Live data from Hacker News

'Karma': A hack used by the UAE to break into iPhones of foes

reuters.com

11–20 of 238 posts

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#11
post #7
post #6

Am I the only one who feels like every time we get news of a government compromising an iPhone through some mystical exploit, the technology around it seems very fanciful?

Like an exploit where all you need to do is enter the target's phone number to compromise their phone?

I think more that they manage to find these exploits and rapidly build infrastructure around it to make it useful.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#12
If the US government gives itself the right to install backdoors / exploit vulnerable software (as opposed to notifying companies about vulnerabilities) then I feel pretty uncomfortable about ex-government hackers just becoming freelance mercenaries using knowledge they may have gleaned from those ops once they move onto their next gig.

I can't think of a great solution to this problem.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#13
Whether or not this hack was developed with the help of Apple (a “backdoor”) or by a third-party exploit, this is exactly what a “golden key” looks like after it gets in the wild.

An espionage tool developed by a major world power proliferates to totalitarian regimes, aided and operated by ex-NSA agents on the payroll, to compromise human rights activists and the political opposition.

If ever there was proof that our devices need to be striving — constantly striving — for absolute security, and can never allow any “trusted party” an authentication or encryption bypass, this article is it.

An exploit like this is incalculably valuable to intelligence agencies. That the exploit would proliferate is undeniable. And the ends to which it would be (has been) used is atrocious.

Probably the only thing different about how intelligence agencies exploited this, and how they would exploit a golden key, is that with the golden key they would be sweeping up every photo on every device, and not just some photos on some devices.

“It was like, ‘We have this great new exploit that we just bought. Get us a huge list of targets that have iPhones now,’” she said. “It was like Christmas.”

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#14
post #3

>Three former operatives said they understood Karma to rely, at least in part, on a flaw in Apple’s messaging system, iMessage. They said the flaw allowed for the implantation of malware on the phone through iMessage, even if the phone’s owner didn’t use the iMessage program, enabling the hackers to establish a connection with the device. To initiate the compromise, Karma needed only to send the target a text message…

This is kind of old. Flaws like this are in use since ever.

http://news.bbc.co.uk/2/hi/technology/8177755.stm

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#15
post #12

If the US government gives itself the right to install backdoors / exploit vulnerable software (as opposed to notifying companies about vulnerabilities) then I feel pretty uncomfortable about ex-government hackers just becoming freelance mercenaries using knowledge they may have gleaned from those ops once they move onto their next gig. I can't think of a great solution to this problem.

we could elect sane leaders...

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#16
post #12

If the US government gives itself the right to install backdoors / exploit vulnerable software (as opposed to notifying companies about vulnerabilities) then I feel pretty uncomfortable about ex-government hackers just becoming freelance mercenaries using knowledge they may have gleaned from those ops once they move onto their next gig. I can't think of a great solution to this problem.

No ethical one at least.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#17
post #12

If the US government gives itself the right to install backdoors / exploit vulnerable software (as opposed to notifying companies about vulnerabilities) then I feel pretty uncomfortable about ex-government hackers just becoming freelance mercenaries using knowledge they may have gleaned from those ops once they move onto their next gig. I can't think of a great solution to this problem.

we could elect sane leaders...

Like Obama? I remember how the NSA was shut down entirely during his tenure, man that was great.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#18
post #17

Earlier quoted context omitted.

we could elect sane leaders...

Like Obama? I remember how the NSA was shut down entirely during his tenure, man that was great.

physicist for president! elect Lisa Randall, or Sean Carroll.

provided, of course, that they agree.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#19
post #12

If the US government gives itself the right to install backdoors / exploit vulnerable software (as opposed to notifying companies about vulnerabilities) then I feel pretty uncomfortable about ex-government hackers just becoming freelance mercenaries using knowledge they may have gleaned from those ops once they move onto their next gig. I can't think of a great solution to this problem.

we could elect sane leaders...

leaders are well insulated from such knowledge for their (legal) safety.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#20
TL;DR: the US attitude ...

  *It’s fine to spy on human rights activists with all the powers of government as long as they’re not American* 
... really gets to the heart of how the US treats the rest of the world. The US is the biggest terror threat in the world today. Its pains are self inflicted and it's enemies created by their very own foreign policy.
Post reply on HN