Live data from Hacker News

'Karma': A hack used by the UAE to break into iPhones of foes

reuters.com

51–60 of 238 posts

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#51
post #37

Earlier quoted context omitted.

You'd think we'd have some special regulations regarding what kind of jobs ex-NSA can have after leaving.

Why do ex-NSA need special regulations? What even makes them special?

Their top security clearances, their access to the deepest darkest secrets of intelligence tools, networks, and systems. Would you trust an employee with your biggest secrets if you knew they were retiring soon and very likely to be hired at many times their current salary by some major competitor?

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#52
post #13

Whether or not this hack was developed with the help of Apple (a “backdoor”) or by a third-party exploit, this is exactly what a “golden key” looks like after it gets in the wild. An espionage tool developed by a major world power proliferates to totalitarian regimes, aided and operated by ex-NSA agents on the payroll, to compromise human rights activists and the political opposition. If ever there was proof that our…

I disagree with the conclusion of absolute security — it won’t happen, and only encourages subversion by people who both need and have a right to access the content. Instead of pontificating, the tech industry should innovate. There’s no reason that hashchains can’t be used to timelock the key, and the enclave export it in response to a signed request. Then we can at least force the compromises through the legal syst…

C'mon everyone, be part of the solution like this person says. The intelligence agencies will never abuse their power. You can trust them. /s

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#53
post #30

Earlier quoted context omitted.

> Eschew flamebait. Don't introduce flamewar topics unless you have something genuinely new to say. Avoid unrelated controversies and generic tangents. https://news.ycombinator.com/newsguidelines.html

with respect, as a non US citizen this whole article to me is deeply offensive. I/we are being targeted simply because we are second class citizens on the web. Good enough to have our data extracted by US corps but our rights are trampled on. This is the essence of it yet you're accusing me of flame-baiting? Please reflect for a minute on how just this is to anyone who has never (and will never) step/ped foot in the…

Accusations of flamebait and similar on HN are a form of censorship, to prevent the community from having to confront difficult issues and “keep the peace” — not legitimate regulation of tone.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#54
post #13

Whether or not this hack was developed with the help of Apple (a “backdoor”) or by a third-party exploit, this is exactly what a “golden key” looks like after it gets in the wild. An espionage tool developed by a major world power proliferates to totalitarian regimes, aided and operated by ex-NSA agents on the payroll, to compromise human rights activists and the political opposition. If ever there was proof that our…

Nobody credible believes for a second that Apple was involved, for whatever it’s worth.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#55

Earlier quoted context omitted.

I disagree with the conclusion of absolute security — it won’t happen, and only encourages subversion by people who both need and have a right to access the content. Instead of pontificating, the tech industry should innovate. There’s no reason that hashchains can’t be used to timelock the key, and the enclave export it in response to a signed request. Then we can at least force the compromises through the legal syst…

C'mon everyone, be part of the solution like this person says. The intelligence agencies will never abuse their power. You can trust them. /s

That’s a deep straw man of what I said, to the point of being non-constructive mocking. You’re just being dishonest to claim I suggested trusting the spy agencies.

Rather, I pointed out that they have a real mission, and they’re going to spend effort accomplishing it. But their mission isn’t to own every device — it’s to own a select few, probably on the order of hundreds or thousands a year. So, if we create a mechanism by which they can do that without owning every device, we can align our goal of protecting most devices with theirs of owning a few.

This in turn increases security for nearly everyone, because powerful agencies no longer have the same motivation to cause harm — and might be persuaded to help. After all, it’s in their interest to prevent large remote compromises — just not a higher priority than maintaining their own access.

Further, the best way to actually restrain them is through a change in government policy, which will only happen when the government believes there’s an alternative solution.

Perhaps you could try responding to the point?

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#56
post #4

I realize it's a really sexy headline, but I'd like for there to be more than 0 proof that this is a real thing. Especially if they claim a vulnerability that's exploitable by only sending a text.

There is no reason to doubt this. It wouldn’t be the first time such a vulnerability was found.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#57
post #48
post #4

I realize it's a really sexy headline, but I'd like for there to be more than 0 proof that this is a real thing. Especially if they claim a vulnerability that's exploitable by only sending a text.

I am 100% sure this is an exploit related to PDU mode SMS messages. Tons of phones of different brands are probably vulnerable to variations of this attack.

I think the asertion that it's on the baseband is correct, for sure

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#58
post #13

Whether or not this hack was developed with the help of Apple (a “backdoor”) or by a third-party exploit, this is exactly what a “golden key” looks like after it gets in the wild. An espionage tool developed by a major world power proliferates to totalitarian regimes, aided and operated by ex-NSA agents on the payroll, to compromise human rights activists and the political opposition. If ever there was proof that our…

I disagree with the conclusion of absolute security — it won’t happen, and only encourages subversion by people who both need and have a right to access the content. Instead of pontificating, the tech industry should innovate. There’s no reason that hashchains can’t be used to timelock the key, and the enclave export it in response to a signed request. Then we can at least force the compromises through the legal syst…

This sounds like a first order objection to a second order concern.

In particular:

> What’s not going to sell, and what the tech industry needs to get over is “lulz, it’ll impossible to intercept military or terrorist information because I need absolute privacy for my saucy emails”

Seems to be an ironic mischaracterisation of the parent’s point, which was precisely that one coubtry’s terrorism is another’s gay rights activist or high ranking foreign official.

From the article:

In 2017, for instance, the operatives used Karma to hack an iPhone used by Qatar’s Emir Sheikh Tamim bin Hamad al-Thani, as well as the devices of Turkey’s former Deputy Prime Minister Mehmet Şimşek, and Oman’s head of foreign affairs, Yusuf bin Alawi bin Abdullah. It isn’t clear what material was taken from their devices.

“Saucy e-mails” is a bit tone deaf :(

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#59

Earlier quoted context omitted.

with respect, as a non US citizen this whole article to me is deeply offensive. I/we are being targeted simply because we are second class citizens on the web. Good enough to have our data extracted by US corps but our rights are trampled on. This is the essence of it yet you're accusing me of flame-baiting? Please reflect for a minute on how just this is to anyone who has never (and will never) step/ped foot in the…

Accusations of flamebait and similar on HN are a form of censorship, to prevent the community from having to confront difficult issues and “keep the peace” — not legitimate regulation of tone.

that's the feeling I sometimes get. Let's all go back and discuss microservices and virtualization and keep pretending technology is neutral. Because if we were actually to confront these issues we might actually get somewhere.

I have said shit before that I regretted and where I have rightly been put in place. The above comment isn't one of them though. Also I'm not a robot so maybe feeling something when I read this scoop is my own fault. idk

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#60
post #4

I realize it's a really sexy headline, but I'd like for there to be more than 0 proof that this is a real thing. Especially if they claim a vulnerability that's exploitable by only sending a text.

There've been similar issues in both iOS and Android before - iOS had one recently where a text would cause repeated app crashes. Back in 2009 there was a full exploit via SMS on iOS, and just a few years back the Android stagefright exploit was barely spared from turning into a giant worm due to exploit mitigations and the diversity of devices. It's quite possible to see these attacks come to light in a much scarier way. That exploit is solid gold and they probably paid a small fortune for it.
Post reply on HN