Live data from Hacker News

NYT journalist hacked with Pegasus after reporting on previous hacking attempts

citizenlab.ca

211–220 of 330 posts

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#211

Earlier quoted context omitted.

they need an actual functional phone. You can't be a journalist and not have a fully functional phone that access the internet whenever needed. I'm sure they use burners for sensitive stuff, but what are they supposed to use for their regular work, calls with the school, car navigation, ...

There are portable hotspots, you know.... I am assuming you use a killswitch VPN to your trusted network. NYT for this journalist. My proposed setup is 3 devices: hotspot, android device without baseband, dumbphone. Hotspot would be the weak link here, security wise, but is easier and cheaper to replace. Nothing on dumbphone would be encrypted. If I were a journalist, I would consider this alternative to being hacked…

iMessage can run over data, right? It sounds like the bugs exploited here were iMessage and WhatsApp holes, not weird mystery-baseband flaws (which are harder to patch but only ever affect a fraction of the phones you want to sell the ability to compromise). So similar Android exploits would just go right through the hotspot and compromise the Android device that does everything.

The only way out of this mess is actually correct code on actually correct hardware. Maybe you have to run Linux and Android at the top to run existing apps, but somewhere below there you need a supervisor that makes security guarantees that are actually true. You can't just port a monolithic C kernel onto hardware that's struggling to be faster than the competition and call it good.

Journalists need to buy communications equipment that doesn't come with that "NO WARRANTY OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE" line in the EULA. Sadly, it is not for sale.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#212

So how do we protect our privacy from the advance of technology? It doesn't seem possible. Just going after NSO is useless.

It depends on what your threat model is. If its individuals, local law enforcement, or even national law enforcement (context dependent) you are trying to hide from, you can obtain phones with cash and make it very difficult to link them to you (use a sim card bought with cash and never give out that number, use a VOIP service for your primary number, use an OS that doesn't send back much telemetry, turn off location…

> use a sim card bought with cash

Varies by country I’m sure, but I was surprised how difficult it was to buy a SIM in Indonesia and Malaysia without an ID. Even little shops wanted an ID or passport number to type in to activate it.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#213

I really hope the blur on the picture ( https://citizenlab.ca/wp-content/uploads/2021/10/Hubbard-Ima... ) isn't hiding anything actually important because that can almost certainly be de-blurred with the right tooling.

man why do people even take the gamble of using a blur just use a opaque box

Opaque boxes have been issues before, when they end up being "semi-transparent" and you can up the brightness to beat them.

Safest is probably just to cut/crop the sensitive bits out.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#214

Earlier quoted context omitted.

Not all, but many restaurants in multiple cities. They use QR codes, no doubt to identify you better (tie you to a specific place and time, maybe to a specific table). Usually I just load the restaurant's website on my phone and read the menu that way. I was also at a play where a QR code was the only way to get the program.

What exactly are you suggesting the QR code is doing? My phone shows me the URL encoded by the QR code before opening, and I've never seen one with any additional information in the URL. They're not dynamically generating QR codes for you...

The static URL encoded by the QR code funnels you to a web page where that page view can be reported back to trackers and incorporated into your advertising profile.

Using your device to read the menu puts your device in the loop where formerly it was not.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#215

I really hope the blur on the picture ( https://citizenlab.ca/wp-content/uploads/2021/10/Hubbard-Ima... ) isn't hiding anything actually important because that can almost certainly be de-blurred with the right tooling.

> I really hope the blur on the picture (https://citizenlab.ca/wp-content/uploads/2021/10/Hubbard-Ima...) isn't hiding anything actually important because that can almost certainly be de-blurred with the right tooling.

Yeah, the right way to use blurring is to mockup a lookalike for content you want to hide, then blur the mockup.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#216

Earlier quoted context omitted.

> zero-click Literally worth millions of dollars on the wholesome greymarkets these days, possibly the most prized, just in case anyone was wondering.

How so?

You don’t need any input from the user/target. Once the malicious code reaches the device the exploit works its magic.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#217
post #12

It would seem to be the rational thing for NSO to hack a journalist who is writing on them, so that they better prepare for what’s coming. As for all the countries that buy and use NSO, to target and kill journalists, they are all close all allies of the US and Israel. And the US and England were also spying on the journalist Julian Assange, and have kept him in prison and tortured him for over a decade. Ben Hubbard…

> the US and England were also spying on the journalist Julian Assange, and have kept him in prison and tortured him for over a decade. Ben Hubbard luckily just got hacked. As you probably know, these assertions are a big stretch for many people. Not everyone considers Assange a journalist. He was living in an embassy for most of those years, so while he was confined, it's not a prison and not torture. Hubbard isn't…

> so while he was confined, it's not a prison and not torture

Did he have freedom to leave the embassy and go somewhere else, if not then it is a form of torture.

CIA also considered killing him.

https://www.theguardian.com/media/2021/sep/27/senior-cia-off...

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#218

I really hope the blur on the picture ( https://citizenlab.ca/wp-content/uploads/2021/10/Hubbard-Ima... ) isn't hiding anything actually important because that can almost certainly be de-blurred with the right tooling.

> I really hope the blur on the picture ( https://citizenlab.ca/wp-content/uploads/2021/10/Hubbard-Ima ...) isn't hiding anything actually important because that can almost certainly be de-blurred with the right tooling. Yeah, the right way to use blurring is to mockup a lookalike for content you want to hide, then blur the mockup.

You don't even need this. I searched "unblur" in Google Play Store, downloaded the first result, tweaked the settings a touch, and I could make out the characters. The whole process took a couple minutes. If the data actually needs to be hidden, this picture should be taken down.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#219

Earlier quoted context omitted.

> zero-click Literally worth millions of dollars on the wholesome greymarkets these days, possibly the most prized, just in case anyone was wondering.

How so?

Governments want them, companies that use them and package to sell to governments will pay you the millions.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#220

I really hope the blur on the picture ( https://citizenlab.ca/wp-content/uploads/2021/10/Hubbard-Ima... ) isn't hiding anything actually important because that can almost certainly be de-blurred with the right tooling.

> I really hope the blur on the picture ( https://citizenlab.ca/wp-content/uploads/2021/10/Hubbard-Ima ...) isn't hiding anything actually important because that can almost certainly be de-blurred with the right tooling. Yeah, the right way to use blurring is to mockup a lookalike for content you want to hide, then blur the mockup.

I just go solid opaque bar. Way easier to do and harder to screw up.
Post reply on HN