> Due to evidence of in the wild exploit, we are now de-restricting this bug 7 days after reporting to Android.
Why is this a good idea?
> Due to evidence of in the wild exploit, we are now de-restricting this bug 7 days after reporting to Android.
Why is this a good idea?
It’s also probably not a terribly great assumption that no one else has independently discovered this vulnerability that’s already been independently discovered twice. Caution suggests we should assume this is in the wild and act accordingly.
We don't know, because we don't know who bought it and how widespread they deployed it.
Amnesty International has specifically criticized NSO specifically regarding UAE activist Ahmed Mansoor. He is currently serving 10 years in jail. UN human rights experts considered his arrest and imprisonment "a direct attack on the legitimate work of human rights defenders". He was monitored by the UAE using NSO technologies.
Amnesty International have also complained that they have been targeted with NSO Group technology - specifically Pegasus. They're currently launching a legal case in Israel to restrict their export license.
A separate case claims that NSO Group used Pegasus to help the Saudis spy on Khashoggi, who was brutally murdered in the Saudi embassy.
I don't think we need to argue about the bad guys in this case.
Sources: https://www.amnesty.org/en/latest/news/2019/09/nso-spyware-h...
https://www.amnesty.org/en/latest/news/2019/05/israel-amnest...
https://www.nytimes.com/2018/12/02/world/middleeast/saudi-kh...
I'd say the upsides outweigh the downsides.
It also seems like you could discover the bug from public sources - it had been created and fixed in the kernel. Apparently at the time not registered as a security issue, but review could discover the link and check for Android's not having the fix.
In the case of Android, "just tell the vendor" is also kind of awkward: There's dozens, if not hundreds of those. If there's an active threat, it's kind of hard to justify not to inform all of them, but could you trust an embargo over so many parties?
> No longer occurring on linux-next, probably fixed by the following commit:
> #syz fix: ANDROID: binder: remove waitqueue when thread exits.
https://groups.google.com/forum/#!msg/syzkaller-bugs/QyXdgUh...
See for example:
https://mobile.twitter.com/grsecurity/status/118005953923380...
I guess it informs us what not to do at the very least. Given the track record, I'm not very optimistic of the vendors pushing a patch very soon (if ever). This keeps us informed at least.
They can easily give that^ information without exposing details of the bug though?
"Actively exploited" by at least law enforcement. It’s sheer folly to presume that if one motivated group has already discovered this that nonetheless somehow others won’t have as well.