Live data from Hacker News

'Karma': A hack used by the UAE to break into iPhones of foes

reuters.com

131–140 of 238 posts

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#131
post #12

If the US government gives itself the right to install backdoors / exploit vulnerable software (as opposed to notifying companies about vulnerabilities) then I feel pretty uncomfortable about ex-government hackers just becoming freelance mercenaries using knowledge they may have gleaned from those ops once they move onto their next gig. I can't think of a great solution to this problem.

> I can't think of a great solution to this problem. There's really only one "final solution" to the problem in the purely technical realm. That would be to make provable security (in the theorem-proving sense) a non-negotiable requirement to all digital logic (both hardware and software) running on networked devices. I don't know if there's even a workable definition that would rigorously describe the goal of such a…

[deleted]

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#132
post #88

>A team of former U.S. government intelligence operatives working for the United Arab Emirates no non-competes? So, when Snowden tells to public about mere existence of NSA hacks - it is a crime, yet when an intelligence operative brings his NSA and the likes sourced detailed technical knowledge to a foreign government - that is kosher.

What do you expect the non-competes to accomplish, exactly? Thanks, California.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#133
I think that the idea of out-of-the-box privacy/security against even a semi-competent adversary on any computer (especially a mobile device) is completely fictitious, and these hack stories play an important role in helping people realize that.

Consider the thousands of people around the world that are involved in making phones in design, hardware, software, manufacturing, signal providers, platform providers, app writers to name a few. Any of them could be malicious actors or accidentally introduce exploitable bugs. The idea that such a complex stack can shield you from very smart and resourceful people that are actively trying to peek though is not reasonable. Everyone, especially people that are "annoying" to powerful entities (corporate or government), should assume that everything they do with their mobile phone is accessible to the people they hope it isn't.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#134
post #6

Am I the only one who feels like every time we get news of a government compromising an iPhone through some mystical exploit, the technology around it seems very fanciful?

It's a corollary of Clarke's law. When technology is described by someone too stupid to understand it (like nearly all journalists), the explanation makes it sound like magic, because that's how the writer sees it.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#136
post #12

If the US government gives itself the right to install backdoors / exploit vulnerable software (as opposed to notifying companies about vulnerabilities) then I feel pretty uncomfortable about ex-government hackers just becoming freelance mercenaries using knowledge they may have gleaned from those ops once they move onto their next gig. I can't think of a great solution to this problem.

> I can't think of a great solution to this problem. There's really only one "final solution" to the problem in the purely technical realm. That would be to make provable security (in the theorem-proving sense) a non-negotiable requirement to all digital logic (both hardware and software) running on networked devices. I don't know if there's even a workable definition that would rigorously describe the goal of such a…

I think your solution needs to extend to the hardware components on the board.

High security MCUs go through great lengths to defeat sideband attacks on the package (some really neat stuff too like failing if exposed to die shaving).

There are secure bus initiatives but they don't extend to the BOM (bill of materials) for all the components.

On top of that, GUI techniques for obscuring physical input (keyboards, UI touches) are needed.

Given Apple's posturing and patch release cadence, I think/feel they are on the side of privacy. Android too. We're on the right track, I wonder if eventually tech will win the arms race for exploits like this? (The rubber hose exploit will always work...)

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#137
post #109

No one read the other Reuters article on this - it may have been criminal for NSA employees to participate in this, at the very least it was highly discouraged. If anything this is a good argument to pay IC employees on the GS payscale better so they're less likely to take jobs with other countries.

Large govt. contractors and sub companies run this and all the other programs like this. There is tacit approval for these ops. I'd even imagine there's a bit of intel being fed back to them from the new employees .

"The FBI is now investigating whether Raven’s American staff leaked classified U.S. surveillance techniques and if they illegally targeted American computer networks" [1]

It's still illegal to use US classified information for a program like this and it's still illegal to target American citizens or networks.

[1] https://www.reuters.com/investigates/special-report/usa-spyi...

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#138
post #83

Earlier quoted context omitted.

So you support China being able to hack any phone globally with a warrant in a Chinese court? Isn't that literally what Huawei are accused of facilitating?

No, I support China being able to spend an appreciable amount of time to crack each phone they have physical possession of, following a court order. I never suggested the ability for remote compromise (what Huawei is accused of), and my exact point is that we can create a cost to cracking each phone — in hashing power and time spent — if we compromise on the topic. No such cost exists now, because they achieve access…

> my exact point is that we can create a cost to cracking each phone — in hashing power and time spent

This is not at all how encryption or security works

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#139
post #76

Earlier quoted context omitted.

Could you please provide some sources?

Wouldn’t it be far more useful for you to provide someone credible making such a claim? If he was wrong this claim would be so trivial to refute that sources seem entirely pointless.

To clarify my earlier comment, I wasn't taking a position one way or the other.

lawnchair_larry made a claim about "nobody credible" believing something. As a lay person in the field, I don't know who these credible people are. Therefore I asked whether lawnchair_larry could tell us who one or more of these credible people are, and where we can read more about what they believe to be true about the situation.

Post reply on HN