Home › Forums › Science & tech › New NSO zero-click attack evades Apple’s iPhone protections
not using an iphone is common sense
fpbp
Zero clicks have existed on Android since they were released
Ah, yes. The typical iToddler response of "but Android!".
this exploit worked on android. android has tons of these. not to mention this is the only zero click exploit that iphones have had in years. im only saying in years because there were some that would crash the device years ago, but they got no access to your device
of course android has malware in the freaking APP STORE so android users are used to it
but in the case of iphones, this is a big deal, which is why it made headlines, and scrotebrains went "itoddlers btfo!"
too bad it only went after specific targets, very few got hit by it, and it was instantly fixed anyway
https://i.imgur.com/jSEPT5L.gif
Learn to cope iToddler
Android has less security vulnerabilities over iShit and is the common sense choice for anyone but 40 year old soccer moms and fat scrote ladies
>android has less security vulnerabilities
hahahahah jesus christ andjeet, the google play store is constantly full of malware. theres literal spyware, identity theft, miners, keyloggers, and RATs in your freaking app store
what a hilarious attempt at lying
also, the people you just mentioned are the android users.
remember, india is 93% android. every developed country is majority iphone.
IPhone can’t sideload. Waste of earths resources.
You can pozzed by receiving a malformed SMS or browsing a website dude.
if youre gonna be a FOSStard on your phone even just go full scrotebrain and get a pinephone. f droid has malware too by the way
imagine your response to the official android app store being full of malware to install it from a store thats far smaller and literally isnt checked for malware at all
keep proving to me that you have nothing of value and do nothing of value on your phone and therefore your opinion is worthless
and again, india is 93% android usage. literally. this is coming from official statistics. you are an andjeet and that will never change. android will never be anything but the poor people phone
why would i need or want to sideload? im not a child, i dont need emulators on my phone. safari has adblock and other extensions officially now. you must be a serious manchild if you think anyone cares about sideloading random shit onto their freaking phone. thankfully as an iphone user i can just install everything the app store and know its fully optimized and secure
>secure
HAHAHAHAHAHAHAHAHHAHAAHAHAHAHAHAHAHAHAHAHAHAHAHA iToddlers will never fail to amuse me with how freaking stupid they are.
>as an iphone user i can just install everything the app store and know its fully optimized and secure
https://web.archive.org/web/20210930172843/https://habr.com/en/post/580272/
>he posts that same exact site talking about that same exact article that nobody cares about because its nothing
literally worse than cherrypicking. hm…. whats a better word? pebble picking? particle picking?
Fact picking.
>as an iphone user i can just install everything the app store and know its fully optimized and secure
https://web.archive.org/web/20210930172843/https://habr.com/en/post/580272/
>f droid has malware too by the way
???
Malware has a fairly broad definition, so it wouldn’t surprise me if some software can come under the label of malware on f-droid.
if you have an old ios device, it’s shit. I have an old ipad mini 1st gen running 32-bit ios 9.3.5 and i can barely do dogwater with it. i have VLC on it yet it cant really work. Yet an even older android tablet (android 4.1.1, 512mb ram) can play back youtube and brosw LULZ flawlessly with KuboraEx and Newpipe legacy and can even do Micro-HDMI out.
>Learn to cope
the post
And you not only doubled down, but tripled down on it!
You’re the gayest type of person on this board.
Show me these.
Android and iOS are both completely compromised
feature phone
>desktop OS
>Desktop OS Running Firefox on 2GB RAM
lmao no
heh.. desktop OS running firefox on 3GB OF RAM if you spend the extra shekels
As an iPhone user I can confirm. Both platforms are absolutely dog shit and if I didn’t need a phone for work (company provided) I wouldn’t use one at all
Not really. You can do something about that on Android, but not on iOS. You can run a custom ROM with microG, not use a Google account, isolate apps with many permissions with Insulate, use App Warden to remove trackers from apps, etc.
Woke af
fpbp
Basado
Which is an index of how overrated common sense is.
