Live data from Hacker News

'Karma': A hack used by the UAE to break into iPhones of foes

reuters.com

191–200 of 238 posts

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#191
post #12

If the US government gives itself the right to install backdoors / exploit vulnerable software (as opposed to notifying companies about vulnerabilities) then I feel pretty uncomfortable about ex-government hackers just becoming freelance mercenaries using knowledge they may have gleaned from those ops once they move onto their next gig. I can't think of a great solution to this problem.

> I can't think of a great solution to this problem. There's really only one "final solution" to the problem in the purely technical realm. That would be to make provable security (in the theorem-proving sense) a non-negotiable requirement to all digital logic (both hardware and software) running on networked devices. I don't know if there's even a workable definition that would rigorously describe the goal of such a…

So, "provably secure" is a catch-22.

If something can be created to be provably secure, then it can be an argument for government legislating a back door.

"You said it's provably secure. Now you can give us provably secure access too without hurting your customer's privacy or security, because they're protected by the 4th amendment."

I don't think this can be solved by technology, I think this comes down to politics of freedom, if you get right down to it. And it looks like you're going to have to have that fight anyway.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#192
post #4

I realize it's a really sexy headline, but I'd like for there to be more than 0 proof that this is a real thing. Especially if they claim a vulnerability that's exploitable by only sending a text.

The description of the hack fits StageFright perfectly[1], which was exactly what it did. The sources may have just changed the affected platform to iOS to gain some traction.

[1] https://en.wikipedia.org/wiki/Stagefright_(bug)

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#193
post #187

I can't help but giggle at the thought of Emirati hackers. For whatever reason my mind can't wrap around the fact that an extremely religious people can also be at the high end of tech (at the very least high enough to figure out 0days and such). Does anyone have any info on since when this has actually been like this? I'd like to look up how their CS education works and that kind of stuff.

The Society of Jesuits aka Jesuits have also conducted technical research in parallel with religious pursuits. Don't see any problem.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#194
post #178

Earlier quoted context omitted.

yeah, but the Australian Government is busy passing laws to require companies like Apple to do something pretty much exactly like this. (And in my mind at least, those laws are without doubt part of a coordinated five eyes security/law-enforcement campaign to push those kinds of laws through everywhere: "Look, it works in Australia!" the Canadians/UK/NZ/US will say...)

That's precisely the GP's point.

Yeah. Right now, nobody (credible) is accusing Apple of enabling this kind of exploit.

If Apple are still selling hardware in Australia in 12 months time, the suspicion will _have_ to be that they have enabled something similar enough to this to be considered untrustworthy... (And not just Apple, any manufacturer or software company doing business in Australia...)

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#195
post #187

I can't help but giggle at the thought of Emirati hackers. For whatever reason my mind can't wrap around the fact that an extremely religious people can also be at the high end of tech (at the very least high enough to figure out 0days and such). Does anyone have any info on since when this has actually been like this? I'd like to look up how their CS education works and that kind of stuff.

There are plenty of religious people in Hacker News. I have no idea why you would think being religious or spiritual would prevent anyone from developing technology.

My religious views do not stem from a lack of intelligence or education.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#196

Earlier quoted context omitted.

> What’s not going to sell, and what the tech industry needs to get over is “lulz, it’ll impossible to intercept military or terrorist information because I need absolute privacy for my saucy emails”. I think it’s been empirically demonstrated that won’t happen. It's very much the other way. Strong encryption algorithms have been available to the public for a long time now. You can ban using them, but the only way to…

I disagree with your analysis — the way most people receive encryption, including criminals and terrorists, is through a provider. Regulating their behavior does change the general trend in security. Further, forcing them to implement their own encryption increases the likelihood they make a mistake while also refocusing the NSA et al to those algorithms instead. What we’ve seen is governments subverting encryption a…

> I’m not trying to accomplish some absolute ideological position

You did.

Any attempt at right of privacy must be mercilessly crushed with maximum force

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#197
post #13

Whether or not this hack was developed with the help of Apple (a “backdoor”) or by a third-party exploit, this is exactly what a “golden key” looks like after it gets in the wild. An espionage tool developed by a major world power proliferates to totalitarian regimes, aided and operated by ex-NSA agents on the payroll, to compromise human rights activists and the political opposition. If ever there was proof that our…

I disagree with the conclusion of absolute security — it won’t happen, and only encourages subversion by people who both need and have a right to access the content. Instead of pontificating, the tech industry should innovate. There’s no reason that hashchains can’t be used to timelock the key, and the enclave export it in response to a signed request. Then we can at least force the compromises through the legal syst…

FakeComments, can you tell who you are?

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#198

Earlier quoted context omitted.

This sounds like a first order objection to a second order concern. In particular: > What’s not going to sell, and what the tech industry needs to get over is “lulz, it’ll impossible to intercept military or terrorist information because I need absolute privacy for my saucy emails” Seems to be an ironic mischaracterisation of the parent’s point, which was precisely that one coubtry’s terrorism is another’s gay rights…

> Seems to be an ironic mischaracterisation of the parent’s point, which was precisely that one coubtry’s terrorism is another’s gay rights activist or high ranking foreign official. My point was that issues like this should be mediated by courts and existing legal systems, not the unilateral decision of technologists. And that society is going to insist that be the case, hence the most effective way to protect those…

> not the unilateral decision of technologists.

It should be, and would the judge disagree, show the honourable justice disagree, make him feel who is the boss in the internets.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#199
post #84

Earlier quoted context omitted.

Nobody credible believes for a second that Apple was involved, for whatever it’s worth.

I was not trying to suggest that, I was trying to convey that once a spy agency has remote access (sanctioned or otherwise) we can see by this example how it is proliferated and abused.

> I was not trying to suggest that

You were by simply stating it. It's the same type of saying-but-not-saying lines that the media uses like "if this allegation proves to be true" or similar such phrases. The fact that you state it suggests to the reader that people think it. If it was an honest mistake in wording on your part that's one thing, but you should probably avoid using such phrasing.

Look at all the people responding to the post you responded to saying that Apple did it. There's no reason to give a forum for such ideas.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#200
post #187

I can't help but giggle at the thought of Emirati hackers. For whatever reason my mind can't wrap around the fact that an extremely religious people can also be at the high end of tech (at the very least high enough to figure out 0days and such). Does anyone have any info on since when this has actually been like this? I'd like to look up how their CS education works and that kind of stuff.

There are plenty of religious people in Hacker News. I have no idea why you would think being religious or spiritual would prevent anyone from developing technology. My religious views do not stem from a lack of intelligence or education.

Not even talking about intelligence here. Sorry. That's an endless time waster I'm not touching.

As mentioned, for whatever reason, I'm having a hard time picturing how people who deem apostasy punishable by death can also manage, research, and exploit modern equipment, and am looking for some indication as to when exactly did they start getting good at it.

Post reply on HN