make you feel safer. You never know when you're going to cross paths with the next Snowden or any whistleblower or human rights activist.
Does this actually read how you intended it to, or was there an invisible comma/parenthesis there?
If there is ever a point when you feel the need to rise up, but can't because you gave in to government and corporate surveillance and lock down in the first place, that would be a pity.
This reminds me of the PlayStation 3. It remained an un-hacked console for so long and the theory goes that the people who wanted to tinker with it could do so without being forced to fight on the same side as the bad guys, because Sony allowed 'Other OS'. When Sony closed off 'Other OS', this gave incentive for people to actually try and jailbreak the system [1].
Yet now the people that just wanted to tinker had to take the same route that people who just wanted to pirate would have to take. By locking the platform down further, Sony only succeeded in merging the two camps (benign tinkerers and pirates). I think there's a lot of validity in this theory.
It's a tough choice. As an iOS user I've long since come to the same acceptance as you - that the added security is worth the extra restrictions. Yet it doesn't have to be this way. Protecting your platform from hackers shouldn't be the same as protecting your platform from SNES emulators or games with adult themes.
[1] I believe it was this talk where this view was put forward, but I might be wrong (at work, can't really double-check): https://www.youtube.com/watch?v=PR9tFXz4Quc
[0] http://jewishbusinessnews.com/2014/03/19/francisco-partners-...
b) And even if selling tools began to violate CFAA, then NSO itself would be sued. As it is a separate entity than the investors, which is the whole point of limited liability....
Short of being triggered completely in the background by an UDP packet, what's worse than this?
> To use NSO Group’s zero-click vector, an operator instead sends the same link via a special type of SMS message, like a WAP Push Service Loading (SL) message. A WAP Push SL message causes a phone to automatically open a link in a web browser instance, eliminating the need for a user to click on the link to become infected.
It goes on to say that messages of this type are increasingly restricted by service providers and newer phone OSes, but that's still pretty horrifying to read.
You really shouldn't connect to untrusted networks at all if you want to be safe from this kind of attack.
Maybe we should all just go back to carrying dumbphones.
Personally, I'd take iOS over any alternative, if security was my biggest concern.
For me the strange thing is that it is on by default on user phones.
or attacks against Secure Enclave.
It's explained in detail here: https://info.lookout.com/rs/051-ESQ-475/images/lookout-pegas...
Apparently it overwrites a system binary that's launched on boot with another apple-signed binary "jsc" (a console javascript interpreter), which will evaluate some sort of .js that re-exploits everything. Pretty clever to re-use apple-signed binaries for nefarious purposes. (The binary must be apple-signed because when booting the kernel isn't exploited yet and so it enforces code signing, obviously).
So they were re-using $3 domains to send out a million dollar exploit? Am I reading this right?!
https://www.evilsocket.net/2016/07/27/How-The-United-Arab-Em...
Etisalat is not your friend. Etisalat has great marketing and is building GSM-based (LTE, etc) networks in many developing nations but it is no friend of an open internet or democratic institutions.
Etisalat is the reason why in some places in the world if you try to run a VoIP to Phone system gateway, armed men with carbines will show up and ransack your offices and home. They will use their influence with whatever local government exists to "deal with" threats to their revenue and/or tax base. This has happened in Pakistan and the UAE.
This is a solid reminder that in the end, your ability to use defensive technology does not actually decide who calls the shots. Power is still ultimately controlled by violence.
Those are enemies of the state. What you consider enemies are not who everybody regards as enemies. That is why there is no such thing as allowing 'good guys' using these tools for good and preventing 'bad guys' using them for bad.
* The only uses for the exploits are either illegal or by government security organizations
* I don't think you can just make an explosive and sell it to a foreign government; I think there are strict export controls (though I know very few details, I only read about companies applying, getting approval, etc.).
* In the 1990s, strong encryption was called a 'munition' and export was restricted. That turned out to be impractical (it was available in many countries and the Internet has no borders), morally questionable (restricting private citizen's privacy), and it fell apart.
