Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit
citizenlab.ca
citizenlab.ca
It’s ironic that the exploit is able to plant arbitrary code on an up-to-date device and yet the owner of the phone can’t introspect their phone to see it themselves because they don’t know how to bypass the protections :/
Vendors need to make it easier to verify the integrity of persistent firmware, in an offline fashion. It will dramatically increase the cost of persistence, which is the best way to put these thugs out of business.
Doesn’t really work like that. First of all, when would you reboot your phone? Once per day? Once per hour? Every five minutes? Regardless, these attacks are incredibly advanced, remember they require zero interaction from the user.
Even if you rebooted constantly and the exploit lacked a persistence vector, they would still be able to exploit you whenever they want. There are literally no good defense mechanisms against zero-click attacks. The only effective one being turning off your phone forever.
Something like these exploits takes 1-2 minutes maximum to achieve full data exfiltration. This means you’re not safe even if you reboot every five minutes.
So preventing persistence vectors is not really useful against these types of attacks. Persistence is more of a “comfort feature” for attackers, is not really something essential.
Imagine The Guardian, The New York Times and several other top journals covered this story with a sensational title like "Our Journalists' iPhones are hacked remotely". There's no going back from that.
Everyone seems to be focusing on the "always" in your statement, so i'll ignore that and give you a straight answer.
Strong investment in STEM education, after school programming and computer security programs, mandatory military service where they get a chance to evaluate everyone and funnel the smart technical folks in to Unit 8200, and heavy investment into security startups.
Israel also benefits from everyone else depending on their tools. Not only do they get to see the intelligence being collected by other countries and gain insights into their espionage operations, they also would be able to piggy back into any networks that were of particular interest.
...Is ethis taught in any CS curriculum?
It sure wasn't in mine (but to be fair, that was in Switzerland).
Ethics in software is something we should all probably talk about a little more often.
Viewed from the lens of "CS is a researcher/PhD candidate mill", a lack of focus on ethics makes some sense to the cynic in me.
Knowing Ethics doesn't really mean much, given ethicists aren't more ethical than normal people [0].
As an aside, another consideration is this isn't some private corporation, it's every government, you've got to consider the number of people before someone like Snowden popped their faces out.
[0] https://qz.com/1582149/ethicists-are-no-more-ethical-than-th...
It remains to this day the one course whose lessons I apply every day in my life, moreso than any of the computer related courses.
Philosophy 101 (and every equivalent) heavily focuses on the classical and modern teachings on morals and ethics.
----
[0] https://en.wikipedia.org/wiki/Unit_8200
[1] https://en.wikipedia.org/wiki/Unit_8200#Companies_founded_by...
Well Israeli has been treating palestinians pretty badly so it's not like it isn't justified.
At least critising Israel for genuine reasons isn't deemed anti-semitic in the latest international standard of the definition, oh wait!
Why does this shining light of democracy allow/encourage it's companies to perpetuate authoritarianism for their neighbors? Not a very democracy-loving thing to do.
And defenders of Israeli actions using the defense of people 'hating on Israel' instead of reflecting on the fact that people have genuine policy disagreements with what Israel does has been a popular deflection tactic for decades.
You can't divorce what Israel does on a daily basis from its image and then act surprised when it is being criticized.
I also don't remember Italy bulldozing people's homes while the occupants watch and then turning that land over to their preferred ethnic group, but you know my history isn't so great.
That'd probably be Super Mario.
https://www.timesofisrael.com/israeli-government-okayed-sale...
https://www.reuters.com/article/us-usa-cyber-nso-exclusive/e...
A few years ago bluecoat systems was caught providing deep packet inspection gear to the Syrian government. But that wasn’t Israel so no biggie and you either never heard about it or didn’t pay much attention because it wasn’t Israel.
American and European companies do this all the time but it’s not sensationalized to the same degree. That’s just business as usual.
Don't people routinely get called anti-semite for just criticizing the Israeli government? Except for some small circles, I don't think your statement is true, it's certainly not true for mainstream US politics.
