Live data from Hacker News

U.S. State Department phones hacked with Israeli company spyware

reuters.com

121–130 of 651 posts

Re: U.S. State Department phones hacked with Israeli company spyware

#122

>In a public response, NSO has said its technology helps stop terrorism and that they've installed controls to curb spying against innocent targets. For example, NSO says its intrusion system cannot work on phones with U.S. numbers beginning with the country code +1. So the point is to stop terrorism and to do that they've immediately ruled that all Americans aren't terrorists. That doesn't seem like a good metric of…

As an obvious statement: I think this should be interpreted similarly to some ransomware not infecting devices with RU keyboards: it's just about avoiding difficult regulatory environments.

The analogy, of course, goes further. Though unlike most ransomware companies, NSO has British and American VC funding.

Re: U.S. State Department phones hacked with Israeli company spyware

#123

>In a public response, NSO has said its technology helps stop terrorism and that they've installed controls to curb spying against innocent targets. For example, NSO says its intrusion system cannot work on phones with U.S. numbers beginning with the country code +1. So the point is to stop terrorism and to do that they've immediately ruled that all Americans aren't terrorists. That doesn't seem like a good metric of…

Most people don't know that the first bit of an area code is the evil bit. https://en.wikipedia.org/wiki/Evil_bit

Re: U.S. State Department phones hacked with Israeli company spyware

#124

Is there a timetable when Apple plans to stop using memory-unsafe languages to avoid memory-bugs? If not, how can the amount of zero-days stop with constant development?

You do know that memory-safe languages are developed using memory-unsafe languages, and eventually execute the binary code on the actual CPU?

A memory safe language can be written in itself.

Re: U.S. State Department phones hacked with Israeli company spyware

#125
Arguably, this is the real use case Pegasus was designed for. A government (Uganda) that does not have a large and mature civil service that would support a G7 level technical domestic intelligence agency went to market for the tools of one (NSO), so they can keep tabs on foreign intelligence agents (state department staff) in their country. I am not a fan of NSO at all, but this case sounds like they're providing sovereignty or statecraft as a service to a government that prefers to buy instead of build their security capability.

When the game is defined as a competition for how to break its rules in the most unexpected ways and with the fewest consequences, Uganda appears to have joined in with aplomb. To me it's the first time an NSO story doesn't seem like a scandal.

Re: U.S. State Department phones hacked with Israeli company spyware

#126

Earlier quoted context omitted.

Only if you count general American military spending as supporting Germany more than Israel? Otherwise, US absolutely provides far more military spending to Israel than to Germany, it's not really comparable.

> Only if you count general American military spending Of course I do. Europe has no real army. France kinda has an army and the U.K got out. If America didn't provide a military umbrella Europe would need to actually build a real army (Europe's contributions to NATO are pitiful). How much would it cost the Europeans to do that? Going back since WW2 that's easily in the trillions.

Given that the US actively engages in military operations in defense of Israel, I would say that it not reasonable to attribute a larger share of the spending to Germany rather than Israel?

Re: U.S. State Department phones hacked with Israeli company spyware

#127

I thought the exploited holes were patched by iOS at some point. How are these phones still getting hacked?

People are notoriously bad at keeping their devices up to date, with some even intentionally disabling updates. This can be prevented by the IT department having MDM profiles with strict update enforcement in place, but I don’t have much hope that the IT department of any given US government office is particularly capable or competent.

The article doesn't say if they were personal or work provided phones. Many people living/working overseas have work and personal phones. Also, almost all of those with personal phones get a local SIM, so they'd get a local non-US (not +1) phone number. I used to be an IT admin with DOS overseas. Updates were enforced, and phones were disabled if they were not upgraded to the most recent version. Starting in about 2019, mobile device security went into overdrive and is very serious now. Additionally, the MDM profiles are quite limiting, so this pushed most people to get personal phones. A huge pain for records retention.

Re: U.S. State Department phones hacked with Israeli company spyware

#128
post #118

The Israel government gets a pass for anything they do. Whether it is lying about nukes or what they've done to Palestine. NSO is a feather in their cap.

Please don't virtue signal, or state flame wars, or use this to posture some kind of agenda.

Please don't mistake yourself for dang

Re: U.S. State Department phones hacked with Israeli company spyware

#129
post #118

The Israel government gets a pass for anything they do. Whether it is lying about nukes or what they've done to Palestine. NSO is a feather in their cap.

Please don't virtue signal, or state flame wars, or use this to posture some kind of agenda.

I’m not seeing any virtue signaling.

Re: U.S. State Department phones hacked with Israeli company spyware

#130

Seems like not-the-smartest move for Israel to mess with one of the few powerful entities that desires its continued existence

Everyone knows already nothing will happen, they will get slap on the wrist as usual and show goes on.
Post reply on HN