Apple and Google can do more to screw up the economics of NSO-style mass exploitation, and should be pressured to do so
This week a group of global newspapers is running a series of articles detailing abuses of NSO Group's Pegasus spyware. If you haven't seen any of these articles …
A Few Thoughts …Matthew Green
Context & Ripple Effects
The Pegasus abuse reporting has turned commercial spyware from a niche security issue into a question of platform responsibility. The contemporaneous call for a ban on the spyware trade frames the opinion’s narrower argument: Apple and Google can raise the operating costs of exploit vendors even without a sector-wide prohibition.
Related coverage then made the platform-security route concrete, with researchers urging greater access to mobile system internals to detect Pegasus-like attacks in real time. Later reporting of new iPhone zero-click exploits, despite fixes, underscores why detection and disruption cannot rest on patching alone.
First-order effects
Apple and Google face pressure to use their control over iOS and Android to make NSO-style exploitation harder to develop, deploy, and detect at scale.
Security researchers and potential targets stand to gain more actionable visibility if the platforms expose the system access needed to identify attacks in real time.
Second-order effects
Commercial spyware vendors would have to absorb higher development and operational costs as platform defenses, telemetry, and detection capacity improve.
Apple’s later move to notify targets of state-sponsored spyware shows how platform-led response can shift protection from post-disclosure patching toward identifying and assisting affected users.
Third-order effects
If Apple and Google treat exploit economics as part of platform governance, mobile operating-system owners become a central enforcement layer alongside governments seeking to curb commercial spyware.
The pattern points to a market in which vendors’ viability depends less on selling a single exploit and more on sustaining access against coordinated platform detection, patching, and user-warning measures.
The trend: Commercial spyware is increasingly being contested through platform gatekeeper controls that seek to make mass exploitation more expensive and more detectable.
The individuals who work on the security teams at Apple are indisputably world-class. How insane though, (though sadly unsurprising) that at Apple, marketing trumps security!? 🤯😭 https://twitter.com/... https://twitter.com/...
So it seems fairly obvious that ripping out memory-unsafe parsing code and disabling advanced (non plain-text) features — while not guaranteed to solve the problem — is still an open problem, something that Apple can devote its enormous resources to. 6/
Another area that Apple has already stepped up their game is in logging. Apple power monitoring telemetry records information about weird process “hang” events, which can sometimes trip up exploits. There's a privacy tradeoff here, but Apple should lean into this. 7/
For starters, no internet-connected device is safe from hacking, so the iPhone is no different in that way. But it has a reputation for excellent security, thanks to Apple's excellent marketing. But Apple's marketing also sometimes gets in the way of security.
This @matthew_d_green blog is a really solid read, since absolute security is a fallacy. “The problem that companies like Apple need to solve is not preventing exploits forever, but a much simpler one: they need to screw up the economics of NSO-style mass exploitation.” https://t…
While we can't have “perfect security”, closing down avenues for interactionless targeted infection sure seems like a thing we can make some progress on. 3/
@k8em0 I'd go further and say not just iMessage but WebKit and anything that parses and handles the utter mess that is the internet. This is one hell of a task
There is a take that companies like Apple are never going to be able to stop well-resourced attackers like NSO from launching targeted attacks. At the extremes this take is probably correct. But adopting cynicism as strategy is a bad approach. 1/ https://twitter.com/...
“Apple will have to re-write most of the iMessage codebase in some memory-safe language, along w many system libraries that handle parsing. They'll also need to widely deploy ARM mitigations like PAC & MTE in order to make exploitation harder.” https://twitter.com/...
Also: I think people need to appreciate the *difference* between “100 high value targets” and “10,000 targets, including random journalists”. There is a big difference from society's point of view... 11/
Right now a couple of non-US journalists I talk to have told me all their sources are clamming up. They're afraid that reporters' phones are tapped with Pegasus. I'm sure the scum who launched these attacks are thrilled with this. 12/
While we may never stop targeted attacks, making them expensive enough *to prevent them from being credibly mass-deployed against journalists* is a huge benefit to society. It represents a qualitative improvement. 13/
And in fact we've seen Apple make some progress on this in the past. Starting recently, Apple added a “firewall” called Blastdoor to iMessage. This is supposed to prevent attacks like Pegasus. Obviously it doesn't work, but it at least ups the cost of these exploits. 4/
The reason Apple added a firewall is because they obviously *don't* feel that iMessage is secure by itself. There's too much unsafe parsing code. Adding a firewall is basically an admission that the core product can't be secured in its current form. 5/
First, look at how Pegasus and other targeted exploits get onto your phone. Most approaches require some user interaction: a compromised website or a phishing link that users have to click. iMessage, on the other hand, is an avenue for 0-click targeted infection. 2/