logoalt Hacker News

the_harpia_ioyesterday at 4:11 PM2 repliesview on HN

decade-old vulns like this are why the 'you're not interesting enough to target' argument falls apart. commercial spyware democratized nation-state capabilities - now any mediocre threat actor with budget can buy into these exploits. the Pegasus stuff proved that pretty clearly. and yeah memory safety helps but the transition is slow - you've got this massive C/C++ codebase in iOS that's been accumulating bugs for 15+ years, and rewriting it all in Swift or safe-C is a multi-decade project. meanwhile every line of legacy code is a ticking time bomb. honestly think the bigger issue is detection - if you can't tell you've been pwned, memory safety doesn't matter much.


Replies

walterbellyesterday at 5:17 PM

> the bigger issue is detection

Apple could do more for device security forensics.

Meanwhile, user app activity goes into "biome" files for theft by malware, https://bluecrewforensics.com/2022/03/07/ios-app-intents/

saagarjhayesterday at 8:07 PM

I’m pretty sure the dyld code involved was written in the last 5 years if not more recently than that