Live data from Hacker News

'Karma': A hack used by the UAE to break into iPhones of foes

reuters.com

41–50 of 238 posts

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#41
post #6

Am I the only one who feels like every time we get news of a government compromising an iPhone through some mystical exploit, the technology around it seems very fanciful?

What's so fanciful about it? We know that remote exploits exist. We know that cellphones have very complex baseband processors which used to have arbitrary memory access and while they've reported been locked down it's not like there hasn't been an arms race finding ways around every other security measure. We don't need any technological breakthroughs to posit that past remote exploits were not the only ones possible.

This is the problem with things like this or the Bloomberg server story: the capabilities are plausible but there's not enough information to know whether or not they're actually true so you're in the position of having to guess about whether someone actually could implement that attack and whether they'd chose to spend that much money.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#43
post #30

TL;DR: the US attitude ... *It’s fine to spy on human rights activists with all the powers of government as long as they’re not American* ... really gets to the heart of how the US treats the rest of the world. The US is the biggest terror threat in the world today. Its pains are self inflicted and it's enemies created by their very own foreign policy.

> Eschew flamebait. Don't introduce flamewar topics unless you have something genuinely new to say. Avoid unrelated controversies and generic tangents. https://news.ycombinator.com/newsguidelines.html

with respect, as a non US citizen this whole article to me is deeply offensive. I/we are being targeted simply because we are second class citizens on the web. Good enough to have our data extracted by US corps but our rights are trampled on. This is the essence of it yet you're accusing me of flame-baiting? Please reflect for a minute on how just this is to anyone who has never (and will never) step/ped foot in the US. Simply saying what I say here might mean I'm being persona-non-grata and harassed at your airports[1]. All of you should reflect on this the next time you come shopping to Europe or take your SO on honeymoon to Paris, Berlin & Milan.

[1] https://www.theregister.co.uk/2017/06/28/mozilla_dev_and_cur...

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#44

Earlier quoted context omitted.

we could elect sane leaders...

And that's a novel idea when they are on the campaign trail... until they start getting daily national security briefings and learn about the attempted attacks supposedly foiled by good SIGINT. No one wants to be the president who turns that firehose off and "causes the next 9/11". I believe that is what happened with Obama.

Given the bumbling numbskulls who still manage to set off bombs, are we really that sure they're stopping anyone?

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#45
post #36

Earlier quoted context omitted.

physicist for president! elect Lisa Randall, or Sean Carroll. provided, of course, that they agree.

Merkel is a physicist. She's great. But then again many physicists were also convinced Nazi officers.

you mean Heisenberg?

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#46

Earlier quoted context omitted.

Please keep in mind that what you hear coming out of Washington does not necessarily reflect the thoughts and feelings of the people it governs. I'd guess that the vast majority of Americans would not support the statement you quoted.

see my reply to module0000 from just now here. I thought that this would be a given, but clearly I was wrong.

I think we might just be extra-sensitive to being lumped together with the actions of our government (even if that's not what you were intending) because this is a forum with many international members.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#47
post #11
post #7

Earlier quoted context omitted.

Like an exploit where all you need to do is enter the target's phone number to compromise their phone?

I think more that they manage to find these exploits and rapidly build infrastructure around it to make it useful.

They don't need to be very fast... the NSA is known to sit on vulnerabilities for years.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#48
post #4

I realize it's a really sexy headline, but I'd like for there to be more than 0 proof that this is a real thing. Especially if they claim a vulnerability that's exploitable by only sending a text.

I am 100% sure this is an exploit related to PDU mode SMS messages. Tons of phones of different brands are probably vulnerable to variations of this attack.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#49
post #13

Whether or not this hack was developed with the help of Apple (a “backdoor”) or by a third-party exploit, this is exactly what a “golden key” looks like after it gets in the wild. An espionage tool developed by a major world power proliferates to totalitarian regimes, aided and operated by ex-NSA agents on the payroll, to compromise human rights activists and the political opposition. If ever there was proof that our…

I disagree with the conclusion of absolute security — it won’t happen, and only encourages subversion by people who both need and have a right to access the content.

Instead of pontificating, the tech industry should innovate.

There’s no reason that hashchains can’t be used to timelock the key, and the enclave export it in response to a signed request. Then we can at least force the compromises through the legal system and require effort to reverse the hashchain. That kind of court authorized targeted access removes the incentive (and justification) for other actors to more deeply compromise the system. In turn, this let’s us provide more security, in practice.

What’s not going to sell, and what the tech industry needs to get over is “lulz, it’ll impossible to intercept military or terrorist information because I need absolute privacy for my saucy emails”. I think it’s been empirically demonstrated that won’t happen.

Be part of the solution.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#50
post #4

I realize it's a really sexy headline, but I'd like for there to be more than 0 proof that this is a real thing. Especially if they claim a vulnerability that's exploitable by only sending a text.

There have been similar vulnerabilities in iOS before, such as the crashing bug that could be exploited by sending a single malformed ligature/combined character in some incredibly obscure Indian script.
Post reply on HN