Live data from Hacker News

'Karma': A hack used by the UAE to break into iPhones of foes

reuters.com

91–100 of 238 posts

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#91

TL;DR: the US attitude ... *It’s fine to spy on human rights activists with all the powers of government as long as they’re not American* ... really gets to the heart of how the US treats the rest of the world. The US is the biggest terror threat in the world today. Its pains are self inflicted and it's enemies created by their very own foreign policy.

Please keep in mind that what you hear coming out of Washington does not necessarily reflect the thoughts and feelings of the people it governs. I'd guess that the vast majority of Americans would not support the statement you quoted.

Yeah we take exception usually to that. With things like gerrymandering being common, the government doesn't really represent the people.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#92
post #83

Earlier quoted context omitted.

The ones courts which governed the relevant company were willing to issue warrants on behalf of — that is, those our regular legal and political systems decide on. For a big multinational like Apple, that’s probably a fair number. But it’s also harder to hide they’re doing that, and let’s us bring pressure on them politically for their political misdeeds. In the end, it’ll be major powers who can — US, Europe, China,…

So you support China being able to hack any phone globally with a warrant in a Chinese court? Isn't that literally what Huawei are accused of facilitating?

No, I support China being able to spend an appreciable amount of time to crack each phone they have physical possession of, following a court order. I never suggested the ability for remote compromise (what Huawei is accused of), and my exact point is that we can create a cost to cracking each phone — in hashing power and time spent — if we compromise on the topic. No such cost exists now, because they achieve access via other means.

The combination of requiring physical possession and appreciable hashing time per crack is a two-layered response to mass-surveillance. That’s the whole basis of the compromise I’m proposing: calling their bluff, and enabling warrant cracks as political cover to shut down mass surveillance and cracking as unnecessary.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#93
>“Some days it was hard to swallow, like [when you target] a 16-year-old kid on Twitter,” she said. “But it’s an intelligence mission, you are an intelligence operative. I never made it personal.”

These people are so fucking revolting, honestly if every there was a basis for intolerance its toward the monsters who say shit like this. You know its wrong, you know you are working for evil, and you do it anyway.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#95
post #65
post #62

Earlier quoted context omitted.

Isn't the UAE muslim? Why Christmas? or is it because UAE dollars bought Christian mercenaries? We are still in the middle ages and the crusades are still raging. Time to get rid of money - or at least build walls that prevent money from crossing borders as well as criminals. We are not worthy of the the technologic advances that a few geniuses have bestowed on us.

That quote is attributed to a former NSA employee. Something being "like Christmas" is a popular American phrase that doesn't indicate one's religion.

Christmas has very little to do with religion, it's a cultural holiday across the world.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#96
post #83

Earlier quoted context omitted.

So you support China being able to hack any phone globally with a warrant in a Chinese court? Isn't that literally what Huawei are accused of facilitating?

No, I support China being able to spend an appreciable amount of time to crack each phone they have physical possession of, following a court order. I never suggested the ability for remote compromise (what Huawei is accused of), and my exact point is that we can create a cost to cracking each phone — in hashing power and time spent — if we compromise on the topic. No such cost exists now, because they achieve access…

The "hashing time per crack" reminds me of the old 48-bit encryption which was mandated to have short, crackable keys. Or even the previous attempt at doing this with the "LEAF". Are you proposing some sort of work function within the crypto enclave? ie you leave the device brute-forcing for a few days and it spits out the key?

The "appreciable time" is going to be subject to constant downward pressure, both politically and technologically.

> political cover to shut down mass surveillance and compromise as unnecessary

Mass surveillance is not going to go away without huge cultural reform of the security services. They don't take concessions.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#97
post #88

>A team of former U.S. government intelligence operatives working for the United Arab Emirates no non-competes? So, when Snowden tells to public about mere existence of NSA hacks - it is a crime, yet when an intelligence operative brings his NSA and the likes sourced detailed technical knowledge to a foreign government - that is kosher.

welcome to reality

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#98
post #12

If the US government gives itself the right to install backdoors / exploit vulnerable software (as opposed to notifying companies about vulnerabilities) then I feel pretty uncomfortable about ex-government hackers just becoming freelance mercenaries using knowledge they may have gleaned from those ops once they move onto their next gig. I can't think of a great solution to this problem.

You can make it illegal for ex-NSA employees to use their knowledge of exploits learned while on the NSA payroll. It may well already be the case for all I know.

I can't imagine that it is not.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#99
post #12

If the US government gives itself the right to install backdoors / exploit vulnerable software (as opposed to notifying companies about vulnerabilities) then I feel pretty uncomfortable about ex-government hackers just becoming freelance mercenaries using knowledge they may have gleaned from those ops once they move onto their next gig. I can't think of a great solution to this problem.

You can make it illegal for ex-NSA employees to use their knowledge of exploits learned while on the NSA payroll. It may well already be the case for all I know.

Quitting your job doesn't let you expose classified secrets, no.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#100
post #12

If the US government gives itself the right to install backdoors / exploit vulnerable software (as opposed to notifying companies about vulnerabilities) then I feel pretty uncomfortable about ex-government hackers just becoming freelance mercenaries using knowledge they may have gleaned from those ops once they move onto their next gig. I can't think of a great solution to this problem.

You can make it illegal for ex-NSA employees to use their knowledge of exploits learned while on the NSA payroll. It may well already be the case for all I know.

Perfect. Then, just hope people follow rules.
Post reply on HN