Despite the hype, iPhone security no match for NSO spyware (2021)
washingtonpost.com
washingtonpost.com
If you have reason to believe you're targeted by state-backed intelligence agencies, you really oughta be working under the assumption that they can see everything you're doing.
Consumer products are in a he unenviable position of trying to combine things that don't combine well.
Rewriting the stack in a safe language would take years (25+ years of code to rewrite).
Saying the vast majority is on ux+flash, is the super common mistake: you don’t see any of the work that is not in the UI portion of an app, that doesn’t mean that’s not getting huge amounts of work.
I am not sure how secure a Nokia 3210 really is, but I could phone and text with it even today I expect. The users are rare, and that is not accidentap
For me, it's fine if they lose some battles, but they should budget to win the war.
As you say, only thing you can do in such case, is to do everything assuming you're being spied upon.
1. Mossad
2. Not Mossad
https://www.usenix.org/system/files/1401_08-12_mickens.pdfhttps://news.ycombinator.com/item?id=27915173
:)
A fun snippet that jumped out at me this time:
> With public key cryptography, there’s a horrible, fundamental challenge of finding somebody, anybody, to establish and maintain the infrastructure. For example, you could enlist a well-known technology company to do it, but this would offend the refined aesthetics of the vaguely Marxist but comfortably bourgeoisie hacker community who wants everything to be decentralized and who non-ironically believes that Tor is used for things besides drug deals and kidnapping plots.
Apple has way more budget than Mossad.
They don't have to compete with apple they just have to find an interesting mistake in their code. On phones with tens of years of legacy firmware/modem/protocol code that's very hard to reliably stop.
(NSO is not Mossad and Mossad doesn't use NSO afaik)
To be fair, this is just as true of an Israeli car repair shop or shawarma joint...
So is every Swiss company, from Swatch to Nestle, just a front for the Swiss Government?
It is far less unrealistic than you think.
Scale numbers to make better financial sense.
Now, one would think there are already more non-NSO security researchers than NSO have, who earn money from bounties and report issues to Apple. Yet NSO has a business model. How?
0: https://jobs.apple.com/en-us/search?search=%22red%20team%22&...
Because Apple's security is actually pretty bad, making their job easy.
No they can’t. If Apple could, they would deploy their war chest billions to do so. People often make the mistake of thinking some objective is money-constrained, and a place like Microsoft could’ve just thrown the most money at mobile in 2008 to be the best mobile OS.
The Israeli’s in these national security level positions work like their life depends on it because they literally believe it does. Good luck replicating that with a gazillion teams of cushy big tech Silicon Valley positions.
NSO makes money reselling the same set of productized exploits. Their business model depends on no one else (apple or other researchers) finding it. Selling an exploit gets you a single payday, selling a service lets them both charge market rate for exploits, but keep doing so.
Honestly I wouldn't be surprised if they had a monthly subscription fee.
> This is not how security works.
what do you mean?
ime this is absolutely how security works regardless of your defense strategy.
*Yes, you do everything in VMs, with a transparent interface.
You do though. You can exploit flaws in the hypervisor to escape the VM and then you've bypassed the Qubes security model. Here's one such example: https://www.qubes-os.org/news/2017/08/15/qsb-32/
Extreme compartmentalization through virtualisation is also insufficient, as it just becomes a matter of “is there a bug in the hyper visor”, to which the answer is yes: every major VM system has had multiple escapes, as another commenter pointed out even your example of qubes os has had them.
I know how hard security is. I know how hard writing bug free code is.
Brushing that aside and saying “just do X and bugs don’t matter”, assumes that somehow the people implementing support for X are immune to the same problems faced by other developers.
iOS isn't. The vulnerability in iMessage led to the whole system compromize.
> every major VM system has had multiple escapes
Qubes uses hardware (VT-d) virtualization, which AFAIK was last time broken by the Qubes founder in 2003: https://en.wikipedia.org/wiki/Blue_Pill_(software).
Every other virtualisation system also uses hardware virtualisation. They’ve been popped. I don’t think it’s unreasonable to suspect that qubes has not had the same degree of offensive interest as, say, VMware.
I would be grateful if you could provide some links.
> I don’t think it’s unreasonable to suspect that qubes has not had the same degree of offensive interest as, say, VMware.
