Live data from Hacker News

'Karma': A hack used by the UAE to break into iPhones of foes

reuters.com

151–160 of 238 posts

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#152
post #13

Whether or not this hack was developed with the help of Apple (a “backdoor”) or by a third-party exploit, this is exactly what a “golden key” looks like after it gets in the wild. An espionage tool developed by a major world power proliferates to totalitarian regimes, aided and operated by ex-NSA agents on the payroll, to compromise human rights activists and the political opposition. If ever there was proof that our…

Nobody credible believes for a second that Apple was involved, for whatever it’s worth.

Nobody?

https://9to5mac.com/wp-content/uploads/sites/6/2018/04/cook4...

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#153

Earlier quoted context omitted.

Wouldn’t it be far more useful for you to provide someone credible making such a claim? If he was wrong this claim would be so trivial to refute that sources seem entirely pointless.

To clarify my earlier comment, I wasn't taking a position one way or the other. lawnchair_larry made a claim about "nobody credible" believing something. As a lay person in the field, I don't know who these credible people are. Therefore I asked whether lawnchair_larry could tell us who one or more of these credible people are, and where we can read more about what they believe to be true about the situation.

How is he supposed to refer you to people not saying something?

This is most definitely a rather silly request.

Can you prove that magic doesn’t exist?

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#154
post #79

Earlier quoted context omitted.

It’s already super illegal for them to leak any of that stuff.

I can imagine there's plenty of "between the lines" stuff you learn as a CIA agent that, while not specifically classified, wouldn't be something you want going to other nations.

I think maybe your opinions on this are largely influenced by movies and not materials the government actually releases.

Can you give me an example of the kind of unclassified information these people should be prevented from sharing?

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#156
post #4

I realize it's a really sexy headline, but I'd like for there to be more than 0 proof that this is a real thing. Especially if they claim a vulnerability that's exploitable by only sending a text.

>Especially if they claim a vulnerability that's exploitable by only sending a text. For some time, it was possible to crash some iPhones by texting them a Taiwanese flag emoji (which was censored by mainland China). https://www.cultofmac.com/561635/apples-taiwanese-flag-ban-l... I don't know offhand if this was a buffer overflow or something else, but if you can crash the OS with a text, you . could likely exploit i…

> I don't know offhand if this was a buffer overflow or something else

It was an issue when the device's local was set incorrectly and would return NULL, leading to a crash in CFStringCompare.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#157
post #6

Am I the only one who feels like every time we get news of a government compromising an iPhone through some mystical exploit, the technology around it seems very fanciful?

Bear in mind that, at one time, iOS devices could be jailbroken [to run arbitrary code] by simply opening a specifically-created PDF; https://www.wired.com/2011/07/jailbreakme-3-0-unlock-your-ip...

Not just arbitrary code, but arbitrary code with kernel privileges!

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#158
post #13

Whether or not this hack was developed with the help of Apple (a “backdoor”) or by a third-party exploit, this is exactly what a “golden key” looks like after it gets in the wild. An espionage tool developed by a major world power proliferates to totalitarian regimes, aided and operated by ex-NSA agents on the payroll, to compromise human rights activists and the political opposition. If ever there was proof that our…

I disagree with the conclusion of absolute security — it won’t happen, and only encourages subversion by people who both need and have a right to access the content. Instead of pontificating, the tech industry should innovate. There’s no reason that hashchains can’t be used to timelock the key, and the enclave export it in response to a signed request. Then we can at least force the compromises through the legal syst…

If I want to have a private conversation where the details of what are said are undiscoverable, I believe that's a right that people should have in a "free country", including over the internet, over phone, and so on. The fact is, I can, using some combination of math and secrets, accomplish this.

I don't think anyone on earth has the right to collect/record/see the contents of my communications other than me and the other participants, until there's reasonable suspicion of a crime.

Covert dragnet snooping is an evil means to any end, and it damages the moral standing of the society that does it.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#159
post #12

If the US government gives itself the right to install backdoors / exploit vulnerable software (as opposed to notifying companies about vulnerabilities) then I feel pretty uncomfortable about ex-government hackers just becoming freelance mercenaries using knowledge they may have gleaned from those ops once they move onto their next gig. I can't think of a great solution to this problem.

> I can't think of a great solution to this problem.

The mentioned government agencies have the "NOBUS" belief: that the concept of "NObody But US" (having access to the "keys to the secrets") works.

This article is just one of a many good examples that it doesn't.

What could work are just the systems which are secure without any exceptions. Which is hard to achieve when enough powerful influences (most often directly or indirectly tax funded, even if not explicitly government organizations) do all they can to make that not happening. It's then easier than it appears to be to achieve the goals of nobody having an access to a really secure system.

An example:

https://en.wikipedia.org/wiki/Dual_EC_DRBG

"In September 2013, The New York Times reported that internal NSA memos leaked by Edward Snowden indicated that the NSA had worked during the standardization process to eventually become the sole editor of the Dual_EC_DRBG standard,[7] and concluded that the Dual_EC_DRBG standard did indeed contain a backdoor for the NSA.[8] As response, NIST stated that "NIST would not deliberately weaken a cryptographic standard."[9] According to the New York Times story, the NSA spends $250 million per year to insert backdoors in software and hardware as part of the Bullrun program.[10]"

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#160

Earlier quoted context omitted.

You can make it illegal for ex-NSA employees to use their knowledge of exploits learned while on the NSA payroll. It may well already be the case for all I know.

Perfect. Then, just hope people follow rules.

Sometimes you have to disincentivize behavior with prison time and things like that and then hope people don't do it. Trying to prevent some crimes ahead of time is a recipe for dystopia.
Post reply on HN