Live data from Hacker News

U.S. State Department phones hacked with Israeli company spyware

reuters.com

21–30 of 651 posts

Re: U.S. State Department phones hacked with Israeli company spyware

#22
post #14

>In a public response, NSO has said its technology helps stop terrorism and that they've installed controls to curb spying against innocent targets. For example, NSO says its intrusion system cannot work on phones with U.S. numbers beginning with the country code +1. So the point is to stop terrorism and to do that they've immediately ruled that all Americans aren't terrorists. That doesn't seem like a good metric of…

NSO has repeatedly shown that their statements are pretty much worthless. It's just damage control. I wouldn't put any stock in the "we avoid +1 numbers" to even be real.

Seriously, they're pretty much the Mark Zuckerberg of their industry.

Re: U.S. State Department phones hacked with Israeli company spyware

#23

I'm waiting for the day that the US declares a foreign corporation as an "enemy combatant", as they have done with foreign citizen wahabbist jihadis and US citizens such as Anwar Al-Awlaki. Given the extent and depth of US-Israeli cooperation and ties, the precedeing theoretical is probably going to remain in the realm of theoretical.

They basically declared the embargoed Iranian corporations as enemy combatants a while ago, if that's what you mean.

Re: U.S. State Department phones hacked with Israeli company spyware

#24
post #2

Huh, it looks like suing a state-sponsored malware manufacturer doesn't prevent them from continuing to hijack your devices. Live and learn, I suppose.

This is based on Apple notifying the employees based on prior behavior of NSO.

Re: U.S. State Department phones hacked with Israeli company spyware

#25

“ NSO says its intrusion system cannot work on phones with U.S. numbers beginning with the country code +1.” Seems like they just need to add a similar patch for apple ids for emails ending in “state.gov”. Not sure why this is such a big deal.

Come on, think about it. Doesn't work for phone numbers starting with +1? So, anyone who buys the right sim card is immune? A team of professional hackers can't find the if-else in the attack binary that enforces that to disable it? They're selling software to cybersecurity teams on the assumption that they can't crack it?

> A team of professional hackers can't find the if-else in the attack binary that enforces that to disable it?

It's probably easier than that. Seems like the kind of thing that would be in a config file (making this up, satire):

[No Spying Allowed - please do not change]

# Really, really, don't change this setting. We are not responsible if you do.

+1 # USA

+3542 # NSO Group

> They're selling software to cybersecurity teams on the assumption that they can't crack it?

No, I think they are telling journalists that their hands are clean, and it totally isn't their fault, not in a million years, that their customer changed their software.

Re: U.S. State Department phones hacked with Israeli company spyware

#26

>In a public response, NSO has said its technology helps stop terrorism and that they've installed controls to curb spying against innocent targets. For example, NSO says its intrusion system cannot work on phones with U.S. numbers beginning with the country code +1. So the point is to stop terrorism and to do that they've immediately ruled that all Americans aren't terrorists. That doesn't seem like a good metric of…

So I just have to buy a US phone to evade detection from NSO? And why didn't that logic work for US State Dept phones?

I'm honestly of the opinion there is nothing that NSO can say that isn't outright lying. This isn't a normal company in anyway.

Re: U.S. State Department phones hacked with Israeli company spyware

#27
post #22
post #14

Earlier quoted context omitted.

NSO has repeatedly shown that their statements are pretty much worthless. It's just damage control. I wouldn't put any stock in the "we avoid +1 numbers" to even be real.

Seriously, they're pretty much the Mark Zuckerberg of their industry.

That is not fair to Mark Zuckerberg.

Re: U.S. State Department phones hacked with Israeli company spyware

#28

“ NSO says its intrusion system cannot work on phones with U.S. numbers beginning with the country code +1.” Seems like they just need to add a similar patch for apple ids for emails ending in “state.gov”. Not sure why this is such a big deal.

As someone who doesn’t have a +1 number I find it hard to take this comment seriously. But could it be possible that some state department employees work outside the US?

Re: U.S. State Department phones hacked with Israeli company spyware

#29

Is there a timetable when Apple plans to stop using memory-unsafe languages to avoid memory-bugs? If not, how can the amount of zero-days stop with constant development?

biggest issue here isn't memory safety but the dumpster fire of imessage format that calls out to privileged parts of the system

Re: U.S. State Department phones hacked with Israeli company spyware

#30

I thought the exploited holes were patched by iOS at some point. How are these phones still getting hacked?

People are notoriously bad at keeping their devices up to date, with some even intentionally disabling updates. This can be prevented by the IT department having MDM profiles with strict update enforcement in place, but I don’t have much hope that the IT department of any given US government office is particularly capable or competent.
Post reply on HN