Qubes relies on Xen. The latter definitely had a lot of offensive interest. I am not aware of any recent escapes of hardware virtualization though.
From processor, to boards, to OS, to the walled garden of apps.
No other tech has that level of control.
Think of the controversy surrounding the Intel ME and other “secondary processors”.
Not an issue with the IPhone (from Apples perspective).
When Google decided they wanted to control all the computing on their servers, from bare metal up, they ran into the ME.
Apple is the only key civilian entity with that level of control.
Google has this stack control in Android, Google Home, Chromebook, etc trivially if it chooses, if it doesn't have that already.
Microsoft can do this on its Cortana smart speakers and Surface Pro X running their (Qualcomms) ARM cpu.
Also I imagine bulk buyers can get Intel ME disabled if they don't want it on their server. AMD PSP can be disabled in the BIOS I believe.
Comparing a phone to a server doesn't make too much sense. A phone is a consumer product like Android or Home and a server is a business product. Apple runs its cloud on Intel or AMD like everyone else.
Wat?
Apple's icloud is partly their datacenter running a mix of systems/hardware and renting out Amazon and Google cloud units, which are Intel/AMD.
Google populates it's datacenters with their own servers. So does Facebook. So does Amazon. Netflix builds their own CDN appliances. Apple absolutely could if they wanted to.
Buying a beige box to put an intel chip is not "your own" servers in the context of this discussion. I'm not sure why you're so rude and confrontational here. We're discussing how Apple has top to bottom control in its consumer devices, not some weird discussion about datacenter packaging. Servers run on AMD/Intel and as such are stuck with the elements of those platforms AMD and Intel dictate. That's not having the entire stack to themselves.
Using today's MacOS as a server is an exercise in pain, largely because there are a number of routine server administration tasks that fundamentally require the GUI in MacOS.
This is untrue. Textbooks on type theory (Pierce’s TaPL comes immediately to mind) will state early on that well typed terms cannot always eliminate all undesirable states.
In fact, there is a tension in encoding all your constraints into the type system (at which point you become a mathematician proving theorems) and producing programs that are actually useful to other people.
it is the height of ridiculousness to ever think you can use anything with the surface of something like a modern phone and be safe against a state. ridiculous. i’ll say it again. ridiculous.
threat models exist for a reason. if anyone ever implied that an apple phone or an android, or pc were safe against this model, this person is a lightweight and you should run fast and far from their advice.
if you’ve ever told people they were safe against a state actor with a smart phone, you need to immediately reevaluate what you do and what you do not know. immediately.
no serious person—including apple themselves—ever made the claim these devices were safe against state determined actors with an off-the-shelf device you can grab from best buy on your way home from work.
It’s constantly connected to uncontrolled networks, constantly downloading media, possesses microphones, cameras, gps, etc
Basically gathers tons of info, and is connected to the internet always and everywhere.
I’d say strong incentives plus unlimited funding.
What they do have is patience and secrecy.
For state attacker the model breaks. The value of a target can be very high. And the available resources - financial, technical, other - are there to fill the budget.
They way you put it, these people fired up a quantum computer and broke the users password hash. What they actually did is the equivalent of an activex control owning a machine in a drive-by attack.
You have no goddamn clue if this is correct or not. Your keys may be compromised, your computer might have spyware on it, your messaging client might be backdoored.
> when Apple, in fact, explicitly allowed remote code execution by untrusted actors
Can you please elaborate what do you mean by that?
If a hacker wants to scam people out of their savings they have a limit on how much money they can potentially earn. I don’t know what the actual numbers are, but let’s say an attacker can hope to extract 100k USD from one in every 10k prospect. If those are the numbers then the attacker can’t waste more than 10 dollar on any individual targets on average or they would start loosing money. I suspect the real numbers are even worse.
On the other hand if you work for a state and you burn a few billion dollars to research some zero day vulnerabilities which you then use to delay the weapons development of your adversaries by a few months you get a medal. Or maybe you don’t but one thing is for sure the state won’t collapse just because of this.
What does it mean in practice. Imagine a scenairo where you left your smart phone at the side of your bed for the duration of a bathroom trip. You return and you look at your phone. Can you trust that the phone on the side of your table is the same you had earlier?
