TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

iPhone flaw exploited by second Israeli spy firm

503 pointsby caaqilover 3 years ago

14 comments

someotherpersonover 3 years ago
Pretty sure this was known since last year[0], although it may be slightly different.<p>The smaller firms are just alphabet soup remixes of the larger ones. I wouldn&#x27;t be surprised if they have the same owners, same staff, same offices -- just with a different logo at the top of a second set of business cards.<p>[0] <a href="https:&#x2F;&#x2F;www.haaretz.com&#x2F;israel-news&#x2F;tech-news&#x2F;.premium.HIGHLIGHT-the-secret-israeli-cyber-firm-selling-spy-tech-to-saudia-arabia-1.9884403" rel="nofollow">https:&#x2F;&#x2F;www.haaretz.com&#x2F;israel-news&#x2F;tech-news&#x2F;.premium.HIGHL...</a>
评论 #30195328 未加载
keewee7over 3 years ago
&gt;In Uganda, for example, NSO&#x27;s ForcedEntry was used to spy on U.S. diplomats, Reuters reported.<p>This was the incident that made US authorities go after NSO. I remember reading that these diplomats were actually involved in espionage.
评论 #30194914 未加载
评论 #30196144 未加载
58x14over 3 years ago
This is unsurprising; the number of individual exploits needed to chain together into a functioning compromise often requires a lot of joint effort.<p>It&#x27;s funny this release comes out at the same time as the FBI&#x27;s disclosure that they &quot;tested&quot; (aka purchased) Pegasus, NSO group&#x27;s packaged exploit software. <a href="https:&#x2F;&#x2F;www.reuters.com&#x2F;world&#x2F;us&#x2F;fbi-says-it-tested-israeli-company-nso-groups-spyware-2022-02-02&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.reuters.com&#x2F;world&#x2F;us&#x2F;fbi-says-it-tested-israeli-...</a>
评论 #30194413 未加载
mcoliverover 3 years ago
For those who are just being exposed to this stuff, This Is How They Tell Me the World Ends: The Cyberweapons Arms Race by Nicole Perlroth was an entertaining read that covers some of the history in this space.
评论 #30196017 未加载
评论 #30195237 未加载
AtlasBarfedover 3 years ago
Is Israel THE go-to haven for security firm and three-letter agencies to arbitrage&#x2F;bypass surveillance regulations?<p>If the CIA isn&#x27;t allowed to do certain things for spying, so ... just have Israel spy on our populace and since we basically fund them and let them spy on us anyway, just make sure their database is open to us?<p>Where else is there 1) the talent and 2) the relative degree of trust?<p>There are a lot of stories from my childhood (of debatable ranking on the conspiracy scale) of the dirty pool and awful unconstitutional behavior by the CIA and other agencies.<p>It is my vague impression that the increased information awareness from the web tempered the bad behavior for a couple decades, but I think the old habits will start reappearing in &quot;cyberspace&quot; once they gain sufficient deniability, and people&#x27;s live reach a level of &quot;mortal&quot; dependence on it.
评论 #30194700 未加载
评论 #30195120 未加载
评论 #30195656 未加载
评论 #30195561 未加载
评论 #30194435 未加载
shmattover 3 years ago
This is comical. Of course more than one person knows about each 0-day at NSO. Maybe they even brought it over from a different place. And they can forward it (for money or ego) to 1000 other people. There truly is no limit, once someone has committed the idea to anyone but themselves<p>NSO (and the smaller, anonymous companies) are famous for bringing in people from Israeli NSA (8200) or Mossad. Why? They&#x27;re not just smart, they also have a bank of 0-days in their brains. Even if they&#x27;re not bringing over actual code, they remember all of the 0-days they were exposed to. There is no way to stop them from &quot;uploading&quot; their knowledge to a new company with a 7 figure compensation package<p>At some point the UAE figured this out, and Dark Matter opened an office in Cyprus. Offering ex-8200 7 figures (in $) to come build cyber weapons for them, limiting their dependency on NSO and export licenses[1]. The Israeli Govt. was furious but it wasn&#x27;t illegal to move abroad and work for a foreign country<p>[1]<a href="https:&#x2F;&#x2F;www.themarker.com&#x2F;technation&#x2F;.premium-1.7972249" rel="nofollow">https:&#x2F;&#x2F;www.themarker.com&#x2F;technation&#x2F;.premium-1.7972249</a> - requires translation to english