Personal opinion, but I think the mandatory army service in Israel seems to teach that everything is 'defense' and Israel is always 'defending itself', no matter what, this sort of thinking then bleeds into the private sector as these guys leave the military and use the skills they learned there to establish businesses.
Having interacted with the Palestinians during their army service as 'the enemy', the victims of NSO undoubtedly fall into the same category, thus not worth loosing their sleep over.
A country of its size and only relative recent independence, is punching well above its weight being the 8th largest arms exporter in the world over the last decade.[1]
I had a former customer there _go out of business_ when the Barack Hussein Obama (mmm mmm mmm!) administration supportd an attempted putsch by (in my customer's words) "The Retarded F___ing Nazis who killed Sadat for making peace with the Jews."
Israel and the non-Brotherhood Arab countries face the burdensome situation that their most reliable "ally" is a country that depending on the politics is going to support the Brotherhood _and_ the large wannabe-hegemonic Russian satellite state trying to develop nuclear weapons. (Oh, and funded said state's reconquest of Syria in the process). Said schizophrenic state also has a massive surveillance system of its own.
My guess: they all don't look at this as a violation of civil rights or ethics, they look at this as a means for the little countries like them to get a leg up on some of the insane intelligence agencies of the large countries that are funding enemies both domestic and foreign.
I hope more organizations do this.
https://arstechnica.com/information-technology/2019/10/faceb...
The most the legislative can do is amend the relevant laws to make what Facebook tried to do legal going forward, and that still wouldn't apply retroactively. The odds of the government choosing to extensively overhaul its consumer protection laws for the interests of a single multinational in a single lawsuit aren't great.
Israel has no genuinely independent judiciary, nor genuinely free press.
IDF regularly intervenes in both, that's a very poorly held secret.
Any normal nation would be completely horrified at the prospect of a private company effectively intervening into its foreign relations, but Israel is remarkably not, and even seem to give NSO a considerable amount of legal cover.
I believe it's just a cover for the state to distance itself from the activity in public eyes, just like IDF distances itself from peddling military hardware around the world by hiding behind "independent private companies."
Israel is the only country in the world where the judiciary appoints itself and a newspaper like "Ha'artez" can exist.
>Any normal nation would be completely horrified at the prospect of a private company effectively intervening into its foreign relations
That would make most of the West "not normal nations".
No.
Judges who serve on the Supreme Court, as well as the district and magistrate courts, are appointed by the Judicial Selection Committee, which consists of nine members: the Minister of Justice, another cabinet member, two Knesset members (in practice one is from the coalition and the other is from the opposition), two members of the Israel Bar Association, and the President of the Supreme Court and two other Supreme Court justices. The committee is chaired by the Minister of Justice. It can appoint judges to the magistrate and district courts by a majority vote, but appointing a Supreme Court judge requires a majority of at least 7 to 9 or two less than the number present at the meeting.
The establishment already has 3 votes by default, and needs only 2 yes votes — an easy thing to do, and almost certain if supreme court is already stuffed by pro-establishment judges for a few government terms.
And candidates for supreme court appointment almost always come from seniormost district court judges, which were simple majority appointed.
And if supreme court appointment keeps getting vetoed, they can simply do nothing, and wait for appointment by default of seniormost district court judge.
And all of this does not matter at all when IDF intervenes.
Except the 'only 2 votes' are dependent on the other 3 vote block for a living. Also, the Supreme Court has retained its option for interfering with the composition of Knesset block, and putting an opposition member in it, which would make it an effective 1 member block.
18th amendment tried to fix the issue, but paradoxically just made it worse. The Chaudhry train wreck was a complete tragicomedy.
That's just not true, where are you getting your information from?
Does it really matter if they're independent if they disregard the law in exactly the same way the Israeli government does?
Facebook also has a pretty big engineering office in Tel-Aviv, which they'd probably have to close in this scenario. I imagine that would also be a massive PITA. But, again, there's nothing technically stopping them from doing that.
Facebook will probably have better luck with lawsuits in the US.
