Live data from Hacker News

Pavel Durov listed in leaked Pegasus project data

theguardian.com

51–54 of 54 posts

Re: Pavel Durov listed in leaked Pegasus project data

#51
post #35
post #34

Earlier quoted context omitted.

I agree about ambient authority etc., but I'm typing this in a sandbox which doesn't allow access to .bashrc. (I'm sure it's not perfect.)

I’m no security researcher so do correct me if I’m wrong but I assume you use firejail which is a suid program - a bug here could cause an escape to even become root. And why would you write a sandbox in a memory safe language…

Yes, you're right to be wary of suid, but primarily against local attacks on my laptop. The suid risk for a remote attacker seems rather less than from remote malware without the sandbox. Opinions may differ.

Re: Pavel Durov listed in leaked Pegasus project data

#52
post #51
post #35

Earlier quoted context omitted.

I’m no security researcher so do correct me if I’m wrong but I assume you use firejail which is a suid program - a bug here could cause an escape to even become root. And why would you write a sandbox in a memory safe language…

Yes, you're right to be wary of suid, but primarily against local attacks on my laptop. The suid risk for a remote attacker seems rather less than from remote malware without the sandbox. Opinions may differ.

Of course you are correct, it is better than no sandbox, I'm just saying that compared to even the now affected Android, ios OSs GNU/Linux is seriously lacking in terms of security.

Re: Pavel Durov listed in leaked Pegasus project data

#53
post #16
post #7

Earlier quoted context omitted.

If you want to fight the Apple-Google duopoly, consider GNU/Linux smarthones Librem 5 and Pinephone.

I love my PinePhone but I can't run WhatsApp on it. I suppose I could use an emulator, but it's slow enough already.

Why would you install a spyware on it?

Re: Pavel Durov listed in leaked Pegasus project data

#54
post #32

Earlier quoted context omitted.

Hardware kill switches are unfortunately pretty much useless. For camera it's okay, but a tape is just as good, for microphone, even the gyrosensors can record voice in some quality. And here is the big thing: there is hardly any threat model where blocking the camera would help when the software stack is a burning pile of C buffer overflows from top to bottom. If you can't trust the software to such a degree, then y…

How well would putting the phone in a lead box work.

Will you leave it there forever?
Post reply on HN