While I believe in liberty and freedom-to-tinker, as I said, this stuff has no legitimate use.
[1] http://www.reuters.com/article/us-nsogroup-m-a-idUSKCN0SR2JF...
This would of course open up a whole new can of worms in the US, as we are constitutionally guaranteed the right to bear arms, but that's just makes it hard, not impossible (and could possibly even serve to provide some much needed nuance to that discussion in the US).
That said, I haven't put a lot of thought into this, so a well reasoned criticism could completely change my stance.
Also, I don't think this concept is limited specifically to exploiting bugs. I think a program that was meant to access and catalog social media accounts for a person while hiding it's accesses as much as possible, but run from a third party's location, might be considered an armament. Same with something designed to DoS a service.If the purpose is to cause harm, it might be an armament. I am aware there's probably a fine line here, and one that would inevitably be abused. I'm not sure how to deal with that, and whether the negatives there outweigh the possible positives overall.
Which means restricting the exploit code is quite useless. But restricting the knowledge itself doesn't work because the same knowledge is necessary to mitigate the vulnerability and to test that the mitigation is effective.
I mean obviously in reality the line between "information" and "software" is non-existent because software is just a type of information, but if you insist on trying to draw a line anyway then it still fails because it's still possible to convey everything of significance using natural language, and the skillset required to convert plain language instructions into software is not rare enough to be prohibitive.
Eh, specialist knowledge yes. Restricted, no. Getting documents on how chips and software has always been somewhat restricted, just be a linux person and try to get documentation from Broadcom on how their wifi/lan chips work, for example.
The battle for end-user control seems surrendered, at least by all but a few.
It doesn't extend to all arms; e.g., you don't have a right to own anti-aircraft guns, weaponized anthrax, or even fully automatic rifles. What side of the line the exploits fall on is of course a question, but if I'm right that their only civilian use is illegal harm to others (e.g., you don't use them to protect your home or hunt deer) then it's simpler.
A great point that I should have thought of. I wish I could edit my original post and add that consideration.
I can draw a conceptual line: Ban using exploits on other people's equipment. But practically, I don't see how to stop that without criminalizing distribution, in which case I can't get my data from my phone (or install a 3rd party OS) without the vendor's permission.
I don't understand what the problem is supposed to be. You don't need laws against knives because there are already laws against assault and murder and there is no harm in having a knife you use to cut carrots. Then you prosecute people for the bad things they actually do.
The justifiable laws against specific weapons are for the exceedingly dangerous ones like plutonium and smallpox. That isn't this.
A good point. In this case it's so hard to catch perpetrators that to stop the crimes, it could be necessary to ban the weapons or their distribution (if that even is a practical option).
Are the other similar situations, where perpetrators are so hard to catch and you have to ban the means? Counterfeiting is all I can think of, and they don't ban color printers they just put tracking tech in them. Also, color printers are dual-use: They have many legitimate uses, exploits have very few.
> The justifiable laws against specific weapons are for the exceedingly dangerous ones like plutonium and smallpox. That isn't this.
Weapons that help foreign governments oppress large parts of their population might qualify, though clearly not all exploits fit that description.
The nearest thing is clearly DMCA 1201. The problem of course being that DMCA 1201 is an epic failure. DRM circumvention tools are widely available to pirates, meanwhile it regularly subjects honest people to a choice between breaking the law and having it interfere with their legitimate activities.
> Also, color printers are dual-use: They have many legitimate uses, exploits have very few.
Exploits seem to have more legitimate uses than illegitimate ones. The only illegitimate use that comes to mind is wrongfully breaking into systems, which is the mirror image of the legitimate use of rightfully breaking into systems, in case you somehow get locked out (or some malicious third party locks you out).
Then on top of that, sysadmins require exploits to verify that a patch actually prevents the exploit. And proof of concept exploits are sometimes the only way to convince a vendor to fix a vulnerability. And academics need to study the newest actual exploits in order to keep up with what currently exists in the wild.
