Recently I was on my phone when I received an email address iMessage and the toast showed an absolutely insane link, when I opened iMessage (not even that conversation) to go delete the thread my phone screen went blank quickly 2 or 3 times in a row, something I've never seen before. I deleted the thread and turned the thing off.
Oops, I must've been remembering Android. Well, it's one way Apple could fix this unconscionably lasting security hole.
Nothing is impossible unless it disobeys the laws of physics(which are also limited to what we currently know)
It would be equivalent to saying, well it isn't economic enough for energy companies to simply create nuclear fusion reactors...
Some things are just extremely hard and there's no obvious answer even if you had "unlimited" funds.
(instead of taking the time to wait for research results, best practices, security reviews and privacy concerns up-front at design-time, and even -- shock -- perhaps deciding not to build some societally risky products in the first place)
Perhaps the associated billions of dollars of spending is indeed the answer, and will translate into measurable improvements. If so, very well.
Perhaps there are Conway-style architectural issues at hand here as well, though. Can disparate teams working on (a large number of) proprietary interconnected products and features reliably produce secure results?
It seems wasteful that similarly-functioning tools -- like messaging apps -- are continuously built and rebuilt and yet the same old issues (generally exacerbated by increasing web scale) mysteriously re-appear time and again.
It would take a sea change in the mindsets of software engineers globally to centralize the software development process around a security mindset. That's not going to happen unfortunately. The vast majority of us have neither the expertise, nor the time, to develop 100% secure code. The best most of us conscientious types can do is to provide comprehensive monitoring, so that a user can use those tools to know if and when something is amiss.
99% of the problem is just wanting to not have to rewrite a hundred parsers in memory-safe languages.
It's just economics and engineering.
They don't have to change everyone's minds or fix the world. They'd need to invest a lot but so far nobody really thinks it's worth it.
Isolation, mitigation and prevention of exploitation is common.
This can be avoided if you have a cross platform high level language like say C# with a big standard library like .Net , the field needs then to make sure the language and core library are safe, most programs use existing libraries and put some business logic on top, I remember that memory safety was a thing before Rust was born, the issue was that either the languages were too slow, were not cross platform or had weird license or were "garbage".
If this gaints like Apple, Google, Facebook would contribute on rewriting or prove that the core libraries they use are correct then things would improve, but how would they continue to increase their obscene profits ?
The essential problem is features. Devs want features. So Python, .NET, etc, and even the browsers try to provide access to those features. But some of those features are simply inherently unsafe. Someone will find a way to compromise this feature or that. How does one provide 100% safe access to the GPU? The file system? And so on. It's not really possible. At some point, the app level dev will have to keep a security mindset when writing his code. Don't do things on the GPU that compromise the system. But that has to be on the app developer if that developer is demanding that the browsers give him/her access to the GPU.
I don't know if I'm being clear? But I hope you can see what I'm trying to say.
Do you have a proof that it is impossible to have a secure calculator application?
About .Net and Python, they are using a lot of wrappers around old unsafe code, so we would need to put more work and eliminate that, MS failed because of their shity Windows first ideals and their FUD,
Easier said than done…
I know is hard, this GPU companies need to keep backward compatibility, support different operating systems(and versions), support old stuff that worked by mistake. and probably some "benchmark cheeting might be hidden in the proprietary drivers too".
Presumably through pointer capabilities.
> The file system?
File system namespacing and virtualization.
I disagree with most of your assertions.
You'll end up making a standard library so big that it will never be secure. And even more portantly, you'll strangle innovation by disallowing improvements to the standard library.
Something like JVM or.Net would be part of the solution because you could pacify developers because they can use their darling language but target the same platform as the others. We still need true engineers to create an OS and Standard library from the ground up, designed for security and not chaotically evolved.
Wanting those things is fine but delivering those things is extremely difficult. JSON/XML/Zip have so many weird edge cases it's maybe impossible to write parsers that are complete to the spec yet also truly secure. XML and Zip bombs aren't explicit features of either format but they're side effects of not being explicitly forbidden.
You're also want "good" parsers without specifying in which dimension you want them to be "good". You can have a complete parser that's reasonably secure but then pay for that with CPU cycles and memory. You can have a small and fast parser that's likely incomplete or has exploitable holes.
We probably need to create better specifications, probably using a log/math language that can verify the specifications are valid and clear. It will be hard since people will need to learn to be more clear but it might also simplify things , say we would have a simple replacement for html and css if the guys creating it would have to do it in such a language.
The giants use json right, so they could put some money together find some experts to write a specification, if json is flawed they can write a new version of it that is correct, then when specification is coded they can release it, and after that this giants can pay some developers to implement it and prove the implementation correctness.
They should repeat it for one image format, they can chose what is a decent image format and do that, then do it for html, audio, video... it will save them money if less security issues happen on their servers or in their users devices. But it will save them money only if it would cost them when their devices get owned, this means we should stop apologizing this bugs with extreme fake stuff like "99.9% of applications have security issues"
Apps are sandboxed, so the damage should be limited to only the exploited app.
Pegasus exploits exploited iMessage et al, which are Apple's own apps with special permissions.
Or rather would be great if Pegasus was the only 0-day out there. It'd be even better if Pegasus were the only 0-click out there.
Here's the thing though, it's not.
That's the world we live in. So the question is, given that fact, how do we get to a world where we can have some level of security? My belief is that everyone from the users to the app devs have to adopt a security mindset.
Users should not download that free app that lets you see what you would look like as your favorite French pastry. They should not click on the link in that sms they got from that strange phone number. They should be careful about giving out their phone number. Give everyone your gmail google phone number instead and let them send texts to that. Then check those texts on your gmail google phone if you're a high profile target. (Or even just a guy/gal who has a few people out there who really don't like them.) Keep a buffer between the world and your phone. Etc etc etc.
Devs want access to the file system. Awesome, but they'd better make sure in using that filesystem they are not inadvertently allowing users to take any actions deleterious to the system. Devs want access to the GPU. Again, no problem. But you'd better know how to write secure GPU code. There is no way a browser, or .NET, or Python or an OS can provide you access to a GPU "safely". If they give you the gun, they expect you will use it responsibly.
Browsers and other platform providers should also act responsibly. I understand developers want features. At the same time, is it responsible to hand out access to these features without some kind of plan to keep irresponsible devs from compromising security at scale? Sometimes there just is no way to do that, and I understand. (Access to the GPU is an example. Devs just have to know what they're doing.) But sometimes it is possible to do things in a more secure fashion, or to just wait on delivering that feature altogether.
Point is, for a secure environment, everyone has to play their part. There are so many of these 0-clicks and 0-days out there in the wild. Everyone wants to make a better environment. Well, I'm not seeing how that happens without getting everyone's cooperation. Or, at a minimum, getting everyone to be a bit more careful with their behaviors.
AFAIK, the hacker broke out of the sandbox in addition to rooting iMessage.
Also, the surface area available to a sandbox is too large. Firecracker like VM isolation is required for safety, which Apple seems to be moving towards when it comes to parsing from their apps at least.