Live data from Hacker News

NYT journalist hacked with Pegasus after reporting on previous hacking attempts

citizenlab.ca

311–320 of 330 posts

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#311
post #62
post #13

Earlier quoted context omitted.

> (I assume it is illegal in America, but how about Israel?) This part doesn't matter much in practicality. Like it is illegal for the US gov't to spy on their citizens. It is illegal for the UK to spy on their citizens. So the NSA made a deal with the UK. They spy on us, we spy on them, and exchange the info. There, the US didn't break the law and neither did the UK. They worked around it. We live in a shadowy world…

> Like it is illegal for the US gov't to spy on their citizens. It is illegal for the UK to spy on their citizens. So the NSA made a deal with the UK. They spy on us, we spy on them, and exchange the info. There, the US didn't break the law and neither did the UK. Let’s not mince words, this is officials of the United States of America conspiring with foreign hostile [0] powers to undermine the rights and security of…

[deleted]

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#312
post #62
post #13

Earlier quoted context omitted.

> (I assume it is illegal in America, but how about Israel?) This part doesn't matter much in practicality. Like it is illegal for the US gov't to spy on their citizens. It is illegal for the UK to spy on their citizens. So the NSA made a deal with the UK. They spy on us, we spy on them, and exchange the info. There, the US didn't break the law and neither did the UK. They worked around it. We live in a shadowy world…

> Like it is illegal for the US gov't to spy on their citizens. It is illegal for the UK to spy on their citizens. So the NSA made a deal with the UK. They spy on us, we spy on them, and exchange the info. There, the US didn't break the law and neither did the UK. Let’s not mince words, this is officials of the United States of America conspiring with foreign hostile [0] powers to undermine the rights and security of…

Allied intelligence services are not enemies within the scope of the Constitutional (or any sane, for that matter) definition of treason.

Nor would the Insurrection Act be in any way needed or relevant to arresting former (or current) intelligence officials for either actual treason, or any illegal conspiracy with allied intelligence services regarding surveillance.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#313
post #150

I really hope the blur on the picture ( https://citizenlab.ca/wp-content/uploads/2021/10/Hubbard-Ima... ) isn't hiding anything actually important because that can almost certainly be de-blurred with the right tooling.

Really? Seems blurred enough to me that even some sort of ML would spit out wrong characters.

It's blurred lightly enough for me to be able to tell at least some characters just with my eyes.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#314

Earlier quoted context omitted.

Great rec! This is one of my favorite technical podcasts. The host does a great job getting into the technical details of the subjects while still appealing to non-techincal listeners. It's really impressive.

Subbed. Any other recos? Been looking to scratch that Reply All itch.

If you join the Patreon, you can get access to bonus shows while also supporting the creator and allowing him to make more episodes. Highly recommend joining the Patreon so we can more amazing content in the future.

https://www.patreon.com/darknetdiaries

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#315

Earlier quoted context omitted.

I’m not sure that regulation really applies much when you operate at that level. How many countries has the US waged war on with the combatants in both sides using US made weapons? The scene has been set again in Afghanistan. It isn’t ICBMs but it’s not a virtuous circle when you are dealing with weaponry.

Has an ICBM ever been used offensively? I would say ICBMs are among the most well-regulated weapons in existence.

I don’t think it’s regulation that has stopped them being used.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#316

Earlier quoted context omitted.

I built a redaction process for a small company once. My critical security step was rendering out the PDF as individual flat image files, then re-assembling it like a traditionally photo-copied document. That way the loss-full operation is enforced, at the cost of forcing end users to OCR unsearchable image-scan (like) PDFs.

It's the only way to be sure!

well if you had an open (.odf) or openable (.doc≈xml) format you could replace strings and be sure something was gone

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#317

Earlier quoted context omitted.

> I really hope the blur on the picture ( https://citizenlab.ca/wp-content/uploads/2021/10/Hubbard-Ima ...) isn't hiding anything actually important because that can almost certainly be de-blurred with the right tooling. Yeah, the right way to use blurring is to mockup a lookalike for content you want to hide, then blur the mockup.

I just go solid opaque bar. Way easier to do and harder to screw up.

> I just go solid opaque bar. Way easier to do and harder to screw up.

There may be graphic design reasons you don't want to do that. A big black redaction bar isn't much of an illustration.

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#318

My security researcher buddy at Apple responsible for investigating this vulnerability told me that the hack is very complex; Apple couldn't even fully figure it out before pushing patches; the patches do not fix all the known bugs used in the vulnerability; the attackers most likely have access to Apple internal source code as well. They are very thankful for Citizen Lab without which the bugs wouldn't have been dis…

Well, if you have billions just sitting around... pay 10's of millions for such a bug bounty?

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#319

Earlier quoted context omitted.

According to wikipedia[1] Pegasus is usually installed via a zero-click iMessage exploit. Open-sourcing Pegasus doesn't seem likely as NSO Group sells it for big bucks. It seems unlikely that Apple has colluded with NSO, as Pegasus is actually a bit of a black eye for the company. I'm not sure what governments can do with an engineer in the right place - in general I'd say "not much, and certainly not as much as with…

Interesting. Didn’t realize it was zero-click. I got a bunch of weird iMessages a few months ago which I didn’t open. How do I check if I’ve been compromised?

iMazing[0] can analyze an iTunes (or Finder in macOS Catalina and later) backup to determine whether Pegasus is present.

[0] https://imazing.com/

Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts

#320

Earlier quoted context omitted.

I don't think you can escape the use of the smart phone. But treating them as "throw-away", as not your device, etc. I think the original landlines, which were/are a few switches connected to a write on one side and some microphones on the other, were close to inherently insecure. Phones haven't ever been "your device" whereas a laptop might, maybe be rendered trustworthy.

I think there should always be physical off-switches for microphones: it should be possible to know that the thing is not listening. But smartphones also have other private information on them than what can be captured by its microphone. I don't think the smartphone is inescapable at all, and I don't think any of the conveniences it offers is worth surrendering one's privacy. But there is a tendency in businesses to…

> I think there should always be physical off-switches for microphones

There is one smartphone with those: https://puri.sm/products/librem-5. The alternative one, Pinephone, has quite inconvenient kill switches.

Post reply on HN