> Weapons that help foreign governments oppress large parts of their population might qualify, though clearly not all exploits fit that description.
Smallpox is inherently dangerous. Some exploits could be specifically dangerous in the sense that some very sensitive systems could be vulnerable to them, but only in the same sense that a Fire Axe could be used to break down some doors leading to very sensitive areas. The problem then is not that the public has access to axes, it's that there aren't enough independent security layers protecting sensitive systems.
And you can't fix that problem by banning tools because a high value target with bad security will fall to a state-level attacker regardless. The only answer is to improve the security of sensitive targets.
I think the equivalent (or much worse, actually) for exploits is something that is self replicating and disruptive. For example, a bug in the BGP routing protocol (or a certain percentage of the common implementations) that propagates bogus routes and disrupts some or all traffic for affected systems and spreads. Something that disrupted a large enough chunk of global traffic would not only be horrendous in its own right, but would also make dissemination of any fix quite problematic.
Then again, I assume it's probably good practice to somewhat lock down how BGP functions in your routers (if that makes sense. I'm not that familiar with it), but a certain incident from last year[1] leads me to believe that's either not possible, hard to do, or people just don't do it.
1: http://www.bgpmon.net/massive-route-leak-cause-internet-slow...
If you have the tooling to keep smallpox and not kill yourself you can also keep ebola around too, if you go to the effort to go find it. Really dangerous stuff and is going to be costly.
The problem here is I can make and keep 'digital smallpox' on my home PC, and for many pieces of equipment it is surprisingly easy to find exploits for them. Are you planning on watching every computer? Every person in the world?
Take a lesson from the failed war on drugs, where there is significant profit motivation people will do what is necessary to make massive amounts of money. There are massive amounts of money in blackhat work.
Fixing it is hard because it requires a lot of independent parties to agree on what to do and update their routers. In theory this is the sort of thing a government could help with by providing funding, to fund research into solutions and/or provide cash incentives to early adopters.
But the market also solves these things eventually, since successful attacks are bad for business. It just takes for the attacks to actually happen first in that case.
It's hard to imagine a scheme under which exploits could be regulated in the US that wouldn't set precedents for whether code was protected speech. I think very few people on HN would be comfortable with those precedents.
Most people don't know about it though. I think everyone thinks we won that "war" completely. Even talking to someone like Phil Zimmermann, he was wasn't aware about it.
Granted it is more about exporting to "rogue states" and more of a registration requirement. But it is something, companies (especially startups) probably forget to do. And I don't know of anyone personally who got in trouble over it.
> It's hard to imagine a scheme under which exploits could be regulated in the US that wouldn't set precedents for whether code was protected speech
Yeah, I was thinking about that too ... and fully support freedom-to-tinker, etc. ...
First, no right is absolute. We can't slander people despite free speech rights, or commit human sacrifice despite freedom of religion, or own a fully automatic machine gun despite a right to bear arms (in the U.S.).
We'd want to create exceptions for research, etc (see below) but I don't think the line is prohibitively hard to draw. The big problem I see is open source security bug reporting: There should be a way to openly notify the vendor and public without releasing the exploit into the wild, but it is a little tricky.
> exploits are more widely used in industry (for testing and red-teaming) than they are by governments
Good point, but I don't think that's a big challenge. Exceptions could be made as they are for other 'munitions' and other illegal products (e.g., drugs used for research).
Is it worth it? I don't think so. Unless you also regulate research, which is a non-starter, you're just driving exploit development out of the US. Substantial amounts of exploit dev are already done by foreign nationals. If virtually all of it leaves the country, what public policy problem have you solved?
A good point. A couple ideas, though neither is sufficient:
* International agreements control distribution of other dangerous goods; that's doable. However, look at how well that works with drugs, and even nukes get around.