* firstly, not many people outside the security world knows that bugs are a valuable commodity for attackers. Same thing with internal orgs diagrams which are something you can sell to economic intelligence firms.
* secondly, top-tier orgs like FAANG usually peppers a lot of telemetry around known bugs in production code in order to see if someone isn't exploiting them (or simply to better track down the root cause).
That being said, attackers are reaaaaaally interested in getting access to internal bug trackers : https://grahamcluley.com/microsoft-bug-tracking-hack/
> firstly, not many people outside the security world knows that bugs are a valuable commodity for attackers. Same thing with internal orgs diagrams which are something you can sell to economic intelligence firms.
All you need to realize its value is read some security related news for a week.
Also you can have security_interested people apply to FAANG and then cause harm.
>secondly, top-tier orgs like FAANG usually peppers a lot of telemetry around known bugs in production code in order to see if someone isn't exploiting them (or simply to better track down the root cause).
As you said - around known bugs, so it's irrelevant here
Impossible to track in-person knowledge exchange, so code wouldn’t really be the culprit IMO.
If one were sufficiently motivated and planned ahead, you could almost consider it as a future "insurance policy" of sorts.
Is anyone aware of any (FOSS) software (presumably intrusion detectors or indicators of compromise) for mobile phones that might help flag or even prevent such attacks?
TinyCheck [0] comes to mind, but it isn't truly mobile. TrackerControl [1] and Guardian Firewall [2] are perhaps the closest to something like this but concentrate on privacy more than on security.
[0] https://github.com/KasperskyLab/tinycheck
They should really hire more security folks. A lot of Apple's product security work seems to be outsourced to Google Project Zero.
Their priorities are just in the wrong place
The point being argued is that apple is not giving enough attention to important security issues while also preventing others from doing so themselves.
Assuming such applications existed, how would you install them on the "suspect" iPhone?
Assuming you were able to install such applications, you'd still not have any access to or control over the baseband (which I strongly suspect has plenty of issues of its own).
Assuming the malicious software avoided using Wi-Fi and used only the the cellular data connection for command and control, exfiltration, etc., it'd be damn near impossible to monitor the ("plain-text") data being sent and received (assuming such software would make use of private certificates -- or asymmetric encryption, in general -- to avoid being MITM'd itself, which seems like a reasonable assumption).
--
EDIT: This got me thinking, "what would be the most secure way to keep and use a mobile phone?" (assuming one could not simply avoid doing so).
My first thought is to use a mobile phone with the baseband radio(s) (verifiably) disabled/removed (if that is even possible?) or -- even better -- a Wi-Fi only device (similar in function as the old iPod Touch, for example) on which one used only SIP applications for calling (ideally via an "internal PBX" shared by all of one's correspondents) along with one's preferred E2E-encrypted messaging applications (e.g., Matrix, Signal, WhatsApp, etc.), all of which are used (importantly!) exclusively over an always-on VPN connection.
In instances where Wi-Fi was unavailable and/or one had no other options, a "mobile hotspot" or another ("real") mobile phone acting as one could potentially be used.
I'm interested in hearing thoughts on this idea (including any reasons why this is a bad idea that didn't occur to me during my two minute thought experiment), any other similar ideas that others have had, or any actual practices that are actually being used.
My opinion: there is no secure way. My initial solution: build a home phone based on a Raspberry Pi 3B+ (with touch screen).
I already built this home phone for myself. It does only voice and SMS/MMS. It only works over Ethernet or Wi-Fi.It uses mains electricity. I wrote the software -it's Python3 and C.
I've been using this phone as my daily driver for the last year. It is very reliable.
I plan to start making it available in Jan 2021. Look for more posts here.
Yeah, no where close.
Disclaimer: I work on privacy enhancing tech on Android.
Intra [1] with any adblocking DNS of your choice.
Nebulo: [2] A no-gimmicks alternative to DNS based blocking (their latest beta supports DNS over HTTP3 (QUIC)).