And how is using Apple products common sense then?
>Apple added an extremely safe iMessage parser in iOS 14 to prevent exploits caused by parsing messages: https://googleprojectzero.blogspot.com/2021/01/a-look-at-imessage-in-ios-14.html
Finally.
It’s only taken them like 7 years.
This along with dozens of insane and scrotebrained engineering flaws just because they know they can do it which no one else but Apple users have to deal with.
slash thread
>woke af department call in an iphone
The common sense here is to throw your tracking device in the bin. (But, honestly, anti-malware softwares that run on iPhone and Android devices are kneecapped in their effectiveness anyway.)
Another one to the long list of apple "bugs" (wich are just secret backdoors to a few select ones), if only yfsgt still updated.
>already fixed in ios 14.8
Wow it’s freaking nothing
Meds. Now.
you cannot fix buffer overflows in legacy programming languages.
as long as that parser isn’t re-written in a modern safe language, it will never be secure.
dickyOS doesn’t have this problem
Where do I sign up
>pegasus spyware
people who bought a gnomish apple phone got hacked by a gnomish spyware company
big surprise. tim cook is probably part of the sayanim
https://i.imgur.com/yyKwAPd.gif
iTODDLERS BTFO
Android is fucken Windows alright. Everything Google does with Linux turns into an adware nightmare.
Chromebook? Fucken plastic shit.
Android? Fucken plastic shit.
Adware everywhere. Everywhere. Security? No more.
I agree with you, but they’re not the topic of this thread.
Well at least iToddlers get something done on their phones without tapping 30 times, installing custom rom, debloating, etc.
When Richard Stallman or FreeBSD release phone I buy. Sony made PS4 PS5 and did not fix FreeBSD, so they can make FreeBSD mobile OS easy. Give them 3 months.
Woke af.
That’s a nice from of cope, but let me refer you back to
>get something done
Lol like what? Browsing Reddit and watching anime and Netflix like all of you itoddlers do? Hell, you don’t even have an actual file manager.
Investment management for one, which statistically speaking is not something Android users are familiar with
statistically speaking average iToddler is Amerimutt
>average amerimutt is 50k USD in debt
oh no no no no no
>Investment management for one, which statistically speaking is not something Android users are familiar with
Look at the sheer amount of fuckups here:
https://github.com/iTODDLERS-BTFO/iToddlers-BTFO
If it was any other company having even one, forget several or all of these, anyone sane would say "Hey, wait a minute, I don’t think I’ll ever buy products from a company like this ever again". But in the case of Apple, people defend them and even this whole board is unfortunately evidence of this.
>emoji lawsuits
>other bs lawsuits
>anti trust bs
You 3rd worlders aren’t even cherry picking at this point because you can’t find massive flaws with apple products
Way to prove me right.
Apple is the industry standard whether or not you like it sonan.
Not for me it isn’t. I don’t have to deal with any of their fuckups, since I never would’ve bought an Apple product. That’s on you and for you.
How do zero-clicks work? Do they just send a text message to your number or similar and then your phone is hacked?
Pretty much yea
The scrotebrains who designed IOS didn’t know how to handle the messages properly so people can just send you code and your phone will run it
You’d think it would be a really simple way to fix but they’re no doubt working with 300 gigs of legacy spaghetti code, half heartedly patched together into the abomination that is IOS
Exploits are not as simple to fix as you think they are, they’re found constantly. Windows, MacOS, Linux, Android, iOS, Chrome, Firefox etc all suffer from them constantly.
>The scrotebrains who designed IOS didn’t know how to handle the messages properly so people can just send you code and your phone will run it
what in the fuck are you talking about? The NSO exploit OP posted targeted a component of CoreGraphics and wasn’t an exploit in iMessage itself.
Apple added an extremely safe iMessage parser in iOS 14 to prevent exploits caused by parsing messages: https://googleprojectzero.blogspot.com/2021/01/a-look-at-imessage-in-ios-14.html
>Apple added an extremely safe iMessage parser in iOS 14 to prevent exploits caused by parsing messages: https://googleprojectzero.blogspot.com/2021/01/a-look-at-imessage-in-ios-14.html
Finally.