It is absolutely 100% sure that the would-be-savings-scammer doesn’t have the resources to camp outside of your bedroom, monitor your comings and goings, sneak in when you leave the room, swap your phone and leave unnoticed. An operation like that costs serious money.
But if a state put in their collective head that their national interest is best served by your phone being swapped then the above can and will happen. They have the resources to do it and they don’t care about “ROI” in a traditional sense.
Now will a state actor sneak in to your bedroom? Probably not, because there are lower hanging fruits to achieve the same cheaper. For example by paying a batalion of nerds to find zero day exploits in complicated software.
The thing about states is that they are higly uneven. One can have slow and inneficient burocracy and crumbling infrastructure and failing healthcare yet still pursue some other goal with dodged persistance. And the truth is if someone decides to spend a billion dollar to hurt you you will be hurt, if they decide to spend a billion dollar to know your secrets your secrets will be known. States can be both bumbling idiots and godlike entities at the same time, maybe even in the same building.
My comment was only about explaining what makes a state level adversary formidable.
Its fun looking at the hardware, wondering what else a component can be made to do besides its obvious legit function.
The Apples preinstalled apps, and default behavior meant the attackers could rely on certain behavior once they were in.
Apples standardization is what got them.
Control doesn't guarantee security, it just assesses accountability. Also, control doesn't mean Apple writes all the software. They outside code like everyone else.
Maybe it shows that even Apple doesn't have the resources to do it, and therefore nobody does.
Then at the end of the day, customers are still installing 3rd party applications, so does apple have to walk all of their code too?
Apple rarely has to “just trust” a part of its stack.
https://en.wikipedia.org/wiki/Intel_Management_Engine
From the Wikipedia article:
The Intel Management Engine (ME), also known as the Intel Manageability Engine, is an autonomous subsystem that has been incorporated in virtually all of Intel's processor chipsets since 2008. It is located in the Platform Controller Hub of modern Intel motherboards.
The Intel Management Engine always runs as long as the motherboard is receiving power, even when the computer is turned off. This issue can be mitigated with deployment of a hardware device, which is able to disconnect mains power.
The Intel ME is an attractive target for hackers, since it has top level access to all devices and completely bypasses the operating system. The Electronic Frontier Foundation has voiced concern about Intel ME and some security researchers have voiced concern that it is a backdoor.
Why not go AMD or do they do something equivalent to the intel ME?
The best we can hope for is using the best tools and practices we have available to make it as hard as possible to make mistakes and therefore as hard as possible for attackers to find exploitable bugs.
In reality tho, that's not really what happens. We still use C (and C++) for example (and other footgun-languages) and/or run billions of lines of badly audited "legacy" code (that wasn't written with the threats we face today in mind) in a lot of places for various reasons[0], and then try to use all kinds of tools as work around to detect past and new mistakes or at least mitigate the severity of outcomes when mistakes happen and are uncovered and exploited by adversaries[1].
And that's not even yet considering supply chain attacks, be it software or hardware ones.
That isn't to say that Apple couldn't still do a lot better...
"Beware of bugs in the above code; I have only proved it correct, not tried it."
[0] Such as maintaining legacy code bases, "performance", interoperability, development speed, developer availability, business ("cost") considerations, etc.
[1] Starting with code reviews, code coverage, unit tests, static analysis, fuzz testing, etc, and then later at runtime ASLR, canaries, retpoline, sandboxes, etc.
When people say "state-level hackers", they appeal to authority like "the state" is something one simply can't win against. And those employed by the state are super-level Uber-hackers. But in reality what it means is:
A state is able to waste billions on mistakes and incompetence. The state gets away with most projects failing.
In reality forensics and post-mortems show the adversary's understanding of tradecraft, opsec and technical understanding of the space was so bad, it's _not_ skill but luck why they won.
There is very little "advanced" about an APT other than unlimited pockets. If you have unlimited pockets you're more likely able to brute-force your way to winning.
state-level is such an opaque concept because of the huge numbers of actors in it, that never get credited. People like systems-thinking and the idea of everything being planned and orchestrated like in a Hollywood movie. And they we forget in many "bAd coUntTiEs" it's a collaboration between criminal enterprise and state enterprise. It includes thousands of "criminals" who can be leaned on or are willing to lean on others. There is also the private-public partnership in some of the more functional countries[1] that adds thousands to this group of people.
the term "state level" is almost useless. It is the language of PR and propaganda. If taken serious as a concept it just means an entire different country.
