Journalist’s phone hacked: all he had to do was visit any website
thestar.com
thestar.com
Don't supply services to these companies (build their website, network...).
I believe by letting people of the hook for participating in this (similar things can be said for e.g. the NSA) we are essentially endorsing the behaviour. If you work on at e.g. NSO group, you are personally responsible for governments surpressing and even killing (just look at SA) critics
I've been helping with some work for a small local gang- we do the usual (murder-for-hire, "debt collection", extortion, etc). Although I only do administrative work - keeping records and such. Pays great. But you know what? My wife- my wife of five years- left me when she found out.
Can you believe that? What a fucking fascist. I didn't do anything wrong. I never killed anybody. And, sure, I did also help machine firearms for folks, and I did help with some supply chain issues to make sure we have a reliable supply of bullets, but I never shot anyone. Not one person.
How dare anybody discriminate against me?
You intended to supply a local gang with guns and ammo to earn profit from it, along with the other actions you took. You purposefully set out to profit from their criminal behaviour in full knowledge of what that entailed.
I'm not surprised your wife left you. Good on her.
Here is a circumstance where your point is not valid, where there is no malicious intent:
- Developer A in dept X finds out developer B in dept Y is working on Z. Is uncomfortable with anything to do with Z.
- Dev A raises this with line manager C and gets pushed back.
- Dev A tries to raise this up higher. Gets push back.
- Dev A decides to leave the company because the workplace has now become increasingly hostile.
Dev A tried to do the right thing and raise up the fact that project Z was unethical. By presuming guilt by association, Dev A is treated exactly the same as Dev B.
Consider engineers at Google. Did every Google engineer work on project dragonfly? Did every engineer know about it until it was leaked to the press? Do the project zero team work on ad tracking?
Bringing it back to your example now. If you were an accountant for a printing shop that just happened to be a front, but you never knew about it or suspected it, that's another story. There's no intent to profit from or knowledge of the criminality. Now you're an innocent bystander who was taking advantage of.
If your wife left you in this situation, I'd feel for you.
This is why we presume innocence until guilt is proven. I, for one, would rather some guilty people slip through the net of justice if it helps us to not habitually punish innocent people for crimes they did not commit.
The world is not perfect, nothing is ever black and white.
Anyway, we can evaluate the permissibly of moral actions using the principle of double effect. As you suggest, we do not always have the luxury of choosing courses of action without some kind of negative side effect. At the same time, it is not morally permissible to engage in intrinsically immoral acts (sorry, utilitarians/consequentialists) nor is it permissible to intend the evil effect. We may also not use the evil effect as a means of attaining the desired good. Finally, there must be a proportionality between the good and bad effects that justifies the toleration of the bad effect.
> it is not morally permissible to engage in intrinsically immoral acts (sorry, utilitarians/consequentialists)
How would anyone define an intrinsically immortal act? It seems dishonest to discard well-established schools of thought while ignoring the very premise that makes them relevant.
> We may also not use the evil effect as a means of attaining the desired good.
> Finally, there must be a proportionality between the good and bad effects that justifies the toleration of the bad effect.
These two statements directly contradict each other.
The parent comment of the comment I replied to (try saying that twice as fast backwards) was attempting to point out that we should avoid using guilt by association. i.e. We should focus on innocence for the individual until guilt is proven.
How do you know for absolute certainty that at least one developer (who has ever worked at NSO at any point in time) never said "this is completely illegal and I'm not comfortable with being near it."?
How do you know for absolute certainty that at least one developer (who has ever worked at NSO at any point in time) never said "You know what, I'm really not comfortable doing this work. I thought this was a good gig and I'd be okay with type of work... but I'm really not. It's killing my soul and I can't stand it."?
> at least I won't give you the benefit of the doubt if you're working there as a dev.
Fair enough. You're entitled to that position.
For me: People can make mistakes. People can get in over their head. People can mistakenly believe the lies other people tell them. I'd rather assume someone is innocent until guilt is proven by evidence.
> Likewise, if you work for Hacking team, you know what you are doing.
What even is a "Hacking" team?
Project Zero could be considered a "Hacking" team. Are they bad people for doing what they do? We know about loads of new zero days thanks to them. Extending this, am I part of a hacking team? I do white hat research. Does that mean I'm bad?
Do you mean "malicious adversary" perhaps? Because that is an entirely different concept. Then we are dealing with malicious intent. That's when someone may indeed be guilty (if backed up evidence, of course).
I believe @black_puppydog is talking about the company that literally is called "Hacking Team"
https://en.wikipedia.org/wiki/Hacking_Team
> HackingTeam is a Milan-based information technology company that sells offensive intrusion and surveillance capabilities to governments, law enforcement agencies and corporations.
From your comment I do take the point that maybe not everyone is aware of all of these actors. But if you sign a contract with them, you either know what you're doing and are cool with it, or you didn't care enough to google them. (And I have a very hard time believing the latter.)
The former I find morally wrong, the latter I find negligent (note the "I find", indicating personal choice here) and I do think both should be disqualifying if not explained well.
Edit: even though my personal attitude towards this doesn't matter in the grand (or even small) scheme of things, I'd consider this a situation where I'd invert the burden of proof. Yes, being associated with these companies should put a burden on the person working there if they want a different job. They should have to think about that before they sign. High-skilled people who consider their offers should have a strong incentive to decline.
I also have a friend named Sammy, who's a doctor. Last night I discovered Sammy got a new job at Planned Parenthood, where a significant part of her time will be spent performing surgical abortions.
How many articles on the web should I read before I'm allowed to stop being friends with Sammy?
Maybe everyone in that organisation is evil and corrupt, but you cannot just assume that and apply summary judgment without due process.
But in this case it is not a criminal organisation, by law, it is a company selling "software weapons" to a government the western governments view as legitimate and therefore ok to sell weapons to, even though it is not at all democratic.
