Live data from Hacker News

NYT journalist hacked with Pegasus after reporting on previous hacking attempts

citizenlab.ca

131–140 of 330 posts

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#131

Earlier quoted context omitted.

Rejecting the smartphone might be a start.

Many restaurants only provide menus via smartphones. Sporting events only accept electronic tickets. How can you reject it, practically?

I have never eaten in such a restaurant and I eat out a lot.

Is this really true where you are? No menus?

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#132

So, what is the legality of this? I've not followed much about this at all, but NSO group appears to be an Israeli company. Do they just sell, or operate the hacking software for their clients? If they operate it, is it illegal for an Israeli company to hack an American citizen (I assume it is illegal in America, but how about Israel?) Is the sale of hacking software regulated in any way?

Since this is an international issue and there's no global "legality", the effect is that locations matter a lot. Presumably, the hacking was done by Saudi authorities from SA, using NSO-developed tools. Citizenship of the target is not very relevant, but it does matter where "the event" happened. If the reporter was in Saudi Arabia when the hack happened, then Saudi laws apply and essentially Saudi government gets t…

There are allegations that the NSO Group doesn't provide the 0days they're using to their customers, so they are in fact performing the intrusions themselves.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#133

Earlier quoted context omitted.

Any phone's location and call history will effectively identify it. Location can be determine with sufficient accuracy for this purpose from cell-tower connections. More so as 5G, with its greater tower density and shorter range, is rolled out. (An actual 5G threat you can get behind.)

They specified using a VOIP number, so there are no calls associated with the phone by the cellular service provider. Wouldn't the attacker need access to both the VOIP service, to obtain the IP address, and the cellular provider, to link the IP address to a device and obtain the location? If you add a VPN to the stack, the VOIP service doesn't know your IP (though I wonder if a VOIP service would work well through a…

So, now you have two problems.

If you're making VOIP calls over a device that is itself connected to mobile networks ... you've still got the connectivity of the device itself to track. Presumably that's a long-lived relationship. At this point the information is limited to location data, but that, at the postal-code level is again sufficient to identify 90% of individuals within the US, based largely on residential and workplace locations.

The notion of having short-lived individually-attributable 5G connection history, perhaps through a dongle- or tether-swapping system, in which many individuals utilise devices for a short period of time, might work. With a sufficient budget, disposable devices might also be an option. (As the cost of SBCs / SOCs falls through $0.10/device, the disposable option might be tractable, leaving SIM card provisioning as the bottleneck.)

The tether is connected over WiFi (the MAC address space is already repetitive, and MAC addresses can be arbitrarily changed at the OS kernel level), giving a two-stage connection to the actual mobile network itself. Frequently-relocating (via a swap) or short-lived / previously unknon tethers, as identified through IMEI is required for mobile connections to work, would still be possible, but at a much greater workload. (I'm very sketch on how 5G identifies specific devices, take what I'm saying here with a few kilos of salt.)

I'd still have concerns with a VOIP device that itself has access to information and computing capabilities, but at least the degree of tracking that's possible over a PSTN direct-dialed mobile handset on a 4G/5G network would be sharply reduced. Other threat vectors remain.

Burner phones on a one-use / short-use cycle would probably be preferable.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#134

Why aren't political exposed persons leaving iphones? It has been known for a while that it is not secure for them. An android tablet connecting to wifi hotspots only, or even lan only, with minimal software, and a dumb phone are more secure than iphone.

no they are not, targeted attack of someone who is capable of using Pegasus is going to be successful regardless a consumer device u choose to use.

"No they are not?" I deserved more than that.

Iphones are a standardized attack surface. Apple prefers vulnerabilities not to be found than to be discovered and patched, leading to NSO holding on their discovered vulnerabilities for longer.

An android device with no modem (baseband) is definitely more secure. Throw in a hardware switch for camera, mics, and wifi, which iphones will never have.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#135
post #18

On the other hand, perhaps the hardware/OS designs of iOS and Android devices are fundamentally flawed, when viewed from a security-first perspective.

I wouldn't say so. The problem is the cyber warfare market created by nation states. If it wasn't for those large spenders, we wouldn't be where we are right now.

IMO nation states had a very negative influence on the internet, bringing secrecy, warfare, balkanized markets, mandatory identification and other closed concepts to a place that worked on open principles.

If states would invest more in security advancement and open research than in warfare, we might have been in a better position.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#136

So how do we protect our privacy from the advance of technology? It doesn't seem possible. Just going after NSO is useless.

> So how do we protect our privacy from the advance of technology? It doesn't seem possible. Just going after NSO is useless. Like we do with anything else: These are crimes, but we are stuck in the mindset of the nascent Internet, when it was a growing experiment, a subculture in our society, harmless, and we wanted to nurture it and give it maximum freedom. Those days are long gone. The Internet is completely integ…

Nothing bad has ever come from letting the government control more of the internet, right?

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#137

Earlier quoted context omitted.

I don't think you can escape the use of the smart phone. But treating them as "throw-away", as not your device, etc. I think the original landlines, which were/are a few switches connected to a write on one side and some microphones on the other, were close to inherently insecure. Phones haven't ever been "your device" whereas a laptop might, maybe be rendered trustworthy.

How can you possibly not escape the use of a smartphone?

Plenty of jobs these days essentially require one, be it for communication, authentication, or what have you.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#138
post #131

Earlier quoted context omitted.

Many restaurants only provide menus via smartphones. Sporting events only accept electronic tickets. How can you reject it, practically?

I have never eaten in such a restaurant and I eat out a lot. Is this really true where you are? No menus?

This is a COVID trend. They still provide physical copy on request.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#139

Earlier quoted context omitted.

I don't think you can escape the use of the smart phone. But treating them as "throw-away", as not your device, etc. I think the original landlines, which were/are a few switches connected to a write on one side and some microphones on the other, were close to inherently insecure. Phones haven't ever been "your device" whereas a laptop might, maybe be rendered trustworthy.

How can you possibly not escape the use of a smartphone?

I recently had to file an insurance claim with my car insurer. The entire process happened through their app. They require you to send them pictures that you took using their app.

One of my banks has been closing branches left and right, and if I want to use my accounts for anything other than debit purchases, I need to use the app. Some banks even charge you when you go to a branch location in person and use a teller to access your accounts.

Some jobs require you to install and use apps on your phone. Last time I was a big box retailer, the floor staff had the company's app installed on their phones so they could do instant price look ups and confirm discounts on their store's inventory.

Even just applying for a job requires an internet browser, and many people's only access to the internet is through their phone.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#140
post #131

Earlier quoted context omitted.

Many restaurants only provide menus via smartphones. Sporting events only accept electronic tickets. How can you reject it, practically?

I have never eaten in such a restaurant and I eat out a lot. Is this really true where you are? No menus?

Not all, but many restaurants in multiple cities. They use QR codes, no doubt to identify you better (tie you to a specific place and time, maybe to a specific table). Usually I just load the restaurant's website on my phone and read the menu that way.

I was also at a play where a QR code was the only way to get the program.

Post reply on HN