And this is why it's saying "unhackable": When one expects a security guarantee to defend against such a large group of diverse actors (or not even being able to identify the adversary in the first place) then to fulfill that promise it will have to be "unhackable".
[1] Australia has a gag-order where you can't even warn your employer when they force you to implement a backdoor in their products.
That's not really relevant. The American intelligence apparatus controls their entire stack too, ordering and autiting custom versions of professors and such.
Probably only 10 years ago, I knew a lot of people who thought careful and conscientious use of encryption and security features could protect sensitive info from governments. That's not a very long time ago.
It's taken a while to sink in -- and to the full extent of it being more and more widely known. That nearly any government can probably trivially get access to anything, using commodity off-the-shelf surveillance software.
(Postscript: Edward Snowden is a hero).
Do you even know what you are asking? You are asking perfect code and hardware, no single mistake on any line of the process. Taking account on every possible scenario and sidescenario you can’t or can think about.
https://bughunters.google.com/about/rules/5745167867576320
I think all this is good until an adversary decides to brick every iDevice, Android, Windows, MacOS, and Linux machine in the US. And by "brick", I mean overwrite firmwares, disable fans, and run at maximum load.
And there are are no commercial off-the-shelf security solutions that can “protect” you. You have to do your own security. This is why Snowden had to painstakingly teach the journalists on how to use GPG to receive his cache. No other way would be trustful enough.
Doesn't it matter which state?
Sure, for US, Russia, China this is probably just true without nuance. For someplace like Israel (small but highly motivated and strong in both espionage and tech) apparently also true.
But should I not expect a FAANG-level company to defend itself from state-sponsored hacking if the state is Uzbekistan or Cambodia?
And if every state can get access to top-tier hacking by having an alliance with $MAJOR_PLAYER, why should we expect that doesn't extend to non-state actors? At which point, are we just giving up on security?
I think Apple absolutely can defend itself against state-funded hackers. Whether they choose to do so is a question of priorities I guess.
State can use selective enforcement of different regulations to strongarm companies doing crazy stuffs..
But that isn’t really a question of technology, and the parent comment was, I think, suggesting it’s an unrealistic expectation on the tech level for companies to beat back state actors.
NSO’s elevator pitch is giving top-tier capabilities to states that can’t develop them in house.
> why should we expect that doesn't extend to non-state actors?
Whether or not that's actually the case is an interesting discussion.
Apple put it in their TV ads, you know.
I think you're making excuses. Apple, owning the entire stack, has the least excuse of anyone. Given their market share they also have a lot of responsibility to be better.
Here we can see their certifications under the Common Criteria:
https://support.apple.com/guide/sccc/security-certifications...
For iOS 14, their most recently certified version, we see under their Security Target under Security Assurance Requirements on page 82:
https://support.apple.com/library/APPLE/APPLECARE_ALLGEOS/CE...
They conform to the AVA_VAN.1 requirement.
The official guidance for what qualifies as conforming to the AVA_VAN.1 requirement for their protection profile is described on page 136:
https://www.niap-ccevs.org/MMO/PP/pp_md_v3.1.pdf
“The evaluator shall conduct penetration testing, based on the identified potential vulnerabilities, to determine that the TOE is resistant to attacks performed by an attacker possessing Basic attack potential.”
Which is consistent with the text of the Common Criteria standard on page 170:
https://www.commoncriteriaportal.org/files/ccfiles/CCPART3V3...
Which by page 31 of the same document corresponds to EAL1 under the old EAL model.
To reach "resistant to attacks performed by an attacker possessing Moderate attack potential" would require conformance to AVA_VAN.4, 3 entire levels higher than their certification (corresponding to EAL5 under the old EAL model) and 1 level higher than any Apple, Google, Microsoft, or Linux system ever created and which has been deemed economically infeasible for them to ever retrofit onto their existing products as stated on page 38 of the same document.
And so no company is going to target a cert level higher than the minimum they need to meet whatever business requirements are driving them to get CC certified.
And CC certainly isn’t a good reference for good security and cryptography engineering practices. It’s not bad, but it misses a lot.
