Live data from Hacker News

Pegasus spyware found on journalists’ phones, French intelligence confirms

theguardian.com

31–40 of 101 posts

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#31
Is there no regulatory or compliance requirements for surveillance software?

Instead of blaming the victims of pegasus, we should focus our attention on the lack of actions from key policymakers and regulatory bodies. It is not possible for every individual to be a technical expert when it comes to malware removal, but we can reduce the likelihood of misusing surveillance software by creating an ethical framework around it, backed by nations that value freedom and democracy.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#33

I wonder what would have happened to windows phone/lumias if things had turned out differently. I also wonder if there was something like that when windows mobile was on the market.

I’m not sure why it would be any different.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#34
Slight OT: the malware indicators of compromise that Amnesty International released have no license, thereby prohibiting use in other projects as far as I understand.

https://github.com/AmnestyTech/investigations/issues/11

If anyone can help on that front it'd be much appreciated.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#35

I wonder what would have happened to windows phone/lumias if things had turned out differently. I also wonder if there was something like that when windows mobile was on the market.

I imagine NSO would have developed WinMo exploits and ported their implants to Windows Phone. They'd pretty much reuse the same C&C servers, and their clients would target those phones just as they do for iPhone and Android.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#36
post #16

Earlier quoted context omitted.

> it would be easy to guarantee that you can get a rootkit-free phone The problem in this case is that you get the malware installed through a no-click required iMessage and not a "supply chain" attack on the image your phone is running on. How would that help?

It would help because knowledgeable people would get to pick what software they run on their phones and iMessage probably wouldn't be on the list.

Journalists (as here) don't usually get to choose the communication software their sources are comfortable communicating over. They install whatever's required to get the story. And they likely wouldn't install an OS that doesn't let them install such apps.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#37
post #13
post #3

Earlier quoted context omitted.

I'm all for having the right to repair. I'm not convinced any of the folks involved ability to root would prevent the situation described.

If you could safely (on the hardware level) replace image of the phone with another, it would be easy to guarantee that you can get a rootkit-free phone - all you need is a trusted image.

> all you need is a trusted image

I bet you, that image will be provided by the trustworthy people from NSO, free of charge or at a price! Whatever makes you trust their image.

IMHO devices should be root-able but with high barriers of entry, something like soldering should be involved. If you are after doing something that you don't understand but a stranger on the internet told you to do it you shouldn't be able to do it.

I just want to remind you that quite recently a few police agencies come together, built a "secure messaging app", fed it to the criminals and tracked all their communication until gather enough information to take down their entire operation.[0]

Or the time when CIA run a Swiss encryption company[1]

[0]https://news.ycombinator.com/item?id=27429311

[1]https://news.ycombinator.com/item?id=22297963

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#38
post #16
post #13

Earlier quoted context omitted.

If you could safely (on the hardware level) replace image of the phone with another, it would be easy to guarantee that you can get a rootkit-free phone - all you need is a trusted image.

> it would be easy to guarantee that you can get a rootkit-free phone The problem in this case is that you get the malware installed through a no-click required iMessage and not a "supply chain" attack on the image your phone is running on. How would that help?

Would it? Wouldn't you still need privilege escalation? Having root access is different from being logged in as the root user. Of course being logged in as root comes with all the same security risks as it does if you do this on Linux. But no one uses root as their main account.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#39
post #37
post #13

Earlier quoted context omitted.

If you could safely (on the hardware level) replace image of the phone with another, it would be easy to guarantee that you can get a rootkit-free phone - all you need is a trusted image.

> all you need is a trusted image I bet you, that image will be provided by the trustworthy people from NSO, free of charge or at a price! Whatever makes you trust their image. IMHO devices should be root-able but with high barriers of entry, something like soldering should be involved. If you are after doing something that you don't understand but a stranger on the internet told you to do it you shouldn't be able to…

So according to you Linux is compromised?

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#40
post #23
post #7

I have seen some manuals were released and some tools reverse engineered. What is currently the best link for a deep technical overview of how these tools work/worked?

As I did not get any replies I share what I found. If anybody has better or more detailed resources, please be kind and feed our curious minds: "Technical Analysis of Pegasus Spyware" https://info.lookout.com/rs/051-ESQ-475/images/lookout-pegas... "Pegasus Spyware" https://en.wikipedia.org/wiki/Pegasus_(spyware) "The Million Dollar Dissident" https://citizenlab.ca/2016/08/million-dollar-dissident-iphon...

Taki taki, beratna!
Post reply on HN