Notes on the Apple/NSO Trident 0days
I thought I'd write up some comments on today's news of the NSO malware using 0days to infect human rights activist phones. For full reference, you want to read the Citizen's Lab report and the Lookout report.Press: it's news to you, it's not news to us
I'm seeing breathless news articles appear. I dread the next time that I talk to my mom that she's going to ask about it (including "were you involved"). I suppose it is new to those outside the cybersec community, but for those of us insiders, it's not particularly newsworthy. It's just more government malware going after activists. It's just one more set of 0days.
I point this out in case press wants to contact for some awesome sounding quote about how exciting/important this is. I'll have the opposite quote.
Don't panic: all patches fix 0days
We should pay attention to context: all patches (for iPhone, Windows, etc.) fix 0days that hackers can use to break into devices. Normally these 0days are discovered by the company itself or by outside researchers intending to fix (and not exploit) the problem. What's different here is that where most 0days are just a theoretical danger, these Continue reading
Get things thrown at you for a good cause.
Juniper also expands Lenovo partnership.
Identity-driven networking technology is intended to keep IoT networks secure.