Earlier quoted context omitted.
> (I assume it is illegal in America, but how about Israel?) This part doesn't matter much in practicality. Like it is illegal for the US gov't to spy on their citizens. It is illegal for the UK to spy on their citizens. So the NSA made a deal with the UK. They spy on us, we spy on them, and exchange the info. There, the US didn't break the law and neither did the UK. They worked around it. We live in a shadowy world…
> Like it is illegal for the US gov't to spy on their citizens. It is illegal for the UK to spy on their citizens. So the NSA made a deal with the UK. They spy on us, we spy on them, and exchange the info. There, the US didn't break the law and neither did the UK. Let’s not mince words, this is officials of the United States of America conspiring with foreign hostile [0] powers to undermine the rights and security of…
NYT journalist hacked with Pegasus after reporting on previous hacking attempts
311–320 of 330 posts
Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts
#312Earlier quoted context omitted.
> (I assume it is illegal in America, but how about Israel?) This part doesn't matter much in practicality. Like it is illegal for the US gov't to spy on their citizens. It is illegal for the UK to spy on their citizens. So the NSA made a deal with the UK. They spy on us, we spy on them, and exchange the info. There, the US didn't break the law and neither did the UK. They worked around it. We live in a shadowy world…
> Like it is illegal for the US gov't to spy on their citizens. It is illegal for the UK to spy on their citizens. So the NSA made a deal with the UK. They spy on us, we spy on them, and exchange the info. There, the US didn't break the law and neither did the UK. Let’s not mince words, this is officials of the United States of America conspiring with foreign hostile [0] powers to undermine the rights and security of…
Nor would the Insurrection Act be in any way needed or relevant to arresting former (or current) intelligence officials for either actual treason, or any illegal conspiracy with allied intelligence services regarding surveillance.
Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts
#313I really hope the blur on the picture ( https://citizenlab.ca/wp-content/uploads/2021/10/Hubbard-Ima... ) isn't hiding anything actually important because that can almost certainly be de-blurred with the right tooling.
Really? Seems blurred enough to me that even some sort of ML would spit out wrong characters.
Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts
#314Earlier quoted context omitted.
Great rec! This is one of my favorite technical podcasts. The host does a great job getting into the technical details of the subjects while still appealing to non-techincal listeners. It's really impressive.
Subbed. Any other recos? Been looking to scratch that Reply All itch.
Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts
#315Earlier quoted context omitted.
I’m not sure that regulation really applies much when you operate at that level. How many countries has the US waged war on with the combatants in both sides using US made weapons? The scene has been set again in Afghanistan. It isn’t ICBMs but it’s not a virtuous circle when you are dealing with weaponry.
Has an ICBM ever been used offensively? I would say ICBMs are among the most well-regulated weapons in existence.
Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts
#316Earlier quoted context omitted.
I built a redaction process for a small company once. My critical security step was rendering out the PDF as individual flat image files, then re-assembling it like a traditionally photo-copied document. That way the loss-full operation is enforced, at the cost of forcing end users to OCR unsearchable image-scan (like) PDFs.
It's the only way to be sure!
Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts
#317Earlier quoted context omitted.
> I really hope the blur on the picture ( https://citizenlab.ca/wp-content/uploads/2021/10/Hubbard-Ima ...) isn't hiding anything actually important because that can almost certainly be de-blurred with the right tooling. Yeah, the right way to use blurring is to mockup a lookalike for content you want to hide, then blur the mockup.
I just go solid opaque bar. Way easier to do and harder to screw up.
There may be graphic design reasons you don't want to do that. A big black redaction bar isn't much of an illustration.
Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts
#318My security researcher buddy at Apple responsible for investigating this vulnerability told me that the hack is very complex; Apple couldn't even fully figure it out before pushing patches; the patches do not fix all the known bugs used in the vulnerability; the attackers most likely have access to Apple internal source code as well. They are very thankful for Citizen Lab without which the bugs wouldn't have been dis…
Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts
#319Earlier quoted context omitted.
According to wikipedia[1] Pegasus is usually installed via a zero-click iMessage exploit. Open-sourcing Pegasus doesn't seem likely as NSO Group sells it for big bucks. It seems unlikely that Apple has colluded with NSO, as Pegasus is actually a bit of a black eye for the company. I'm not sure what governments can do with an engineer in the right place - in general I'd say "not much, and certainly not as much as with…
Interesting. Didn’t realize it was zero-click. I got a bunch of weird iMessages a few months ago which I didn’t open. How do I check if I’ve been compromised?
Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts
#320Earlier quoted context omitted.
I don't think you can escape the use of the smart phone. But treating them as "throw-away", as not your device, etc. I think the original landlines, which were/are a few switches connected to a write on one side and some microphones on the other, were close to inherently insecure. Phones haven't ever been "your device" whereas a laptop might, maybe be rendered trustworthy.
I think there should always be physical off-switches for microphones: it should be possible to know that the thing is not listening. But smartphones also have other private information on them than what can be captured by its microphone. I don't think the smartphone is inescapable at all, and I don't think any of the conveniences it offers is worth surrendering one's privacy. But there is a tendency in businesses to…
There is one smartphone with those: https://puri.sm/products/librem-5. The alternative one, Pinephone, has quite inconvenient kill switches.