Live data from Hacker News

Pegasus spyware found on journalists’ phones, French intelligence confirms

theguardian.com

61–70 of 101 posts

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#61
post #3
post #2

Ironically, users themselves are disallowed from rooting their phones. Right to root, is right to repair.

I'm all for having the right to repair. I'm not convinced any of the folks involved ability to root would prevent the situation described.

I think it would have, because the primary attack vector is your messaging app. Some Android phones, such as mine, are locked in such a way that this cannot be uninstalled. I can use another messaging app but this one will still run on my phone which means that it can still be exploited.

Unfortunately, the only way to secure my phone because it no longer receives updates is through rooting, but this phone is not a model that can be rooted so my plan is to buy a new phone and root that, and probably remove all text messaging apps or find a way to sandbox them in a secure environment.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#62

Earlier quoted context omitted.

The Pegasus thing didn't even survive a reboot, it was reinstalled by using the 0-day again on a fresh boot. Replacing the image would have done nothing if they were flashing a version that still had the iMessage vulnerability.

But if that imessage vulnerability was FOSS and you could flash your own image, you could fix it and move on with your life.

its not like there are no security vulnerabilities in FOSS apps either

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#64
post #36

Earlier quoted context omitted.

It would help because knowledgeable people would get to pick what software they run on their phones and iMessage probably wouldn't be on the list.

Journalists (as here) don't usually get to choose the communication software their sources are comfortable communicating over. They install whatever's required to get the story. And they likely wouldn't install an OS that doesn't let them install such apps.

That's a niche use case. You might not be able to choose what app they require to communicate over, but you can choose what device to install it onto, like a burner, couldn't you? Some apps you might not mind on your personal phone, others you probably do.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#66
post #56

Earlier quoted context omitted.

A depressing thought experiment a professor once posited many years ago....Hitler comes to power in the internet era and now has state of the art tools to find people of certain traits, vs manpower and spies to discover them. Ability to go through your entire lives digital footprint. Every picture. Every video you've created, or viewed on a website. Every location you've visited, how long you were there, and who was…

It's pretty much what we have in China now.

There are programmes doing this in the West as well.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#67
post #56

Earlier quoted context omitted.

A depressing thought experiment a professor once posited many years ago....Hitler comes to power in the internet era and now has state of the art tools to find people of certain traits, vs manpower and spies to discover them. Ability to go through your entire lives digital footprint. Every picture. Every video you've created, or viewed on a website. Every location you've visited, how long you were there, and who was…

It's pretty much what we have in China now.

To the positive spin for China, they tend to target only their fellow citizens and have some internal coherency and moral. NSO is an Israeli national problem that sells the spying capabilities to the highest bidding crook dictator around the world.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#68
post #64
post #36

Earlier quoted context omitted.

Journalists (as here) don't usually get to choose the communication software their sources are comfortable communicating over. They install whatever's required to get the story. And they likely wouldn't install an OS that doesn't let them install such apps.

That's a niche use case. You might not be able to choose what app they require to communicate over, but you can choose what device to install it onto, like a burner, couldn't you? Some apps you might not mind on your personal phone, others you probably do.

Well, yes, but if you think about it, the whole point of a journalist's work phone is just to aggregate a bunch of "burner" accounts. And that's exactly what an attacker would want to steal from a journalist: conversations between them and (or contact details of) another source.

Which is all to say, ideally a journalist would have N phones, one per source. But that's impractical.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#69
post #60
post #18

Earlier quoted context omitted.

It could help by simply being sufficiently different . The only reason this type of malware is such a widespread problem is the large monoculture of potential targets. Just like in agriculture (e.g. potatoes, bananas), a monoculture allows a single pathogen to affect an entire crop. In security this is a class break [1]. Utilizing different software implementations limits the scope of this type of attack. The current…

On the flip side, having a monoculture is good because you made more eyes looking at the same piece of code.

How many people have seen the iMessage source code? A handful of devs at Apple? Closed, proprietary software by definition prevents "more eyes" from looking. Even if we consider an open source product where having "many eyes" review the code is at least hypothetically possible, a large number of people using the software doesn't imply there is also a large amount of people reviewing it.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#70
post #3
post #2

Ironically, users themselves are disallowed from rooting their phones. Right to root, is right to repair.

I'm all for having the right to repair. I'm not convinced any of the folks involved ability to root would prevent the situation described.

If anything, it would likely make it worse, since you'd now have "convincing the user to install your payload", recreating the phishing problems of desktop platforms.
Post reply on HN