Live data from Hacker News

Pegasus spyware found on journalists’ phones, French intelligence confirms

theguardian.com

71–80 of 101 posts

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#71
post #62

Earlier quoted context omitted.

But if that imessage vulnerability was FOSS and you could flash your own image, you could fix it and move on with your life.

its not like there are no security vulnerabilities in FOSS apps either

No, but when they appear, _you can fix them_.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#72
post #55
post #12

Earlier quoted context omitted.

And the same invariable lie is always used, "oh, don't worry, we're only going to use this against the bad guys". Bad guys only exist in a world without nuance.

bad guy is a just not a term that should be trusted when coming from politicians at this point. "bad" is an opinion in the sports of politics and power, because they are worried about their own hind end, not that of the state at large.

Exactly. 'Bad' and 'terrorist' is just the word play decision of some politician who surely does not have your best interest at heart.

People are really getting fed up with being lied to on a constant, grand scale.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#73
post #58

Earlier quoted context omitted.

But if that imessage vulnerability was FOSS and you could flash your own image, you could fix it and move on with your life.

>But if that imessage vulnerability was FOSS and you could flash your own image 1. the vulnerability wasn't FOSS. It was kept under wraps because otherwise it would get discovered and apple would patch it 2. what makes you think that amateurs working in their free time can patch 0days faster than the vendors themselves?

It's not yet even possibly to reliably detect the infection because of the closed nature of the device.

I think I'd like to check my iPhone, but I can't reliably do that.

So that, for a start, would help.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#74
post #58

Earlier quoted context omitted.

>But if that imessage vulnerability was FOSS and you could flash your own image 1. the vulnerability wasn't FOSS. It was kept under wraps because otherwise it would get discovered and apple would patch it 2. what makes you think that amateurs working in their free time can patch 0days faster than the vendors themselves?

It's not yet even possibly to reliably detect the infection because of the closed nature of the device. I think I'd like to check my iPhone, but I can't reliably do that. So that, for a start, would help.

>I think I'd like to check my iPhone, but I can't reliably do that.

but you can, via itunes backup.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#77
post #69
post #60

Earlier quoted context omitted.

On the flip side, having a monoculture is good because you made more eyes looking at the same piece of code.

How many people have seen the iMessage source code? A handful of devs at Apple? Closed, proprietary software by definition prevents "more eyes" from looking. Even if we consider an open source product where having "many eyes" review the code is at least hypothetically possible, a large number of people using the software doesn't imply there is also a large amount of people reviewing it.

>Closed, proprietary software by definition prevents "more eyes" from looking

But we were talking about the general case of monoculture, not closed source monoculture. Even for closed source software, where more eyes are prevented from looking "by definition", having a monoculture can in theory allow more code audits to be done, because of economy of scale.

> large number of people using the software doesn't imply there is also a large amount of people reviewing it.

Right, but roughly speaking, the number of reviewers should monotonically increase given an increase in users. Whether that produces better security overall is anyone's guess. My point was just that there was a counteracting force to consider.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#78

Earlier quoted context omitted.

It's pretty much what we have in China now.

To the positive spin for China, they tend to target only their fellow citizens and have some internal coherency and moral. NSO is an Israeli national problem that sells the spying capabilities to the highest bidding crook dictator around the world.

> To the positive spin for China, they tend to target only their fellow citizens and have some internal coherency and moral.

This is a terribly disturbing comment to me, who cares that they "tend to only target their citizens?"

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#79
post #62

Earlier quoted context omitted.

its not like there are no security vulnerabilities in FOSS apps either

No, but when they appear, _you can fix them_.

Are there actual hard numbers on whether open-to-all-eyes is beneficial at all scales?

For example, do public eyes actually catch and did more Linux bugs than three letter agencies? And would this situation be worse if Linux were a very well funded, closed source Windows?

I’m ignorant on whether the open source security mantra is founded upon religion or evidence.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#80

Earlier quoted context omitted.

To the positive spin for China, they tend to target only their fellow citizens and have some internal coherency and moral. NSO is an Israeli national problem that sells the spying capabilities to the highest bidding crook dictator around the world.

> To the positive spin for China, they tend to target only their fellow citizens and have some internal coherency and moral. This is a terribly disturbing comment to me, who cares that they "tend to only target their citizens?"

[deleted]
Post reply on HN