Earlier quoted context omitted.
And that's a novel idea when they are on the campaign trail... until they start getting daily national security briefings and learn about the attempted attacks supposedly foiled by good SIGINT. No one wants to be the president who turns that firehose off and "causes the next 9/11". I believe that is what happened with Obama.
Given the bumbling numbskulls who still manage to set off bombs, are we really that sure they're stopping anyone?
'Karma': A hack used by the UAE to break into iPhones of foes
121–130 of 238 posts
Re: 'Karma': A hack used by the UAE to break into iPhones of foes
#122I realize it's a really sexy headline, but I'd like for there to be more than 0 proof that this is a real thing. Especially if they claim a vulnerability that's exploitable by only sending a text.
This article doesn't cite sources, but the other one cites Lori Stroud, a former developer of the application. https://www.reuters.com/investigates/special-report/usa-spyi...
Re: 'Karma': A hack used by the UAE to break into iPhones of foes
#123If the US government gives itself the right to install backdoors / exploit vulnerable software (as opposed to notifying companies about vulnerabilities) then I feel pretty uncomfortable about ex-government hackers just becoming freelance mercenaries using knowledge they may have gleaned from those ops once they move onto their next gig. I can't think of a great solution to this problem.
There's really only one "final solution" to the problem in the purely technical realm. That would be to make provable security (in the theorem-proving sense) a non-negotiable requirement to all digital logic (both hardware and software) running on networked devices. I don't know if there's even a workable definition that would rigorously describe the goal of such an effort.
... But I believe that if provable security was important enough to everyone (just like "winning the war" in the 1940s or "getting to the moon" in the 1960's), we might possibly achieve it -- at least below the OS syscall level in a few major OSs and in several important userland libraries.
However, that ignores the human element of security, which can't ever be completely solved via mere human effort. People will always be vulnerable to social engineering, for example.
Re: 'Karma': A hack used by the UAE to break into iPhones of foes
#124No one read the other Reuters article on this - it may have been criminal for NSA employees to participate in this, at the very least it was highly discouraged. If anything this is a good argument to pay IC employees on the GS payscale better so they're less likely to take jobs with other countries.
Re: 'Karma': A hack used by the UAE to break into iPhones of foes
#125Earlier quoted context omitted.
It’s already super illegal for them to leak any of that stuff.
I can imagine there's plenty of "between the lines" stuff you learn as a CIA agent that, while not specifically classified, wouldn't be something you want going to other nations.
Re: 'Karma': A hack used by the UAE to break into iPhones of foes
#126If the US government gives itself the right to install backdoors / exploit vulnerable software (as opposed to notifying companies about vulnerabilities) then I feel pretty uncomfortable about ex-government hackers just becoming freelance mercenaries using knowledge they may have gleaned from those ops once they move onto their next gig. I can't think of a great solution to this problem.
> I can't think of a great solution to this problem. There's really only one "final solution" to the problem in the purely technical realm. That would be to make provable security (in the theorem-proving sense) a non-negotiable requirement to all digital logic (both hardware and software) running on networked devices. I don't know if there's even a workable definition that would rigorously describe the goal of such a…
Re: 'Karma': A hack used by the UAE to break into iPhones of foes
#127Earlier quoted context omitted.
No, I support China being able to spend an appreciable amount of time to crack each phone they have physical possession of, following a court order. I never suggested the ability for remote compromise (what Huawei is accused of), and my exact point is that we can create a cost to cracking each phone — in hashing power and time spent — if we compromise on the topic. No such cost exists now, because they achieve access…
The "hashing time per crack" reminds me of the old 48-bit encryption which was mandated to have short, crackable keys. Or even the previous attempt at doing this with the "LEAF". Are you proposing some sort of work function within the crypto enclave ? ie you leave the device brute-forcing for a few days and it spits out the key? The "appreciable time" is going to be subject to constant downward pressure, both politic…
FakeComments was mostly talking about targeted surveillance, but I agree with him/her in spirit, since I believe that mass surveillance is not going to go away. Ever. So you can either yell futilely into the wind as it happens over your objections, up to, including, and perhaps going beyond a swarm of camera-bearing networked nanodrones coating the planet, or you can try to nudge it towards happening on slightly preferable terms.
Re: 'Karma': A hack used by the UAE to break into iPhones of foes
#128Earlier quoted context omitted.
> I can't think of a great solution to this problem. There's really only one "final solution" to the problem in the purely technical realm. That would be to make provable security (in the theorem-proving sense) a non-negotiable requirement to all digital logic (both hardware and software) running on networked devices. I don't know if there's even a workable definition that would rigorously describe the goal of such a…
"final solution" is generally a poor phrase to use: https://en.wikipedia.org/wiki/Final_Solution
Re: 'Karma': A hack used by the UAE to break into iPhones of foes
#129Earlier quoted context omitted.
That’s a deep straw man of what I said, to the point of being non-constructive mocking. You’re just being dishonest to claim I suggested trusting the spy agencies. Rather, I pointed out that they have a real mission, and they’re going to spend effort accomplishing it. But their mission isn’t to own every device — it’s to own a select few, probably on the order of hundreds or thousands a year. So, if we create a mecha…
My suggestion is to make phones secure by default, and if you need to track someone then use a network of cameras in public areas.
Re: 'Karma': A hack used by the UAE to break into iPhones of foes
#130If the US government gives itself the right to install backdoors / exploit vulnerable software (as opposed to notifying companies about vulnerabilities) then I feel pretty uncomfortable about ex-government hackers just becoming freelance mercenaries using knowledge they may have gleaned from those ops once they move onto their next gig. I can't think of a great solution to this problem.
we could elect sane leaders...