评论 #30197941 未加载
评论 #30200549 未加载
usuiover 3 years ago
I had a thought after thinking about the publicity of this second exploit: If Facebook says iOS is causing $10B loss of revenue (<a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=30190216" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=30190216</a>) then it would be in their interest to hurt the public&#x27;s opinion on iPhone privacy&#x2F;security.
评论 #30195692 未加载
评论 #30197345 未加载
评论 #30197641 未加载
dc-programmerover 3 years ago
This is getting out of hand. Now there are two them!
评论 #30194552 未加载
评论 #30194616 未加载
rootsudoover 3 years ago
Question:<p>If device is jailbroken, and you apply root limit and other things to break standard features. Would it make it harder to exploit an ios?<p>I would imagine you can do default hardening like modifying the software version label so when the software queries it will be unable to automatically &quot;arm&quot; itself and apply persistence.<p>Are there any packages&#x2F;places where this is already discussed?<p>If not, then I guess I will pick up some older iphone devices and play along - because it seems to be a great point - I highly doubt there is much sophistication in these malwares and there has to be some sanity checks that make it so that if you are <i>targetted</i> it will not &quot;reveal&quot; itself.<p>And of course the basic one of VPN, and forcing to change the DNS servers which the ios devices operates on.
评论 #30199503 未加载
chezzwizzover 3 years ago
The only thing that I took from this was NSO Group, blacklisted for selling to foreign governments, demonstrated an iPhone exploit and another reason to stay awake in foreign countries.<p>in related news: * <a href="https:&#x2F;&#x2F;arstechnica.com&#x2F;tech-policy&#x2F;2022&#x2F;02&#x2F;report-nso-offered-us-firm-bags-of-cash-for-help-spying-on-cellphone-users&#x2F;" rel="nofollow">https:&#x2F;&#x2F;arstechnica.com&#x2F;tech-policy&#x2F;2022&#x2F;02&#x2F;report-nso-offer...</a> * <a href="https:&#x2F;&#x2F;www.techdirt.com&#x2F;articles&#x2F;20220121&#x2F;13492148329&#x2F;spying-begins-home-israels-government-used-nso-group-malware-to-surveill-own-citizens.shtml" rel="nofollow">https:&#x2F;&#x2F;www.techdirt.com&#x2F;articles&#x2F;20220121&#x2F;13492148329&#x2F;spyin...</a>
A4ET8a8uTh0over 3 years ago
I am not sure if it was already covered, but at this point one has to assume that every government that can obtain it, will[1]. I do find it odd however that FBI did given some of the more recent revelations about hacks against US using same software.<p>[1]<a href="https:&#x2F;&#x2F;www.jpost.com&#x2F;international&#x2F;article-695290" rel="nofollow">https:&#x2F;&#x2F;www.jpost.com&#x2F;international&#x2F;article-695290</a>
thunderbongover 3 years ago
<a href="https:&#x2F;&#x2F;archive.md&#x2F;UGmhy" rel="nofollow">https:&#x2F;&#x2F;archive.md&#x2F;UGmhy</a>
gostsamoover 3 years ago
What are the chances that they bought the vulnerability from the same place? Finding something like that at the same time if it was there for awhile is rather suspect.
评论 #30193065 未加载
gatacaover 3 years ago
Why doesn&#x27;t Apple just buy NSO and use them as an internal defense group?
评论 #30193953 未加载
评论 #30194334 未加载
评论 #30194181 未加载
评论 #30194959 未加载
评论 #30195445 未加载
评论 #30194156 未加载
评论 #30194080 未加载
评论 #30194180 未加载