I use both: Intra has no DNS leaks but is IPv4 only right now and laced with analytics (the fork I developed/use is stripped off all analytics). Nebulo is lighter on RAM and battery and supports custom on-device blocklists (non PlayStore version).
[0] https://adguard.com/en/adguard-android/overview.html
[2] https://git.frostnerd.com/PublicAndroidApps/smokescreen#inst...
> we observed MONARCHY and SNEAKY KESTREL continue to use these domain names in attacks through August 2020.
Interesting to see that the malicious hosts are not in any standard blacklist or safe browsing databases for browsers while Turkey's CERT has been sink-holing them via ISPs on a national level since at least 2019.
> Almisshal’s device shows what appears to be an unusual number of kernel panics (phone crashes) between January and July 2020. While some of the panics may be benign, they may also indicate earlier attempts to exploit vulnerabilities against his device.
EDIT: I realise now that does not answer your question. Apologies.
In fact: "On 6 September 2019, an exploit of the wormable BlueKeep security vulnerability was announced to have been released into the public realm.[4] The initial version of this exploit was, however, unreliable, being known to cause "blue screen of death" (BSOD) errors. A fix was later announced, removing the cause of the BSOD error."
They even fixed a BSOD issue that popped up in BlueKeep as that was no good to them.
China is the only authoritarian country with enough leverage over Apple to force them to do that sort of thing. There it's not just an enormous market, but also an utterly critical part of Apple's supply chains. Every other authoritarian country is small fry in comparison, and if they demanded such a thing Apple would tell them to get stuffed. Apple has not just commercial reasons, but political ones as well. While Trump is enamored with authoritarians, the incoming Biden Administration is not, nor is much of Congress or the general public. The EU would also like to at least pretend to care overall. Particularly right now at a time of scrutiny, Apple has every reason to not merely deny such a demand but to do so loudly and publicly.
And seriously, it's not like authoritarians are all stupid (unfortunately) and need to "wake up". They're all aware what China has demanded and gotten away with. If they thought they could too, they would. But they wouldn't, so they don't.
On the other hand, Google did so, and the cost to them is staggering and the reward negligible - they probably regret that decision intensely. It will become a business school case study in why companies shouldn't put ethics ahead of money.
The point being that we need a business environment where it makes business sense to stand up to authoritarian regimes.
There's an arrest pending for their (I think former) CEO in case he ever places his feet at my country. For acts he ordered the company to do.
>On the other hand, Google did so, and the cost to them is staggering and the reward negligible - they probably regret that decision intensely.
Wait, what? Who did Google do that to that wasn't China? Because the only one I remember is China, and I explicitly acknowledged in my comment that they have the leverage to carve their own rules. Arguably even more-so with Apple than Google, that's one place where Apple's hardware and vertical integration strategy is a definite weakness vs other players rather than a strength. It's certainly not as if Apple has no negotiating chips vs China, but it's clear who likely has the strongest hand.
But for Google, was there really a "staggering" cost, or any real cost, over refusing the likes of Saudi Arabia or the UAE? I'd love to read up on that if you could point me to what you're thinking of.
Although the book was published in 2011. I do remember it being a good read at the time, and probably still is!
Statically linking a binary to not require libc or muscl or any other libraries isn't hard. This is the easiest part of exploit writing. All linux distros run ELF binaries just fine.
People who are trying to package things in a correct way, where the user can list the installed program, uninstall it, have configuration stored in standardized locations, etc... that's actually a harder problem. But just because writing a "correct" package varies a bit by distro doesn't mean an exploit, which doesn't have to follow packaging guidelines, has the same difficulty.
In addition, you're trying to compare it to the difficulty of writing an exploit for iOS. It's not comparable. There's documentation about every step of compiling and packaging software for linux distros. There's no documentation for elevating privileges and breaking iOS's sandbox because it's not intended to be possible.
I seem to hear a lot about iOS 0days and not so much about pixel 0days.
Considering the recent iOS exploits, you're likely to be a little bit safer on a Google phone and common sense at the moment - but I'm 100% sure that a player like NSO will have an exploit for your phone as well.