So the company is acting within the law (probably), but we probably agree, that it is not moral to do so. If we agree on that, than it is also not ok, to support a company who is doing wrong. So I agree, to avoid people, who do no ethical work. But I don't know enough of the companies in question to make that final judgement and judge case by case, like always.
Rules/laws/policies are to prevent abuse/evil things and to serve people! RULES ARE ALWAYS MUTABLE and should punish abusers of law/rules/policies, NOT the people it is built to serve. Rules must/will change and they should always benefit people who are doing the right thing.
I will give a simple example on why we should go above the law and think a lot of things using basic common sense;
Recently our country introduced camera's on highways to avoid speeding. The govt is so rigid on the rule now that they have already fined people who were speeding in an event of emergency and even ambulances. And I read complains of these people on Facebook. Instead of the laws working to protect and serve, we see it happening the other way.
What we as a society lack is process/structure to handle the outstanding/exceptional scenarios. We need to build a system which tolerates outstanding/exceptional situations so that the system doesn't break down. But unfortunately, we don't tolerate any outstanding situations and it breaks down.
This organisation is doing bad things, and this is not the first or second time this has happened. So the whole world and especially the employees should definitely know what they are doing. They are engineers aren't they? So they are bound to be smarter than the average folks. There is no need for benefit of the doubt with them.
And let's starts acknowledging that many countries are still only in the drafting phase when it comes to dealing with most of the digital abuses, bad things. Most democratic systems are super slow when it comes to digital crimes and laws. So current laws are not sufficient and hence should not be used gauge the severity of the incidents the law cannot handle.
Also remember, Facebook started struggling a lot after the cambridge analytica scandal to hire, because people didn't want to affiliate with them. So this works. We should call them and the employees out for a better world. :)
You didnt have a choice to be born German, you do have a choice to work for NSO.
So the question is more, does the accountant who was keeping books of the belongings taken from the Jews have moral (and legal?) responsibility? And yes I believe he does (and the courts in Germany agreed look up Oskar Gröning).
My point of view is, yes! Unless he opposed in a meaningful way. But most did their duty and did so proudly. And after the war everyone just did their duty because hey had to and no one was a nazi.
But the question also applies to today. The US for example use turtore and murder. So for some family members of people being murdered, because they attended a wedding in afghanistan, the whole US is guilty and therefore a legimitate target. I do not think so, but I think people in the US should take this more into consideration when thinking about terrorist. Most terrorist legitimate their actions (and get support) by saying they fight back the evil empire.that brings them only bombs.
If we talk about its legal, whose laws should we even apply?
And it makes sense. The concept is valid, if you knowingly support criminal activity, which you do by associating with them, you are guilty (by varying degree). Mere familiy members of the mafia in italy for example will usually not being prosecuted, even though they are part of it.
What you mean with guilt by association, is when the nazis for example enprisoned whole families, because one member was part of the resistance. And from the point of view of the Nazis this also makes sense. Because family members do support each other and are close(in ideology), so one enemy in a group means, there are probably more and if not, then it is an example for others not to help anyone resisting even if it is your brother and rather stop or support them.
So the problem with guilt by association to me is not the concept, but how it is applied.
The cruel, despotic government is the problem in the first place, not the tactics they use.
And this concrete case here is about supporting authorian, cruel governments, by (indirectly) working for them.
And I am free to despise and avoid people by my own standards, no matter that they are within the borders of the law.
In the case of criminal and civil proceedings, sure, but a boycott on my part is an application of my own moral compass, not of the law. I don't owe anyone a "fair trial" for the judgement that guides my own free actions.
If for any other reason than absolute necessity you work for an organization that serves authoritarian, anti-democratic regimes with tools designed specifically to implement policies to that end, I will think poorly of you for no other reason. I won't trust that you are able to make decent moral choices. I will base my own conduct on that judgement. My conduct insofar that it's clearly legal should not be the subject of a fair trial.
Your argumentation is exactly how how totalitarian governments commit atrocities, divide the responsibilities up enough so that every little cog can justify to themselves that what they are doing is not morally wrong. I know I'm coming close to invoking Godwins law, but Oskar Gröning had a moral (and even legal) responsibility for his actions, even if he did not kill anyone himself.
This is absurd. A "right to a fair trial" is the standard for criminal trials, which are associated with criminal punishments -particularly but not always- imprisonment and execution. The right to a fair trial has never been a standard we as individuals are obliged to follow in other contexts; for example: it would be ridiculous to think "a trial" is needed before we decide whether we should continue doing business with a company that dismisses its employees for being gay or trans.
Similarly, there is a long history of consumer boycott movements to pressure both companies and nations into acting more ethically; from Apartheid South Africa, to confectionary and fruit companies, to oil companies, to which eggs we might choose to buy. In none of those circumstances is a "right to a fair trial" a relevant concern.
A better question might be: How unethical does a company have to be before the act of just working for them should be considered immoral enough to merit public rebuke and repudiation? I don't think there's a lot of companies that reach that threshold, but I'm adamant that some should: Blackwater is the most obvious choice here.
My emotionally charged actions to not be your friend or colleague requires no evidence or proper investigation. If you want to be my friend/colleague, stop being an asshole. It's that simple.
Fair trial is about the government enforcing laws, not about social groups enforcing morals and ethics. No one has the right to a trial when you act like an asshole and no one wants to be your friend because of it.
Seriously: boycott, divest, sanction NSO Group and similar businesses.
On the other hand, their product is just a tool which can be used for good (stopping terrorists) or evil (spying on human rights activists). Just like a kitchen knife can be used for good (cooking a meal) or evil (stabbing people). So I find it hard to find the moral justification for the actions you suggest. The problem is not the tool or the tool's manufacturer, it's how it gets used.