0: https://www.theguardian.com/technology/2013/dec/05/barack-ob...
1: https://web.archive.org/web/20210203152520/https://www.wired...
Though, in the long run, I wonder if Androids can be more secure than iPhones.
"the most secure computer has neither power nor connectivity"
android has a lot more functionality than ios, hence it is less secure.
I also have no doubt it has no intention of doing so. It honestly seems very naive to believe that a huge multinational corp would not allow state level access.
https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...
At the top level, the vulnerability is in a parser for a compressed image format. The parser isn’t scriptable or programmable, but the code is subverted, exposing some very primitive logic operators that can be applied to image data. Specifically AND, OR, XOR and XNOR.
The attack then uses these fundamental Boolean operators to construct virtual circuits to emulate a primitive custom CPU architecture using only raw bitwise logic, and uses that to run a virtual machine implementing a bespoke Turing complete bytecode interpreter. This then runs the rest of the payload as a program that implements the spyware functionality.
It’s bonkers.
Paranoiacs will start with "do we need to handle any user messages at all? that's untrusted data!", much less "do we need to support ALL SORTS of image formats, including some handled by obscure, obsolete libraries that noone truly knows how they work?".
The fact that the messaging application allowed untrusted data to escape the sandbox via obscure data processing libraries they didn't write themselves is a proof of lack of internal software risk assessment process. I hope they learned their lesson and code is now reviewed by people not incentivised to rubber stamp everything the moment in lands on their desks.
Almost certain they did not learn any lesson. Like you say, they’re marketing security. If they had made investments we would have heard of it (big hires, security rampup etc).
Anecdotal, but It seems like Apple’s DNA is still very hardware focused. People in my friends group have all interviewed there but none of them accepted offers because they would never match other Big Tech.
"Anecdotal, but It seems like Apple’s DNA is still very hardware focused. People in my friends group have all interviewed there but none of them accepted offers because they would never match other Big Tech."
It seems most of the real magic, long term R&D ROI, and difficult hires. Now rest in the switch from OEM to in house made chips. I would be interested in others perceptions of this.
A modern phone is built on tech from chips like a Z80. However now the amount of chemical engineers, electrical engineers, process, and so on has changes so dramatically.
We have large teams of people becoming so specialized the first stack software is far more times the abstraction it was year by year.
Security is hard. Just like quality, they both take back seats more and more often since they generally only hurt ROI.
Sadly, the biggest surface, aside from the users themselves, is likely still the web browser. With them being nothing short of mini OSes, I am not sure one can make a secure modern phone. If you have secrets, design your opsec around the assumption that your phone is easily hackable.
It’s one more component that limits how thin the device can be, it’s an ingress point for water (Apple was never going to add a flap), and if you’re the kind of person who digs symmetry then a giant hole on one side looks ugly.
Luckily for them, the market came their way. Bluetooth headphones were massively outselling wired headphones by that point, and it’s one of those areas Apple loves to work in - a space where they can add some proprietary magic (H-series chips, instant pairing, auto source switching) that makes what would otherwise be a relatively ordinary product into a remarkable one.
As in - NSO's ties to the Israeli government were filled with corruption and NSO was using its own technology in exchange on Israeli citizens.
There is (quite a big) public inquiry and people from NSO will likely (finally) go to jail.
It's quite a big scandal here https://www.calcalistech.com/ctech/articles/0,7340,L-3927410...
This is following two other scandals relating to NSO in Israel that are getting quite a lot of press here.
For example the inquiry suggests that police members used Pegasus to spy on opposition leaders who opposed Netanyahu a-la-Watergate.
To be clear this _is_ a watergate level scandal here and you'd be hard pressed to find a news website in Israel not mentioning NSO on the homepage.
(Edit: noted I didn't post any citations like https://www.haaretz.com/israel-news/.premium-netanyahu-gave-... or https://www.jpost.com/international/article-694887 but happy to post references on any of the above since it's very easy to find these references (it's all over the news) and I personally dislike NSO)
My 0.2$ on this topic: prevention is nice but not good enough against a persistent or unknown threat. Mobile devices lack EDR coverage, even enterprises install an MDR and forget about it. I want every child process, network connection and interprocess call that falls out of baseline logged. Compromises happen, discovering them months later is the big issue at hand. If you're a journalist or dissident then you or your benefactors should be able to purchase a mobile endpoint security monitoring service that will actively monitor for exploitation and prevent known threats based on good intel. Crowdstrike is the only company that comes close to supporting this.
