The truth is that “Zero-Click” hacks are becoming increasingly rare.
But of course everything is new for journos unfamiliar with the field.
The truth is that “Zero-Click” hacks are becoming increasingly rare.
But of course everything is new for journos unfamiliar with the field.
1. Memory safety mitigations became much more common (Vista)
2. Browsers adopted sandboxing (thanks IE/Chrome)
3. Unsandboxed browser-reachable software like Flash and Java was moved into a sandbox and behind "Click to Play" before eventually being removed entirely.
4. Auto-updates became the norm for browsers.
And that genuinely bought us about a decade. The reason things are changing is because attackers have caught back up. Browser exploitation is back. Sandboxing is amazing and drove up the cost, but it is not enough - given enough vulnerabilities any sandbox falls.
So it's not that security is getting worse, it's that security got better really really quickly, we basically faffed around for a decade more or less making small, incremental wins, and attackers figured out techniques for getting around our barriers.
If we want another big win, it's obvious. Sandboxing and memory safety have to be paired together. Anything else will be an expensive waste of time.
It’s still a completely different world. We’ve come a long way from back when Paunch was printing money with Blackhole.
I think it would be detected quickly because the most likely payload dropped would be ransomware. which makes it immediately obvious to users they got owned. I don't think it would take longer than a day to discover a zero day exists in $BROWSER once a group starts a campaign using it.
All software distributors that expose attack surface to a large consumer base have all had plenty of time to learn how to deal with a major security hole that needs to be patched asap. Once a researcher tweets about a 0day in $BROWSER, there'll be an incomplete patch 1 day later. 4 days later the final patch is out. Auto updates ensure every user has the patch the moment they go online.
But I do think we can still see a CCG using a browser exploit to infect people, but I don't think we'd see exploits packaged and sold inside exploit kits.
I suppose that could make a generalized kit much harder to sell. Once it's sold once you basically have to assume it'll be burned soon.
Time will tell.
And you're definitely right that they are far more rare. Worms used to be nasty is now fast and easily they spread. Security has come a long way since then.
That said, we could go further on security. But is selling people on using more secure software and hardware. Even something as simple as bounds checking has a cost. Look at the reception of the Windows 11 change to have Virtualization Based Security turned on by default. People are upset about it because it takes away performance for security that they claim they don't need on their home computer.
And then there's resistance from developers. For some reason people get really upset about mechanisms designed to improve security without increasing runtime overhead when they make compile time take longer. If your application is used by any significant number of people, surely the amount of runtime you're saving dwarfs the amount of extra time to compile.
Few vaguely reliable RCE bugs aren’t wormable. Even ones requiring significant user interaction are wormable, office macros are wormable.
Workable bugs are far more common than actual worms.
There really isn't something new here other than a fancy name - or I am not seeing the point.
A zero click remote code execution, would be for example where the attacker send a message, and their phone just processing the message on it's own is enough for the attacker to execute code on the victims device.
A non zero click vulnerability can be mitigated by being cautious. A zero click vulnerability cannot.
You get owned without clicking hence zero click. Is it different from RCE? A subset? Doesn't matter. Title could have said RCE.
No amount of caution will save you when the exploit is injected into a major website.
Why bother with such meaningless distinction? Does your browser never hit any http:// resources?
I think this just goes to show how silly this new terminology is.
Most of it is not behind air gap. And unless things get a lot worse it wont be.
Proper air gaping is hard, expensive and pain in the ass, on the ongoing basis.
That's why almost none does it. Not even most military systems are air gaped.
And yet in most organizations, airgapping is an alien concept. Even for machine tools that could kill someone.
Security vs convenience...
It's a special kind of naive to assume that airgapping is a technological problem rather than a human behavior problem.
Systems need to work assuming that they are bathed in a hostile environment at all times.
RCE occurs on a system with a listening daemon/service (e.g. web, SQL, DNS SSH).
Zero-click describes an issue on a client system where usually a user would have to click something to trigger it, but doesn't as parsing/processing happens before the user actually sees anything (e.g. via an SMS on a phone).
> Zero-click describes an issue on a client system where usually a user would have to click something to trigger it, but doesn't as parsing/processing happens before the user actually sees anything (e.g. via an SMS on a phone).
Historically these have been referred to as RCE.
FWIW You are essentially describing a service listening on the network. It’s silly to try to make an artificial distinction based on some irrelevant L4 differences.
Client services with zero interaction, have traditionally been regarded as safer, usually for client side attacks we'd expect a trigger from user action (e.g. a link being clicked, a PDF file being opened).
Just because you don't find something to be useful as a distinction in your line of work doesn't necessarily mean that it's not useful to anyone ...
iMessage isn’t meaningfully different from Apache, instead of listening on a TCP number it listens on your Apple user id.
From any useful perspective, RCE and zero-click exploits are the same thing. The latter is just a fancy name for the moron journalists like the one who wrote this article to bandy about to lure in some readers.
That or maybe drive-by downloads / java/activeX code execution, which have become more rare
Guy’s a boss.