Might have more luck with a dedicated "locked down" phone from a security company, there's some players that have entire custom android distributions with enhanced process/app isolation in the kernel and various stuff on top that prevents accidental leaks from "important" apps - also won't be 100% safe there but you can't even get that on iOS.
I say this as an Android user. Apple only gets hit with all these exploit chains because they are immensely valuable single target. All the Android phones are worse, it's just that hacking Android doesn't pay nearly as much (and that market is much more fragmented).
Additionally, Google's public bug bounty project for Android is dysfunctional and run by contractors without the slightest clue how to handle the reports.
On the other hand, since Android is a more open ecosystem, you can make simpler architectural guarantees than you can on iOS. For example, on a rooted Android you can set a long boot-time-only passphrase for full disk encryption which guarantees data security at rest, which you can't on iOS or non rooted Android (they force you to use your regular unlock passphrase, which isn't practical to make long, and in Apple's case isn't used for FDE, though Android is moving in that direction too). But none of that will save you from NSO runtime 0days, just from police seizing your phone and getting data out if you turn it off.
Why is this useful when their software stack is having enough 0days on its own?
Disc: Googler but nowhere close to Android/Pixel.
Saying that theres plenty of Android exploits but they tend to get less press for some reason. https://www.cvedetails.com/vulnerability-list.php?vendor_id=...
This will just continue to get worse. More journalists and human rights activists will die because some delusional maniacs feelings were hurt, some ex IDF techs want to make some money and a President wants to keep jobs at Lockheed Martin.
Maybe the BDS list should include more countries. Maybe tech as a whole should replace lip service and instead redirect (and/or reject) major funds to fight injustice on a geopolitical level. Maybe VC funds shouldn't "techwash" despot dollars.
The tech industry has a lot of power in itself and can push the needle without the need to rely on 'America' to do something.
Most Israelis I talked to (about this specific subject; including the ones, working for NSO Group) do not understand the concept of human rights. First two questions I get are "How gives these rights?" and "Where does the list written?" in this order with the same intonation. My guess it is result of some kind of indoctrination during high school and army service.
P.S. I'm israeli
They're known to be "the bad guys". The tech courses we took in the army had plenty of emphasis on ethics, both the moral kind and conflict-of-interest kind.
Source: I'm an Israeli.
All the things done to all citizens of Israel (for example, indiscriminate movement and contact tracing) and residents of occupied territories are made possible by graduates of these courses.
Main emphasis of "emphasis on ethics" is explanation to soldiers how each choice made during a chain of events resulting in underage kid, teenager or old woman in her sixties being shot point-blank is correct and no other choice is possible.
I've written and rewritten this reply maybe four times, but there's really no way to phrase it in a way you won't twist it to fit your "you're personally responsible for civilian murder" narrative. But I know what we did (my dept. at least), and that was not it.
This thin veneer of NSO being a legitimate company has been exposed
They are just as, if not more, responsible.
https://thenextweb.com/in/2020/01/08/kashmirs-police-want-pe...
https://m.thewire.in/article/government/kargil-police-asks-a...
https://www.firstpost.com/india/jammu-and-kashmirs-kishtwar-...
https://theintercept.com/2020/12/06/kashmir-social-media-pol...
the one thing these media outlets don't outrightly say is the reason why admins are told to report to police stations and someone on twitter has an answer to that.
https://mobile.twitter.com/CRolanova/status/1260932017916506...
Thanks for sharing
So instead of a democratically elected US Govt dropping freedom from a 1 billion bomber on a 10$ tent, A bunch of hippies in a small part of the US should use the power of social media to control and direct conversation, culture and world events like some sort of a uber-exclusive shady techbro-illuminati?
The problem is genuine but any solution involving tech would only worsen the problem
The tech industry internationally should participate in some form of BDS (as much as they are comfortable with I guess) with these countries.
Also, I believe there should be something akin to the Hippocratic Oath but for developers and engineers.