Which is why I find it suspicous that Signal do not provide the client for non-Android and non-iOS systems, both not very secure.
Do you mean 0.02 or is inflation really running that high?
But I also like to share these kind of posts when I want to make example about like the absolute lack of knowledge in terms of security of apple, like having the guts to release to public a system where password files / shadow and sudoers are world writable just shows that they really have no idea what they're doing
And I wouldn't consider myself a fanboy or like justify this kind of posts like mine as "HN is notoriously against apple" I would more likely say that HN audience is a bit into tech, and if you are into tech and understand how systems work then you can't just ignore these kind of things when you see them so you forcefully end up just trying to dodge a system like apple
iMessage on iOS is part of the OS, and does some message handling in kernelspace. Yes, it has blastdoor, but even since blastdoor sandboxing has been introduced, there have been multiple iMessage CVEs which lead to a full device compromise. See this project zero post for more about iMessage [0].
What I'm trying to say here, is that on an iPhone, no matter what messenger you use, some iMessage exploits can pwn that messenger anyway since iMessage cannot be disabled, and has privileged OS level access.
On the other hand, android does have "google messenger" or whatever the OEM installed, and it may not be uninstallable, but it's sandboxed away from the OS in the same way every other app is. There have been exploits based on kernel-space processing of media attachments on android too, but those actually did depend on the app being used, so if you switched SMS apps to one which rejected such an attachment, or otherwise processed it differently, you actually could be secure. Said another way, on android you actually can turn off the default messenger and use signal for SMS. On iOS, that's not so realistic.
[0]: https://googleprojectzero.blogspot.com/2021/01/a-look-at-ime...
This would be a nice thing to have, yeah
> If you're a journalist or dissident then you or your benefactors should be able to purchase a mobile endpoint security monitoring service that will actively monitor for exploitation and prevent known threats based on good intel. Crowdstrike is the only company that comes close to supporting this.
lol no. Commercial EDR software sucks whether it is Crowdstrike or Carbon Black or Cylance.
That's like saying commercial firewalls suck. Do you mean the UI perhaps? They all allow you to specify detection rules like with ids and fw but the out of the box stuff is good enough to catch APTs but obviously not perfect. Althougj out of those I can only recommend crowdstrike falcon, defender ATP is also decent. Red teamers have bypasses for some, it's a cat and mouse game but can you find one instance where an actual threat actor intentionally evaded an EDR?
Matthew Green et al already did: https://securephones.io
> If you're a journalist or dissident then you or your benefactors should be able to purchase a mobile endpoint security monitoring service that will actively monitor for exploitation and prevent known threats based on good intel.
I am actively building one such open source app (for Android). We are half-way there. One my friends was editor-in-chief at a big media company and his frustrations made it clear to me that they were sitting ducks. Though, securing folks in high risk profession is not easy, at all. But one ought to start somewhere. And it is clear, the eventual solution needs to be external to the phones themselves.
I don't think just securing the hardware is enough (though, even that isn't fully done), the software itself remains hard to tame. Add to the fact that folks (including attackers) can "install" arbitrary things on their Androids, the problem gets only worse.
Then, there's the social and legislative aspects as well. For example, no one can raid your home without a search warrant, that's illegal. Similar thing needs to exist in the digital space. This at least thwarts illegal spyware, if not the law enforcement themselves from snooping about people's digital lives.
An effort to get us all to assume that iphones were these impenetrable digital bastions of freedom?
"Well if they FBI can't even access a terrorists information, surely my questionable messages are safe!"
Turns out all they needed to do was send the phone a txt message?
[0] https://en.wikipedia.org/wiki/FBI%E2%80%93Apple_encryption_d...
I was only following the mainstream news headlines back then... not paying super close attention... but I failed to read that part. I assumed they were never able to access it to this very day.
Along with 99% of the rest of North America who can only read so much about computer security I am sure.
> On March 28, the government announced that the FBI had unlocked the iPhone and withdrew its request.