But hacking tools: to what extent are they actually being used for good? Stuxnet is the clearest example I know of these tools almost certainly decreasing a threat to US citizens (at least for the time before it was found out). But beyond that, there’s very little publicly accessible information demonstrating that these tools are actually effective at stopping or decreasing terrorism. Moreover, even if they turn out to be effective at that, their use in this manner comes with other questionable effects on law and personal rights. I don’t think the knife is a good analogy because while everyone agrees that a knife can be put to either good or bad effect, there’s not consensus on whether hacking tools can even be used for any good.
In that particular case (but not the majority of cases) the target of the hack was an Israeli citizen who was practicing terrorism (against the Arab minority). After their info was intercepted they were arrested and the situation was de-escalated.
Tech like this saved lives that day. I don't think it justifies the freedom cost, but let's not forget real lives are saved by tools like Pegasus.
Additionally, even if the tools are developed and used only by governments that are deemed democratic today (e.g. USA, Israel, Germany) and under strict independent and parliamentary oversight, who can guarantee that future governments of these country will be democratic (obvious recent cases Brazil, Poland, Hungary, but one might also ask that question about the US)?
These are tools of the Regime, and some regimes will wield them against minorities (like Uyghurs in China), journalists (in Mexico and Jamal Khashoggi in Saudi Arabia) and protesters (in Belarus).
Should we stop selling steel to the US because it could be used to put migrant kids in cages, or weapons because it could be used to invade random countries? I’m not saying the answer is obvious, I’m saying the problem is complex and multifaceted.
Take Morocco: not the best government (somewhat theocratic, absolutist monarchy, big on unaccountable and torture-oriented secret police), but overall more peaceful and stable than its neighbors. Do “we” help continuing this state of thing, or do “we” let malcontent bubble up and risk turning it into a failed state and civil war? It’s shades of grey all around, sadly.
I think the question, although genuine, has a flaw, that is, reasoning in terms of "good or bad".
"Good or bad" for whom? Is something that is "not good" inherently "bad" and viceversa?
Is something "good" only because is "decreasing a threat to US citizens"? What about the consequences of "decreasing a threat"? Like Guantanamo Bay, Patriot Act, this poor guy (https://news.ycombinator.com/item?id=23625215), bombing a country thousands of miles away?
"Good or bad" is relative, just like right or wrong. It's difficult to correctly grasp a concept or conceal an idea by just defining it as "good or bad".
> Stuxnet is the clearest example I know of these tools almost certainly decreasing a threat to US citizens...
However, you still have to make value judgements at some point when organizing a society. It’s literally impossible to do so otherwise. Even if you make a conscious effort to not organize socially — I.e. to embrace anarchy — you’ve made at least an implicit value judgment that governance isn’t worth the limitations it requires of the people (I.e. limitation of individual freedom is “bad”).
“good” and “bad” are messy things to deal in, but they still have their place. Any answer to “should we allow NSO group to operate” has to make a value judgement at some point. I think it actually helps to make that explicit — for example my point should still stand in most other value systems precisely because it refers to “good” and “bad” — which vary across value systems — without prescribing what is good or bad.
I could have been more clear about separating an example (stuxnet — the thing which brings in a value system) out of the argument itself. But I couldn’t find a way to do it without sacrificing brevity or readability. Such are the limitations of communication, particularly written :|
There is a whole branch of philosophy dedicated to that: it's called Ethics (https://en.wikipedia.org/wiki/Ethics).
When an entire branch of philosophy exists for that sole purpose, categorizing things into to "bad" or "good", in whatever area, is oversimplifying.
By this logic an equally good use would be to sabotage American military-industrial complex thus reducing threat to the citizens of many countries around the world.
Absence of evidence is not evidence of absence, particularly in this context where the actors involved are highly incentivized to keep success stories well-hidden and well-guarded.
You'll never know about all of the terrorist attacks that didn't happen.
That applies to lots of technology things though. With the NSO group specifically though, wouldn't their tech have Sales people that need to actively court and sell it to potential customers?
NSO knowingly sells tools to repressive regimes that use them to violate human rights. If you sell a knife to someone you know is going use it for murder then you're culpable and your behavior is immoral.
I'm sure there are dozens of companies like NSO that you just don't know about.
It's more like a self guiding missile. It's meant to hurt, so that makes NSO pretty dodgy.
We should focus on making things more secure. While security is a tough problem, it's also somewhat surprising that properly sandboxing a browser is so difficult.
Maybe, but it'll make them way way more expensive.
Higher prices are how you attract MORE talent!
In order for a company to attract superior talent, they need the entire package to be better than the competition (lifestyle, salary, free pizza, prestige, etc).
Even with a mitm attack on your browser, this shouldn't have happened.
Couple that with compliance being driven by ethics and non-compliance being driven by money - it will never work.
We should focus on increasing security
However it's worth mentioning they really don't see it that way. A lot of people working for NSO (or the NSA) see themselves as making a personal sacrifice for public safety.
Also, NSO doesn't operate said technology it just sells it - so it's a bit more like going after people making anti DRM software or p2p sharing software. The only big difference is that NSO is making money.
To say, ‘we will only sell our software to countries who promise not to use it to violate human rights, and if we catch them doing it, we will suspend it’ is just hand waving. The software is designed to be undetected. That’s the whole point.
A actual policy would be that ‘we do not sell our software to countries who have a bad human rights track record, as defined by <independent group>’ ... but that would cut into sales.
I am just saying NSO is an extension and a tool of the US government and its regional (mostly controlled but somewhat autonomous) colonial ally Israel. So arguing about who gets Pegasus when the US government regulates it rather directly (through the "ethics subcommittee" in Israel that is semi-supervised by the US delegate) is ironic and funny.
> However it's worth mentioning they really don't see it that way. A lot of people working for NSO (or the NSA) see themselves as making a personal sacrifice for public safety.
Yes we as humans are very good in justifying our own actions to ourselves. It also doesn't help if it's in your employers interest to reinforce this perception, creating a culture of "we are what stands against evil". This makes it even more important that outsiders will tell them that we hold a different moral judgement.