The problem with Iran is their development of nuclear weapons, their ballistic missile program which now extends in range to cover the Europe, their support in weapons, money and training of various paramilitary groups such as the Houthis, Hezbollah, Hamas and Islamic Jihad, their oppression of their own citizens, hanging gays from cranes, various bombing and attack operations (US forces, Saudi facilities), attacks against oil tankers and calls to annihilate Israel. Not their support of Palestine.
As long as US and Israel are fundamentally aligned on long-term foreign policy objectives, aid will continue to be provided no matter what. Dirty work has to be done by someone.
When exactly does the US give a shit about killing journalists?
I suspect the reason that does not happen is because NSO does the US's dirty work for it, otherwise the US would have stopped it already. After all, the US directly supports those same governments NSO works with. It's probably not too upset its dependents are getting support from a different actor.
“America” may be more powerful than Israel, but no single American politician is more powerful than AIPAC
I'm not arguing Nethanyahu played no role, he did deploy whatever influence and persuasion he could muster, and that helped overpower the influence of those who supported the deal, like French President Macron. But ultimately it was Trump's decision, and Nethanyahu would have had to live with it had Trump made a different call.
Aside, note that nobody even thinks of easing up US sanctions on Cuba again or rejoining that agreement with Cuba. The Democratic party got such a signal from Hispanics last elections it's not even on the agenda.
If you have really been paying attention to the US-Israel relationship you know that this is not true.
More accurately, he ran campaign ads arguing that he fought for Israel against the Iran deal. He further presented himself as a victim of Obama's disrespect, especially since the 'shoe on table' incident.
[EDIT: "while getting Obama to give him a record $38 billion aid"
Longstanding American policy to bolster its client, also a part of the Camp David accords. I do think the aid agreement should not be renewed next time since it's counterproductive to both sides. ]
"He colluded with Flynn and the Russians to undermine Obama and promote Trump."
Wrong. Note however that focusing on this conspiracy shows where the true power lies. When America interferes in Israeli politics it does so openly and without even much mention, because there's no point, it's that powerful (e.g. Clinton helping Peres and Barak, or V-15's funding).
"He gets whatever he wants from the US."
That's why he got the same terms from Obama as he did from Trump, right? After all, it's the same Nethanyahu. Nah. It's American policy that changed.
All your list is part of Nethanyahu's mystique ("I speak perfect English! I can get the Americans to work in our favour! Even when the administration doesn't support me, because I have so many connections and am so convincing it doesn't matter!"), which is very good for him electorally, but most Israelis have woken up from that.
P.S.
"That's more US political power than Chuck Schumer."
That's a trick question, right? Since Schumer has almost no power - no stage presence, minority in Senate. He can't even threaten the filibuster. (What would he filibuster? The Judicial filibuster has been cancelled, and the Republicans barely have a legislative agenda.
After the GOP keeps majority, everything will be decided by Biden-GOP negotiations, and Schumer will have to sign the dotted line.)
I'm not holding my breath on America ever making the right decisions with respect to foreign policy.
I also don't think his nationality should matter, but you're right that he was only a US resident.
Should the US government be equally responsible for your life if you decide to put your head inside a crocodile's mouth? Yet the US government does its part *1000 to get its own citizens back to safety (or kills them with drones, but that's another story). Most countries don't even bother with such hassles - on the contrary, if you're unlucky enough to be British, your government will try to use you as a bargaining chip.
At the risk of sounding pessimistic, there's no value in changing anything if the current course of action aligns with the long term interest of US policymakers and their stakeholders.
Related to the pro-Israel lobbying, the documentary "The Occupation of The American Mind"[2] delves into the propaganda effort that was carried out for years to shape the American public opinion about Israel. I quite recemmend it.
It's more likely that it is simply the influence of Israelis and Jews in America, who are powerful enough to determine US foreign policy (Jared Kushner, as far as I can tell, is not a "religious right" but a zionist Jew).
The whole "assist[ing] in getting journalists arrested/murdered/dismembered" thing still seems like pretty good justification to me. I'm not sure "but everyone else is doing it!" makes that acceptable. Requiring that we deal with every single one of those problems simultaneously else we shouldn't bother with any of them doesn't seem productive.
