Live data from Hacker News

Pegasus spyware found on journalists’ phones, French intelligence confirms

theguardian.com

21–30 of 101 posts

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#21
post #16
post #13

Earlier quoted context omitted.

If you could safely (on the hardware level) replace image of the phone with another, it would be easy to guarantee that you can get a rootkit-free phone - all you need is a trusted image.

> it would be easy to guarantee that you can get a rootkit-free phone The problem in this case is that you get the malware installed through a no-click required iMessage and not a "supply chain" attack on the image your phone is running on. How would that help?

It would help because knowledgeable people would get to pick what software they run on their phones and iMessage probably wouldn't be on the list.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#22
post #2

Ironically, users themselves are disallowed from rooting their phones. Right to root, is right to repair.

Once the system is compromised the best repair is a full reset (and even better swapping the device, not that the restore image has been tampered with ...) root powers are needed for analysis. But that's nothing a normal user can do ... But on the larger point: I agree there should be an option for suers to replace firmware and become root. But limiting root access makes work for Pegasus and others harder, which is g…

> But limiting root access makes work for Pegasus and others harder, which is good.

It's not enough to "make it harder", to actually know whether it's a useful mitigation you would have to compare how much harder it makes it compared to what inconvenience it caused for that. Pegasus has no problem getting root right now. I strongly suspect they have a built up hoard of 0-days to apply in case the current faorite technique is patched (how else could you make a business out of it? If you're running a business you can't allow some other party to control your main product).

So, how much does limiting root access hurt Pegasus? Very little, IMO. A case could be made that it helps them, in the same way that excessive regulation helps large companies, which already have resources and experience dealing with it that smaller companies must overcome to enter the market. Pegasus, and the ability to hack into phones on-demand, may have been largely hidden from the public because it was relegated to a few large players.

And what does everyone get for this? Vendor lock-in, higher prices, less control over your own devices.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#23
post #7

I have seen some manuals were released and some tools reverse engineered. What is currently the best link for a deep technical overview of how these tools work/worked?

As I did not get any replies I share what I found. If anybody has better or more detailed resources, please be kind and feed our curious minds:

"Technical Analysis of Pegasus Spyware"

https://info.lookout.com/rs/051-ESQ-475/images/lookout-pegas...

"Pegasus Spyware"

https://en.wikipedia.org/wiki/Pegasus_(spyware)

"The Million Dollar Dissident"

https://citizenlab.ca/2016/08/million-dollar-dissident-iphon...

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#24
post #18
post #16

Earlier quoted context omitted.

> it would be easy to guarantee that you can get a rootkit-free phone The problem in this case is that you get the malware installed through a no-click required iMessage and not a "supply chain" attack on the image your phone is running on. How would that help?

It could help by simply being sufficiently different . The only reason this type of malware is such a widespread problem is the large monoculture of potential targets. Just like in agriculture (e.g. potatoes, bananas), a monoculture allows a single pathogen to affect an entire crop. In security this is a class break [1]. Utilizing different software implementations limits the scope of this type of attack. The current…

This is a good principle in terms of reducing the overall blast radius of exploits. But to do this the implementations should genuinely be independent.

In practice we may find a monoculture within a hidden layer of the stack than we're optimizing for, such as an OS kernel method, TLS library or chipset which coincidentally has captured the entire market. When a clever enough exploit on a common resource is found, then the problem transforms to one of coordinating patching for the same, wherein a broad ecosystem of higher level components (like Android or PCs) becomes nearly impossible to thoroughly cover. As such malware authors may potentially still get away with writing a single version of their software so long as they target low-level enough. With sufficient fragmentation they don't even need to invent their own exploits, just use publicly known CVEs that they can brute-force against older devices.

(Not saying you're wrong, your recommendation may still be better in the long-run. We're after all weighing the risk level of black swan events, such as a zero-day on a low level of the stack, or a high level of the stack on a high-volume vendor)

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#25
post #7

I have seen some manuals were released and some tools reverse engineered. What is currently the best link for a deep technical overview of how these tools work/worked?

"Forensic Methodology Report: How to catch NSO Group’s Pegasus"

https://www.amnesty.org/en/latest/research/2021/07/forensic-...

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#26
post #9

Earlier quoted context omitted.

Terrorists, journalists, only a few letters are different.

Yes, just a word edit distance of 13 (6del, 7adds). It's the same distance as changing to ;=) EDIT: Yes I miscalculated, I overlooked the r.

Edit distance, sedis shun'ist. They are all ists; what more do we need to know?

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#28
"Bredoux added: “It takes a bit of time to realise it, but it’s extremely unpleasant to think that one is being spied on, that photos of your husband and children, your friends – who are all collateral victims – are being looked at; that there is no space in which you can escape. It’s very disturbing.”"

Welcome to the future! It's pretty much the same as the past, only more effective.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#29
post #3
post #2

Ironically, users themselves are disallowed from rooting their phones. Right to root, is right to repair.

I'm all for having the right to repair. I'm not convinced any of the folks involved ability to root would prevent the situation described.

The device would have to be treated as inherently untrustworthy, like your laptop or a PC in a cafe or library. That is unlike the (Edit: false) current expectation that the hardware and OS of the device are a trusted platform.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#30
post #13
post #3

Earlier quoted context omitted.

I'm all for having the right to repair. I'm not convinced any of the folks involved ability to root would prevent the situation described.

If you could safely (on the hardware level) replace image of the phone with another, it would be easy to guarantee that you can get a rootkit-free phone - all you need is a trusted image.

The Pegasus thing didn't even survive a reboot, it was reinstalled by using the 0-day again on a fresh boot. Replacing the image would have done nothing if they were flashing a version that still had the iMessage vulnerability.
Post reply on HN