How Google’s Project Zero ended up attacking all iPhone users
- sep
- 02
- Posted by Michael
- Posted in Okategoriserade
When does a team dedicated to ferreting out bugs, exploits, and vulnerabilities turn into its own form of malware attack? For Google's Project Zero, the answer just may have been this week.
Project Zero is the name for Google's team of security researchers tasked with tracking down and reporting zero-day vulnerabilities in operating systems, websites, and apps.
Zero-day as in they've not previously been disclosed and, so, haven't been fixed.
On Thursday, August 29, 2019, Project Zero blogged a "very deep dive" into just that — a chain of 0-day vulnerabilities that they said were being used by a small collection of hacked websites as an indiscriminate watering hole attack against iPhone users.
Here's what they said:
There was no target discrimination; simply visiting the hacked site was enough for the exploit server to attack your device, and if it was successful, install a monitoring implant. We estimate that these sites receive thousands of visitors per week.
Back on February 1st, 2019, they'd given Apple a 7-day deadline to fix the 14 vulnerabilities across 5 exploit chains, because that's how PZ rolls, and Apple did just that — the iOS 12.1.4 patch was released on February 7th, 2019.
So, last week's blog post wasn't about disclosure any more. It was about a deep dive. And it was legit amazing. Project Zero went into excruciating detail about the exploit chains found in the wild.
Except in two critical, crucial areas:
- The websites involved in the attacks.
- Any other operating systems that were subject to the attacks.
Why that's so critical, so crucial is simple: Facts shape coverage but so does the absence of facts.
Like I tweeted immediately after the blog post surfaced, if it was a tiny cluster of sites in a remote region vs. major multinational sites like Amazon or YouTube, that's a vastly different threat level to address.
Terrific drill-down on a web-based iOS exploit chain. But, I can’t find any info on what kind of sites were being used? If they were a tiny cluster in a remote region vs. major multinational, it’s a very different threat level.https://t.co/CZM4SksLMN
— Rene Ritchie (@reneritchie) August 30, 2019
Likewise, if it was iOS only, that's a vastly different narrative than if it was targeting Android and Windows as well.
And, yeah, we saw the results of Project Zero's write-up immediately with re-blog after re-blog covering it as an iPhone-only story that everyone in the world with an iPhone needed to worry about, if not outright panic over.
I knew it was just a matter of time before my parents saw the story on the BBC or some other mainstream media outlet and were concerned enough to ask me about it.
That took less than 24 hours, of course.
I was tempted to throw out a video fast, pointing out that missing context and saying something didn't smell right. But I didn't want to add to the noise, so I started asking around to see if I could find out some signal instead.
It was only in the last couple of days that the story started becoming clearer.
First, Zack Whittacker on TechCrunch found out that it was indeed China that was using the iPhone hacks to target Uyghur Muslims in the Xinjiang region.
According to Whittacker:
It's part of the latest effort by the Chinese government to crack down on the minority Muslim community in recent history. In the past year, Beijing has detained more than a million Uyghurs in internment camps, according to a United Nations human rights committee.
Thomas Brewster at Forbes — actual Forbes, not the hot mess that is Forbes Contributor Network — confirmed and expanded on the TechCrunch report, adding that Android and Windows users were also targeted, not just iPhone and iOS.
According to Brewster:
That Android and Windows were targeted is a sign that the hacks were part of a broad, two-year effort that went beyond Apple phones and infected many more than first suspected.
TechCrunch added:
That suggests the campaign targeting Uyghurs was far broader in scope than Google initially disclosed.
Yeeeaaaaah.
And that's a huge, huge problem.
As I, and many other people have said repeatedly, code is so complex that there will be bugs and there will be exploits and all that can be done about them is ethical disclosure by researchers, fast fixes by companies, and responsible reporting by not just the media but everyone involved.
Project Zero, by virtue of being owned and operated by Google, which operates two of the major software platforms with ChromeOS and Android, has an additional hurdle to overcome — they need to go out of their way to report on Google. Demonstrably. Above reproach, as they say.
What they did here was the opposite of that. Worse. They didn't under-report on Google. They failed to report on Google.
You could go so far as to call it lies of omission.