> Also, NSO doesn't operate said technology it just sells it - so it's a bit more like going after people making anti DRM software or p2p sharing software. The only big difference is that NSO is making money.
Apart from the fact that people don't die or get tortured because of p2p software, the question is also should someone working on e.g. biological weapons be able to absolve themselves by saying "I did not throw the bomb?". Yes, they did not throw the bomb, but they made a tool designed for one purpose only, to be put into that bomb, and they were fully aware of its purpose. They hold as much responsibility as the person using it.
If you work for a company like NSO you are willingly complicit in violations of human rights. That's not the kind of person I want to work with.
I do agree that individuals should be held accountable for their work but it's the degree of the work that is problematic. Is it direct contribution or is it indirect contribution?
If I am working on an open source project used by NSA to hack you, am I responsible? No. That type of moral policing would be bad.
If someone is writing software directly for hacking you, then yes they are responsible but then you must consider all the actions of the org where they used that tool. People might work on these tools because of terrorism or believe in security of the state. That's by no means bad but how the org go about that can be bad and infringe rights. They don't have control over it. Now if they don't quit over the bad reuse of their tool and are not constraint by something (a person working for NSA is likely to get another job without problem), then I think there's something to be said about the personal responsibility.
Verifying the degree of contribution from outside is very hard to do as most details of what happens inside the orgs remains a secret. What their employees are told is wildly different than what they end up doing.
That said, I don't believe targeting individuals will have much effect. It's actively bad because there's an easy road here. Hold the org accountable. If we go down the path of wasting energy on ex-communicating individuals, orgs may get a free pass. It's not hard to replace people in a big org especially a monopoly. Go for the low hanging fruits. Boycott the org.
What we have is the logical extension of the social justice, or SJW, movement. Which even 2 years ago, in my recollections, would have been met with utter disdain. Somehow we've arrived at a time when social justice has a new-found legitimacy and few detractors still speaking out about it.
To me this is scarier than a mob, who usually have a figurehead around whom they rally. The SJWs have been building their seat of power on the shoulders of social media celebrities.
This is Huxleyan populism. People 'follow' others from their sofa, they 'like' things without critical assessment, bolstering support for an ill-defined cause based on memetic catchphrases and sound-bite signals.
I do refuse to own a cellphone. What about you. Since you're suggesting the boycott, can you?
If the phone wasn't proprietary, would it have made any difference?
The answer is obvious.
Is it? I'm not overly familiar with any security exploits, but my understanding is that (at least for Android) the phone OS is often woefully out of date simply because the vendor stopped supplying updates. The end user generally can't supply updates themselves because everything is locked down in a decidedly user hostile manner.
For the vendor's part, they often stop supplying updates (as I understand it) because the proprietary hardware doesn't have it's drivers upstreamed into the kernel (they're proprietary after all) which leads to a completely unjustifiable maintenance burden. They can't simply open source things because the hardware manufacturers generally require NDAs.
As far as the hardware goes, my (probably woefully incomplete) understanding is that it remains proprietary due to a combination of attempting to maintain a competitive edge through secrecy, licensing complexities due to containing third party IP, and DRM issues (which are again a licensing concern).
It seems to me this has already happened. We only call these things phones for legacy reasons, but the iPhone broke the design link with actual phones and turned the phone aspect into just another communications app.
This is a frightening 8-part series about the abuse of "Pegasus" in Mexico 2017-2019: https://citizenlab.ca/2017/02/bittersweet-nso-mexico-spyware...
Here's a category of articles on the citizenlab.ca web site described as "Investigations into the prevalence and impact of digital espionage operations against civil society groups": https://citizenlab.ca/category/research/targeted-threats/
https://en.globes.co.il/en/article-novalpina-capital-and-fou...
I assume because it was founded by three Israeli citizens, in Israel, and the HQ and staff almost all work near Tel Aviv.
And while Novalpina Capital provided funding, that was only in a partnership with two of the original founders, as a buy-out.
No.
And I didn't claim anything of the sort.
- A remote code execution vulnerability. There are almost certainly multiple vulnerabilities at play here, since long gone are the days where a single vuln gave arbitrary code execution.
- a way to bypass the encryption/https, unless the remote code execution was on a layer before encryption (which seems unlikely). EDIT: Apparently the hack only works on non-encrypted websites.
- Once remote code is achieved, they most certainly need a way to elevate privileges in order to make the hack more persistent and tap into other apps.
There are most likely several CVEs at play here. The amount of effort that went into this hack is, frankly, terrifying.
There are still websites that don't use HTTPS.
For websites that do use HTTPS, if they haven't configured something like HSTS, HPKP or Expect-CT, typing example.com into a web browser will make it will send an unencrypted HTTP request to http://example.com. If the website's content is served only HTTPS, the server will most likely respond with something that redirects the web browser to the HTTPS version of the website (most likely a HTTP 301 or 302 status code). The initial unencrypted HTTP request can be intercepted and modified.
Apple should disable javascript for non https sites.
However, you only need 1 http website to pull off the attack, so its not really a problem that hsts is great at addressing since its opt i per server. The easy way to do this attack is control the local wifi, and make the login landing page malicious.
If bad guys can make a certificate dated February 2018 and valid until May 2021 that certificate will be accepted in Chrome despite not having any SCTs. A real one from that date probably does have SCTs but Chrome only required them in April 2018. Setting Expect-CT now might make Chrome reject that certificate for lacking SCTs if it was shown on a subsequent visit.
A year from the now the window is closed, Chrome will reject a certificate that says it was issued more recently and lacks SCTs, and it will also reject a certificate that says it was issued longer ago, because that violates Baseline Requirements on validity periods. But for now a February 2018 certificate could be valid yet not require SCTs.
All Google-owned TLDs are HSTS-pre-loaded, so if you use a domain in a Google TLD (e.g. example.app) then browsers always use HTTPS anyway. Unfortunately it's unlikely that many older, popular TLDs will pre-load HSTS so most users will be unprotected for the foreseeable future.
