Earlier quoted context omitted.
Great rec! This is one of my favorite technical podcasts. The host does a great job getting into the technical details of the subjects while still appealing to non-techincal listeners. It's really impressive.
Subbed. Any other recos? Been looking to scratch that Reply All itch.
NYT journalist hacked with Pegasus after reporting on previous hacking attempts
281–290 of 330 posts
Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts
#282Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts
#283Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts
#284Earlier quoted context omitted.
Amusingly enough, people have even screwed this up. I recall some government agency trying to censor data with a black bar, but the problem was that the data was in a SVG-like document, so people could just delete the bars from the document and see the apparently-censored text.
I remember a version of this happening with PDFs
https://eclecticlight.co/2020/12/11/how-effective-and-safe-i...
Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts
#285Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts
#286Earlier quoted context omitted.
Amusingly enough, people have even screwed this up. I recall some government agency trying to censor data with a black bar, but the problem was that the data was in a SVG-like document, so people could just delete the bars from the document and see the apparently-censored text.
I built a redaction process for a small company once. My critical security step was rendering out the PDF as individual flat image files, then re-assembling it like a traditionally photo-copied document. That way the loss-full operation is enforced, at the cost of forcing end users to OCR unsearchable image-scan (like) PDFs.
Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts
#287Earlier quoted context omitted.
This depends on your threat model (what is illegal, who chooses to prosecute, etc) I was driving home today and the satnav warned us about driving over speed limit (74 mph on UK motorway). Ok. But the solution to that is technology - and organisation. There are speed cameras on this road. But most of the time they don't take images or don't trigger an action. If every road camera triggered a warning / fine on every v…
> which we give up and decriminialise Or governments will continue to have those laws on the books and prosecute them with discretion (which is what happens today). It is very convenient for those in power when every person is already guilty of something.
If society is not free or fair, that's the problem to fix first.
Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts
#288Earlier quoted context omitted.
It depends on what your threat model is. If its individuals, local law enforcement, or even national law enforcement (context dependent) you are trying to hide from, you can obtain phones with cash and make it very difficult to link them to you (use a sim card bought with cash and never give out that number, use a VOIP service for your primary number, use an OS that doesn't send back much telemetry, turn off location…
>use a sim card bought with cash and never give out that number This is near impossible now. I tried a few years ago to get an anonymous phone to activate an anonymous twitter account and you have to provide too much information to activate the sim card across the major providers and other companies that use their infrastructure.
Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts
#289Earlier quoted context omitted.
> zero-click Literally worth millions of dollars on the wholesome greymarkets these days, possibly the most prized, just in case anyone was wondering.
How so?
Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts
#290Earlier quoted context omitted.
What exactly do you mean by "treated like mercenaries", what should be the treatment in your opinion ? In general, countries do hire mercenaries/private military contractors/etc, and it is not considered anything special, and many powerful countries (including e.g. the USA) routinely use mercenaries in their campaigns. the "sending" nation may restrict their people and companies from mercenary actions abroad if they…
Presumably the GP means that the NSO employees should be held personally responsible for actions taken by the NSO group, without diplomatic cover or ability to claim that they're law enforcement/military/intelligence. They are civilians, not uniformed government employees.
They can be held personally responsible in USA criminal courts no matter if they're civilians or uniformed SA government employees - if a foreign government agent does something on your soil, you can (and should) apply standard criminal law can no matter if they're an uniformed employee in their service or not - for example, the Russian officers UK charged with Salisbury Novichok poisonings. However, USA courts can't enforce any judgements without cooperation of the host countries.
And Saudi Arabia can arbitrarily ignore the victims' complaints, foreign charges and convictions and their enforcement if they want, no matter if the violators civilians or uniformed government employees, that's only a difference if SA chooses to make that distinction. Uniforms would imply some differences in their rights according to Geneva convention if they would be captured as prisoners of war in an active armed conflict, but this is not an active armed conflict and they have not been captured as PoWs.
With respect to extradition or local prosecution Saudi Arabia can arbitrarily extend their protection to whomever they choose to, no matter what their status or citizenship is - if they have not made e.g. a bilateral treaty with USA where they agree that they will extradite such people, they do not have to do so.