news.volyx.in

NSO group iPhone zero-click, zero-day exploit captured in the wild (citizenlab.ca)

1446 points by ericzawo · 1083 days ago · 832 comments on HN

Article summary

Citizen Lab discovered an actively exploited zero-click vulnerability in iPhones, which was used to deliver NSO Group's Pegasus spyware. The exploit, called BLASTPASS, involved sending malicious images via iMessage and could compromise iPhones running the latest version of iOS without any user interaction. Apple has issued patches for the vulnerability and recommends that users update their devices immediately. The discovery highlights the importance of supporting civil society organizations in identifying and reporting security threats.

Main themes

  • iPhone security
  • zero-click exploits
  • messaging app security
  • end-to-end encryption
  • Lockdown Mode
  • BlastDoor service
  • NSO Group and Pegasus spyware
  • civil society and security threats

What commenters say

  • iMessage's architecture is a security disaster due to its complexity and legacy requirements.
  • Google's messaging apps are not secure because they are not end-to-end encrypted by default.
  • Encryption does not protect against malicious payloads being sent, and security measures like Lockdown Mode are necessary.
  • The cost of zero-click zero-day exploits is extremely high, and they are not used haphazardly.
  • Apple's BlastDoor service is an attempt to mitigate these types of exploits, but it may not be enough.
  • Lockdown Mode can block these types of attacks, but it may be too restrictive for some users.
  • The trade-off between security and convenience is a major issue in messaging apps, with some arguing that security should take priority.
  • The ability to modify client implementations to expose messages to third parties is a concern, even if messages are encrypted at rest and in transit.