Live data from Hacker News

'Karma': A hack used by the UAE to break into iPhones of foes

reuters.com

81–90 of 238 posts

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#81

Earlier quoted context omitted.

C'mon everyone, be part of the solution like this person says. The intelligence agencies will never abuse their power. You can trust them. /s

That’s a deep straw man of what I said, to the point of being non-constructive mocking. You’re just being dishonest to claim I suggested trusting the spy agencies. Rather, I pointed out that they have a real mission, and they’re going to spend effort accomplishing it. But their mission isn’t to own every device — it’s to own a select few, probably on the order of hundreds or thousands a year. So, if we create a mecha…

[deleted]

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#83
post #63

Earlier quoted context omitted.

I think the underlying point is "which intelligence agencies would be allowed to compromise devices like this"?

The ones courts which governed the relevant company were willing to issue warrants on behalf of — that is, those our regular legal and political systems decide on. For a big multinational like Apple, that’s probably a fair number. But it’s also harder to hide they’re doing that, and let’s us bring pressure on them politically for their political misdeeds. In the end, it’ll be major powers who can — US, Europe, China,…

So you support China being able to hack any phone globally with a warrant in a Chinese court? Isn't that literally what Huawei are accused of facilitating?

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#84
post #13

Whether or not this hack was developed with the help of Apple (a “backdoor”) or by a third-party exploit, this is exactly what a “golden key” looks like after it gets in the wild. An espionage tool developed by a major world power proliferates to totalitarian regimes, aided and operated by ex-NSA agents on the payroll, to compromise human rights activists and the political opposition. If ever there was proof that our…

Nobody credible believes for a second that Apple was involved, for whatever it’s worth.

I was not trying to suggest that, I was trying to convey that once a spy agency has remote access (sanctioned or otherwise) we can see by this example how it is proliferated and abused.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#85

Earlier quoted context omitted.

C'mon everyone, be part of the solution like this person says. The intelligence agencies will never abuse their power. You can trust them. /s

That’s a deep straw man of what I said, to the point of being non-constructive mocking. You’re just being dishonest to claim I suggested trusting the spy agencies. Rather, I pointed out that they have a real mission, and they’re going to spend effort accomplishing it. But their mission isn’t to own every device — it’s to own a select few, probably on the order of hundreds or thousands a year. So, if we create a mecha…

> . But their mission isn’t to own every device — it’s to own a select few, probably on the order of hundreds or thousands a year.

Things like Room 641A show that the government doesn't even need to engage the courts to collect data on millions of people and further, that they are not limiting their collection efforts to a few hundreds or thousands of devices a year.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#86
post #6

Am I the only one who feels like every time we get news of a government compromising an iPhone through some mystical exploit, the technology around it seems very fanciful?

Yes. It likely that the reporters don't understand the technology involved, so their reporting on that topic is pretty vague. Humans tend to look where there's light, even if they know that't not the most likely place to find it. That said we have the words exploit, imessage, full access, email/phone number. We can piece together that they use a 'buffer overrun' style exploit to break out of iMessage, and and possibly several other exploits, till they have remote code execution on the device, and then they install a bot/server to collect data. Really difficult in practice, but a familiar pattern. IIRC there's a Wired article recently that reviews similar tech from another company, the author of that article says he sets his phone down in their office, and minutes later they have access to all his data.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#87

Earlier quoted context omitted.

Which courts? Which legal systems? Legal systems and courts of nations who believe political speech is a crime and that alternative lifestyles are capital offenses?

The ones who are capable of compelling the phone company to obey over political pressure from other sources. This is a strict improvement over the current situation, where the answer is “anyone who has money”.

Are you forgetting that time that the spy agency collected call records on millions of Americans through a secret court? [1]

As the other commenter points out, this only adds an attack vector and does not do anything to eliminate any.

The same incentives exist on all sides to find exploits regardless of an additional “legal” channel to crack the encryption. Particularly because your political enemies use the same devices and you can’t get a court order to tap their phones (usually).

[1] - https://www.google.com/amp/s/amp.theguardian.com/world/2013/...

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#88
>A team of former U.S. government intelligence operatives working for the United Arab Emirates

no non-competes? So, when Snowden tells to public about mere existence of NSA hacks - it is a crime, yet when an intelligence operative brings his NSA and the likes sourced detailed technical knowledge to a foreign government - that is kosher.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#89
post #5
post #3

>Three former operatives said they understood Karma to rely, at least in part, on a flaw in Apple’s messaging system, iMessage. They said the flaw allowed for the implantation of malware on the phone through iMessage, even if the phone’s owner didn’t use the iMessage program, enabling the hackers to establish a connection with the device. To initiate the compromise, Karma needed only to send the target a text message…

I wonder if this is https://www.theguardian.com/technology/2016/jul/22/stagefrig... again, the article mentions 2016.

Seems like a likely candidate.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#90
post #17

Earlier quoted context omitted.

we could elect sane leaders...

Like Obama? I remember how the NSA was shut down entirely during his tenure, man that was great.

As a matter of interest, do you believe that the sane option is to shut down the NSA entirely?
Post reply on HN