Live data from Hacker News

Pegasus spyware found on journalists’ phones, French intelligence confirms

theguardian.com

41–50 of 101 posts

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#41
post #37

Earlier quoted context omitted.

> all you need is a trusted image I bet you, that image will be provided by the trustworthy people from NSO, free of charge or at a price! Whatever makes you trust their image. IMHO devices should be root-able but with high barriers of entry, something like soldering should be involved. If you are after doing something that you don't understand but a stranger on the internet told you to do it you shouldn't be able to…

So according to you Linux is compromised?

The point is, you wouldn't know unless you have complete understanding on every aspect of your device and every bit of the software.

Nobody would be installing a Linux kernel and use the phone like that, they would be installing a distro. There are so many vectors of attack, the person who puts the distro together doesn't need to have malicious intent, the supply chain could be compromised.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#43

Is there no regulatory or compliance requirements for surveillance software? Instead of blaming the victims of pegasus, we should focus our attention on the lack of actions from key policymakers and regulatory bodies. It is not possible for every individual to be a technical expert when it comes to malware removal, but we can reduce the likelihood of misusing surveillance software by creating an ethical framework aro…

> Is there no regulatory or compliance requirements for surveillance software?

Nope! It's not even clear if Pegasus and its employees broke any laws. (Though I would love to see CFAA and copyright law tested against this.) Optimistically, this might be the wake-up call to change that.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#44
post #34

Slight OT: the malware indicators of compromise that Amnesty International released have no license, thereby prohibiting use in other projects as far as I understand. https://github.com/AmnestyTech/investigations/issues/11 If anyone can help on that front it'd be much appreciated.

IANAL but arguably, those indicator files are merely lists of information, and therefore are not subject to copyright. They are not, on their own, a creative work.

https://www.nolo.com/legal-encyclopedia/types-databases-that...

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#45
post #37

Earlier quoted context omitted.

> all you need is a trusted image I bet you, that image will be provided by the trustworthy people from NSO, free of charge or at a price! Whatever makes you trust their image. IMHO devices should be root-able but with high barriers of entry, something like soldering should be involved. If you are after doing something that you don't understand but a stranger on the internet told you to do it you shouldn't be able to…

So according to you Linux is compromised?

You know, it's getting so big and warty that I'd be surprised if it wasn't.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#46
post #42

but remember, NSO is just doing the dirty work that needs to be done /s They're knowingly selling to untrustworthy organizations knowing they'll be used for criminal purposes. They're criminals, and should be treated as such.

Yeah. They are like unlicensed gun sellers who have a surprised pikachu face when that gun turns up in a murder investigation.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#47
post #37

Earlier quoted context omitted.

> all you need is a trusted image I bet you, that image will be provided by the trustworthy people from NSO, free of charge or at a price! Whatever makes you trust their image. IMHO devices should be root-able but with high barriers of entry, something like soldering should be involved. If you are after doing something that you don't understand but a stranger on the internet told you to do it you shouldn't be able to…

So according to you Linux is compromised?

Probably not intentionally, but there are likely a bunch of 0-day exploits we don’t know about.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#48
post #23

Earlier quoted context omitted.

As I did not get any replies I share what I found. If anybody has better or more detailed resources, please be kind and feed our curious minds: "Technical Analysis of Pegasus Spyware" https://info.lookout.com/rs/051-ESQ-475/images/lookout-pegas... "Pegasus Spyware" https://en.wikipedia.org/wiki/Pegasus_(spyware) "The Million Dollar Dissident" https://citizenlab.ca/2016/08/million-dollar-dissident-iphon...

Taki taki, beratna!

Im ta nating!

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#50
post #13

Earlier quoted context omitted.

If you could safely (on the hardware level) replace image of the phone with another, it would be easy to guarantee that you can get a rootkit-free phone - all you need is a trusted image.

The Pegasus thing didn't even survive a reboot, it was reinstalled by using the 0-day again on a fresh boot. Replacing the image would have done nothing if they were flashing a version that still had the iMessage vulnerability.

But if that imessage vulnerability was FOSS and you could flash your own image, you could fix it and move on with your life.
Post reply on HN