Then the find/buy a new exploit and do it again.
It's the same with any of these hacking technology companies, they have to keep moving at the very edge of what is possible.
Apple could indeed fix some CVEs that they know about but every new OS/app/library release has the potential to introduce new CVEs that hackers can exploit.
It's a moving target indeed but due to the increased complexity and questionable quality of modern software there's no way they're going out of business, quite the contrary.
and if a government did it, it would not be much harder for them to do it to everyone in the world at the same time before any exploits get fixed...
All you then have to do is network-inject on a user who visits a non-HSTS site by entering it in their address bar.
No need to bypass encryption.
Could you go into this in a little more detail?
I'm inferring that chains of vulnerabilities are needed to go from some starting point to arbitrary code execution. Is that correct?
Have efforts to secure computer systems over the past ~2 decades succeeded, at least in that much more effort needs to be invested in order to get to the point of arbitrary code execution?
To get ACE, you will generally need a couple of primitives, such as an ArbR/ArbW coupled with an infoleak to get ROP. This will allow you to execute arbitrary code, but you're still stuck within the confines of the current process' privileges. Phone apps are generally heavily sandboxed, and the web browsers tend to be sandboxed even harder. Having ACE in some arbitrary process won't give you the ability to do anything: filesystem will still be out of reach, most of the time you won't even be able to see other processes or even make network requests. So you'll need to break the sandbox.
Breaking the sandbox tend to involve looking for an RCE in a process outside the sandbox that you can communicating with over an IPC channel. And you'll likely need to do this twice: once to break free of the browser sandbox, and once to break the "App" sandbox. If we take a look at chrome for instance (which is very well documented[0][1]), they have sandboxing mechanisms built-in to disallow access to most resources (like the filesystem) to most of its processes, and to prevent access to most of the kernel API surface. And then Android further sandboxes all apps to disallow them from accessing each-other's data. So again you'd have to find another bug somewhere to bypass this.
There are tons of mitigations techniques being developed to make bugs harder to exploit, from Pointer Authentication (making it much harder to exploit ArbR/ArbW bugs) to Control Flow Integrity (making it much harder to create a ROP chain). Of course, not all apps actually have those mitigations in place, but the web browsers tend to enable most, for instance chrome has CFI enabled[2].
[0]: https://chromium.googlesource.com/chromium/src/+/master/docs...
[1]: https://chromium.googlesource.com/chromium/src.git/+/master/...
[2]: https://www.chromium.org/developers/testing/control-flow-int...
RCE: Remote Code Execution. It's fairly straightforward, but basically any vulnerability that allows you to run (native) code without physical access to the phone (e.g. when a user visits a website).
ACE: Arbitrary Code Execution. Basically any technique that allows taking control of the execution to execute your own arbitrary code.
ArbR/ArbW/ArbCall: Arbitrary Read, Arbitrary Write, Arbitrary Call primitives. They tend to be the "basic unit" which you can weave together to further poke at things once you've gained ROP.
ROP: Return Oriented Programming, a technique used to take control of execution when you have the ability to overwrite the Return Pointer of the current stack frame (for instance, from a stack buffer overflow). ROP is used because nowadays, most processes adhere to W^X (Write Xor Execute, basically a memory page is never both writable and executable at the same time), meaning we can't just inject shellcode and jump to it anymore. You can find a small tutorial on ROP at [1].
ROP This can then be used to generate various primitives (ArbW can be achieved by weaving together a "ROP Chain" that calls memcpy with the right registers, for instance).
IPC: Inter-Process Communication. Imagine a Unix Pipe, where two processes communicate with each-other over stdin/stdout. This is an example of an IPC. There are other IPC mechanisms (D-Bus, Unix Sockets, localhost...). When a process is sandboxed, it will sometimes need access to things beyond its sandbox (like accessing the filesystem to access a cached image or something). To do so, it will talk to another process over an IPC mechanism, with a well-defined protocol.
All apps, including Safari, are sandboxed. Apps can't run arbitrary code to affect other apps. So they had to break out of that.
The system itself is sandboxed. Restarting the phone resets it, in many ways, to a "known" state. So they had to install something that would persist across rebooting the phone.
Hmm, might make me think twice now about going to http://neverssl.com/ in a dubious location.
Further, there is competition for having the most secure browser. it's not controversial to say the 12 years ago IE, Firefox and Safari were pretty bad at security and Chrome in 2008 pushed them all to up their game.
Apple's stance on browser engines is at best claiming security by obscurity. Either apps are sandboxed or they aren't. If they are then it would be safe to run any browser engine. If they aren't then having only one means users have no choice when that one fails.
>The malicious code even wipes crash logs, making it impossible to determine exactly what weaknesses were exploited to take over the phone, said Claudio Guarnieri, head of Amnesty International’s Security Lab, in an interview.
I want to post this Everytime someone claims Apple is best for security. We need logic to fight marketing.
The real threat in this case was that sending the right string of data to a browser let a malicious actor execute a RCE and install malware. Either you trust the browser to be secure against such attacks or you can't trust much of anything.
This seems a lot more complicated than just going to any unencrypted website via network redirection of some sort. Do most people routinely visit encrypted sites that are easily hacked to target an RCE on an individual?
If someone were to be "secure enough" to be running drugs/guns/children - they'd _have_ to be totally disconnected from the internet and cellular networks, and probably all their first and second level associates as well.
I don't have any sympathy for those people, but sadly a journalist critical of a government has all the same problems there, and that's bad for humanity.
I've heard several times that this is largely driven by the crappier flavors of "media platform" and bottom-of-the-barrel ad networks breaking in spectacular fashion due to CORS and mixed-content problems when the main site tries to switch to HTTPS.
I don't doubt there are some bespoke ad servers or other dark corners of ad infrastructure where HTTPS support is still lacking, but that should be rare at this point.
That said,we still have to scan every creative for https compliance because a lot of them say they are but aren't.
