The battle for the world’s most powerful cyberweapon
nytimes.com
nytimes.com
The most likely reasons the FBI paid for access to Pegasus are: 1. It is another tool that frankly does not cost very much if you are the FBI. 2. The part of the FBI that bought it likely does not have authorization or possibly even knowledge of the other tools and contracted with NSO to gain those capabilities at the cost of just some money. This is like how a developer team in large stodgy old mega corporation might not be able to get IT to setup their servers so they just get a budget that they spend on AWS to do an end-run around their own IT organization.
The zero days are likely occasionally being discovered and fixed, but buying a zero-click zero day for Android/iPhone on the black market only costs on the order of $1-2M at retail. If you have your own competent team you can reasonably expect to find a zero-click zero day with only a few person-months of effort which, even at US wages, is only a few 100k per zero day. At those prices, you could keep a dozen or so stockpiled for less than the cost of starting a McDonalds franchise, so they likely did maintain a dozen or so at any one time, so if one was discovered they could just switch over to a different one and write off the old one as a cost of doing business.
They absolutely do have competition. One high profile example is Hacking Team. In terms of overall competition, I do not have any hard information, but given the size of the vulnerability markets there are probably at least a couple dozen to a few hundred organizations similar in scope to the NSO group. We do not hear about them because they mostly sell to governments.
""" The zero days are likely occasionally being discovered and fixed, but buying a zero-click zero day for Android/iPhone on the black market only costs on the order of $1-2M at retail """
In reality the final packaged product is worth exponentially more.
Also, Israel produces some of the best security research talent on the planet due to their national focus on cybersecurity, and funneling some of the most talented students in the country directly to 8200 starting in high school, and some of them end up going to NSO group after. None of the vulnerabilities/exploits in the Vault 7 leaks come close to the sophistication of the FORCEDENTRY exploit. I'm not saying the US doesn't have better capabilities and the NSA most certainly does because they have suppliers like Azimuth, but a lot of what you've stated is based in fantasy.
I dont see why the FBI wouldn't buy Pegasus. Does the above poster think the FBI can just call the NSA and tell it to decrypt a bunch of stuff? The NSA has its own mission and its based on national security interests, not solving the everyday crime the FBI works on. The government isn't just one big club. I'm guessing its likely the NSA isn't going to offer up its best tools to catch someone providing abortion access in Texas or "stealing" academic papers from JSTOR or "pirating" comic book movies. Not only is it a waste of their resources but every time a tool like this is used, the detection of that tool is possible, and with that detection Apple or whomever would figure out what the exploit is doing and patch against it. Now that tool is wasted because some FBI boss wanted a promotion thinking if he impersonated an Associated Press journalist to hack a teenager again like they did in 2007 it would impress some authoritarian higher up.
They can't waste these precious exploits on some culture war, IP enforcement thuggery, leftist organizers, unions, and mid-range drug dealers the FBI regularly beats up, murders (think Filiberto Ojeda Rios), harasses, and spies on. Even the NSA is low-key ACAB. So they just say no and tell the FBI to just let NSO potentially burn their exploits. The NSA and military intelligence has better things to spend it on (think Stuxnet-like scenarios).
tldr; the FBI operates on a level far below these other organizations and are far less important than any of them in the grand scheme of things. They're just well funded cops with all the problems cops bring. They're not getting NSA tools because they don't need them the same way your county sheriff doesn't need MRAPs to drive around in.
You are correct, I do not work in exploit development. My numbers are based on quotes vulnerability brokers have given for their inventory of zero-click iOS vulnerabilities (and other OS and application vulnerabilities) to some of my coworkers over the years. I have heard they have increased in price recently, though due to increased demand rather than increased difficulty of discovery, but I doubt the price of a raw exploit has breached the $10M mark yet. I have no knowledge as to the pricing on a final packaged consumer-friendly UI product.
Reasonable forms for a sufficiently quantified answer include, but are not limited to:
1. A numerical value to purchase from a broker.
2. A numerical value for the budget a competent organization (such as NSO) might allocate to a team to restock their hoard at a profitable return.
3. The number, skill, likely salary, and time/person-months a competent organization might allocate to restock their hoard at a profitable return.
4. The estimated return on a vulnerability. Giving an estimate of the expenditure bound to maintain profitability.
5. The estimated number of vulnerabilities NSO is finding per year given their budget.
6. The estimated number of vulnerabilities NSO has currently hoarded given their budget. Giving an estimate of the embodied expenditures to date.
7. The estimated amount of time for a NSO vulnerability to be burned allowing the estimation of required replenishment rate.
This is not an exhaustive list of reasonable quantifications, but I think at least something along these lines should provide an adequate quantification to demonstrate the degree to which I am underestimating the state of affairs.
Just for clarification, am I correctly understanding your answer to 1b as the price of a zero-click iOS exploit being ~$4M in contrast to my stated $1-2M? If so, I will not openly contest that claim here and thank you for your time. Anybody reading to this point can substitute my earlier claims for $4M if so.
Who needs 0-days when you have Cunningham's Law[1]?