> The unidentified method used to unlock Farook's phone - costing more than $1 million to obtain - quit working once Apple updated their operating system.
Are you being sarcastic here?
Because that's exactly what any big corporation focused on profits over people would do.
Exactly that.
Take the money from the people and the money from big brother.
Win, win.
Operating Systems exist to securely multiplex the resources of a system and make them fairly and reliably available to the user of that system. In order to do so, the first order of business is that the system should observe the principle of least privilege. That is, it should grant no privileges by default, and only grant access to the resources required for a task to complete.
iOS, Android, Linux, Unix, Windows, pretty much any modern operating system makes zero provisions for enforcing the principle of least privilege.
Analogy: You owe someone $5 for an ice cream cone. Do you hand over your wallet and all of your 2fa credentials to that person, and hope they only take $5? No, you reach into your wallet, and extract a $5 bill. That is a capability that gives the holder $5 of spending power.
If you don't have a $5, you could give them $20, but your maximum loss would be that token. You don't have to worry about losing your title to your car during the transaction.
There is no equivalent mechanism for the average user to securely tell the OS to run this program with these resources, and trust that nothing else will happen, nor hidden surprises persist.
---
Note that the crude "grant access to X" flags present in some phone OSs are NOT capabilities, though them might have that same overloaded name.
---
Note that wallets aren't seen to be impractical, and people have been using them for a very long time. If you're tempted to say that an OS can't reflect that simplicity and ease of use, you just need to give people a few iterations to get it right.
---
We need capability based security. We'll keep having these stories until we get it deployed widely.
We do this all the time with online transactions. Just because the website says $5, in principle when they charge your bank they could ask for as much as they like.
I think this is most common with European payment gateways.
You’re just not familiar with them. iOS has pervasive sandboxing allowing for fine-grained access control to system resources. Most sandbox profiles start by denying everything by default and adding in things deemed necessary for the program. The issue is that 1. sometimes the things added in are too broad or 2. the sandboxing mechanism itself is broken via an exploit.
Why, though?
I find it extremely plausible that there is no sandbox which can prevent programs from escaping, and that the same is not true of physical separation. (Obviously even physically separated machines are prone to problems too; but I believe it is possible to resolve them.)
Regarding 'don't be nihilistic', I really don't think that's what I'm doing; I'm suggesting a path forward, a different course of action. It doesn't seem any more nihilistic to say 'let's move away from shared hardware' than to say 'let's move away from md5'.
It depends on your threat model: https://www.qubes-os.org/faq/#how-does-qubes-os-compare-to-u....
> I'm suggesting a path forward, a different course of action.
It's not a practical path for most people. It's expensive and very cumbersome. You effectively suggest to give up. Good sandboxing is much, much better than physical separation, because it's actually doable. I run Qubes as my daily driver. I can't imagine managing a bunch of machines.
Also, Intel ME is disabled and neutralized on my machine, Spectre is patched (and hyper-threading is disabled on Qubes). Such things are also extremely rare.
I don't really buy the arguments given there. All but the first of the 'cons' listed regarding physical separation apply equally well to virtual machines. There is a link to a longer paper; I will read it later; perhaps it has more compelling arguments.
> expensive
Most people are using phones and computers that cost hundreds of dollars. The cheapest raspberry pi is, what, $5? Getting a few of those would not be prohibitive for many people.
> very cumbersome
That is true, but we can do something about it. How cumbersome was it to habitually run software in vms, before qubes?
> That is true, but we can do something about it.
Perhaps we can use Qubes Air for that: https://www.qubes-os.org/news/2018/01/22/qubes-air/.
But I doubt that normal people will be able to do any of that any time soon. Even Qubes is not convenient enough for them now. See also: https://forum.qubes-os.org/t/how-to-pitch-qubes-os/4499/16
I have been informed that raspberry pis are hard to come by and are now retailing for close to $50. They have historically been cheap, and many other electronics are currently also quite expensive due to extenuating global factors; it seems likely that they will return to historical prices within low 1s of years.
[0] https://img.washingtonpost.com/rf/image_1484w/2010-2019/Wash...
(I make no comment about if the NSA has found other ways into Google or Google has willingly let them in, I do not know the answers to those questions)
Our field is in denial about the importance of diversity to security.
Biologists have no problem understanding this. Why can't we?
