Live data from Hacker News

NYT journalist hacked with Pegasus after reporting on previous hacking attempts

citizenlab.ca

151–160 of 330 posts

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#151
post #150

I really hope the blur on the picture ( https://citizenlab.ca/wp-content/uploads/2021/10/Hubbard-Ima... ) isn't hiding anything actually important because that can almost certainly be de-blurred with the right tooling.

Really? Seems blurred enough to me that even some sort of ML would spit out wrong characters.

Known font, known range of possible characters (almost certainly ascii), and probably several blurred characters in there that we know (like the t in attachment). If the blur is differentiable per-character, it's probably reversible.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#152

Earlier quoted context omitted.

They specified using a VOIP number, so there are no calls associated with the phone by the cellular service provider. Wouldn't the attacker need access to both the VOIP service, to obtain the IP address, and the cellular provider, to link the IP address to a device and obtain the location? If you add a VPN to the stack, the VOIP service doesn't know your IP (though I wonder if a VOIP service would work well through a…

So, now you have two problems. If you're making VOIP calls over a device that is itself connected to mobile networks ... you've still got the connectivity of the device itself to track. Presumably that's a long-lived relationship. At this point the information is limited to location data, but that, at the postal-code level is again sufficient to identify 90% of individuals within the US, based largely on residential…

Thanks ... To emphasize a point that you seem to imply, the goal of security is to raise the costs of the attacker; anything can be defeated, of course.

If by "two problems" you mean that VOIP adds an additional problem, I don't quite grok it. It isn't a panacea, as you point out, but seems like a clear improvement.

Another advantage of VOIP is that you can easily obtain throwaway phone numbers.

> If you're making VOIP calls over a device that is itself connected to mobile networks ... you've still got the connectivity of the device itself to track. Presumably that's a long-lived relationship. At this point the information is limited to location data, but that, at the postal-code level is again sufficient to identify 90% of individuals within the US, based largely on residential and workplace locations.

Good point. They still don't know who I talk to and when, but they certainly can figure out who I am. I wonder how expensive the latter is, which I'd guess it depends on whether that analysis and the sharing of it is done automatically or takes a special request.

> The tether is connected over WiFi

I'm not sure that helps privacy: Wifi networks are likely shorter range than 5G cells, and the networks are well mapped. I suppose it does require involvement of someone with the map, but that might be easy to obtain.

> the MAC address space is already repetitive, and MAC addresses can be arbitrarily changed at the OS kernel level

I think iOS and Android randomize MAC addresses these days ?

> Burner phones on a one-use / short-use cycle would probably be preferable.

Yes, but a single burner phone, between the hardware and a one month plan, can cost $75-100. Using lots of them is out of reach for many people.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#153

Earlier quoted context omitted.

He was arrested in 2019 so your “over a decade” claim is demonstrably wrong. Could you point to amnesty international claiming belmarsh is torture?

His confinement to the Embassy of Equador since 2010 amply qualify as both imprisonment and torture [0]. If you like to argue that it does not literally qualify then I suggest you don't in the interest of not wasting everybody's time. [0] https://www.bbc.com/news/world-48473898

>His confinement to the Embassy of Equador since 2010

Assange, as a bail jumper and fugitive, requested and received asylum from Ecuador.

He could have, at any time, left the Ecuadorian embassy. In fact, had he done so, he'd likely have been investigated, prosecuted and potentially convicted of the charges against him.

Had that come to pass, it's entirely likely that Assange would have completed any sentence of incarceration years ago and have been back to banging Swedish girls for quite a while.

As we'll see, Assange might be convicted of violating the Computer Fraud and Abuse Act[0] which, under these specific circumstances (n.b.: IANAL) would carry a sentence of not more than five years, with the opportunity to reduce that sentence[1] by more than six months, assuming he is not given parole.

As to the completely bogus "charges" of violating the Espionage Act of 1917[2], no journalist has ever been convicted under that law.

As such, had Assange not decided for himself to jump bail and become a fugitive, he would most likely have been a free man for at least several years right now.

[0] https://www.law.cornell.edu/uscode/text/18/1030

[1] https://www.carmichaellegal.com/federal-sentencing-reduction...

[2] https://en.wikipedia.org/wiki/Espionage_Act_of_1917

Edit: Fixed typo. I need to do better proofreading before I post. :(

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#154

Earlier quoted context omitted.

> I'm English ... and Welsh, Cornish, Scottish and tangentially Irish, not to mention German (check my username). Sorry, but this is absolutely nonsensical to me, how can you be all these nationalities? Were you born on the most insane round trip flight ever or what? Edit: And sorry, as a Scot (One actually born there); 'the country' is not called 'Great Britain'. As a nationality we group identify as both $member-co…

We are called Great Britain because that is what James VI (I in England) called us when Scotland and England finally merged into Great Britain. He was our first joint King. The other Britain is Brittany - https://en.wikipedia.org/wiki/Brittany . Have a look at the county names in Brittany and see if they look suspiciously like Devon and Cornwall. My family/surname is Gerdes. In Scotland, that is rendered as Girders.…

Sorry but: https://en.wikipedia.org/wiki/Great_Britain GB is the island. It has fuck all to do with France.