* At least stop sophisticated organizations (defense contractors, SV firms, etc.) from making them for foreign governments. Their skills are harder, though not impossible, to replace. Perhaps ban the sale of exploits - taking away the profit motive - but permit distribution for personal, research, etc. purposes.
It's a very difficult problem.
There's also some bigtime cognitive availability bias happening here. We read lurid stories centering on "zero-day exploits" and say "something must be done". But no matter what these articles say, it seems cosmically unlikely that an exploit dealer is worth a billion dollars; the entire exploit trade is a rounding error compared to the switching and filtering equipment companies knowingly sell China and Iran for use in putting dissidents to death.
And slander is not a criminal offense but a civil one -- one has to prove actual damages to win a slander suit (at least in the US.) So spyware could fall under the slander concept where the victims could sure based on actual damages incurred.
So one would need to prove that a piece of spyware caused them actual damages. Then you get into some other interesting unintended consequences: could a browser extension or even a cookie be construed as being spyware? They kind of are -- except (generally) you consent to those things. However were would the line be drawn? Could a company like Mixpanel find themselves inadvertently having their product being considered a munition?
I take to to a slightly absurd extreme to illustrate how good intentions can have ridiculous consequences. Governments don't have the best track record when it comes to anticipating unintended consequences.
IIRC, thats still on the books. Its just one of those sleeping paragraphs since the PGP release.
[1]https://www.pmddtc.state.gov/regulations_laws/documents/offi...
[2] https://www.bis.doc.gov/index.php/policy-guidance/encryption
Ummm... tell that to the Chinese or anyone, anywhere in the world trying to watch the complete international Netflix catalog. And as for VPNs, they're like the tunnels under the actual physical borders which are also not impenetrable.
Malware shouldn't be considered a munition any more than encryption should have been.
Unless the malware actually makes your phone explode, then it's a stretch to call it a munition.
Do we really want governments getting into the code review business?
Phineas Fisher, we need you now.
BRB, gonna go slot me an icebreaker...
See https://www.zerodium.com/program.html
Someone who discovers/developers a remote Jailbreak like this can apparently sell it for a cool half-million.
By the time the bounty expired only 1 team had won.
https://www.zerodium.com/ios9.html
So pricing has some fluidity, but you're looking at at least 500k.
Yep. And even middle men who will clear 7 figures taking a 15% fee. A dated article, but it has a "price list" of sorts, which is interesting: http://www.forbes.com/sites/andygreenberg/2012/03/23/shoppin...
Others like Doctorow and Stross has voiced similar views. In Stross' case, he apparently shelved the third part of a trilogy because the NSA was outpacing him.
http://www.antipope.org/charlie/blog-static/2013/12/psa-why-...
https://www.zerodium.com/ios9.html
It was claimed November of last year. I wouldn't be surprised if this "Trident" was sold by Zerodium. Glad it's patched.
Edit:
I just saw the Citizen Lab article on this:
https://citizenlab.org/2016/08/million-dollar-dissident-ipho...
They mention the Zerodium bounty as well.
Also depending on how old the kids are it might actually work in reverse =)
http://blogs.wsj.com/digits/2014/08/01/can-this-israeli-star...
What other 0-days do they have in their pockets?
If you are being targeted for surveillance smartphones are a very bad idea depending on your adversary. A cheap phone that is refreshed regularly will probably be your best bet.
Don't buy it traceably or in the same place, use the same model, use the same SIM, turn it on in the same geographic location, or call the same people!
I can't help but think at this point we've totally lost control of our devices..
Even on desktop machines (Linux or Mac for me), there are processes running that I don't really know what they are doing. The OS is actually very complex and you could insert another process and it can go and send stuff out and it would be hard to notice. I was also thinking in context of Windows 10 sending out who knows what all the time ( I don't use windows, but I think they called telemetry..).
In the past when everything wasn't connected together and the connections were slower this wasn't as much of an issue. Although that does allow us to patch quickly and easily. Apple sees to it you'll be hounded till you update..