I'm just trolling, but it apparently did happen here. :)
1a. $2M for something. Maybe a messenger/important app?
1b. $3.5-4M for zero click in default install (sandbox escape + local privilege escalation)
2. $20M for high level individual talent for a firm like NSO with a $250M revenue/$150M expenses.
3. $400k for a senior engineer. $250k-500k spot bonus for a person in the team who finds a zero-click. Some other words.
4. 500% to 1000%. Some other words.
5. 0-2 zero-click on-hand or maybe per year. 1-3 lesser ones in messaging/browsers/etc I think? Some other words.
6. The answer to 5 is sparse enough that statistics do not really apply.
7. 7-15 months.
Have you actually looked at the Vault 7 leaks? There’s nothing there far beyond the capabilities of a NSO-type actor. NSO is at the level of a nation state, but so are all the nation states. It’s easy to think that funneling infinite money at something will just make you that much better at something, but this isn’t true at all. Otherwise Apple and Google and Microsoft would just be unimaginably distanced from every other smaller company, and I’m sure you agree that they are not ;)
Anyone even vaguely familiar with the Vault 7 leaks knows that they made the CIA look like a bunch of kindergarteners.
There’s no doubt about the NSAs capabilities, but the Vault 7 crowd was clearly playing in the same league as most NSO group customers.
> JBIG2 doesn't have scripting capabilities, but when combined with a vulnerability, it does have the ability to emulate circuits of arbitrary logic gates operating on arbitrary memory. So why not just use that to build your own computer architecture and script that!? That's exactly what this exploit does. Using over 70,000 segment commands defining logical bit operations, they define a small computer architecture with features such as registers and a full 64-bit adder and comparator which they use to search memory and perform arithmetic operations. It's not as fast as Javascript, but it's fundamentally computationally equivalent.
One can make much more money with the DoD than the DoJ.
Not directly, NSA requests tech companies to slow down 0day research so they and others can exploid them.
https://www.amazon.com/This-They-Tell-World-Ends/dp/16355760...
I'm not sure what would happen, though, if someone claimed that a CA had issued a certificate for their domain without permission. Assuming they could detect this and get the certificate revoked quickly, any attack could at least be stopped (after the damage had potentially already been done).
You're right, though, that there's little incentive for a government to not use "legal" methods to subvert a CA within its jurisdiction, and accuse the complaining site owner of false-flag attacking their own domain for media attention, or some other excuse.
If anything, I'm surprised that a government hasn't tried to poison-the-well of this system by creating a few boy-who-cried-wolf scenarios already.
Things like that are a lot more useful than fooling someone about some silly website.
Updates to your OS or secure apps (lmao) funded by the abc soup (Signal and Free Radio Asia, read up) could be signed by the government.
For the greater good, citizen.
Things have got a bit worse recently, with the Google Play Store requiring app developers to let it build and sign the packages itself[0], but I suppose the argument is that if you don't trust Alphabet with the app signing keys, you shouldn't trust it with the signing keys for the OS updates you download.
(If your Android updates are signed by keys controlled by an entity other than Alphabet, then you can presumably use an alternative app repo too).
[0] https://www.theregister.com/2021/07/01/android_app_bundle/
I'm of the opinion that the NSA must have a long running covert program to discourage the adoption of secure operating systems.
Multilevel Secure Operating Systems have existed since the 1980s, yet most people haven't even heard of them.
Except for the Xbox. Someone hacking an Xbox would lose _Microsoft_ money through piracy, which hurts their bottom line!
As a result, the Xbox runs a type 1 hypervisor with various compiler hardening options like Control Flow Integrity enabled, and are generally some of the most locked down consumer devices sold today.
What's Apple's motivation beyond bad press? iMessage was parsing media sent to it with a pdf parser. Sure, some activists in repressive regimes will get spied on and executed, but it's just so much effort to invest dev effort on rewrites for security when you could find new ways to send cute animated gifs to each other.
From what I can tell all NSO's rigmarole of making a virtual machine in the PDF parser is to work around the existing mitigations.
I guess they could also turn on asan etc in production but that's more than a few percent slowdown.
The whole OS feels much slower than regular Google Android, Osmand (map app) is barely usable (on a Pixel 4XL which isn't a low end phone by any means).
So I don't think we can discount how much slower a device will be with a more secure OS. It might be invisible on desktops, but certainly not on mobile.
Android and iOS are optimized in general and for example Google or Samsung also optimize and distribute it for specific hardware. GrapheneOS is not well funded and has little influence in hardware development. The development of Graphene from AOSP is pretty much guaranteed to de-optimize it in the short term.
While there is little about mobile that would cause a secure OS to be noticably slower, much less mature software with many fewer deployments is expectedly less optimized.
Immunity can't prevent disease from entering your body either; They can only make it harder and actively respond to intrusion.
