Live data from Hacker News

NYT journalist hacked with Pegasus after reporting on previous hacking attempts

citizenlab.ca

231–240 of 330 posts

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#231

Earlier quoted context omitted.

> I really hope the blur on the picture ( https://citizenlab.ca/wp-content/uploads/2021/10/Hubbard-Ima ...) isn't hiding anything actually important because that can almost certainly be de-blurred with the right tooling. Yeah, the right way to use blurring is to mockup a lookalike for content you want to hide, then blur the mockup.

I just go solid opaque bar. Way easier to do and harder to screw up.

Amusingly enough, people have even screwed this up. I recall some government agency trying to censor data with a black bar, but the problem was that the data was in a SVG-like document, so people could just delete the bars from the document and see the apparently-censored text.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#232
post #12

It would seem to be the rational thing for NSO to hack a journalist who is writing on them, so that they better prepare for what’s coming. As for all the countries that buy and use NSO, to target and kill journalists, they are all close all allies of the US and Israel. And the US and England were also spying on the journalist Julian Assange, and have kept him in prison and tortured him for over a decade. Ben Hubbard…

He was arrested in 2019 so your “over a decade” claim is demonstrably wrong. Could you point to amnesty international claiming belmarsh is torture?

If you count being forced in a box by government entities as imprisoned, he's been imprisoned since 2012. If you're a stickler for being literal, he's if nothing else been captive since 2012.

Not to mention the UN's guy whose job is assessing whether a person is being tortured has repeatedly said that yeah, what's being done to him counts as torture.

«Painting a picture of progressively severe suffering inflicted on Mr. Assange from his prolonged solitary confinement, the Special Rapporteur upheld that it not only amounts to arbitrary detention, but also to torture and other cruel, inhuman or degrading treatment or punishment.»

https://news.un.org/en/story/2020/12/1079542

https://www.ohchr.org/EN/NewsEvents/Pages/DisplayNews.aspx?N...

https://www.bbc.com/news/world-48473898

https://www.nytimes.com/2019/05/31/world/europe/julian-assan...

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#233

So, what is the legality of this? I've not followed much about this at all, but NSO group appears to be an Israeli company. Do they just sell, or operate the hacking software for their clients? If they operate it, is it illegal for an Israeli company to hack an American citizen (I assume it is illegal in America, but how about Israel?) Is the sale of hacking software regulated in any way?

I read that it's export-controlled now in the US, https://www.theverge.com/2021/10/22/22740155/commerce-depart... ( "New US rules on spyware exports try to limit surveillance tech like Pegasus" ) edit: and HN thread https://news.ycombinator.com/item?id=28933981 ( "U.S. tightens export controls on items used in surveillance of private citizens" )

NSO is in Israel. US export controls do not apply.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#234

Earlier quoted context omitted.

You don't even need this. I searched "unblur" in Google Play Store, downloaded the first result, tweaked the settings a touch, and I could make out the characters. The whole process took a couple minutes. If the data actually needs to be hidden, this picture should be taken down.

It sounds like you didn’t read the post you are replying to. They indicated a mock copy should be made to avoid techniques reconstructing the data.

Yeah, I replied to the wrong comment, sorry. I navigated away and skimmed to figure out where I was when I came back.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#235

Earlier quoted context omitted.

Not all, but many restaurants in multiple cities. They use QR codes, no doubt to identify you better (tie you to a specific place and time, maybe to a specific table). Usually I just load the restaurant's website on my phone and read the menu that way. I was also at a play where a QR code was the only way to get the program.

What exactly are you suggesting the QR code is doing? My phone shows me the URL encoded by the QR code before opening, and I've never seen one with any additional information in the URL. They're not dynamically generating QR codes for you...

Have you used them at restaurants? I've avoided it, so I don't know.

I didn't mean they generate QR codes dynamically. It wouldn't be hard at all to encode the table number, for example, and then of course they have the time and know your reservation, and thus can identify their customer's phone.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#236

Earlier quoted context omitted.

They actually did it with iOS 14 (named Blastdoor) but apparently it's not helping much. Considering how tightly integrated iMessage is with iOS, it doesn't seem likely that it will really be fixed in an easy manner.

Ironic that Apple limiting their apps in the same way they limit 3p apps would've likely solved this vulnerability, unless the attack was only "0-click access to full chat.db"

Except there are tons of examples of iOS sandbox escapes over the last few years. I definitely don't consider iOS sandboxing a security control at this point.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#237

Earlier quoted context omitted.

> So how do we protect our privacy from the advance of technology? It doesn't seem possible. Just going after NSO is useless. Like we do with anything else: These are crimes, but we are stuck in the mindset of the nascent Internet, when it was a growing experiment, a subculture in our society, harmless, and we wanted to nurture it and give it maximum freedom. Those days are long gone. The Internet is completely integ…

You forget that the internet is post nationalism. Borders no longer exist and your domestic agency limited to the USA would be worthless. Or worse, serve as a pawn in the hands of Big Tech.

I agree that is a serious challenge, but I don't think we're learning much from extremes like "worthless".

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#238

Earlier quoted context omitted.

It depends on what your threat model is. If its individuals, local law enforcement, or even national law enforcement (context dependent) you are trying to hide from, you can obtain phones with cash and make it very difficult to link them to you (use a sim card bought with cash and never give out that number, use a VOIP service for your primary number, use an OS that doesn't send back much telemetry, turn off location…

> use a sim card bought with cash Varies by country I’m sure, but I was surprised how difficult it was to buy a SIM in Indonesia and Malaysia without an ID. Even little shops wanted an ID or passport number to type in to activate it.

Same in Australia, buying a SIM card is impossible without ID by law. https://mojoknows.com.au/en/prepaid-sim-card-activation-in-a... For Australians that's driver license, for visitors that's passport + visa too, with a visa-validity check.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#240
post #231

Earlier quoted context omitted.

I just go solid opaque bar. Way easier to do and harder to screw up.

Amusingly enough, people have even screwed this up. I recall some government agency trying to censor data with a black bar, but the problem was that the data was in a SVG-like document, so people could just delete the bars from the document and see the apparently-censored text.

I remember a version of this happening with PDFs
Post reply on HN