Live data from Hacker News

NYT journalist hacked with Pegasus after reporting on previous hacking attempts

citizenlab.ca

221–230 of 330 posts

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#222

Earlier quoted context omitted.

What exactly are you suggesting the QR code is doing? My phone shows me the URL encoded by the QR code before opening, and I've never seen one with any additional information in the URL. They're not dynamically generating QR codes for you...

The static URL encoded by the QR code funnels you to a web page where that page view can be reported back to trackers and incorporated into your advertising profile. Using your device to read the menu puts your device in the loop where formerly it was not.

Sure, if I suspend disbelief and assume that no other search engines or navigation services were used that do similar tracking—but the GP was specifically calling out QR codes, and they use the website anyway.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#224
post #158

Earlier quoted context omitted.

IIRC, within the FBI’s jurisdiction and international don't go together. Isn't the FBI restricted to operating nationally only? But to answer your question more fully, you can't solve this problem without supranational cooperation. A "police force" working to safeguard the Internet would have to work under authority of the UN, not any single nation.

There is INTERPOL

Which is just a communications mechanism, it doesn't have any enforcement power on its own.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#225

It should be explained to public how such exploit take place, with open sourcing necessary parts. Otherwise there is no way for us to know it wasn't intentional at first place. I am not meaning there is a possibility like Apple as a company decides to put exploits. However governments can easily do it with single engineer at right place.

According to wikipedia[1] Pegasus is usually installed via a zero-click iMessage exploit. Open-sourcing Pegasus doesn't seem likely as NSO Group sells it for big bucks. It seems unlikely that Apple has colluded with NSO, as Pegasus is actually a bit of a black eye for the company. I'm not sure what governments can do with an engineer in the right place - in general I'd say "not much, and certainly not as much as with the courts and guys with guns, the other things a government can do.

1 - https://en.wikipedia.org/wiki/Pegasus_(spyware)

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#226
post #158

Earlier quoted context omitted.

Why a new agency? This is already very much within the FBI’s jurisdiction. Why is the international surveillance of U.S. journalists and their sources not visibly a priority? In my opinion it’s a matter of policy. This comes from the top down. Bringing justice to international actors opposing democratic ethics is regrettably less of a priority today than enforcing highly publicized and politicized criminal cases.

IIRC, within the FBI’s jurisdiction and international don't go together. Isn't the FBI restricted to operating nationally only? But to answer your question more fully, you can't solve this problem without supranational cooperation. A "police force" working to safeguard the Internet would have to work under authority of the UN, not any single nation.

The U.S has an MLAT with Israel and routinely extradites. If the crime was committed on U.S. soil (intrusion, conspiracy), my understanding is that it is within U.S. jurisdiction.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#227

Darknet Diaries recently had an episode with John Scott-Railton from Citizen Lab on how he was allegedly being spied on by the makers of Pegasus, and then lured them into a trap https://darknetdiaries.com/episode/100/

Great rec! This is one of my favorite technical podcasts. The host does a great job getting into the technical details of the subjects while still appealing to non-techincal listeners. It's really impressive.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#228
post #180

Earlier quoted context omitted.

No, most are zero-click silent exploits. They own your phone persistently then delete the incoming message that pwned you.

Are other messaging apps on iOS ever getting RCE exploits like this? Can’t they sandbox iMessage so this isn’t possible no matter how many bugs the app has?

It's possible other apps are getting exploits, but those are less valuable since they're not installed by default.

As it stands, the most recently published information about the exploits were in the image parsers. So any app that used the default image parsers may have been affected, but might not have the same ability to escalate the exploit via other exploits. Plus you get back to the lack of ubiquity of the app, and the difficulty in targeting.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#229

Earlier quoted context omitted.

> I really hope the blur on the picture ( https://citizenlab.ca/wp-content/uploads/2021/10/Hubbard-Ima ...) isn't hiding anything actually important because that can almost certainly be de-blurred with the right tooling. Yeah, the right way to use blurring is to mockup a lookalike for content you want to hide, then blur the mockup.

You don't even need this. I searched "unblur" in Google Play Store, downloaded the first result, tweaked the settings a touch, and I could make out the characters. The whole process took a couple minutes. If the data actually needs to be hidden, this picture should be taken down.

It sounds like you didn’t read the post you are replying to. They indicated a mock copy should be made to avoid techniques reconstructing the data.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#230

Darknet Diaries recently had an episode with John Scott-Railton from Citizen Lab on how he was allegedly being spied on by the makers of Pegasus, and then lured them into a trap https://darknetdiaries.com/episode/100/

Great rec! This is one of my favorite technical podcasts. The host does a great job getting into the technical details of the subjects while still appealing to non-techincal listeners. It's really impressive.

Subbed. Any other recos? Been looking to scratch that Reply All itch.
Post reply on HN