Live data from Hacker News

Scanning your iPhone for Pegasus

arkadiyt.com

41–50 of 81 posts

Re: Scanning your iPhone for Pegasus

#41

Earlier quoted context omitted.

Reach out to Amnesty Tech and/or Citizen Lab for help establishing whether this is a real infection or a false positive. If it's real: Adjust your behavior to account for the fact that once you know you're a target, there is no device on the market and no practical measures you can use to maintain safety. Assume everything you do on or near a computer used by you or a close contact is being monitored. The level of ef…

How about use your phone as only a data modem and do everything on a chrome os device, which have no known malware. Just don't install chrome extensions and you are safe. Also avoid installing apps on your phone This is basically what I wish I had, except back in reality there's no Chrome device that's the size of my cell phone. There are some with cellular modems.

> on a chrome os device

You instantly lost.

Re: Scanning your iPhone for Pegasus

#45
post #44

Any way to check iPhones if you don’t have a Mac?

On Arch Linux, I installed libimobiledevice from source ( https://github.com/libimobiledevice/libimobiledevice ), as the newest version in Pacman didn't connect to my iPhone. I also installed usbmuxd via Pacman.

After installing it myself, I realized the container already has it. You just need to give the container access to your USB controller

Re: Scanning your iPhone for Pegasus

#46

Earlier quoted context omitted.

Walls have never been fool proof, though that doesn't mean building them is a waste of time.

The walls are financial, not security. The security is a lie.

Both can be true at once.

It's actually a pretty big security win that I don't have to worry about what my grandma downloaded from the internet for her iPhone for instance, the way I have to worry about her laptop. Apple profits from this, and I really don't mind.

Re: Scanning your iPhone for Pegasus

#47

Earlier quoted context omitted.

Reach out to Amnesty Tech and/or Citizen Lab for help establishing whether this is a real infection or a false positive. If it's real: Adjust your behavior to account for the fact that once you know you're a target, there is no device on the market and no practical measures you can use to maintain safety. Assume everything you do on or near a computer used by you or a close contact is being monitored. The level of ef…

How about use your phone as only a data modem and do everything on a chrome os device, which have no known malware. Just don't install chrome extensions and you are safe. Also avoid installing apps on your phone This is basically what I wish I had, except back in reality there's no Chrome device that's the size of my cell phone. There are some with cellular modems.

No malware except for the google operating system

Re: Scanning your iPhone for Pegasus

#48
post #41

Earlier quoted context omitted.

How about use your phone as only a data modem and do everything on a chrome os device, which have no known malware. Just don't install chrome extensions and you are safe. Also avoid installing apps on your phone This is basically what I wish I had, except back in reality there's no Chrome device that's the size of my cell phone. There are some with cellular modems.

> on a chrome os device You instantly lost.

Chrome OS is probably the most secure system to use from an exploit perspective.

Just never install an Android app on it (that feature doesn't have the same guarantees as the rest of the system), and preferably use a guest account on it (that's how they run it in security competitions)

You basically have to break four layers to exploit that. You have to break the web renderer, then out of the browser sandbox, then you need to exploit the kernel to be able to write outside the (non persistent) guest account storage, then you need to exploit the firmware/secure boot chain so secure boot doesn't detect your modifications to the filesystem when the system next boots.

Re: Scanning your iPhone for Pegasus

#49

Earlier quoted context omitted.

I'm no expert, but if you ask me, I would completely erase the phone, upgrade it via DFU, and start fresh. After setting it up again, run another backup and rerun the tool to doublecheck. That or ditch the phone

What’s the best procedure for getting data off a compromised iPhone before wiping? Plugging it into other devices via usb or backing up to iCloud seems sketchy to me but maybe I’m overly paranoid.

> Plugging it into other devices via usb

You've never plugged your phone into your computer before? If so, I doubt it could cause more harm to do it again unless you haven't done it since your device was infected. You're just mentally aware of it now, but how long has it been there and how many devices have you plugged your phone into since then, even just to charge? If you never plug your phone into another device, it's moot, but I suspect most people do at sometime or another. "Hey, can I plug my phone in real quick to charge a bit" type stuff. Airdrop is good for quick, small files, but I'm not going to be transferring multiple gigabytes of 4k video via wifi speeds that way.

Re: Scanning your iPhone for Pegasus

#50

Earlier quoted context omitted.

The walls are financial, not security. The security is a lie.

Both can be true at once. It's actually a pretty big security win that I don't have to worry about what my grandma downloaded from the internet for her iPhone for instance, the way I have to worry about her laptop. Apple profits from this, and I really don't mind.

> I don't have to worry about what my grandma downloaded from the internet for her iPhone

Yet you're ironically responding about an article telling how to find if your iPhone has been infected with Pegasus, one of the worst most obtrusive security vulnerabilities you can have, period.

Post reply on HN