And Google, for their part, have done and said nothing to address it.
TechCrunch:
A Google spokesperson would not comment beyond the published research.
Forbes:
Neither Microsoft nor Google had provided comment at the time of publication. It's unclear if Google knew or disclosed that the sites were also targeting other operating systems.
Now, it's up to you if you want to ascribe any sinister conspiracy motives to this. Google does compete with Apple on operating systems and phones, and both have big launches this fall.
But it's tough to imagine Project Zero would ever be part of that, or Google, in general, having enough integration between teams to even coordinate anything like that.
What I think is Project Zero is composed of a bunch of nerds who just want to write about a cool exploit chain they found in the wild.
And it is cool. iOS is uniquely hard to break into. This one took 14 vulnerabilities over 5 exploit chains.
Put things in perspective:
— 62657156686f6a75636a4d21506a736699a0f1548b (@Morpheus______) August 30, 2019
- These aren't new 0-days. They've all been patched over time, hence why 5 chains used.
- Apple actually strives for security/privacy. Others make a business from flouting the latter.
- What, Android is more secure? *Cough* CamScanner*Cough* 🤮
It's the exciting thing to talk about. But by effectively leaving out so much of the story, Project Zero shaped the story — and they shaped it wrong.
iOS is by no means the most popular operating system but wow is it the most popular headline. And that's what we got. Headline after completely distorted headline. Story after incomplete story.
So much attention, which I think is what Project Zero really wants.
But it's not about attention. It's about reputation.
Project Zero are superheroes, no doubt. Proven many times over. But they should want to be the Justice League. Not The Boys.
They should aim to stamp out exploits, not become part of social engineering attacks against iPhone users.
And that's what happened with this story. A lot of iPhone owners were made to be afraid beyond what the actual threat level warranted. All because the original blog post lacked context it should never have lacked.
I can easily justify 0day use for legitimate national security threats given narrow scoping and targeted use, but what has been uncovered by project zero is absolutely not that, and one of the most frightening things I have seen in my “career” as an iOS 0day researcher.
— qwertyoruiop (@qwertyoruiopz) September 1, 2019
It also delayed the start of much more important conversation. While people were worrying or gloating over iOS security, they weren't considering the existence of these exploits in general and how they're being used not just for national security but to target individuals and communities.
Burn all 0days indeed.
Update: Volexity, in a wide-ranging report on China's digital crackdown in the region, added this to the attack surface:
Mobile device users running Android OS targeted via an exploit that will deliver a 64-bit ARM executable
Attacker's arsenal includes Google Applications for gaining access to e-mails and contact lists of Gmail accounts via OAuth