What's 'creative' when it's a noun? A producer of 'content'?
edit- I do not have javascript-driven pages, they are PDFs or simple content
There are easily found examples of malicious content being injected into HTML -- malvertisements for example. I can only imagine what might get injected into a PDF which can run javascript [1]. PDF readers aren't exactly known for their security.
Frankly, I'd much rather be able to talk to you about something downloaded from your site and get you to fix it instead of allowing a third party to infect me and point fingers at you.
But I'm saying that what you're serving and what the user receives can be different. When you're using plain unencrypted HTTP then anyone between you and the user can inject javascript into the PDF. The user can get a PDF file with javascript in it even though you didn't put any javascript in it.
certbot is too hard to set up?
>edit- I do not have javascript-driven pages, they are PDFs or simple content
The issue is that if the http protocol can be tampered with, even if all you serve is plain text, the attacker can change your response to contain javascript. Anyone visiting using a browser (with scripts enabled) will be vulnerable.
You should see the list of root certificate shipped with most major browsers.
I did a quick manual count of yesterday's HN front page articles according to hckrnews.com and found 8 non-https links (vs. 109 total non-dead links). 2 of these have a working https version.
I use the HTTPS Everywhere extension set to the new "Encrypt All Sites Eligible" option. Instead of using a list as previous HTTPS Everywhere, this tries to access all websites via https and pops up a warning if it doesn't work (most of the time; one of the six non-https supporting sites was misconfigured in a way that didn't get the popup). Since I want to know anytime I access an http site, I choose the "open insecure page for this session only" option if I want to look at an http page to make sure that it tries the https site again in the future and that I know any time I am visiting an http site. There are simpler extension that just do that, but unfortunately they are not Firefox Recommended extensions that are monitored by Mozilla. Hopefully it won't be too long before browsers do this themselves.
The main root cause for missing https in HN submissions is old github pages before 2016.
GitHub rolled HTTPS but didn't enable it by default for older sites. Gotta go to settings and tick https.
In fact you can program almost any device (including very old and simple) to be a plain old HTTP client or a server but this is not the case with modern HTTPS.
Besides, delivering vulnerability payload via advertising network is far more reliable — with http-only exploit chain police would have to wait and hope that Omar will someday visit an http-only site. I would expect a pricey exploit toolkit, used by governments, to be more robust than that.
LE is still tedious as heck to set up on your own, though, so I guess people who haven't migrated to modern hosting yet are still being left behind. Most hosting-for-devs platforms these days give you HTTPS by default and don't think would even let you host a website without.
Here's what I recently did when I deployed a new site [0]:
{dnf,yum,apt-get,whatever} install -y certbot
certbot certonly --webroot -w /srv/_default -d systemd.software -d www.systemd.software
Certbot went through the registration process in the terminal window. Enter in an email address and read over the terms of service and then it goes and does its thing and finally spits out a success message telling me where the certificate and private key are on the filesystem.Then just point an nginx configuration file to the two [1] and tell nginx to test and reload its configuration.
cp nginx.conf /etc/nginx/default.d/systemd.software.nginx.conf
nginx -t && nginx -s reload
Then, LetsEncrypt will send an email to me notifying me that one or more certificates are about to expire (20 days, 10 days, 1 day ...). I even decided to test that and make sure that works (on a different site a couple years ago) [2]. The certificate can be updated using the certbot-renew service: systemctl start certbot-renew.service
Google searches show several examples which put the renewal service on a timer.That's it! I'm not sure what you think is tedious about that process. Would you care to elaborate?
[0] https://systemd.software/index.html
[1] https://github.com/inetknght/systemd.software/blob/44c584c68...
[2] https://knightoftheinter.net/img/LetsEncrypt_Expiration_Warn...
caddy file-server --domain example.com
example.com is now running https via letsencrypt (assuming you own example.com)January 31 of this year I got an email telling me that my LE client used the older ACMEv1 protocol, not the newer ACMEv2 protocol. They gave me 4 months notice to update my LE client to something compliant. I burnt the time and did the work.
On March 3 myself and many others[0] got an email demanding that we manually re-issue our certificates because of a vulnerability discovered in the LE service. They gave us one day to comply, after that they would revoke the certificates and our users would receive security errors. I begrudgingly went through all my servers and issued the command to forcibly renew certificates. Not a huge burden for me, but likely a bigger burden for larger operations.
As the feature set grows (new challenge types, wildcard support, etc.) and the service gets even more popular, it's going to be an even bigger target and the effects of a monoculture will really be felt. I'm starting to see the value in paying for certificates, and more specifically, using providers that don't provide a public certificate issuance API (or at least stick it behind a paywall.)
How many times would LE have to accidentally issue gstatic.com or fbcdn.net before they get the Symantec treatment[1]? Too big to fail: It's not just for investment banks. And that should give anyone seeking a decentralized internet pause.
[0]: https://www.zdnet.com/article/lets-encrypt-to-revoke-3-milli...
[1]: https://www.zdnet.com/article/mozilla-warns-it-plans-to-dist...
I agree that some problems are unfortunate. But let's contrast for a moment. LetsEncrypt has demonstrated track record of quickly fixing issues. Symantec has a demonstrated track record of hiding issues instead of fixing them.
It's wise to consider options carefully. LetsEncrypt isn't the be-all end-all service for TLS and your needs might not be compatible. But I don't think it's fair to shove LetsEncrypt aside just because it's had its share of problems.
For a free service it's pretty damn reputable.
Let's Encrypt has lowered the bar, but it's still a bar that needs to be overcome.
In particular a current Certbot (or similar software from other developers) will conclude that it should try to replace a certificate which has been revoked and not only certificates that will shortly expire. So if a similar event happened, and you missed the email, your Certbot will treat the certificates much as if they'd expired and replace them automatically.
