Live data from Hacker News

'Karma': A hack used by the UAE to break into iPhones of foes

reuters.com

221–230 of 238 posts

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#221
post #219

Earlier quoted context omitted.

The goal of probably secure computing would be merely to (hopefully) extend the mathematical certainties of cryptography to computers and software. The politics of cryptography wouldn’t change, they would only be broadened. Intentional back doors would still be possible, and the ramifications of building them would be just as dire. So the best provable security could do would be to eliminate security holes like buffe…

Then you're probably using the wrong language.

Well I did say "in the theorem-proving sense", meaning that the code undergoes formal verification. There are programming languages for which each function is a theorem that is proved at compile time. That's what I meant.

There are some low-level libraries that have already been partially converted to theorem-proved functions for the sake of security.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#222
Taking the sources of the article on their word...

They said the tools use faded in late 2017 due to apple patches and that compromise required only sending a text message. Examining CVE's up until late 2017 may give more of an idea of how this tool worked. Judging from a cursory review, there are many remote code exploits so it would be hard to narrow down. But this is what I chose to look at when considering CVE's between Jun 2017 and Dec 2017 that could effect iMessage. Many of these are classified as Denial of Service bugs but often those can be extended to code execution with extensive research.

IOKit https://www.cvedetails.com/cve-details.php?t=1&cve_id=CVE-20...

IOMobileFrameBuffer https://www.cvedetails.com/cve-details.php?t=1&cve_id=CVE-20...

CFString https://www.cvedetails.com/cve-details.php?t=1&cve_id=CVE-20...

CoreText https://www.cvedetails.com/cve-details.php?t=1&cve_id=CVE-20...

CoreText https://www.cvedetails.com/cve-details.php?t=1&cve_id=CVE-20...

Fonts? https://www.cvedetails.com/cve-details.php?t=1&cve_id=CVE-20...

ImageIO https://www.cvedetails.com/cve-details.php?t=1&cve_id=CVE-20...

Messages https://www.cvedetails.com/cve-details.php?t=1&cve_id=CVE-20...

SQLite https://www.cvedetails.com/cve-details.php?t=1&cve_id=CVE-20...

SQLite https://www.cvedetails.com/cve-details.php?t=1&cve_id=CVE-20...

SQLite https://www.cvedetails.com/cve-details.php?t=1&cve_id=CVE-20...

SQLite https://www.cvedetails.com/cve-details.php?t=1&cve_id=CVE-20...

SQLite https://www.cvedetails.com/cve-details.php?t=1&cve_id=CVE-20...

Kernel: too many to count

These were compiled by reviewing the apple security mailing list https://lists.apple.com/archives/security-announce/2017

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#223
post #102

Earlier quoted context omitted.

with respect, as a non US citizen this whole article to me is deeply offensive. I/we are being targeted simply because we are second class citizens on the web. Good enough to have our data extracted by US corps but our rights are trampled on. This is the essence of it yet you're accusing me of flame-baiting? Please reflect for a minute on how just this is to anyone who has never (and will never) step/ped foot in the…

It's flamebait because it's not a new critique, and it's tangential to the article. So it's likely to attract people trying to rebut your critique, but neither your argument not the rebuttal would add anything new. If there was a thread about someone discussing us spying methods and policies against non-us citizens, your comment would not be flamebait. See the difference?

most comments are thoughts and opinions and only few provide new critique. The OP comment here, though presented in an obnoxious way, is new critique because no one else has discussed the civil liberty bias deployed by agents. Though the OP presents this in an offensive way, which is maybe breaking a different rule than just "new critique"

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#224
Overlooked: the apathy required to become techno-mercenaries started with the agents convincing themselves that spying on nationals was different than foreign nationals while working in the NSA. To resist this apathy cyber intelligence agents working for any government/corporation should deploy a moral compass that assumes they are working for the UAE.

This also begs for international conventions. New international conventions would provide a psychological back-stop against the infosec industry's unchecked nationalism. When an agent asks themselves "is what I am doing okay" international convention and law would give them an alternative to compare with other than the militarist default of "yes".

