Live data from Hacker News

U.S. State Department phones hacked with Israeli company spyware

reuters.com

211–220 of 651 posts

Re: U.S. State Department phones hacked with Israeli company spyware

#211

I don't understand the focus on NSO in these stories. If U.S State Department personnel in Uganda were shot from an M-16, would the headline mention "an American arms manufacturer"? No, because it's ridiculous. For better or worse, NSO's product is a weapon. How is it any different from an M-16? Where is the outrage towards the people who used this weapon against the State Department?

U.S. weapons manufacturers receive a lot of criticism too, both domestically in the U.S. and internationally. The comments here focus on NSO because the story is about what NSO did. This is computer tech kind of community so you’re going to see more computer weapon stories here than stories about improper use of rifles.

The U.S sells super sophisticated weapons such as attack drones, F-15s or nuclear submarines. The tech behind these things is probably super interesting and there's a lot of software involved. If you look at the comments here, around 90% of them don't care about the tech at all but focus on bashing Israel. This isn't a tech story.

Re: U.S. State Department phones hacked with Israeli company spyware

#212

This is a typical "shadow government" symptom. You have forces working within the government that 1) have their own agendas; 2) have connection to international communities, usually military-intelligence ones; 3) have almost zero regulation; 4) even many high ranking government officials don't know about them because they are brotherhood-like closed circles. This reminds me of Operation Gladio or Propaganda Due but d…

Implying that Israeli spying on the US is some fringe "shadow government" sub-group of the Israeli government is strange given a long, long history of high profile Israeli spying incidents against the US. https://en.wikipedia.org/wiki/Lawrence_Franklin_espionage_sc... https://en.wikipedia.org/wiki/Jonathan_Pollard https://en.wikipedia.org/wiki/Ben-Ami_Kadish https://en.wikipedia.org/wiki/Jack_Parsons_(rocket_engineer…

By saying "shadow government" I mean groups within the US government that has connection to say NOS.

Again I don't have concrete proofs so I could be 100% wrong. But reading world history especially cold war history makes me be sceptical to certain things.

Re: U.S. State Department phones hacked with Israeli company spyware

#213

I don't understand the focus on NSO in these stories. If U.S State Department personnel in Uganda were shot from an M-16, would the headline mention "an American arms manufacturer"? No, because it's ridiculous. For better or worse, NSO's product is a weapon. How is it any different from an M-16? Where is the outrage towards the people who used this weapon against the State Department?

Unlike a firearm which has no intelligence or software, NSO retains significant control over their product.

U.S drones and F-15s don't have software?

Re: U.S. State Department phones hacked with Israeli company spyware

#214

Earlier quoted context omitted.

I know you're joking but for anyone that's not in on the joke: https://www.bbc.com/news/world-europe-24690055

Wow! You found one instance of the US spying on a friendly government. That totally justifies NSO leasing spyware to authoritarian third world regimes! Carry on folks, nothing to see here.

It doesn't justify it, but if we're going to take a stance against spyware, we have to take a stance against all spyware. That includes the home-rolled stuff that the NSA pushes out to Apple and Google.

Re: U.S. State Department phones hacked with Israeli company spyware

#215
post #189

Is anyone working on a microkernel design for privacy-sensitive devices (like phones) that would prevent outright this class of kernel-level arbitrary code execution exploits? We're stuck with iOS and Android for the foreseeable future, but is there hope that we'll get this right some day? Actually, would a microkernel design even be sufficient? Given that hackers exploit deserialization, memory safety, and variable…

User-space ACE would still be enough to do something like this. All sorts of user-space apps have the relevant permissions and are not secured against attacks to the necessary extent to stop a state level actor.

Re: U.S. State Department phones hacked with Israeli company spyware

#216

I don't understand the focus on NSO in these stories. If U.S State Department personnel in Uganda were shot from an M-16, would the headline mention "an American arms manufacturer"? No, because it's ridiculous. For better or worse, NSO's product is a weapon. How is it any different from an M-16? Where is the outrage towards the people who used this weapon against the State Department?

Speak plainly. Are you suggesting this is a company being unfairly singled out just because it's Israeli?

It being Israeli is definitely a big part of why this story is so huge. Why do you think it's making huge headlines then - what's your theory? The fact that 8 American diplomats got their phones hacked?

Re: U.S. State Department phones hacked with Israeli company spyware

#217

Is there a timetable when Apple plans to stop using memory-unsafe languages to avoid memory-bugs? If not, how can the amount of zero-days stop with constant development?

You do know that memory-safe languages are developed using memory-unsafe languages, and eventually execute the binary code on the actual CPU?

Most memory-safe languages I've used self-host their compiler and standard library (i.e. they're written in the language itself).

Re: U.S. State Department phones hacked with Israeli company spyware

#218

Earlier quoted context omitted.

This is just another incident in a long list that goes back decades of Israel getting carte blanche to do whatever they want to the US with little to no repercussion. The most famous probably being USS Liberty ( https://en.wikipedia.org/wiki/USS_Liberty_incident )

Why would Israel be allowed to do whatever they want?

https://en.wikipedia.org/wiki/American_Israel_Public_Affairs...

Re: U.S. State Department phones hacked with Israeli company spyware

#219

Earlier quoted context omitted.

Didn't they get pretty close with Huawei when the previous president issued an executive order in response to state spying fears that: * banned the sale of any of their phones or networking products in the US * banned US companies selling product to Huawei * cut funding to wireless carriers using Huawei equipment ...and then pressured allied countries to do the same?

The investigation into Huawei was going on for many years prior to 2016. It's not exactly an initiative of the previous president. I sat in briefings about Huawei and ZTE in 2007. Regretfully can't say more.

Are you personally upset about the clear intelligence failures and extrfiltration of protected information?

I've grown up watching this unfold and I'm shocked that the power groups seem to be so ineffectual at times that it's laughable(but that may be by design...)

Re: U.S. State Department phones hacked with Israeli company spyware

#220

Slapping down the NSO doesn't fix the problem. We should be glad we even know that their software exists, imagine if it was completely hidden from the public? The problem is that Apple needs to fix this. Security is an arms race, and the more visibility we have into where it is weak, the better for everyone. To paraphrase the motorcycle repair episode of Winter Steele, "You are stronger now for having been fixed." IM…

Great commentary. The US is hopefully looking into why these employees are using iPhones + local SIM. And if that has been approved in the past, maybe re-think that
Post reply on HN