news.volyx.in

NSO Group iMessage Zero-Click Exploit Captured in the Wild (citizenlab.ca)

940 points by jbegley · 1835 days ago · 326 comments on HN

Article summary

Researchers discovered a zero-day zero-click exploit, called FORCEDENTRY, used by the NSO Group to infect Apple devices with Pegasus spyware. The exploit targets Apple's image rendering library and was effective against iOS, MacOS, and WatchOS devices. Apple has released an update to patch the vulnerability, and users are urged to update their devices immediately. The discovery highlights the ongoing issue of mercenary spyware companies facilitating surveillance and espionage activities.

Main themes

  • NSO Group and Pegasus spyware
  • Apple device vulnerabilities
  • Surveillance and espionage
  • Government use of spyware
  • Privacy and security concerns
  • Alternative technology options

What commenters say

  • The NSO Group's business model is based on exploiting vulnerabilities and selling surveillance capabilities to governments, which can lead to reckless use and discovery by investigatory organizations.
  • The use of spyware by governments, such as Germany, raises concerns about the integrity of European telecoms and the potential for tracking down dissidents.
  • Some argue that the only way to avoid surveillance is to not use popular products like Apple or Google, while others believe that removing tech from daily life is not a viable solution.
  • The issue of spyware and surveillance is complex, and there are no easy choices between security and privacy, with some arguing that clientside scanning of media for wrongthink is a concern.
  • The NSO Group's actions have been likened to war crimes, and some believe that they should be held accountable for their role in facilitating human rights abuses.
  • Others argue that the focus should be on finding ways to stop the exploitation of vulnerabilities, rather than just treating the symptoms.
  • The lack of updates for older operating systems, such as Mojave, is a concern for users who may be left vulnerable to exploits.
  • Some users are considering alternative options, such as GNU/Linux phones, to avoid the risks associated with popular products.