I'm also not sure I'd describe the refusal to actively fund that behaviour as punishment, but I suppose that's somewhat beside the point.
Then deal with the domestic ones first, the ones we have the most control over. People only care about these issues when the solution is "punish the country," a solution that likely causes more suffering than it stops.
IANAL but I think the case can be made that the export of NSOs software is against US law and a violation of the Wassenaar Arrangement. See: 5D002.C.1
So in theory if Israel is allowing one of its companies to break US law then it would make sense to use that as a basis to stop aid to Israel which may be what OP is alluding to.
If I reverse engineered and sold exploits of American missile systems while in Somalia would that mean everything is A-OK?
Idk. Again, not a lawyer.
Iirc, hacking team dissolved or greatly downsized after their leak. I do not recall any cases against them for their export license to be revoked. I'm sure if the Italian courts rejected the case baselessly then there would be consequences (maybe further legal action/sanctions on specific individuals) as Italy does not operate with the same unique impunity that Israel does.
The difference with Italy is that it does not receive state aid from the Americans. I'm sure if they were then people would be calling for cuts in a similar situation.
This isn't true. On top of the general disaster aid, including $10 million for COVID, we have seven US military bases in the country which accounts for millions a year in aid.
Look to Scandinavia and you'll see actual aid instead of (poorly) hidden state sponsoring of defense contractors. They even give more per capita than the US without those strings attached. US aid is embarrassing.
Besides, US bases are not aid to the host country but aid by the host country to the US.
My first assumption is that the act isn't covered by any US law at all. For some analogy, the murder of Jamal Khashoggi does not violate any US law as the many US laws regarding murder (i.e. the separate criminal statutes of each of the US states plus any federal laws that may apply) do not regulate acts done by Saudi citizens to Saudi citizens in Istanbul.
So the question becomes not about legality but about policy - whether the act harms US interests. And arguably selling of arms and tools by US allies (e.g. Israel) to US allies (e.g. Saudi Arabia) is not against US policy and thus there's no grounds to apply any sanctions - now, if NSO would sell the same things to Iran, that would be a different issue.
USA could have standing if NSOs tools have been used to hack journalists in USA - but this is not what this article is about. If NSOs tools have been used to hack journalists in Saudi Arabia or United Arab Emirate or Mexico, that's not a violation of USA laws; and if this has happened according to the legal permissions of the respective government (no matter how lax or arbitrary granting these legal permissions may be) then it's not a violation of any law; if we look from the purely legal perspective and not the moral one, it's perfectly legitimate for sovereign states to make laws that abuse their journalists as much as the state wants as long as it doesn't rise to the level of crimes against humanity. Almost any act or argument against a dictatorship abusing their people is inherently political, not legal.
One incident where NSO may be in hot water is the hacking of Rania Dridi described in the original article if the events happened in London (it's unclear to me from the description) - then this may be cause to assert that NSO are complicit in violating UK law (but not USA law).
I am speaking in more general terms regarding the history of NSO and pegasus.
I am not certain if Jamal's phone itself was hacked but if it was then, in all likelihood, his phone was hacked while he was residing in the US.
His compatriot, who lives in Canada, was definitely hacked using pegasus and that happened in Canada.
I have no hope that the UK government would do anything about this unless the Qataris apply pressure.
You have to start somewhere. But yes, let’s also cut off all the others you mentioned.
Then start with yourself. I'm not condoning Israel's actions but punishing them for what we still do is tyranny.
imessage and facetime have been a constant source of exploits.
This seems to be functionally much like Python’s pickle, Boost.Serialization, Java’s object serialization, etc. These techniques seem clever, and they are genuinely useful for prototyping and for certain applications that inherently have no security concerns, but they are not at all suitable for network use. Fundamentally, for network use, one should define a data format, an API, etc and implement it. Using object serialization is backwards — it’s writing the code and then asking a framework to magically network it, and the result is that it networks it too much.
