Live data from Hacker News

'Karma': A hack used by the UAE to break into iPhones of foes

reuters.com

111–120 of 238 posts

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#111
post #88

>A team of former U.S. government intelligence operatives working for the United Arab Emirates no non-competes? So, when Snowden tells to public about mere existence of NSA hacks - it is a crime, yet when an intelligence operative brings his NSA and the likes sourced detailed technical knowledge to a foreign government - that is kosher.

welcome to reality

Now imagine what's going to be possible in Australia with their compulsory surveillance laws...

Though, I wouldn't be super surprised if they banned people they forced to implement exploits from leaving country =X

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#112

Earlier quoted context omitted.

Christmas has very little to do with religion, it's a cultural holiday across the world.

"Christmas is an annual festival, commemorating the birth of Jesus Christ, observed primarily on December 25 as a religious and cultural celebration among billions of people around the world." https://en.wikipedia.org/wiki/Christmas

This may be a disturbing thought to some, but a great many people don't give a damn about any supposed virgin birth. To them, it's about getting time off from work to visit family, various pagan-derived decorations around the home (https://en.wikipedia.org/wiki/Yule), seasonal desserts, and of course consumerism/consumption (particularly the giving of gifts, which is what "like Christmas" in this instance refers to.)

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#113
post #10
post #7

Earlier quoted context omitted.

Like an exploit where all you need to do is enter the target's phone number to compromise their phone?

TFA says they need to send the target a text message. The exploit must be something like a buffer overflow in iMessage. Which we know bugs like this have been fixed. Remember the text of death which could crash any iPhone from a couple years ago?

"Bugs like this have been fixed" != "all bugs like this have been fixed". That is, some similar bugs having been fixed does not make such an exploit impossible.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#114
post #12

If the US government gives itself the right to install backdoors / exploit vulnerable software (as opposed to notifying companies about vulnerabilities) then I feel pretty uncomfortable about ex-government hackers just becoming freelance mercenaries using knowledge they may have gleaned from those ops once they move onto their next gig. I can't think of a great solution to this problem.

You can make it illegal for ex-NSA employees to use their knowledge of exploits learned while on the NSA payroll. It may well already be the case for all I know.

how about we make it illegal to hack into systems unauthorized? oh wait...

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#115
post #79

Earlier quoted context omitted.

Their top security clearances, their access to the deepest darkest secrets of intelligence tools, networks, and systems. Would you trust an employee with your biggest secrets if you knew they were retiring soon and very likely to be hired at many times their current salary by some major competitor?

It’s already super illegal for them to leak any of that stuff.

I can imagine there's plenty of "between the lines" stuff you learn as a CIA agent that, while not specifically classified, wouldn't be something you want going to other nations.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#116

Earlier quoted context omitted.

Wouldn't the police have a "right" to know if a person has any weapons? Detaining everyone and performing a full cavity search for any and all infractions is just the police exercising their "right" to such information. Will you be the first to bend over and spread for the cops "right" to peace of mind? "That it is better 100 guilty Persons should escape than that one innocent Person should suffer, is a Maxim that ha…

> "That it is better 100 guilty Persons should escape than that one innocent Person should suffer, is a Maxim that has been long and generally approved." I wonder if that maxim is still generally approved. It seems like some authoritarians would prefer that 100 innocents would suffer than one guilty person should escape. I suppose it depends how you define "innocent" and "suffer". Under modern law, everyone is guilty…

That maxim seems to ignore the possibility that those 100 free guilty people could do more damage to that one innocent person than a prison sentence can.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#117
post #12

If the US government gives itself the right to install backdoors / exploit vulnerable software (as opposed to notifying companies about vulnerabilities) then I feel pretty uncomfortable about ex-government hackers just becoming freelance mercenaries using knowledge they may have gleaned from those ops once they move onto their next gig. I can't think of a great solution to this problem.

sounds like maybe they should get a warrant and get legitimate access on an individual basis rather than being allowed to hack everything, you don’t need to hack me if I let you in, it should be just as illegal as it is for them to poke around in my house without a warrant

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#118

Earlier quoted context omitted.

Wouldn't the police have a "right" to know if a person has any weapons? Detaining everyone and performing a full cavity search for any and all infractions is just the police exercising their "right" to such information. Will you be the first to bend over and spread for the cops "right" to peace of mind? "That it is better 100 guilty Persons should escape than that one innocent Person should suffer, is a Maxim that ha…

> "That it is better 100 guilty Persons should escape than that one innocent Person should suffer, is a Maxim that has been long and generally approved." I wonder if that maxim is still generally approved. It seems like some authoritarians would prefer that 100 innocents would suffer than one guilty person should escape. I suppose it depends how you define "innocent" and "suffer". Under modern law, everyone is guilty…

I think, even in places that believed the maxim, 9/11 changed the calculation. Now the question is: How many innocent people should be jailed in order that 3000 innocent people not be killed?

Mind you, I'm not saying it's right. I'm just saying that this is how the authorities are thinking.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#119

Earlier quoted context omitted.

That’s a deep straw man of what I said, to the point of being non-constructive mocking. You’re just being dishonest to claim I suggested trusting the spy agencies. Rather, I pointed out that they have a real mission, and they’re going to spend effort accomplishing it. But their mission isn’t to own every device — it’s to own a select few, probably on the order of hundreds or thousands a year. So, if we create a mecha…

My suggestion is to make phones secure by default, and if you need to track someone then use a network of cameras in public areas.

Better yet, scrap the network of cameras and employ a load of uniformed, unarmed police officers wearing body cams. (The cameras should default to deleting footage after a few hours, unless the officer presses a button to save it, and all arrests not recorded due to "missing" footage are deemed invalid).

This helps communities to feel the reassurance of a trusted police presence, creates local jobs, and provides a decentralised alternative to having a single network controlled by a few hidden, unaccountable individuals. Putting a human conscience behind every single camera seems like a good way to prevent tyranny and encourage whistle-blowers.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#120
post #12

If the US government gives itself the right to install backdoors / exploit vulnerable software (as opposed to notifying companies about vulnerabilities) then I feel pretty uncomfortable about ex-government hackers just becoming freelance mercenaries using knowledge they may have gleaned from those ops once they move onto their next gig. I can't think of a great solution to this problem.

You can make it illegal for ex-NSA employees to use their knowledge of exploits learned while on the NSA payroll. It may well already be the case for all I know.

I hope with all my heart this is treated as the treason it is and not a "plausibly deniable" part of this recent policy of sucking up to brutal Arabian dictatorships regardless of atrocity.
Post reply on HN