It doesn't pass the common-sense sniff test that platforms and services as popular as Google's wouldn't be targeted by this type of attack, which makes the lack of reporting by Project Zero even more troubling.
Senaste inläggen
- Mac dominerade marknaden för AI-kapabla datorer 2024 trots Windows tillväxt
- Trump kritiserar Apple för att behålla sina mångfaldspolicies
- Rykte: Apples Face ID-dörrklocka kan få Magsafe-stöd
- Phil Schiller uttryckte oro över App Stores avgifter för externa köp
- Indonesien häver fem månader långt försäljningsförbud för Iphone 16
Senaste kommentarer
Arkiv
- februari 2025
- januari 2025
- september 2024
- augusti 2024
- juli 2024
- juni 2024
- maj 2024
- april 2024
- mars 2024
- februari 2024
- januari 2024
- december 2023
- november 2023
- oktober 2023
- september 2023
- augusti 2023
- juli 2023
- juni 2023
- maj 2023
- april 2023
- mars 2023
- februari 2023
- januari 2023
- december 2022
- november 2022
- oktober 2022
- september 2022
- augusti 2022
- juli 2022
- juni 2022
- maj 2022
- april 2022
- mars 2022
- februari 2022
- april 2021
- mars 2021
- januari 2021
- december 2020
- november 2020
- oktober 2020
- september 2020
- augusti 2020
- juli 2020
- juni 2020
- maj 2020
- april 2020
- mars 2020
- februari 2020
- januari 2020
- december 2019
- november 2019
- oktober 2019
- september 2019
- augusti 2019
- juli 2019
- juni 2019
- maj 2019
- april 2019
- mars 2019
- februari 2019
- januari 2019
- december 2018
- november 2018
- oktober 2018
- september 2018
- augusti 2018
- juli 2018
- juni 2018
- maj 2018
- april 2018
- mars 2018
- februari 2018
- januari 2018
- december 2017
- november 2017
- oktober 2017
- september 2017
- augusti 2017
- juli 2017
- juni 2017
- maj 2017
- april 2017
- mars 2017
- februari 2017
- januari 2017
- december 2016
- november 2016
- oktober 2016
- september 2016
- augusti 2016
- juli 2016
- juni 2016
- maj 2016
- april 2016
- mars 2016
- februari 2016
- januari 2016
- december 2015
- november 2015
- oktober 2015
- september 2015
- augusti 2015
- juli 2015
- juni 2015
- maj 2015
- april 2015
- mars 2015
- februari 2015
- januari 2015
- december 2014
- november 2014
- oktober 2014
- september 2014
- augusti 2014
- juli 2014
- juni 2014
- maj 2014
- april 2014
- mars 2014
- februari 2014
- januari 2014
Kategorier
- –> Publicera på PFA löp
- (PRODUCT) RED
- 2015
- 25PP
- 2nd gen
- 32gb
- 3D Touch
- 3D-kamera
- 4k
- 64gb
- 9to5mac
- A10
- A9X
- Aaron Sorkin
- Accessories
- Accessories, Apple Watch, iPhone
- adapter
- AirPlay
- AirPods
- Aktiv
- Aktivitetsarmband
- Aktuellt
- Alfred
- Allmänt
- AMOLED
- Android Wear
- Angela Ahrendts
- Ångerätt
- Animal Crossing
- Animal Crossing New Horizons
- announcements
- Ansiktsigenkänning
- app
- App Store
- Appar
- Apple
- Apple Beta Software Program
- Apple Book
- Apple CarPlay
- Apple Event
- Apple iMac
- Apple Inc
- Apple Inc, Consumer Electronics, iCloud, iOS, iPhone, Mac, Mobile, Personal Software, Security Software and Services
- Apple Inc, iCloud
- Apple Inc, iOS
- Apple Inc, iPhone
- Apple Inc, MacBook
- Apple Inc, Mobile Apps
- Apple Inc, Monitors
- Apple Mac Mini
- Apple Macbook
- Apple MacBook Air
- Apple MacBook Pro
- Apple Macos