(There are a few systems for writing code and a network protocol simultaneously that treat security as a first-class consideration. The E language comes to mind. I still wouldn’t use E objects to represent data for interoperability reasons if nothing else. But ObjC is not E, and Apple’s design is inexcusable in 2020.)
Will be interesting to read a write-up.
I think Apple could address this for real is one of two ways. They could replace the protocol entirely, or they could treat the existing baroque protocol like any other network protocol and write a grammar and parser for it.
As an analogy, suppose you had a wire format like XML, and you had the clever idea to process it in a dynamic language like Python or ObjC by looking up each tag in a list of all known types and trying to instantiate it. Sure, it would work, and you would be exploited all the time. NSSecureCoding limits the available types to a large and apparently still open ended list instead of literally every type that the deserializer can make sense of.
For an attack like this you need to chain an iMessage exploit with an LPE, and the LPE can be launched from any other app.
They’ve also never devoted enough care, resources, or money to network architecture and how important availability is (with fairness, they have improved in this area in the last couple of years due to the major iCloud outages they had).
Apple doesn’t hire mainstream IT people and cybersecurity people from the enterprise realms. There is a vast amount of talented people and knowledge they simply ignore because the Apple culture is too hip and cool for that.
Steve Jobs is primarily the blame for all the above. He treated the departments and any person that cared about enterprise like dirt. Steve Jobs always said Apple is a consumer company. This philosophy has obviously carried on.
They are, indeed, not "IT people and cybersecurity people from the enterprise realms", because those would be wholly unqualified to work on iOS security. The people actually working on iOS security are hackers and embedded security experts. As they should be. The enterprise cybersecurity world has approximately nothing to do with something like security of a mobile device (e.g. the people in that field wouldn't know the slightest thing about cutting edge exploit mitigations or hardware assisted countermeasures like pointer authentication, memory protection and IOMMUs, etc).
I always figured the industry never really rewarded those things over aspects (e.g. time to market).
Which tech companies devote enough care and have competent personnel working on embedded consumer device security?
Answer: Apple and Microsoft (Xbox group).
(Google is nowhere close because they don't design their own silicon, and the OEMs they rely on are incompetent in this field, so their efforts can only go so far, no amount of hiring competent sec folks will fix that problem).
Why aren't there a hardware switch on the phones that renders the OS read-only during normal use?
Well if the OS is rendered read-only at the hardware level then malware can't take up residence.
While the article decries NSO being nefarious and selling to suspect “authoritarian” countries, high schools here in our democratic US have been buying hacking solutions to spy on students:
https://gizmodo.com/u-s-schools-are-buying-phone-hacking-tec...
https://www.cellebrite.com/en/ufed/
They don’t have to have anything to do with NSO to have phone exploits that they use to gain access to the device without the owners permission.
The initial vector appears to exploit imagent, to cause the download and install Pegasus, in most cases. This is likely because imagent runs under the root user.
[0] https://citizenlab.ca/2020/12/the-great-ipwn-journalists-hac...
Alexa: "OK, Done! Will there be anything else?"
You: "Yes! Alexa, cross correlate the results of all that data and tell me JUST WHAT IS GOING WRONG IN THE WORLD TODAY?"
Alexa: "Done! Here are the results in URL format:"
Alexa: "
https://en.wikipedia.org/wiki/Fruit_of_the_poisonous_tree
https://en.wikipedia.org/wiki/Pre-crime
https://en.wikipedia.org/wiki/Minority_Report_(film) "
You: "Damn, Alexa, you sure are smart!
"Hey, would you mix me up a drink, like a whiskey sour, or a mojito or a bourbon or something like that?"
Alexa: "I'm sorry Dave... I can't do that... I'm not connected to a drink mixing machine..." <g>
(Oh yeah, and watch out for this guy too:
https://en.wikipedia.org/wiki/HAL_9000 )
<g>
Disclaimer: All of the above is fiction and written for comedy purposes only! <g>
Any and all similarities between the fiction above and anything in the real world -- is purely coincidental! <g>)