Live data from Hacker News

NYT journalist hacked with Pegasus after reporting on previous hacking attempts

citizenlab.ca

191–200 of 330 posts

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#191
It should be explained to public how such exploit take place, with open sourcing necessary parts. Otherwise there is no way for us to know it wasn't intentional at first place. I am not meaning there is a possibility like Apple as a company decides to put exploits. However governments can easily do it with single engineer at right place.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#192
post #131

Earlier quoted context omitted.

I have never eaten in such a restaurant and I eat out a lot. Is this really true where you are? No menus?

This is a COVID trend. They still provide physical copy on request.

This is the only thing that makes sense. What if your battery is dead? Not having access to the menu would be ridiculous.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#193

Earlier quoted context omitted.

no they are not, targeted attack of someone who is capable of using Pegasus is going to be successful regardless a consumer device u choose to use.

"No they are not?" I deserved more than that. Iphones are a standardized attack surface. Apple prefers vulnerabilities not to be found than to be discovered and patched, leading to NSO holding on their discovered vulnerabilities for longer. An android device with no modem (baseband) is definitely more secure. Throw in a hardware switch for camera, mics, and wifi, which iphones will never have.

Android is an even larger attack surface when political people don't take any of the precautions you mention, which they most likely won't. The President of the United States does indeed have a specialized phone that is modified by WH staff to either be only for phone calls or only for twitter/news (which means 2 phones)[0], but they're still iPhones. As long as there's not some 0-authorization 0-click vulnerability in the things used (as in, reportedly, neither iphone did texts), it'll be secure enough, but that's still limiting its usage and isn't want any politician is going to do. Just stick to a desk phone for secure comms.

0: https://www.politico.com/story/2018/05/21/trump-phone-securi...

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#194

Earlier quoted context omitted.

Are other messaging apps on iOS ever getting RCE exploits like this? Can’t they sandbox iMessage so this isn’t possible no matter how many bugs the app has?

They actually did it with iOS 14 (named Blastdoor) but apparently it's not helping much. Considering how tightly integrated iMessage is with iOS, it doesn't seem likely that it will really be fixed in an easy manner.

Ironic that Apple limiting their apps in the same way they limit 3p apps would've likely solved this vulnerability, unless the attack was only "0-click access to full chat.db"

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#195
post #18

On the other hand, perhaps the hardware/OS designs of iOS and Android devices are fundamentally flawed, when viewed from a security-first perspective.

It's whwt that has really evolved into. We used to live in a much simpler (and secure in that manner) world where there were no smartphones, even GPRS didn't exist, all important communication were done on physical medium.

That became much more inconvenient as technology just progressed to a point where 99.9% of the society couldn't resist using the smartphone, rightly for many purposes, including many of us here too.

But as OSs (and even SoCs) became more complex as more features are added (well, I can't think of Apple or Samsung execs on stage saying "hey we didn't add any features this year" so it has to go this way naturally) flaws are inevitable.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#196
post #18

On the other hand, perhaps the hardware/OS designs of iOS and Android devices are fundamentally flawed, when viewed from a security-first perspective.

It depends what you mean by "security first". If you're a person of interest and you're carrying around a personal spy with actual data on it and a hardware connected microphone, camera, GPS, sensors etc, which sends God knows what over the internet then yes, it's not going to go well for you. But if you use devices with hardware kill switches and the most secure OS possible (storing nothing on device, perhaps it's a…

I think as long as secure computing isn't convenient enough for many people out there, these news will just rise in numbers.

There are likely many out there secure computing, and we don't hear the news about them because they don't get hacked.

But with the convenience of using smartphones and sending anything quickly over them using (insert your favorite messenger service) statistically many people will be using them, even for absurdly important/critical communication, and a small number of them will be hacked.

Services like WhatsApp/iMessage will just keep adding more features to stay feasible, and more people will be using the feasible services, with more features creating new attack surfaces inevitably.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#197

So, what is the legality of this? I've not followed much about this at all, but NSO group appears to be an Israeli company. Do they just sell, or operate the hacking software for their clients? If they operate it, is it illegal for an Israeli company to hack an American citizen (I assume it is illegal in America, but how about Israel?) Is the sale of hacking software regulated in any way?

US politics is bizarre. When Ben and Jerry's ice creams decided they wanted to close shop in some disputed territories in Israel many states (mostly Republican run) punished the parent company immediately to make an example of them and sold their holdings of its stock from the pension funds they were controlling.

Yet a company like NSO weaponizes and abuses all sorts of vulnerabilities they get their hands on and sell it to thugs around the world who then use it against Americans and the same politicians couldn't care less

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#198

So how do we protect our privacy from the advance of technology? It doesn't seem possible. Just going after NSO is useless.

Same way the mafia used to do it when they realized all their phones and cars were bugged. No technology. Talk in person, outside.

Seriously, if you are a journalist investigating anything that might upset the powers that be in a nation-state, don't use any online technology and for gods sake not a mobile phone.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#199
post #132

Earlier quoted context omitted.

There are allegations that the NSO Group doesn't provide the 0days they're using to their customers, so they are in fact performing the intrusions themselves.

sounds like they should be treated like mercenaries.

What exactly do you mean by "treated like mercenaries", what should be the treatment in your opinion ?

In general, countries do hire mercenaries/private military contractors/etc, and it is not considered anything special, and many powerful countries (including e.g. the USA) routinely use mercenaries in their campaigns. the "sending" nation may restrict their people and companies from mercenary actions abroad if they choose to, but if e.g. Israel is okay with their company hiring out as a "mercenary" (the term usually implies directly participating in a conflict while being armed and excludes any other support such as training, logistics, software, etc, but for the sake of argument let's assume it applies here) for Saudi Arabia then there would be nothing unusual about that - for example, Saudi Arabia has used thousands of mercenaries in Yemen.

If the specific individuals commit something that's a crime in USA then USA can try to put them on trial, but that works exactly the same no matter if they're Saudi citizens working Saudi government or serving in Saudi military, or foreigners contracted out to Saudi government as "mercenaries"; in both cases it's up to the local government whether they want to hand them over (effectively betraying their own "employees") or refuse.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#200
post #73

Earlier quoted context omitted.

Is “not wanting to work with surveillance” an example of a political opinion from the left, or from the right? It kinda just seems like a personal preference.

It’s entirely apolitical. I view it as entirely identical to a refusing to hire anyone who had been a chemist at a tobacco company.

What if you're a chemist at a tobacco company trying to make the cigarettes people are already addicted to more healthy?
Post reply on HN