Also if you didn't replace a revoked certificate the thing is: Online revocation is broken. Most of your users will not have noticed your certificate was revoked. Popular browsers do have an out-of-band way to enforce revocation but they didn't use it on that Let's Encrypt incident because they felt it was low risk. So maybe some people are running Internet Explorer (really?) or have explicitly turned on revocation, everybody else doesn't even see a warning page.
Our concern with Symantec was inadequate oversight.
This is not some clumsy "Three strikes and you're out" rule. Symantec did not have the culture needed to do the job properly and we had no confidence that their management was capable of instilling such a culture.
If you're American or just follow American events somewhat you may have seen the "One rotten apple" argument being pulled apart in respect of problems with their police. Symantec used this argument, asserting on two occasions that their policies were fine but an employee had fallen short and this employee was terminated so now everything is fine. I am not sure I believe them but it doesn't matter because:
That is not good enough. We need public CAs to design procedures so that merely incompetent or lazy employees cannot sabotage things. Because individual humans are by their nature incompetent and lazy, such problems are to be expected and must be allowed for in your processes.
The big incident that blew up for Symantec was Crosscert. Symantec had not explicitly disclosed that the Crosscert relationship existed. In fact even if you read their paperwork closely (as we did after the incident) they actually simply did not disclose key facts about the relationship to anyone, not to their users, not to relying parties (ie you and me), and not to their independent auditor. Perhaps not even to their own board of directors (of course maybe private documents available to the board had such a disclosure).
It is likely that in practice Symantec as a corporation was unaware of what Crosscert were doing. Even if one or two Symantec employees had a good idea, the organisation as a whole was ignorant. As a result there was in practice no oversight over this entirely separate entity in a foreign country issuing certificates!
We concluded that building confidence in a new management of new infrastructure would take several years and that was the minimum we could allow. At first Symantec decided to fight this at the executive level, which of course only made us more confident that we'd been correct not to have confidence in them. When that failed (my impression is that trying to bully Google senior management isn't a good strategy) they settled upon a plan of selling their CA business instead.
So all that's a long way from Let's Encrypt accidentally mis-issuing a certificate from their own systems to bad guys.
It took me maybe 10 minutes to set up for my nginx setup. Debian and OpenSUSE both package letsencrypt's certbot. Tedious to set up and maintain is essentially the opposite of my experience.
Or my other 1 liner cron job that runs certbot for other demos.
If the web server is compromised, then it’ll inject the malicious JavaScript code into the HTML, and transmit that to you. SSL is irrelevant in this regards.
Unless when not using SSL, then the HTML is getting intercepted in flight, and a malicious JavaScript code is injected into the HTML.
Is that more of what we are now seeing these days? The routers are compromised, and the HTML is getting compromised too.
This is a legitimate question.
Granted, I’m fully in support of SSL. Nobody should be seeing what you are browsing. This leaves too much digital breadcrumbs lying around.
It significantly helps to prevent MITM [1] (Man-in-the-middle) attacks. (without scary certificate warnings anyways)
>If the web server is compromised, then it’ll inject the malicious JavaScript code into the HTML, and transmit that to you. SSL is irrelevant in this regards.
The web server isn't compromised in this case, presumably the network is compromised.
>Unless when not using SSL, then the HTML is getting intercepted in flight, and a malicious JavaScript code is injected into the HTML.
Yes.
>Is that more of what we are now seeing these days? The routers are compromised, and the HTML is getting compromised too.
"Stingray" devices [2] spoof mobile towers so cellphones are tricked into believing they're connecting to "Just another cell phone tower" and at that point traffic can be captured/modified.
>Granted, I’m fully in support of SSL. Nobody should be seeing what you are browsing.
It's more than people just knowing what you're browsing (or issues such as leaking passwords/private info), it's that if someone can MITM you, they can also transparently modify unencrypted data (including adding exploits).
I suspected MITM is now technically feasible. Although I wasn’t quite sure how widespread it was.
The stingray is indeed worrying. And it’s been around for nearly 20 years now.
So everyone with a cell phone, or using WiFi over a cellular hotspot, can now get caught up in a MITM exploitation attack, if they browse a non-https website.
When will the network providers now issue a blanket ban on browsing over plain http?
Always on VPN on the phone beats this, imho.
But you can establish a point-to-point secured connection tunnel with the VPN.
Then the VPN goes to the non-SSL website, and gets the html in plain text.
But, if there are compromised routers between the VPN and the website, then you can still be MITM attacked.
Hmm.. a determined foe can still checkmate you, for visiting a non-SSL website, even over VPN.
If the insecure website itself is in Morocco then he's hosed either way, whether the website is behind SSL or not.
Let's say you're a Mexican drug lord or Saudi prince. You know this tech exists and the US/Israeli/European governments use it.
Then, you see this article, and see all the comments in the comment section about how competent, scary and balance-changing the technology is.
Basically: I think these pieces are bought for and paid by NSO through a PR firm, but you are not the target. When we leave comments like "NSO's tech is so good it has to be regulated!" or "NSO's tech is dangerous!" we are playing directly into the PR firm's clever hands.
It's like an article about how good the AR-15 or the F-35 are. Obviously to me (and most of the readers) it's mostly "why are we focusing on technology of death" but we are not the target.
Remember, the vast majority of people working for NSO worked for Israeli and US intelligence bodies. They serve in the 8200 unit doing malware analysis trailed by the NSA and then go work for NSO on the same sort of technology.
(If you want to get an idea of how much, I recommend "Permanent Record" but if you don't like Snowden then check out how far ahead intelligence bodies were _historically_ compared to public knowledge - WW2 crypto being a good analogy)
This lets the US government (and the Israeli government in turn) to make money off the technology without going through the same international regulatory systems.
The US government (or Israeli government) can stop companies like NSO in a single decision but they are not since it is making them money.
It's up to us (the citizens) to pressure them to do so and to promote security best practices and work on better tools to make it harder to breach peoples' privacy.