It’s only taken them like 7 years.
They can be anything, they just require no input from the user or anyone else on the device.
Whether it’s a browser exploit that just visiting the webpage runs it, receiving an image, an sms message, whatever.
https://i.4cdn.org/g/1633332629372.webm
>shitskin tan
dropped
Good luck with your binary blob "write-once" shitty outsourced firmware effort, frekkin 0day heaven /vendor partition and failed project treble on Android.
Good luck with the endless fuckery that is popups, dialogs, endless wizards and endless settings that is the norm on Android where you are distracted every fucken second from being productive on master race PC.
Good luck with trying to hammer every tracking app down with more apps, while getting pwned by open-source library exploits like WebKit and we are all vulnerable anyways.
Just don’t fucken say you got it all figured out right sis.. Cuz you don’t have a frekkin clue where to start to audit your android shit and its impossible to secure it 100% no matter how autistic Greta you are.
Its not possiOMG to secure your phones 100%. Yesterdays secure phone gets pwned 2morow.
But at least us iToddlers don’t waste time on the endless effort in securing an android.. its worthless in the end.
Cry scriptkiddie brave browser neckbeard communist hak5 normie android tears..
>Good luck with your binary blob "write-once" shitty outsourced firmware effort, frekkin 0day heaven /vendor partition and failed project treble on Android.
>
>Good luck with the endless fuckery that is popups, dialogs, endless wizards and endless settings that is the norm on Android where you are distracted every fucken second from being productive on master race PC.
>
>Good luck with trying to hammer every tracking app down with more apps, while getting pwned by open-source library exploits like WebKit and we are all vulnerable anyways.
>
>Just don’t fucken say you got it all figured out right sis.. Cuz you don’t have a frekkin clue where to start to audit your android shit and its impossible to secure it 100% no matter how autistic Greta you are.
>
>Its not possiOMG to secure your phones 100%. Yesterdays secure phone gets pwned 2morow.
>
>But at least us iToddlers don’t waste time on the endless effort in securing an android.. its worthless in the end.
>
>Cry scriptkiddie brave browser neckbeard communist hak5 normie android tears..
>https://github.com/iTODDLERS-BTFO/iToddlers-BTFO
scrote, GrapheneOS is literally more secure than iOS.
That xda-developers winzip job that is GrapheneOS still won’t save you from /vendor partition 0days or system libraries like WebKit, its all like running custom shell on Windows, you still are not in control. Advocating privacy on a scrotebrained messed up Linux flavor called Android from the largest data-collection company in the world is literal hypocrisy
>won’t save you from /vendor partition 0days or system libraries like WebKit
Prove that this isn’t purely theoretical and that it has affected phones outside of testing facilities and such. There’s also this if you want to do something about Webkit:
https://www.bromite.org/system_web_view
>its all like running custom shell on Windows, you still are not in control
It’s not like that at all since Windows isn’t open source and there’s no way to use a version of it that is. Custom ROMs are compiled using AOSP and with root you are in control of everything.
>Advocating privacy on a scrotebrained messed up Linux flavor called Android from the largest data-collection company in the world is literal hypocrisy
No, it isn’t. Privacy can’t be perfect and especially on a smartphone, but Android is the only usable mobile platform which allows you to improve it. An example of hypocrisy would be running as much FOSS on Windows as possible and thinking your efforts aren’t defeat by the OS they’re running on.
> Custom ROMs are compiled using AOSP and with root you are in control of everything.
The iOS Jailbreak community is way more hardcore than the kids-section with Franco’s kernel over at xda-devs, KEK.
Yeah, it’s so hard core that jailbreaking is one iOS version behind and most of what you could achieve with it has been added to iOS over the years, so no one really bothers. I can only imagine how tedious it is to get jailbreak working in the first place. I’m not sure what for at this point, aren’t Cydia and the like abandoned and it’s not even useful for getting apps for free?
