Live data from Hacker News

NYT journalist hacked with Pegasus after reporting on previous hacking attempts

citizenlab.ca

171–180 of 330 posts

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#171
post #158

Earlier quoted context omitted.

Why a new agency? This is already very much within the FBI’s jurisdiction. Why is the international surveillance of U.S. journalists and their sources not visibly a priority? In my opinion it’s a matter of policy. This comes from the top down. Bringing justice to international actors opposing democratic ethics is regrettably less of a priority today than enforcing highly publicized and politicized criminal cases.

IIRC, within the FBI’s jurisdiction and international don't go together. Isn't the FBI restricted to operating nationally only? But to answer your question more fully, you can't solve this problem without supranational cooperation. A "police force" working to safeguard the Internet would have to work under authority of the UN, not any single nation.

The UN isn't a government; it has no real legal authority (international 'law' is something different), no law enforcement. It has no legitimacy - who elected them?

It's an association of governments, where they get together and organize things. All the power is in the individual governments. There are some grey areas and exceptions, but overwhelmingly the above is the case.

The UN could coordinate cybercrime law and national agencies.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#172

Earlier quoted context omitted.

So, now you have two problems. If you're making VOIP calls over a device that is itself connected to mobile networks ... you've still got the connectivity of the device itself to track. Presumably that's a long-lived relationship. At this point the information is limited to location data, but that, at the postal-code level is again sufficient to identify 90% of individuals within the US, based largely on residential…

Thanks ... To emphasize a point that you seem to imply, the goal of security is to raise the costs of the attacker; anything can be defeated, of course. If by "two problems" you mean that VOIP adds an additional problem, I don't quite grok it. It isn't a panacea, as you point out, but seems like a clear improvement. Another advantage of VOIP is that you can easily obtain throwaway phone numbers. > If you're making VO…

The "two problems" is an additional attack surface --- the cellular network tether, which by design and function leaks subscriber-linked information without any compromise necessary, and the VOIP device itself, which continues to be susceptible to its own attacks leaking information, including contacts, call data, messaging data and metadata, email, browser history, and its own location history through both WiFi connections and in all probability, GPS-based location.

On connecting to the tether over WiFi, the advantages over cellular data or Bluetooth is that a WiFi identity (MAC address, SSID) can be arbitrarily changed, and in fact are in consumer-grade hardware (yes, iOS uses a distinct MAC per connected network AFAIU, not positive of Android). This could be modified on every network connection, or even within a single session (requiring periodic reconnects). Other means of specific host identification via TCP/IP and 802.11 protocols are fairly limited.

On increasing workload, much surveillance is done via mass-produced hardware and software, and targets frequently-encountered devices (e.g., stock mobile phones, iOS, and Android systems). Adopting measures and methods other than these ... leaves a signature, but also means that specific new surveillance methods need to be devised for a specific target.

Also: in case anyone mistakes me for an expert on this area, I'm not. I've general familiarity with methods, techniques, protocols, devices, and operating systems.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#173

I really hope the blur on the picture ( https://citizenlab.ca/wp-content/uploads/2021/10/Hubbard-Ima... ) isn't hiding anything actually important because that can almost certainly be de-blurred with the right tooling.

man why do people even take the gamble of using a blur just use a opaque box

A certain subset of hackers have had a Gaussian-blur fetish for half a decade now, at least.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#174

Earlier quoted context omitted.

Many restaurants only provide menus via smartphones. Sporting events only accept electronic tickets. How can you reject it, practically?

By going to restaurants with proper service (if at all) and not going to sporting events.

Not practical for 99.99% of the population.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#175
post #158

Earlier quoted context omitted.

Why a new agency? This is already very much within the FBI’s jurisdiction. Why is the international surveillance of U.S. journalists and their sources not visibly a priority? In my opinion it’s a matter of policy. This comes from the top down. Bringing justice to international actors opposing democratic ethics is regrettably less of a priority today than enforcing highly publicized and politicized criminal cases.

IIRC, within the FBI’s jurisdiction and international don't go together. Isn't the FBI restricted to operating nationally only? But to answer your question more fully, you can't solve this problem without supranational cooperation. A "police force" working to safeguard the Internet would have to work under authority of the UN, not any single nation.

There is INTERPOL

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#176
post #132

Earlier quoted context omitted.

Since this is an international issue and there's no global "legality", the effect is that locations matter a lot. Presumably, the hacking was done by Saudi authorities from SA, using NSO-developed tools. Citizenship of the target is not very relevant, but it does matter where "the event" happened. If the reporter was in Saudi Arabia when the hack happened, then Saudi laws apply and essentially Saudi government gets t…

There are allegations that the NSO Group doesn't provide the 0days they're using to their customers, so they are in fact performing the intrusions themselves.

sounds like they should be treated like mercenaries.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#177

I really hope the blur on the picture ( https://citizenlab.ca/wp-content/uploads/2021/10/Hubbard-Ima... ) isn't hiding anything actually important because that can almost certainly be de-blurred with the right tooling.

Those strings in the center look like UUIDs.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#179
post #159
post #143

Earlier quoted context omitted.

What can a company do when presented with a legal, legitimate warrant? We talk like Apple in this example has a choice to say “no”: they don’t, though.

The company shouldn't have your plaintext data in the first place.

No company should, but we don't live in that world (for a number of reasons), and if they do then they must follow instructions given by the government via warrants.

One of the issues I have is that those warrants are rubber-stamped out. We should change how the judiciary approaches that, raise the bar law enforcement has to meet to be able to request that data, while also encouraging the use of encryption at every level.

Until we make those changes (which I'm of the opinion the wider society does not have an appetite for the legal and usability trade-offs that come with the even if I personally do), I guess I'm confused by what we're demanding when we point out that a company based in the US cooperates with valid legal requests from the US government.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#180

Do these types of iMessage attachment exploits require the victim to do anything on their end? Downloading the attachment? Opening the message ? That part is unclear to me

No, most are zero-click silent exploits. They own your phone persistently then delete the incoming message that pwned you.
Post reply on HN