Live data from Hacker News

Scanning your iPhone for Pegasus

arkadiyt.com

71–80 of 81 posts

Re: Scanning your iPhone for Pegasus

#71

I ran this tool and found a trace that I was infected (malware detected in CrashReporter.plist). Any clue what I should be doing, if anything, to address this?

Reach out to Amnesty Tech and/or Citizen Lab for help establishing whether this is a real infection or a false positive. If it's real: Adjust your behavior to account for the fact that once you know you're a target, there is no device on the market and no practical measures you can use to maintain safety. Assume everything you do on or near a computer used by you or a close contact is being monitored. The level of ef…

The safest device would be a classical PC for general computing. No smartphone OS of course. Still vulnerable, but probably a lot safer.

Re: Scanning your iPhone for Pegasus

#72
post #41

Earlier quoted context omitted.

> on a chrome os device You instantly lost.

Chrome OS is probably the most secure system to use from an exploit perspective. Just never install an Android app on it (that feature doesn't have the same guarantees as the rest of the system), and preferably use a guest account on it (that's how they run it in security competitions) You basically have to break four layers to exploit that. You have to break the web renderer, then out of the browser sandbox, then yo…

Chrome OS is probably the OS that leaks the most personal info and behavior of all OS combined. It is inexcusable to subject children to it in my opinion. Advertisers know how to groom.

Re: Scanning your iPhone for Pegasus

#73

Earlier quoted context omitted.

The walls are financial, not security. The security is a lie.

Both can be true at once. It's actually a pretty big security win that I don't have to worry about what my grandma downloaded from the internet for her iPhone for instance, the way I have to worry about her laptop. Apple profits from this, and I really don't mind.

Normal users a far more exposed through smartphones than they ever were with PCs that can download the worst trojans.

Re: Scanning your iPhone for Pegasus

#74
post #50

Earlier quoted context omitted.

> I don't have to worry about what my grandma downloaded from the internet for her iPhone Yet you're ironically responding about an article telling how to find if your iPhone has been infected with Pegasus, one of the worst most obtrusive security vulnerabilities you can have, period.

Do you think nation states who spent a fortune on Pegasus are going after my grandmother? I think you're missing the big picture for most normal people.

Since the law doesn't protect citizens from illegal surveillance, no matter if that is your grandma or not, this kind of security is extremely important.

Re: Scanning your iPhone for Pegasus

#75

Earlier quoted context omitted.

still missing the point

Nope, the point is that the security is not only not real (tfa) but it's actually worse since you need to root to detect it.

But that point is wrong. All security is layers, nothing is bulletproof.

Re: Scanning your iPhone for Pegasus

#76

Earlier quoted context omitted.

Do you think nation states who spent a fortune on Pegasus are going after my grandmother? I think you're missing the big picture for most normal people.

Since the law doesn't protect citizens from illegal surveillance, no matter if that is your grandma or not, this kind of security is extremely important.

What do you mean by “this kind of security.”

Of course this is a big deal. But I think people are sort of missing the point. Nation States will always find a way in. There’s really no kind of security that stops a persistent well resourced threat.

If you think android/ is immune to an advanced persistent threat, you're wrong.

Apple will fix these vulnerabilities, and then these professional hackers will get back to work on finding a new way in. The goal isn't 100% impenetrable security--that's impossible. The goal is really imposing a high enough cost so that as few as possible are capable of getting in.

There is not a rampant security problem on iOS. But there are still vulnerabilities for those with the resources to find them. That's only surprising to people that don't follow the security world.

Re: Scanning your iPhone for Pegasus

#77

Earlier quoted context omitted.

Since the law doesn't protect citizens from illegal surveillance, no matter if that is your grandma or not, this kind of security is extremely important.

What do you mean by “this kind of security.” Of course this is a big deal. But I think people are sort of missing the point. Nation States will always find a way in. There’s really no kind of security that stops a persistent well resourced threat. If you think android/ is immune to an advanced persistent threat, you're wrong. Apple will fix these vulnerabilities, and then these professional hackers will get back to w…

States probably have dragnet surveillance and devices like iPhones make this far easier than it should be.