- Apple Maps
- Apple Music
- Apple Music Festival
- Apple Music Radio
- Apple Offer
- Apple Online Store
- Apple Park
- Apple Pay
- Apple Pencil
- Apple Podcast
- Apple Store
- Apple Store 3.3
- Apple TV
- apple tv 4
- Apple TV 4K
- Apple Watch
- Apple Watch 2
- Apple Watch 8
- Apple Watch 9
- Apple Watch Apps
- Apple Watch SE
- Apple Watch Series 2
- Apple Watch Sport
- Apple Watch Ultra
- Apple Watch, Headphones
- Apple Watch, iPhone
- AppleCare
- AppleTV
- Application
- Applications
- Apps
- AppStore
- Apptillägg
- Apptips
- AppTV
- April
- Arbetsminne
- armband
- Art Apps
- Återköp
- återvinning
- Åtgärdsalternativ
- atvflash
- Audio Apps
- Augmented REality
- Back-to-school
- Bakgrundsbilder
- BankId
- Barn
- Batteri
- batteriskal
- batteritid
- Beats
- Beats 1
- Beats Solo 2 Wireless
- Beats Solo2
- Bebis
- Beginner Tips
- Belkin
- Bendgate
- beta
- Beta 3
- betaversion
- betaversioner
- bilddagboken.se
- bilder
- bilhållare
- billboard
- Bioteknik
- Blendtec
- Bloomberg
- Bloons TD 5
- Bluelounge
- Bluetooth
- Böj
- Booking.com
- Borderlinx
- bose
- bugg
- Buggar
- Buggfixar
- Butik
- C More
- Calc 2M
- Camera
- Camera Apps
- Campus 2
- Canal Digital
- Carpool Karaoke
- Caseual
- Catalyst
- CES 2015
- Chassit
- Chip
- Chrome Remote Desktop
- Chromecast
- citrix
- clic 360
- CNBC
- Computer Accessories
- Computer Accessories, Laptop Accessories
- Connect
- Cydia
- Dagens app
- Dagens tips
- Damm
- Danny Boyle
- Data
- datamängd
- Datorer
- Datortillbehör
- Datum
- Defense
- Dekaler
- Designed by Apple in California
- Developer
- Development
- Digital Inn
- Digital Touch
- Digitalbox
- DigiTimes
- Direkt
- Discover
- display
- DisplayMate
- Dive
- Docka
- Dräger 3000
- Dropbox
- Droples
- DxOMark
- E-post
- earpod
- EarPods
- Earth Day
- Eddie Cue
- eddy cue
- Educational Apps
- Ekonomi
- Ekonomi/Bransch
- El Capitan
- Elements
- ElevationLab
- Elgato Eve
- Elgato Eve Energy
- EM 2016
- Emoji
- emojis
- emoticons
- Enligt
- Entertainment Apps
- EU
- event
- Eventrykten
- EverythingApplePro
- Faceshift
- facetime
- Fäste
- Featured
- Features
- Feng
- Film / Tv-serier
- Filmer
- Filstorlek
- Finance Apps
- Finder For AirPods
- Finland
- FireCore
- Fitbit
- Fitness Accessories
- Fjärrstyr
- Flurry
- Födelsedag
- fodral
- Förboka
- Force Touch
- förhandsboka
- Första intryck
- Forumtipset
- foto
- FoU (Forskning och Utveckling)
- Fource Touch
- Foxconn
- FPS Games
- Framtid
- Fre Power
- Frontpage
- Fullt
- Funktioner
- Fuse Chicken
- Fyra
- Gadgets
- Gagatsvart
- Gamereactor
- Games
- Gaming
- Gaming Chairs
- Gästkrönika
- General
- Gigaset
- Gitarr
- Glas
- GM
- Google Maps
- Google Now
- gratis
- grattis
- Guide
- Guider
- Guider & listor
- Guld
- hack
- Halebop
- hållare
- Hälsa
- Hårdvara
- HBO
- HBO Nordic
- Health
- Health and Fitness
- Health and Fitness Apps
- Hej Siri
- Helvetica Neue
- Hemelektronik
- Hemknapp
- Hemlarm
- Hermes
- Hitta min iphone
- Hjärta
- högtalare
- HomeKit
- HomePod
- Homepod Mini
- hörlurar
- htc
- Hue
- Humor
- i
- I Am A Witness
- IBM
- iBolt
- iBomber
- iBook
- icar
- iCloud
- iCloud Drive
- iCloud Voicemail
- iCloud.com
- iDevices
- IDG Play
- idownloadblog
- iFixit
- ikea
- iKörkort
- iLife
