news.volyx.in

0-days exploited by commercial surveillance vendor in Egypt (blog.google)

534 points by mikece · 1067 days ago · 239 comments on HN

Article summary

Google's Threat Analysis Group discovered a 0-day exploit chain used by a commercial surveillance vendor in Egypt to install spyware on iPhones. The exploit chain was delivered via a man-in-the-middle attack and included three vulnerabilities that were patched by Apple in iOS 16.7 and iOS 17.0.1. The vendor also had an exploit chain for Android devices. The discovery highlights the risks of commercial surveillance and the importance of prompt patching.

Main themes

  • Commercial surveillance
  • Exploit chains
  • Common Criteria certification
  • Security assurance
  • Formal methods
  • Vulnerability patching

What commenters say

  • Commercial surveillance vendors pose a significant threat to online users and their activities can have serious consequences.
  • The Common Criteria certification process is flawed and does not guarantee a product's security.
  • Achieving high assurance levels in the Common Criteria certification process is extremely difficult, if not impossible, for large commercial vendors.
  • The certification process is more focused on compliance than actual security, and certifications do not necessarily reflect a product's ability to withstand attacks.
  • Some argue that formal methods and high assurance levels are necessary for secure products, while others believe that these methods are impractical for complex systems.
  • The security of a product is not solely determined by its certification level, but also by its design, implementation, and testing.
  • The use of formal methods and high assurance levels can provide strong security guarantees, but may not be feasible for all types of products or systems.