I can think of: 1. Develop software in the open. 2. Teach security and cryptography widely using openly-developed syllabus. 3. Encourage parallel initiatives.
I don't think you are referring to racial or gender or cultural diversity.
Similarly if there are 5 sophisticated attackers after your secrets, some may have cracked your phone security, but not others. If you use more different phone OSes you increase the chance that more attackers have exploits for at least some of your phones.
Also using more phone types complicates training, increases the work you must do checking for vulnerabilities, diluting your efforts.
If you have robot armies or something it gets even more dangerous to put all your eggs into one vendor basket.
Better diversity would also mean more choices, which mean some devices are more tailored to needs of a certain type of consumers, like business and government ones. They get less gifs to send, but have their software developed by paranoid people and "do not leak any secrets ever", and "no rce" are their first and only sprint goals.
So basically, now choice is between bad alternative and the even worse one.
Asking for more choices is an important proposition, I'd say
Besides, tens of thousands of separate software companies can easily develop in parallel.
There's only a bottleneck when you assume that this stuff has to come from a BigTech giant. The same mistake people made with PCs and Windows in the 1990s.
In other words, never provide inputs for unsolicited execution.
The Battle for the World’s Most Powerful Cyberweapon (2022-01-28)
A Times investigation reveals how Israel reaped diplomatic gains around the world from NSO’s Pegasus spyware — a tool America itself purchased but is now trying to ban.
https://www.nytimes.com/2022/01/28/magazine/nso-group-israel...
If others can, so does Apple. If it’s based on resources, Apple is far ahead (even large governments don’t put so much resources into one application, let alone small companies).
In fact, Apple’s valuation is incomparable relative to NSO’s and Mossad’s.
And why don’t US politicians protect US citizens?
If there is something else at play, it’s good to highlight it at some point. But I doubt it will be acknowledged to public till decades later.
If the cost of developing an exploit is lower than the market value of selling that exploit (either raw or productized), then the platform will be broken.
All companies can do is increase that cost - ideally to infinity (eg unbreakable). There are numerous ways to do that, and at this point I think it’s reasonable to think that the cost being hit is time rather than money.
There’s only a finite amount of engineering time available and how to spread that is hard. You could say that “everyone should be working on security”, but that doesn’t work because then people don’t upgrade (I recall multiple articles saying that people were updating to get even something as trivial as new emojis, but obviously other big features matter as well).
You could say “rewrite the unsafe code in a safe language”, which is not something that could be done in any reasonable amount of time, especially while retaining ABI compatibility.
So google, apple, ms, etc try to make the correct trade offs and improve the overall security posture of their platforms, but as long as there’s a market of organisations with functionally unlimited budgets the best they can do in the near future is increase the cost.
The goal of the defender is to push the cost of attacking the software above the cost of doing something else.
> All companies can do is increase that cost - ideally to infinity (eg unbreakable)
Unbreakable isn't remotely possible.
The continuing denial that U.S. intelligence agencies are all up in Apple, Google, Microsoft, Facebook etc. is surprising.
It's always easier to shift blame onto someone else, especially on other cyber terrorists.
I just wish there would be industrial standards for basic security, I don't care protecting myself against governments (yet).
There are very few people who can be targeted by governments, so I will always be suspicious of people who can evade government surveillance, unless if you're a journalist, of course.
Always curious to see how we can rationalize these kind of purpose in life.
1) money
2) the belief that if you don't build it then someone else will, so might as well be paid for it first
At least I imagine that's the only way people who build spyware and blockchain technologies can sleep at night.
1) money
I think the major driving force is machismo and competition. People I've met have into this sort of thing have an image of themselves as Matrix-style hackers. It's easy for business types to exploit that.
Be the best hacker working with the best hackers in the world.
".. Developing technology to prevent and investigate terror and crime"
I guess that their initial intentions were good, but a lot of clients (govs) abused it. It's still their fault for not acknowledging or putting breaks for these kind of actions.
(Actually, you might want to read a few works of fiction which feature well-written Evil Geniuses. Or some "I was a CIA agent..." biographies.)
I think it's important to remember that CIA agents are people, and not necessarily evil or geniuses.
The one former CIA agent I know is to this day haunted by the time he killed a civilian during the Vietnam war over fifty years ago.