Its doesn't seem easy to fix. Maybe safer languages will lead to less hackable code.
That's been the case pretty much since Windows 2000 (or even 98).
> In the past when everything wasn't connected together and the connections were slower this wasn't as much of an issue
Viruses were really bad even when everything was pretty much airgapped. They were not vectors for state-level attacks only because of cultural elements (you weren't walking with an exploitable beacon in your pocket; there was little value in exploiting what were basically glorified typewriters; and established interests weren't taking this sort of thing particularly seriously outside of the US).
> Maybe safer languages will lead to less hackable code.
JavaScript is fairly safe: it runs in a VM, right? Guess what was used to persist this exploit across reboots...
I don't think this is something that we can "fix" at all. Door locks are ridiculously ineffective and exploitable, but very few people feel the need to use anything different. Similarly, computing devices will always be exploitable one way or the other, but people will keep using them; what we can do is to limit the surface attack as much as possible, and to avoid placing everything online (hello, IoT!) just for the hell of it.
I don't run Linux so I can't comment on that one, but surely there are "simple" Linux distributions that don't start countless unrecognizable processes?
Mac is a hopeless case; a veritable plethora of inexplicable processes.
In contrast, I just logged in to my OpenBSD firewall. I was able to easily recognize everything that was running. The OpenBSD startup procedure is very simple to understand. It's easy to know exactly what processes are started and why.
tl;dr: horses for courses
"iOS 9.3.5 provides an important security update for your iPhone"
40.5 MB. Great! Tapped "Download and install". It's greyed out. Huh?
Oh, "this important security update requires a Wi-Fi network connection to download". Really? It's only 40.5 MB. Let me decide, please, how I use my data.
Am I missing a setting that allows me to install an important security update on a network of my choosing?
For extra hilarity, if you have two iphones available, you can use the personal hotspot feature between them and install the updates even though it's all 3g/4g anyways.
(yes, I realize how silly all of this sounds :-))
Ops like Mexico vs Cartels?
Also, since when is selling weapons to governments unethical?
"Apple also tells us that these bugs were fixed in the latest versions of the iOS 10 public and developer betas, which were released last week."
"The kit appears to persist even when the device
software is updated and can update itself to easily
replace exploits if they become obsolete."No need for a whole new phone.
I'm sure you can find a way to spear phish somebody and send them a Linux ELF binary that they will then execute, but accomplishing that is considerably harder than on Windows/OSX/Android/iOS.
I'm afraid people are just as foolable and code just as executable on Debian as on any other platform. Additionally, vulnerabilities on Android are likely exploitable on Debian.
You will not survive an attack from a state adversary because you used Qubes, or OpenBSD, and certainly not TAILS (which is not particularly secure, just well integrated with Tor). You will survive because you are familiar with your tools of choice and you know how to secure them.
As a final note, if you're being targeted by a nation state, getting an pre-owned ThinkPad will probably result in getting a pre-0wn3d ThinkPad.
replace "UAE" with "Ethiopia" or any other authoritarian regime.
Would this even be practical? I realize TAILS is an attempt at bringing these tools to as many people who may not be technical, but for a smaller, more tech-saavy group, would this work?
Shouldn't there be methods for detecting these kinds of things in source code or more priority given to preventing it in the C/low-level community?
https://citizenlab.org/wp-content/uploads/2016/08/image13-76...
It has the effect of introducing a line-break into the middle of a line, rather than at either end. I've never encountered this before and it took my brain a few seconds to catch on.
I'd be really curious how native bilingual readers of both a right-to-left and left-to-right language would read that. Does it look natural? Where do your eyes go first?