Edit: sigh, okay you are a little bit right, but besides of course the settling after the whole Gallic period, and the Brittons, the Normans, and the Saxons -- please, forget all that we are talking about the term GB right now and this only refers to the island.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#155
post #150

I really hope the blur on the picture ( https://citizenlab.ca/wp-content/uploads/2021/10/Hubbard-Ima... ) isn't hiding anything actually important because that can almost certainly be de-blurred with the right tooling.

Really? Seems blurred enough to me that even some sort of ML would spit out wrong characters.

Not at all, I can already make out the characters and recognized quickly that all but the last 4 blurred characters are hexadecimal and the last appear to be [a-z][A-Z]

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#156
My security researcher buddy at Apple responsible for investigating this vulnerability told me that the hack is very complex; Apple couldn't even fully figure it out before pushing patches; the patches do not fix all the known bugs used in the vulnerability; the attackers most likely have access to Apple internal source code as well. They are very thankful for Citizen Lab without which the bugs wouldn't have been discovered. Also, there are likely many more compromised phones out there and Apple is kind of scratching their heads on how to fix, or even detect it. How do you fix a vulnerability that's secret and that no one knows is actively exploited?

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#157

Earlier quoted context omitted.

The government’s ability to prevent software distribution is limited significantly by the first amendment. Selling “a tool for hacking” is fine, selling “a tool for committing crime” would be illegal, but that distinction just comes down to picking the right marketing copy. The government can however restrict the import and export of software quite broadly. This is not legal advice, obviously.

>The government’s ability to prevent software distribution is limited significantly by the first amendment. Selling “a tool for hacking” is fine, selling “a tool for committing crime” would be illegal, but that distinction just comes down to picking the right marketing copy. The government can however restrict the import and export of software quite broadly. An interesting point. Given the vendor and customers for NS…

The sales pitch is basically the only thing that can make it illegal, because it’s illegal to knowingly do anything for the purpose of assisting somebody else commit a crime. That’s why it would be illegal to have a “burglary tools” section at a hardware store, even if they only difference between that and any other hardware store is words on a sign.

Even with regards the restricting import, the government is largely limited to sanctioning particular actors involved in the transaction.

I’m really a bit surprised that this isn’t more widely understood on HN. Anybody who operated a web server in the 90s is likely to know about Bernstein vs DoJ, and even if you operate one today you’re still likely to encounter the idea of an “export cipher”.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#158

Earlier quoted context omitted.

> So how do we protect our privacy from the advance of technology? It doesn't seem possible. Just going after NSO is useless. Like we do with anything else: These are crimes, but we are stuck in the mindset of the nascent Internet, when it was a growing experiment, a subculture in our society, harmless, and we wanted to nurture it and give it maximum freedom. Those days are long gone. The Internet is completely integ…

Why a new agency? This is already very much within the FBI’s jurisdiction. Why is the international surveillance of U.S. journalists and their sources not visibly a priority? In my opinion it’s a matter of policy. This comes from the top down. Bringing justice to international actors opposing democratic ethics is regrettably less of a priority today than enforcing highly publicized and politicized criminal cases.

IIRC, within the FBI’s jurisdiction and international don't go together. Isn't the FBI restricted to operating nationally only?

But to answer your question more fully, you can't solve this problem without supranational cooperation. A "police force" working to safeguard the Internet would have to work under authority of the UN, not any single nation.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#159
post #143

Earlier quoted context omitted.

> We live in a post-privacy world because Apple and Google happily pass your data back to world governments in the name of stopping terrorism, or whatever the social cause du-jour is. To illustrate this point, Apple gives up users' data for about 150,000 users/accounts in the US[1] a year in response to government data requests. [1] https://www.apple.com/legal/transparency/us.html

What can a company do when presented with a legal, legitimate warrant? We talk like Apple in this example has a choice to say “no”: they don’t, though.

The company shouldn't have your plaintext data in the first place.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#160
post #22

Forget Y Combinator -- come build the next great surveillance start-up at the IDF's Unit 8200, the world's greatest hacker school and incubator for mass surveillance start-ups. With generous subsidies from US taxpayers, Unit 8200 lets you level up your surveillance game by practicing on 4.5 million Palestinian beta-testers. (Go nuts, it's not like they can sue you!) Plus, say goodbye to those moral qualms -- at 8200,…

8200 has many alumni including many security products, including those protesting about the treatment of Palestinians This is despite being members of the IDF https://www.richardsilverstein.com/2014/09/12/israels-nsa-st...

[deleted]
Post reply on HN