Forget Y Combinator -- come build the next great surveillance start-up at the IDF's Unit 8200, the world's greatest hacker school and incubator for mass surveillance start-ups. With generous subsidies from US taxpayers, Unit 8200 lets you level up your surveillance game by practicing on 4.5 million Palestinian beta-testers. (Go nuts, it's not like they can sue you!) Plus, say goodbye to those moral qualms -- at 8200,…
NYT journalist hacked with Pegasus after reporting on previous hacking attempts
201–210 of 330 posts
Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts
#202So how do we protect our privacy from the advance of technology? It doesn't seem possible. Just going after NSO is useless.
It depends on what your threat model is. If its individuals, local law enforcement, or even national law enforcement (context dependent) you are trying to hide from, you can obtain phones with cash and make it very difficult to link them to you (use a sim card bought with cash and never give out that number, use a VOIP service for your primary number, use an OS that doesn't send back much telemetry, turn off location…
Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts
#203Earlier quoted context omitted.
The company shouldn't have your plaintext data in the first place.
No company should, but we don't live in that world (for a number of reasons), and if they do then they must follow instructions given by the government via warrants. One of the issues I have is that those warrants are rubber-stamped out. We should change how the judiciary approaches that, raise the bar law enforcement has to meet to be able to request that data, while also encouraging the use of encryption at every l…
The sentiment towards Apple is just disappointment today. Their 'ecosystem' approach has had detrimental effects on the consumer electronics market, and has given them a frightening amount of power over the flow of information. Apple's treatment has been generally irresponsible, though: they do nothing to assuage the general public of what's running in their OSes, rather choosing to occasionally throw out unverifiable whitepapers of how these systems might work, but we've got no way to verify that. For a company that claims 'privacy is a human right', I was really hoping to dig into something more profound.
The biggest issue is that we're taking Apple at face-value. They're documented liars, and their insistence on being right contrasts with their tacit rejection of transparency. They operate without accountability, and the only people keeping them in check have a mutual interest in creating a monopoly. Their factories are staffed by political prisoners, and they're the only FAANG company who's comfortable operating in China's homeland. It's crazy how people forget this with nothing more than a little marketing and some diversity in their iPhone commercial.
I expect better from a company with more money in the world than anyone else. But maybe this is yet another reminder that shareholders don't care about your security, privacy or peace-of-mind.
Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts
#204Earlier quoted context omitted.
No, most are zero-click silent exploits. They own your phone persistently then delete the incoming message that pwned you.
Are other messaging apps on iOS ever getting RCE exploits like this? Can’t they sandbox iMessage so this isn’t possible no matter how many bugs the app has?
Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts
#205So how do we protect our privacy from the advance of technology? It doesn't seem possible. Just going after NSO is useless.
> So how do we protect our privacy from the advance of technology? It doesn't seem possible. Just going after NSO is useless. Like we do with anything else: These are crimes, but we are stuck in the mindset of the nascent Internet, when it was a growing experiment, a subculture in our society, harmless, and we wanted to nurture it and give it maximum freedom. Those days are long gone. The Internet is completely integ…
Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts
#206I really hope the blur on the picture ( https://citizenlab.ca/wp-content/uploads/2021/10/Hubbard-Ima... ) isn't hiding anything actually important because that can almost certainly be de-blurred with the right tooling.
man why do people even take the gamble of using a blur just use a opaque box
Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts
#207Earlier quoted context omitted.
This is a COVID trend. They still provide physical copy on request.
This is the only thing that makes sense. What if your battery is dead? Not having access to the menu would be ridiculous.
You're not wrong that this fundamentally excludes those who don't have (powered-up) smartphones. But it's not like restaurants and bars had the luxury of thinking through and choosing to have these effective new smartphone requirements: they adapted to Covid for their survival, and the odd case who got unlucky with a dead phone is just collateral damage.
Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts
#208Earlier quoted context omitted.
Known font, known range of possible characters (almost certainly ascii), and probably several blurred characters in there that we know (like the t in attachment). If the blur is differentiable per-character, it's probably reversible.
Even without automation. Just make a list of blurred alphanumerics, then match every blurred character in the picture against the character list. with some patience probably doable in a single day
Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts
#209Earlier quoted context omitted.
No, most are zero-click silent exploits. They own your phone persistently then delete the incoming message that pwned you.
> zero-click Literally worth millions of dollars on the wholesome greymarkets these days, possibly the most prized, just in case anyone was wondering.
Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts
#210Earlier quoted context omitted.
> So how do we protect our privacy from the advance of technology? It doesn't seem possible. Just going after NSO is useless. Like we do with anything else: These are crimes, but we are stuck in the mindset of the nascent Internet, when it was a growing experiment, a subculture in our society, harmless, and we wanted to nurture it and give it maximum freedom. Those days are long gone. The Internet is completely integ…
You forget that the internet is post nationalism. Borders no longer exist and your domestic agency limited to the USA would be worthless. Or worse, serve as a pawn in the hands of Big Tech.