>>august 24
Even what I consider the best and most responsible android manufacturer SAMSUNG doesn’t release security updates to anything but the latest models and with long intervals:
https://www.sammobile.com/samsung/samsung-galaxy-security-updates
Pray you are not vulnerable. KEK!
I don’t have to pray since I don’t buy phones which don’t have good community support so I can keep my phone updated as soon as possible. And I’ve done so since the original S1 days. It’s not like there are reports every other week about millions of phones getting exploited if security patches are a couple of months out of date. On the other hand iOS updates introduce throttling after a year, so..
community support is worthless.
can’t patch binary blobs.
>Second, many users have likely read about the Quadrooter vulnerability coming out of DEF CON. Here, we have a bit of bad news. Of the four reported CVEs, we’ve been able to plug the ones that affected OSS code (ie the kernel), specifically CVE-2016-2059 and CVE-2016-5340. However, some of the reported vulnerabilities lie within OEM binary blobs, meaning we don’t have source access to resolve them.
>So what does this mean? Unfortunately, for many devices we may never be able to completely resolve the outstanding issues, as OEMs are unlikely to release updated blobs across the generations of devices CM 13.0 supports
https://web.archive.org/web/20161223020015/https://www.cyanogenmod.org/blog/cm-13-0-release-znh5y
LineageOS also communicates this with some vendor patch level which they cannot update. picrel.
security-conscious custom roms like Graphene will immediately drop support when there are no more patches from the vendor:
https://grapheneos.org/faq#legacy-devices
>community support is useless
No, it isn’t. But for you it might be if you’re still somehow using Cyanogenmod and a ROM from 2016.
>can’t patch binary blobs
Prove that this is a real actual threat end users should be worried about.
>LineageOS also communicates this with some vendor patch level which they cannot update. picrel.
It doesn’t matter since you’re getting security updates pretty much the same time they’re pushed into AOSP. That’s why one would be using custom ROMs among other things.
>security-conscious custom roms like Graphene will immediately drop support when there are no more patches from the vendor:
Alright, Graphene is available for like 10 Pixel devices and it’s not like it matters to me since Pixels are only really a thing in the US and I’m not from there.
You can eat your fucken Android plushie toy when I say Elcomsoft and Cellebrite among other slimey forensic companies keep these a secret.
I’ve spoken to a police officer in private on numerous occassions and he always said Androids does not pose a problem to the police. But iOS is pretty tough for them to extract/exploit if secured and updated. KEK!
community support is worthless.
can’t patch binary blobs.
>Second, many users have likely read about the Quadrooter vulnerability coming out of DEF CON. Here, we have a bit of bad news. Of the four reported CVEs, we’ve been able to plug the ones that affected OSS code (ie the kernel), specifically CVE-2016-2059 and CVE-2016-5340. However, some of the reported vulnerabilities lie within OEM binary blobs, meaning we don’t have source access to resolve them.
>So what does this mean? Unfortunately, for many devices we may never be able to completely resolve the outstanding issues, as OEMs are unlikely to release updated blobs across the generations of devices CM 13.0 supports
https://web.archive.org/web/20161223020015/https://www.cyanogenmod.org/blog/cm-13-0-release-znh5yLineageOS also communicates this with some vendor patch level which they cannot update. picrel.
security-conscious custom roms like Graphene will immediately drop support when there are no more patches from the vendor:
https://grapheneos.org/faq#legacy-devices
He.. just proved that. And I have contacts in mobile forensics with law enforcement who say iOS pose a bigger challenge. You do know that CIA and FBI time and time again has contacted Apple directly for backdoors because of their top kek security they couldn’t break right? And the bug bounty is $500k not $50k like android (only for AOSP) go figure..
>But iOS is pretty tough for them to extract/exploit if secured and updated. KEK!
