Live data from Hacker News

NYT journalist hacked with Pegasus after reporting on previous hacking attempts

citizenlab.ca

241–250 of 330 posts

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#241

Earlier quoted context omitted.

Great rec! This is one of my favorite technical podcasts. The host does a great job getting into the technical details of the subjects while still appealing to non-techincal listeners. It's really impressive.

Subbed. Any other recos? Been looking to scratch that Reply All itch.

Very different show, but I enjoy the Accidental Tech Podcast (aka "ATP").

It's a weekly news show that focuses on tech (mainly Apple). They do a good job with technical details and talking through tech product decisions (why did Apple/Google/FB do X? What are its merits?). People have sort of polarized opinions about each of the 3 hosts, but IMO they each have their moments.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#242

I feel like phones should just have a "scrub anything that isn't ASCII text" option for paranoid folks. No unicode, no emoji, no media. I mean, I guess they could still f*ck that up, and maybe it'd be admitting defeat, but still.

AIUI part of the problem is that iMessage is a poor legacy design and relies on generic macOS serialization primitives. It's not like HTML where you can just scrub all the tags out. This can't be changed without breaking compatibility due to end to end encryption (the server can't adapt between versions). So there is a big attack surface inherent to the design, and Apple are stuck with it.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#243

Earlier quoted context omitted.

They actually did it with iOS 14 (named Blastdoor) but apparently it's not helping much. Considering how tightly integrated iMessage is with iOS, it doesn't seem likely that it will really be fixed in an easy manner.

Ironic that Apple limiting their apps in the same way they limit 3p apps would've likely solved this vulnerability, unless the attack was only "0-click access to full chat.db"

They do limit their own apps (they even specifically sandboxed part of the iMessage handling, more than a standard app). The exploit chains that NSO uses include sandbox escapes.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#244

Earlier quoted context omitted.

How can you possibly not escape the use of a smartphone?

I recently had to file an insurance claim with my car insurer. The entire process happened through their app. They require you to send them pictures that you took using their app. One of my banks has been closing branches left and right, and if I want to use my accounts for anything other than debit purchases, I need to use the app. Some banks even charge you when you go to a branch location in person and use a telle…

Pretty much all those things you can do over old channels still. The app is optional. I can do everything my mobile banking website can do over the phone. The last time I filed a claim with my insurer, everything happened via back and forth emailing.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#245

I feel like phones should just have a "scrub anything that isn't ASCII text" option for paranoid folks. No unicode, no emoji, no media. I mean, I guess they could still f*ck that up, and maybe it'd be admitting defeat, but still.

This necessarily excludes people whose primary language for communication does not fit in a Latin alphabet.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#246
post #180

Do these types of iMessage attachment exploits require the victim to do anything on their end? Downloading the attachment? Opening the message ? That part is unclear to me

No, most are zero-click silent exploits. They own your phone persistently then delete the incoming message that pwned you.

It's actually not persistent; AIUI Pegasus these days is designed to be ephemeral to avoid forensic analysis. If you reboot your phone it's gone (but they can just own you again with another message). Of course, most people don't reboot their phones very often.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#247

It should be explained to public how such exploit take place, with open sourcing necessary parts. Otherwise there is no way for us to know it wasn't intentional at first place. I am not meaning there is a possibility like Apple as a company decides to put exploits. However governments can easily do it with single engineer at right place.

According to wikipedia[1] Pegasus is usually installed via a zero-click iMessage exploit. Open-sourcing Pegasus doesn't seem likely as NSO Group sells it for big bucks. It seems unlikely that Apple has colluded with NSO, as Pegasus is actually a bit of a black eye for the company. I'm not sure what governments can do with an engineer in the right place - in general I'd say "not much, and certainly not as much as with…

I understood the parent comment as requesting that iOS be made open source to allow a further understanding of how the exploit works. My response to that would be that making things open source makes this process easier, but is not, by and means, a requirement for this ability.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#248

Why aren't political exposed persons leaving iphones? It has been known for a while that it is not secure for them. An android tablet connecting to wifi hotspots only, or even lan only, with minimal software, and a dumb phone are more secure than iphone.

they need an actual functional phone. You can't be a journalist and not have a fully functional phone that access the internet whenever needed. I'm sure they use burners for sensitive stuff, but what are they supposed to use for their regular work, calls with the school, car navigation, ...

Just use a dumb phone and a garmin like journalists did in the early 2000s?

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#249

Earlier quoted context omitted.

The static URL encoded by the QR code funnels you to a web page where that page view can be reported back to trackers and incorporated into your advertising profile. Using your device to read the menu puts your device in the loop where formerly it was not.

Sure, if I suspend disbelief and assume that no other search engines or navigation services were used that do similar tracking—but the GP was specifically calling out QR codes, and they use the website anyway.

You don't have to suspend disbelief to come up with such a scenario. When I go to the bar down the street from my apartment, order food and a drink, pay cash and then leave, it was not an interaction that was likely to become part of my advertising profile. Now it is.

It's not comparing websites accessed via QR against every other already tracked thing in society, it's comparing it with laminated pieces of paper.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#250

So how do we protect our privacy from the advance of technology? It doesn't seem possible. Just going after NSO is useless.

Same way the mafia used to do it when they realized all their phones and cars were bugged. No technology. Talk in person, outside. Seriously, if you are a journalist investigating anything that might upset the powers that be in a nation-state, don't use any online technology and for gods sake not a mobile phone.

It’s very difficult to live a normal life without using technology of some kind.
Post reply on HN