> If you think android/ is immune to an advanced persistent threat, you're wrong.

Some of these devices are probably even more vulnerable. But the heterogeneity of systems is what provides practical security and systems like iOS are the opposite of that. Through this uniform software environment you create the juicy target in the first place.

Also anything in the Apple cloud is highly vulnerable to state actors anyway. Not only in the Apple cloud of course.

Re: Scanning your iPhone for Pegasus

#78

Earlier quoted context omitted.

What do you mean by “this kind of security.” Of course this is a big deal. But I think people are sort of missing the point. Nation States will always find a way in. There’s really no kind of security that stops a persistent well resourced threat. If you think android/ is immune to an advanced persistent threat, you're wrong. Apple will fix these vulnerabilities, and then these professional hackers will get back to w…

States probably have dragnet surveillance and devices like iPhones make this far easier than it should be. > If you think android/ is immune to an advanced persistent threat, you're wrong. Some of these devices are probably even more vulnerable. But the heterogeneity of systems is what provides practical security and systems like iOS are the opposite of that. Through this uniform software environment you create the j…

> But the heterogeneity of systems is what provides practical security and systems like iOS are the opposite of that.

This may be the first time someone tried to argue the fragmented nature of Android makes it more secure.

It is true that iOS, being as uniform as it is, can present a plum target. The difference is that this also means that with one fell swoop Apple can mitigate vulnerabilities for a billion devices--and they do.

One of the primary reasons to buy an iPhone is Apple's commitment to update support for many, many years. All phones will have vulnerabilities. That is inevitable. The most important part is manufacturer commitment to promptly fixing them when they're found.

> States probably have dragnet surveillance and devices like iPhones make this far easier than it should be.

The cost of these exploits makes it unlikely that it's truly dragnet. You don't want to risk burning your expensive exploit by going after literally everything. The wider you cast the net, the more likely you are to be found, your exploit patched, your infrastructure compromised. Again, platform security is not about being impenetrable--it's about imposing costs high enough to limit the number of players and the corresponding damage.

Re: Scanning your iPhone for Pegasus

#79

Earlier quoted context omitted.

States probably have dragnet surveillance and devices like iPhones make this far easier than it should be. > If you think android/ is immune to an advanced persistent threat, you're wrong. Some of these devices are probably even more vulnerable. But the heterogeneity of systems is what provides practical security and systems like iOS are the opposite of that. Through this uniform software environment you create the j…

> But the heterogeneity of systems is what provides practical security and systems like iOS are the opposite of that. This may be the first time someone tried to argue the fragmented nature of Android makes it more secure. It is true that iOS, being as uniform as it is, can present a plum target. The difference is that this also means that with one fell swoop Apple can mitigate vulnerabilities for a billion devices--…

Android isn't the alternative draft to iOS, it is similar in significant properties. Alternatives would be relatively open PC systems for example. That diversity grows with more uncommon operating systems, which are currently endangered by MS secure boot btw, which would put PC in the same boat as mobile systems.

This isn't about favorites, I own Apple devices myself, although only MacOS and I don't expose by ID to Apple. Doing so is a major risk for the case your OS gets compromised.

As with Windows PCs in the past, you become a target with popularity.

With dragnet surveillance I mean that state actors scoop up every source they can get their hand on. It doesn't need justification because they already moved the goalpost to wanting to access encrypted information. Als the other sources aren't even questioned anymore.

Re: Scanning your iPhone for Pegasus

#80

Earlier quoted context omitted.

Reach out to Amnesty Tech and/or Citizen Lab for help establishing whether this is a real infection or a false positive. If it's real: Adjust your behavior to account for the fact that once you know you're a target, there is no device on the market and no practical measures you can use to maintain safety. Assume everything you do on or near a computer used by you or a close contact is being monitored. The level of ef…

The safest device would be a classical PC for general computing. No smartphone OS of course. Still vulnerable, but probably a lot safer.

> classical PC for general computing. No smartphone OS

Pinephone and Librem 5 smartphones can run a desktop OS for general computing. So smartphones should still be possible.

Post reply on HN