In contrast, until a few years ago, it was official government policy that EAL4 certification (i.e. "demonstrating resistance to penetration attackers with an Enhanced-Basic attack potential"[5]) was adequate for government systems. This likely corresponds to Class C2 under the old Orange Book standard. This standard was chosen in the interest of allowing standard IT commercial vendors, such as Microsoft and Unix vendors, to submit competitive bids because it was deemed economically and technically infeasible for those systems to be retrofitted with adequate security to achieve a higher standard[6]. So, they instead set the standard to a level achievable by standard commercial IT vendors. They have since reduced it to EAL2 because they determined that requiring a EAL4 certification was too onerous, disqualified large vendors such as FireEye, and was unnecessary as the layering of enough EAL2 systems, each like a piece of swiss cheese, would result in systems comparable to EAL4 systems.
[1] https://www.commoncriteriaportal.org/files/ccfiles/CCPART3V3... Page 34
[2] https://www.niap-ccevs.org/profile/Info.cfm?PPID=65&id=65
[3] https://www.niap-ccevs.org/MMO/PP/pp_skpp_hr_v1.03.pdf Page 84
[4] https://www.commoncriteriaportal.org/files/ccfiles/CCPART3V3... Page 42
[5] https://www.commoncriteriaportal.org/files/ccfiles/CCPART3V3... Page 38
[6] https://www.commoncriteriaportal.org/files/ccfiles/CCPART3V3... Page 38
They've 'democratised' the coup d'état and the absolute cover-up.
Shame on all of them.
How about we do a YC startup and buy a few RCEs for android and iphone from zerodium and do this? (Just kidding to undermine the "most powerful" exaggeration in the title)
When they first presented their case against NSO, Facebook’s lawyers thought they had evidence to disprove one of the Israeli company’s longtime claims — that the Israeli government strictly prohibits the firm from hacking any phone numbers in the United States. In court documents, Facebook asserted it had evidence that at least one number with a Washington area code had been attacked. Clearly someone was using NSO spyware to monitor an American phone number.
But the tech giant didn’t have the entire picture. What Facebook didn’t appear to know was that the attack on a U.S. phone number, far from being an assault by a foreign power, was part of the NSO demonstrations to the F.B.I. of Phantom — the system NSO designed for American law-enforcement agencies to turn the nation’s smartphones into an “intelligence gold mine.”
No, it wasn't. It was the product of the entire industrial capacity of the United States. The amount of Deuterium required for a fission bomb took years of labor by hundreds of thousands of people to produce. The "ideas" were worthless without the physical infrastructure and industrial capacity to carry out the construction.
Software, on the other hand, requires nothing more than really really smart people and a $200 laptop.
basically instead of "Credit card purchase -> phone number -> person ID" they would use "credit card purchase -> semi-persistent hash -> person ID"
You can assume there are many such weaknesses. Nothing is perfectly secure. Nuclear weapons plans are stolen, RSA's crypto keys were stolen ... your phone isn't protected on that level. Security is about raising the cost for an attacker beyond the value to that attacker: if you have data perceived to be worth $1M, make it cost $10M to steal it.
But the cost to the defender is relatively high. There is no way your phone, whatever you use, is perfectly secure; there is no way every app on your phone is perfectly secure; the cost would be astromical to the vendors. There are endless possible holes.
The question is, what is the perceived value of the contents of your phone? Are you the Secretary of Defense or the CEO of a Fortune 100 company? An international terrorist? If they really want you, they've got you (unless you pay for some serious personnel). They could just replace your phone with an identical one containing a little extra hardware, for example.
But your phone almost certainly isn't perceived to have that level of value.
So in essence, they're selling limited time exploits to load malware and I guess having to constantly find new exploits to sell. Hell of a business model for sure.
https://www.occrp.org/en/the-pegasus-project/how-does-pegasu...
In that case it can't be as perfect as they claim, except they have a huge list of apps to target what very well could be the case.
Edit:// Oh
> including Gmail, Facebook, WhatsApp, FaceTime, Viber, WeChat, Telegram, Apple’s built-in messaging and email apps, and others.
Rock, meet paper.
RSA is based on the assumptions that factoring prime numbers and finding discrete logarithms are both hard. ECC is based on the assumption that the subtraction analogue of that weird additiony thingy is hard. Afaik, neither of these things has been proven.
It's not even clear (at least to me) what a proof of "difficulty" would look like. You would have to prove that no mathematical process could exist that was capable of (for example) factoring a composite number N in less than M steps (where M is a function of N), and prove that each step has some minimum energy or time requirement, to ground the "difficulty" in terms of things that we can use our current understanding of physics to reason about.
According to Wikipedia, the "quantum complexity-theoretic Church–Turing thesis" states that: "A quantum Turing machine can efficiently simulate any realistic model of computation."[0] but even assuming this is true, and that we could build a practical general purpose quantum computer, the word "efficiently" here only means "up to polynomial-time reductions", and I don't think we can know in advance what polynomial-time reductions could be discovered.
[0] https://en.wikipedia.org/wiki/Church%E2%80%93Turing_thesis#V...
Also, "steps" here would have to be measured in terms of operations on a physical machine (or at least an idealised perfectly efficient physical machine), but different architectures would allow different operations, and that's before we start considering different models of computation.
MSM editors are a little tech literate these days but they have no authority on the matter. Any other contenders?