- Illusion Labs
- iMac
- IMAP
- iMessage
- iMessages
- iMore Show
- Incipio
- InFuse
- Inspelning
- Instagram-flöde
- Instrument
- Intel
- Internet/Webbtjänster
- iOS
- iOS 10
- iOS 12
- iOS 17
- iOS 18
- iOS 5
- iOS 7
- iOS 8
- iOS 8 beta
- iOS 8.1.3
- iOS 8.2
- iOS 8.3
- iOS 8.4
- iOS 8.4.1
- iOS 9
- iOS 9 beta 4
- iOS 9.1
- iOS 9.1 beta 2
- iOS 9.2
- iOS 9.2.1
- iOS 9.3
- IOS Games
- ios uppdatering
- iOS, iPad, MacOS
- iOS, iPhone
- ios9
- iPad
- iPad Accessories
- iPad Air
- iPad Air 2
- iPad Air 3
- iPad Air 5
- iPad Apps
- iPad Mini
- iPad mini 4
- iPad Mini 6
- iPad mini retina
- iPad Pro
- iPad, iPhone, Mac
- iPad, iPhone, Mobile Apps
- iPad, iPhone, Streaming Media
- iPados
- iphone
- iPhone 12
- iPhone 14
- iPhone 14 Pro
- iPhone 15
- iPhone 16
- iPhone 17
- iPhone 5
- iPhone 5S
- iPhone 5se
- iPhone 6
- iphone 6 plus
- iPhone 6c
- iPhone 6s
- iPhone 6S plus
- iPhone 7
- iPhone 7 display
- iPhone 7 Plus
- iPhone 7s
- iPhone Accessories
- iPhone Apps
- iPhone Cases
- iPhone SE
- iphone x
- iPhone XS
- iPhone XS Max
- iPhone, Mobile Apps
- iPhone, Smart Locks
- iPhone7
- iPhoneGuiden
- iPhoneguiden.se
- iPhones
- iPod
- iPod Nano
- iPod shuffle
- ipod touch
- iSight
- iTunes
- iWatch
- iWork
- iWork för iCloud beta
- Jailbreak
- James Corden
- Jämförande test
- Jämförelse
- Jet Black
- Jet White
- Jönssonligan
- Jony Ive
- Juice Pack
- Juridik
- Just mobile
- kalender
- kalkylator
- Kamera
- Kameratest
- Karriär/Utbildning
- Kartor
- Kevin Hart
- keynote
- Keynote 2016
- KGI
- KGI Security
- Kina
- Klassiskt läderspänne
- Kod
- Kollage
- koncept
- konceptbilder
- köpguide
- krasch
- Krascha iPhone
- Krönika
- Kvartalsrapport
- Laddhållare
- laddningsdocka
- Laddunderlägg
- läderloop
- lagar
- Lagring
- Lajka
- Länder
- lansering
- laserfokus
- Layout
- leather loop
- LG
- Liam
- Lifeproof
- Lightnigport
- lightning
- Linux
- LinX
- live
- Live GIF
- Live Photos
- Live-event
- Livsstil
- Ljud & Bild
- Logitech
- LOL
- Lösenkod
- Lösenkodlås
- Lovande spel
- LTE
- Luxe Edition
- M3
- M3TV
- Mac
- Mac App Store
- Mac Apps
- Mac Mini
- Mac OS
- Mac OS X
- Mac OS X (generellt)
- Mac OS X Snow Leopard
- Mac Pro
- Mac, MacOS
- Mac, Online Services
- Mac, Security Software and Services
- Macbook
- Macbook Air
- Macbook Pro
- MacBook, MacOS
- Macforum
- Macintosh
- macOS
- MacOS, Security Software and Services
- Macs
- MacWorld
- Made for Apple Watch
- magi
- Magic
- MagSafe
- Martin Hajek
- matematik
- Meddelanden
- Media Markt
- Medieproduktion
- Mediocre
- Messaging Apps
- Messenger
- MetaWatch
- Mfi
- Michael Fassbender
- microsoft
- Mikrofon
- Minecraft
- Ming-Chi Kuo
- miniräknare
- minne
- Mixer
- Mixning
- Mjukvara
- mobbning
- Mobile Apps
- Mobile Content
- Mobilt
- Mobilt/Handdator/Laptop
- Mobiltelefon
- Mockup
- Mophie
- mors dag
- moto 360
- Motor
- MTV VMA
- multitasking
- Music
- Music Apps
- Music, Movies and TV
- Musik
- Musikmemon
- MW Expo 2008
- native union
- Nätverk
- Navigation Apps
- nedgradera
- Netatmo Welcome
- Netflix
- Netgear Arlo
- News
- Niantic
- Nike
- Nikkei
- Nintendo
- Nintendo Switch
- Nöje
- Norge
- Notis
- Notiscenter
- nya färger
- Nyfödd
- Nyheter
- Officeprogram
- Okategoriserade
- OLED
- omdöme