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#225
post #13

Whether or not this hack was developed with the help of Apple (a “backdoor”) or by a third-party exploit, this is exactly what a “golden key” looks like after it gets in the wild. An espionage tool developed by a major world power proliferates to totalitarian regimes, aided and operated by ex-NSA agents on the payroll, to compromise human rights activists and the political opposition. If ever there was proof that our…

Nobody credible believes for a second that Apple was involved, for whatever it’s worth.

Can't tell if you mean credible as in credible or credible as in "credible"

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#226

Earlier quoted context omitted.

Nobody credible believes for a second that Apple was involved, for whatever it’s worth.

Nobody? https://9to5mac.com/wp-content/uploads/sites/6/2018/04/cook4...

Is that Tim Cook and Saudi Arabia's MBS?

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#227

Earlier quoted context omitted.

>Mass surveillance is not going to go away without huge cultural reform of the security services. They don't take concessions. FakeComments was mostly talking about targeted surveillance, but I agree with him/her in spirit, since I believe that mass surveillance is not going to go away. Ever. So you can either yell futilely into the wind as it happens over your objections, up to, including, and perhaps going beyond a…

>"It is the common fate of the indolent to see their rights become a prey to the active. The condition upon which God hath given liberty to man is eternal vigilance; which condition if he break, servitude is at once the consequence of his crime and the punishment of his guilt." – John Philpot Curran: Speech upon the Right of Election for Lord Mayor of Dublin, 1790. (Speeches. Dublin, 1808.) as quoted in Bartlett's Fa…

Anyone can find a quote that says anything.

>"If you want a picture of the future, imagine a boot stamping on a human face — forever." - George Orwell: 1984, 1949.

Welp, guess that's it for freedom. A person from the past wrote something. No more for us to do here.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#228

Earlier quoted context omitted.

>Mass surveillance is not going to go away without huge cultural reform of the security services. They don't take concessions. FakeComments was mostly talking about targeted surveillance, but I agree with him/her in spirit, since I believe that mass surveillance is not going to go away. Ever. So you can either yell futilely into the wind as it happens over your objections, up to, including, and perhaps going beyond a…

It's not going to happen on "slightly preferable terms". Either those with political power in society want surveillance, or they don't. If they do, they'll take all that they can get, and the only thing cooperating with them will do is make it all happen faster - the moment you provide a "compromise" surveillance scheme to them on a silver platter is the moment when they'll start devising how to get around the remain…

So you simultaneously think the other side is so powerful that you cannot even compromise with them without being pushed back further, but they are also so weak that you believe you can achieve a total victory without conceding any points? How you you reconcile that? Or do you just resign yourself to fighting for a purer goal since you know you will lose without achieving it regardless?

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#229
post #30

Earlier quoted context omitted.

> Eschew flamebait. Don't introduce flamewar topics unless you have something genuinely new to say. Avoid unrelated controversies and generic tangents. https://news.ycombinator.com/newsguidelines.html

with respect, as a non US citizen this whole article to me is deeply offensive. I/we are being targeted simply because we are second class citizens on the web. Good enough to have our data extracted by US corps but our rights are trampled on. This is the essence of it yet you're accusing me of flame-baiting? Please reflect for a minute on how just this is to anyone who has never (and will never) step/ped foot in the…

That's what happens when you are on someone else's web. So far, China is the only one deciding they are unhappy enough with the arrangement to build their own web, but the option exists for any country, or even non-geographically-bound organization if you are willing to tolerate shitty satellite connections.

Re: 'Karma': A hack used by the UAE to break into iPhones of foes

#230

Earlier quoted context omitted.

Please review the following with explicit citations. https://en.wikipedia.org/wiki/Global_surveillance_disclosure...

That’s a non-responsive answer, and you know it.

The PRISM program alone shows the NSA's intent to collect as much information as possible. This in conjunction with the Utah Data Center makes it pretty aparrent what the goal was.
Post reply on HN