Live data from Hacker News

Pegasus spyware found on journalists’ phones, French intelligence confirms

theguardian.com

11–20 of 101 posts

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#11
post #4
post #2

Ironically, users themselves are disallowed from rooting their phones. Right to root, is right to repair.

>users themselves are disallowed from rooting their phones What? how's that possible?

In practice, not by law.

Or at least often not by law, there are some stupid laws around WiFi/broadband etc. which can be interpreted to state that it's not allowed for a phone to be sold which can be rooted (without a hack) as the user could use it to setup a WiFi hot-spot which uses non-legal frequencies. This law was made because supposedly that (with routers) is a problem, except it isn't as far as I know and it as pure lobby work from a certain industry which also loves the user to be forced to use their routers.

(PS: Also country dependent.)

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#12
post #10

Well, I thought it was only terrorists that were targeted?

One man's journalist is another man's .... ;-)

And the same invariable lie is always used, "oh, don't worry, we're only going to use this against the bad guys". Bad guys only exist in a world without nuance.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#13
post #3
post #2

Ironically, users themselves are disallowed from rooting their phones. Right to root, is right to repair.

I'm all for having the right to repair. I'm not convinced any of the folks involved ability to root would prevent the situation described.

If you could safely (on the hardware level) replace image of the phone with another, it would be easy to guarantee that you can get a rootkit-free phone - all you need is a trusted image.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#14
post #9

Well, I thought it was only terrorists that were targeted?

Terrorists, journalists, only a few letters are different.

Yes, just a word edit distance of 13 (6del, 7adds).

It's the same distance as changing to ;=)

EDIT: Yes I miscalculated, I overlooked the r.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#15
post #9

Earlier quoted context omitted.

Terrorists, journalists, only a few letters are different.

Yes, just a word edit distance of 13 (6del, 7adds). It's the same distance as changing to ;=) EDIT: Yes I miscalculated, I overlooked the r.

Such trivialities do not matter in a TRULY FREE country, and please look over here, not over there.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#16
post #13
post #3

Earlier quoted context omitted.

I'm all for having the right to repair. I'm not convinced any of the folks involved ability to root would prevent the situation described.

If you could safely (on the hardware level) replace image of the phone with another, it would be easy to guarantee that you can get a rootkit-free phone - all you need is a trusted image.

> it would be easy to guarantee that you can get a rootkit-free phone

The problem in this case is that you get the malware installed through a no-click required iMessage and not a "supply chain" attack on the image your phone is running on. How would that help?

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#17
post #16
post #13

Earlier quoted context omitted.

If you could safely (on the hardware level) replace image of the phone with another, it would be easy to guarantee that you can get a rootkit-free phone - all you need is a trusted image.

> it would be easy to guarantee that you can get a rootkit-free phone The problem in this case is that you get the malware installed through a no-click required iMessage and not a "supply chain" attack on the image your phone is running on. How would that help?

You could replace the image with software that doesn't support iMessage, for example.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#18
post #16
post #13

Earlier quoted context omitted.

If you could safely (on the hardware level) replace image of the phone with another, it would be easy to guarantee that you can get a rootkit-free phone - all you need is a trusted image.

> it would be easy to guarantee that you can get a rootkit-free phone The problem in this case is that you get the malware installed through a no-click required iMessage and not a "supply chain" attack on the image your phone is running on. How would that help?

It could help by simply being sufficiently different. The only reason this type of malware is such a widespread problem is the large monoculture of potential targets. Just like in agriculture (e.g. potatoes, bananas), a monoculture allows a single pathogen to affect an entire crop. In security this is a class break[1].

Utilizing different software implementations limits the scope of this type of attack. The current trend to increasing centralization and forced-update monoculture is a huge gift to malware authors: they only have to write one version of their malware to affect everyone.

[1] https://www.schneier.com/blog/archives/2017/01/class_breaks....

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#19
post #16
post #13

Earlier quoted context omitted.

If you could safely (on the hardware level) replace image of the phone with another, it would be easy to guarantee that you can get a rootkit-free phone - all you need is a trusted image.

> it would be easy to guarantee that you can get a rootkit-free phone The problem in this case is that you get the malware installed through a no-click required iMessage and not a "supply chain" attack on the image your phone is running on. How would that help?

The argument isn't that granting more freedoms to the owner of the device will magically make it more secure in all cases, for most it won't.

The argument is that removing freedoms from owners in the name of security is a false dichotomy because bad actors will still gain the ability to execute arbitrary code whilst owners of devices won't be able to do so.

Also, if I could provide the software I want to run, I'd probably not have iMessage.

Post reply on HN