- Omsättning
- OS X
- OS X El Capitan
- OS X Mavericks
- OS X Yosemite
- Outlook
- Övrig mjukvara
- Övrigt
- PanGu
- papper
- patent
- PC
- pebble
- Pebble Smartwatch
- Pebble Steel
- Pebble Time
- Pebble Time Steel
- Persondatorer
- Petter Hegevall
- PewDiePie
- Philips
- Philips Hue
- Phones
- Photoshop
- Planet of the apps
- Plex
- Pluggar
- Plus
- Plusbox
- Podcast
- Podcast Apps
- Pokemon
- Pokemon Go
- Policy
- Porträttläge
- PP
- Pris
- priser
- problem
- Problems
- Productivity Apps
- Program
- Prylar & tillbehör
- Publik
- publik beta
- QuickTime
- räkenskapsår
- räkna
- ram
- RAM-minne
- Rapport/Undersökning/Trend
- Rea
- Reading Apps
- recension
- Red
- reklaamfilm
- reklam
- reklamfilm
- reklamfilmer
- rekord
- Rendering
- reparation
- Reportage
- Reptest
- ResearchKit
- Retro
- Review
- Ring
- Ringa
- Rocket Cars
- Rosa
- Rumors
- Rumours
- RunKeeper
- rykte
- Rykten
- Safir
- Säkerhet
- Säkerhetsbrist
- Samhälle/Politik
- samsung
- Samtal
- San Francisco
- SAP
- security
- Security Software and Services, VPN
- Series 2
- Servrar
- Shigeru Miyamoto
- Sia
- Simulation Games
- Siri
- SJ Min resa
- skal
- Skal iPhone 6
- skal iPhone 6s
- skärm
- SKärmdump
- Skärmglas
- Skribent
- skribenter medarbetare
- Skriva ut
- skruvmejsel
- skydd
- Skyddsfilm
- Skype
- slice intelligence
- Smart
- smart hem
- Smart Home
- Smart Keyboard
- Smart klocka
- Smart Lights
- smartphone
- Smartwatch
- SMS
- Snabbt
- Snapchat
- Social Apps
- Software
- Solo2
- sommar
- Sonos
- Sony
- soundtouch
- Space Marshals
- spår
- Speakers
- Special Event
- Spel
- Spelkonsol
- Spellistor
- Split Screen
- Split View
- Sport
- Sportband
- Sports Apps
- spotify
- Spring forward
- Statistik
- Steve Jobs
- Stickers
- Stockholm
- Stor iPhone
- Storlek
- Story Mode
- Strategy Games
- streama
- Streaming
- Streaming Devices
- Streaming Media
- stresstest
- Ström
- Studentrabatt
- stylus
- Super Mario Run
- support
- Surf
- Surfplatta
- svenska
- sverige
- Sverigelansering
- Switch
- Systemstatus
- Systemutveckling
- tåg
- Taig
- Tangentbord
- Taptic Engine
- Tårta
- tät
- Tävling
- Taylor Swift
- Teknik
- tele 2
- Telefoner
- Telekom
- Telia
- Test
- Tid
- TikTok
- Tile
- tillbehör
- Tim Cook
- TIME
- TimeStand
- Tiny Umbrella
- Tips
- Toppnyhet IDG.se
- Touch ID
- TouchID
- tower defence
- trådlös laddning
- Trådlösa hörlurar
- trådlöst
- trailer
- Travel Apps
- Tre
- TrendForce
- TripAdvisor
- Trolleri
- trump
- TSMC
- Tum
- tv
- TV Apps
- tvätta
- tvOS
- tvOS 9.2
- tvOS beta 2
- Tweak
- Typsnitt
- Ubytesprogram
- UE MegaBoom
- Unboxing
- Underhållning/Spel
- unidays
- United Daily News
- Unix
- Updates
- Uppdatera
- uppdatering
- Upplösning
- upptäckt
- USA
- Ut på Twitter
- utbyte
- utbytesprogram
- Utilities Apps
- Utlottning
- utrymme
- utvecklare
- varumärke
- Vatten
- Vattentålig
- vattentät
- vävt nylon
- Verktyg
- Viaplay
- Vibrator
- video
- Videoartiklar och webb-tv (M3/TW/CS)
- Villkor
- viloknapp
- Virtual Reality
- Virus
- visa
- Vision Pro
- VLC
- Volvo on call
- VPN
- W1
- Waitrose
- Watch OS
- WatchOS
- WatchOS 2
- watchOS 2.0.1
- watchOS 2.2
- Webbtv (AppTV)
- wi-fi
- Wifi-samtal
- Windows
- Windows 8
- WWDC
- WWDC2015
- yalu
- Youtube
- Zlatan