TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Zerodium expects iOS exploit prices to drop as it announces surplus

73 pointsby jwileyabout 5 years ago

5 comments

londons_exploreabout 5 years ago
How about another theory...<p>The kind of organisations that use these exploits rarely want to use the same one twice. That would link the two uses, which could reveal who was attacking who or why.<p>However, anti-rooting protections on iOS devices are such that the vast majority of organisations don&#x27;t have any kind of logging or analysis infrastructure set up which could trace which devices have a specific exploit run against them.<p>The exploit is probably delivered by an encrypted channel, so even if you did full traffic logging from all employee devices to the internet, you still wouldn&#x27;t have enough info to know which devices were infected, since the attacker will surely use a different server each time to deliver the exploit.<p>That suddenly makes it much safer to reuse exploits, so there isn&#x27;t such a big market for a new exploit for every covert operation.<p>The same isn&#x27;t true of Android - there are plenty of apps which will trace syscalls, dump logs, send suspicious files for analysis, etc. That makes reusing an exploit a risky business for three letter agencies, especially if you&#x27;re attacking another three letter agency who probably has their own custom anti-malware type software just waiting for you to trip a tripwire.
_0w8tabout 5 years ago
I wonder what is the reason for that? I doubt Apple code quality dropped significantly. Is it simply because more people started to look for vulnerabilities? Or was it because better tools to discover the bugs became available?
评论 #23216284 未加载
评论 #23214984 未加载
评论 #23215117 未加载
saltedonionabout 5 years ago
What is the business model of this company? Are they selling such exploits to whoever is willing to pay the most?<p>And does this mean Android is more secure?
评论 #23214652 未加载
评论 #23214673 未加载
评论 #23216723 未加载
masnaoabout 5 years ago
seems like a guerrilla marketing campaign to make researchers know sandbox is broken but they are still shopping for persistence.
评论 #23215306 未加载
captn3m0about 5 years ago
I made a few guesses on a previous thread: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=23170237" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=23170237</a>