If stingray devices work by tricking your phone to connect with older protocols like 3G, why aren't those protocols deprecated just like we deprecate older encryption methods that are no longer secure?
For example, the laws on what is allowed to use encryption and what is not differ significantly from country to country. There are also often older installations that only provide 3G support.
Basically, it's complicated and there are a lot of different reasons but it mostly comes down to the world being a big place with lots of different laws and requirements, yet people want a phone that works everywhere.
GSM downgrade attacks as well as USB SDR gears came out late 3G era, I kind of trust 3GPP guys for protection for LTE onwards but if GSM downgrade attacks are your primary concern in your life you can move to Japan and get contract on au by KDDI as KDDI flat out ignored CSFB to CDMA2000 and went all VoLTE
Wouldn't it be easier (at least on android) to go to mobile network settings and change it to "lte only" or "3g only"? As for using au by KDDI, I'm not even sure whether using their SIM cards will prevent a downgrade attack. It's possible that they still support 2g for roaming use, for instance.
I’m not sure how “LTE Only” options work on every phones, moving across countries to just make a phone behave certain way is beyond absurd but verifying how it’s working might be a bit of challenge?
regarding roaming, you mean a fake GSM tower with backend going over a VPN to a GSM tower somewhere the phone could roam to? That I didn’t realize. That could happen indeed.
I usually have it set, and in areas that only have 3G coverage, I get no signal unless I change the setting.
They can be, but that adds cost to running a cell phone network. Since very few people ask for their cell phone communications to be secured, companies just don't do it. it's like how GPS is completely unsecured - anyone with a couple hundred bucks can interfere with GPS signals. Maybe route a cruise ship into an island, or a random driver to a sketchy area of town.
> Why aren't stingray devices considered an attack on the cell network?
LEO's use them very frequently to conduct investigations and gather evidence. Just look at the current debate around full-device encryption. USA Law Enforcement really likes access to information. Telecommunications (and a lot of the inernet: TCP/IP, DNS, etc) were initially set up to be open - security was an afterthought. And they just never bothered to add security later on.
Also deprecating old things is hard. People still expect to be able to pick up a charged Nokia phone from 2001 and call 911 on it.
The author directly contradicts the headline used here:
> The website must use “clear text” which means the URL starts with “http” not “https.”
Both wind up eventually to the same place, but the first redirects to the second.
That can be a link, it can be an old bookmark, etc.
Worse if it was a targeted ad, the https:// link could be just a redirect back to an http:// link, something the browser probably has no trouble doing.
Doesn't HSTS prevent exactly this? Sure, not every website implements it, but the most visited ones overwhelmingly do - it's certainly misleading to say "any website" in that context.
Doesn't even have to be a link. If you type addresses like most be people do (ie. without https://), the browser is going to attempt http first. So any manually typed in address will be vulnerable as well.
That's trivially disproven by typing "example.com" in the address bar and hitting enter. Both chrome and firefox goes to the http version not the https version, even though the https version is available.
Even if that were true though, an attacker in a position to perform an MITM attack can also block the https connection from going through, forcing the browser to make a http connection.
It seems like Apple has patched it in iOS 9.3.5, though: https://nvd.nist.gov/vuln/detail/CVE-2016-4657
Breaking ranks in this case is a 10 year jail sentence if you get caught.
Funnily enough, the ex-head of malware analysis for NSO recently released this https://www.jsof-tech.com/ripple20/ and "switched ranks" to the light side.
Would a trusted VPN help? Or would hijacking the traffic at the point of departure (his phone / the air) still manage to corrupt the payloads?
From the looks of the associated CVEs, it is buffer overflow attack against Safari. The exploit is probably to use a MitM attack to inject the payload into an arbitrary website.
It’s sold by the NSO group, that has repeatedly tried to smear and spy on organisations that report on them knowingly selling to and supporting governments that are using these tools to attack HRAs, etc.
I assume that they have updated it since it first came to light, as the vulnerabilities at the time were all fixed.
Note that the vulnerabilities that they use are all the same ones used by jailbreaks, so fixing them necessarily means preventing jailbreaks.
Well, unless there was a method to jailbreak your device that did not require a chain of software vulnerabilities.
This goes right up there with "the backdoor for which only we'll have the key".
This is a concept that is sadly missing in well-intentioned people.
I’m imagining a proxy like tool that lets high exposure individuals to request webpages, have them downloaded/parsed, and possibly rendered before handing them off to the client device.
Perhaps it would let the client download https normally but switch modes for any http requests (if I understand what happened here correctly.)
Essentially if you are using http:// anywhere on your site (including transitively loaded resources) you are putting your users at risk - the same thing was exploited with the great cannon or whatever that DoS from the Chinese gov was called.
If you were properly trained for, you should have already realized that cellphone is not trustworthy way of communication.
On mobile, highly recommend using a browser that supports extensions or pressuring companies to enable third party browsers. It's not overstating it to say that our legislators should compel that competition, it's a national security issue that journalists, intelligence officials, and the President using devices by a certain manufacturer cannot change the browser or use helpful extensions like HTTPS Everywhere.
https://www.eff.org/deeplinks/2018/12/how-https-everywhere-k...
Software is insecure.
> Anyway this can be prevented?
Stop using insecure software.
Just reboot my phone every morning?
I suspect that Mr. Radi would have been safe if he had 1) used a PinePhone, with cellular and WiFi radios turned off, and a USB-connected cellular modem; and 2) hit the Internet through a VPN, Orchid, Tor or LokiNet.
If you think not, please share, because I hate spreading BS.
Edit: Well, someone seems to think that I'm wrong, but they aren't saying why. Just sayin'.
But yes, he would have been vulnerable to malicious sites exploiting browser bugs, as one always is. I mitigate that by compartmentalizing activities in multiple machines and VMs. For example, the host that this VM is running on contains absolutely no information about my meatspace identity.
Or one can use Session, and there are apps for Windows, MacOS, Linux, Android and iOS.