Yeah yeah yeah yeah yeah and my uncle also works at Nintendo.
https://www.nytimes.com/2020/10/21/technology/iphone-encryption-police.html
>You do know that CIA and FBI time and time again has contacted Apple directly for backdoors because of their top kek security they couldn’t break right?
Don’t tell me you fell for that marketing PR bullshit and thought that Apple with its forever proprietary iOS and permanently locked bootloaders really cares about your privacy. Guess you did. That’s why you’re defending them. Anyway, it was broken eventually and the CSAM thing was reverse engineered and found to be working even on iOS 14 (14.3) even though they said they were just planning on implementing it.
https://en.wikipedia.org/wiki/FBI%E2%80%93Apple_encryption_dispute
https://www.iphonehacks.com/2021/08/developer-reverse-engineers-apples-csam-finds-serious-flaws.html
This is your own link alright..
“We may unlock it in a week, we may not unlock it for two years, or we may never unlock it,” Cyrus R. Vance Jr., the Manhattan district attorney, testified to Congress in December. “Murder, rape, robberies, sexual assault. I do not mean to be dramatic, but there are many, many serious cases where we can’t access the device in the time period where it is most important for us.”
"Forensic tools take time to be developed and criminals the police catch are usually not the brightest ignoring updates time and time again."
"Because of all the possible combinations, a six-digit iPhone passcode takes on average about 11 hours to guess, while a 10-digit code takes 12.5 years."
Not so shabby.. 12.5 years with 10 digits. What about 20 alphanumeric and special chars?
"Their flagship tools cost roughly $9,000 to $18,000, plus $3,500 to $15,000 in annual licensing fees, according to invoices obtained by Upturn."
Its a nice business to sell tools that can only crack outdated software. The easiest trick in the book to reap glowscrotes money by "magic" forensic wizards! That seems like the cheapest option to be honest..
"The police can send the trickiest phones to crack, such as the latest iPhones, to Cellebrite, which will unlock them for about $2,000 a device, according to invoices. Law enforcement can also buy a similar premium tool from Cellebrite. The Dallas Police Department spent $150,000 on one, according to the records."
Check Cellebrite’s official menu on their website, it only supports older iOS versions. You will have to spend enormous amounts of money and resources and be terror-tier to be even considered.
>i asked the feds and they say its fine, dont use android its soo insecure and prevents us feds from cucking you!
another reason to use android and de garden gnomegle it
>your OS asking you to confirm what you want to do is a bad thing
I don’t know you’re even arguing for. That no amount of security can be gained and that you should just not care and let your machines and phones get infected with whichever avoidable malware? Also, ad blockers exist you caveman. You don’t need to have a local VPN tunnel in order to have ad blocking on Android and you can also have ad blocking, a VPN and a firewall running at the same time. And you can also run custom ROMs with microG on Android phones if you want to gain back security and privacy as much as reasonably possible.
Apple has worse security then both MS and Android. I’m surprised it took so long for the cracks in ios to start showing
moroccan here : pegasus is not us.
thank you and have a nice day
>already patched
>meanwhile on lagdroid
>Hundreds of scam apps hit over 10 million Android devices
>a new round of takedowns involving about 200 apps and more than 10 million potential victims shows that this longtime problem remains far from solved—and in this case, potentially cost users hundreds of millions of dollars.
>>Hundreds of scam apps hit over 10 million Android devices
>>a new round of takedowns involving about 200 apps and more than 10 million potential victims shows that this longtime problem remains far from solved—and in this case, potentially cost users hundreds of millions of dollars.
>and all the same apps present on the AppStore
it was literally android only lmao
>proceeds to not list example of these horrible all encompassing pieces of software and who it affected
As you can see, others can mimic what you did. It’s not very hard.
>couldn’t possibly find the article from what was posted
>i actually posted some info
>he just assumes it’s on the app store too
>august 24
*farts*
enjoy your blueborne vulnerable poodroid
freaking hell man, every freaking time there’s a new exploit for X, when we will live in a freaking world free of malware, spyware, etc. freaking garden gnomes