My native language is Hebrew, and we don't bother translating most technical terms to Hebrew. You end up with technical documents looking something like this:
".yadot patch a desaeler Apple .iOS 9.3 ni ytilibarenluv privilege-escalation a dnuof srehcraeser ehT"
In newspapers, where lines are typically short, you get the effect in the screenshot in question. E.g.:
"Everyone gets a day .ni tnew eH
.dias eh ",off tomorrow
You can't really get used to that. You actually have to read the second line sideways from the middle!By the way, typing mixed text is even worse than reading it. You have to press alt+shift every 2-3 words to switch layout. If that's not bad enough, Office 2007 (if I'm not mistaken) introduced a 0.5-1sec lag after each keyboard layout switch. Imagine typing out an entire document like that. I lost my nerve a couple of times.
In many cases we avoid this issue by simply writing technical documents in English, but sometimes that's not an option.
Since I left my previous comment, I came across some Apple presentations on new work they've been doing in iOS 9 and iOS 10 on internationalisation including RTL and mixed-content support. It sounds like there's a lot of work still to do, but I was pleased to see they've at least started multilingual input sources now (in iOS 10, autocorrect can work with multiple languages without having to switch keyboards, though I'm guessing this only works with Latin alphabet languages for now?).
I wonder if we'll ever see privacy conscious apps using some sort of obfuscation. So that every time you update your app, the attacker will have to reverse-engineer the symbol names again.
It seems like a compile or link time tool could find method call & selector references. As long as your app isn't calling methods using strings, or doing something else tricky, I think it could work.
Or you could just write the app in swift. It's the Objective-C runtime that makes it so easy to intercept method calls.
> I wonder if we'll ever see privacy conscious apps using some sort of obfuscation.
Actually Apple can do that already since they have bitcode for many applications. For now it's only required for watchOS and tvOS apps, but might become requirement for every app in future.I suppose it's close to LLVM-bytecode so perfect for obfuscation.
edit: What platform would be recommended, if you happen to be a high value target though. Using iOS at least seems to raise the cost of infiltration significantly judging by this http://www.forbes.com/sites/andygreenberg/2012/03/23/shoppin....
FWIW - I only journal with ink and paper. I never trust digital files, and I sometimes forget how many backups I have of the same photo or other file.
I've never done any reverse engineering so I'm not sure how you'd go about recording what an infection like this does to your device...
Just kidding. The difference here is that a government doesn't want to do such as provide reasonable suspicion or go publicly in front of a judge.
1. never click on links in e-mails. 2. if you're targeted by a nation state, you're screwed. 3. everybody is vulnerable to rubber-hose cryptography.
I believe the article also says it disables the auto-update mechanism. So if you've seen an auto-update prompt recently, your odds are better.
The background audio recording must be terrible for battery life.
Big budget operation!
Somewhat hilariously, they appear to be funded in part by donations from Palantir.
> Alarmingly, some of the names suggested a willingness on
> the part of the operators to impersonate governments and
> international organizations. For example, we found two
> domain names that appear intended to masquerade as an
> official site of the International Committee of the Red
> Cross (ICRC): icrcworld.com and redcrossworld.com.Edit: that story is now flagged as dupe, can we at least get the URL changed to this much more in-depth article? https://citizenlab.org/2016/08/million-dollar-dissident-ipho...
> That a country would expend millions of dollars, and
> contract with one of the world’s most sophisticated cyber
> warfare units, to get inside the device of a single human
> rights defender is a shocking illustration of the serious
> nature of the problems affecting civil society in
> cyberspace. This report should serve as a wake-up call
> that the silent epidemic of targeted digital attacks
> against civil society is a very real and escalating
> crisis of democracy and human rights.
https://deibert.citizenlab.org/2016/08/disarming-a-cyber-mer... That the companies whose spyware was used to
target Mansoor are all owned and operated from
democracies speaks volumes about the lack of
accountability and effective regulation in the
cross-border commercial spyware trade.
While these spyware tools are developed in
democracies, they continue to be sold to
countries with notorious records of abusive
targeting of human rights defenders. Such
sales occur despite the existence of
applicable export controls.The story is great but I really doubt this. I'm wondering what made him suspect the link? Does he send all the links he receives to Citizen Lab?
Some people.