Live data from Hacker News

U.S. State Department phones hacked with Israeli company spyware

reuters.com

221–230 of 651 posts

Re: U.S. State Department phones hacked with Israeli company spyware

#221

Earlier quoted context omitted.

The investigation into Huawei was going on for many years prior to 2016. It's not exactly an initiative of the previous president. I sat in briefings about Huawei and ZTE in 2007. Regretfully can't say more.

Are you personally upset about the clear intelligence failures and extrfiltration of protected information? I've grown up watching this unfold and I'm shocked that the power groups seem to be so ineffectual at times that it's laughable(but that may be by design...)

It's an absolute shitshow from top to bottom. The people who know what they're doing in intelligence/counter-intelligence agency infosec/netsec (and within major DoS and DoD contractors) have been fully aware and ringing the alarm bells for years. The technologically unsophisticated politicians have been mostly ignoring it.

Re: U.S. State Department phones hacked with Israeli company spyware

#222
post #189

Is anyone working on a microkernel design for privacy-sensitive devices (like phones) that would prevent outright this class of kernel-level arbitrary code execution exploits? We're stuck with iOS and Android for the foreseeable future, but is there hope that we'll get this right some day? Actually, would a microkernel design even be sufficient? Given that hackers exploit deserialization, memory safety, and variable…

I'm not convinced microkernels are the answwr but we do have QubesOS.

Re: U.S. State Department phones hacked with Israeli company spyware

#223
post #204

Earlier quoted context omitted.

This wasn't done by NSO knowingly. I have no reason not to believe them on that, they have a financial and strategic interest not to piss America off that bad. Also - Uganda is not Iran, it's a friendly country. Unfortunately someone there decided to use it against American diplomats which is unfortunate.

> This wasn't done by NSO knowingly. In the past month or so, there was a front page story on HN about NSO and a journalist, detailing evidence that NSO-controlled servers served up the exploit to the journalist's phone. This suggests that the NSO group has less of an arms-length relationship with their clients than they let on. It seems that at least for some clients, they're running some variant on exploits-as-a-se…

That still doesn't mean they knew about this. How would they even know it were American phones? Its very possible it were some IPhone with a Ugandan sim card. How do you know who's using it - do the Ugandans tell you? It's a very real possibility NSO servers simply show some Ugandan number. I have no more knowledge on this than anyone here but I don't find it realistic NSO would take this chance.

Re: U.S. State Department phones hacked with Israeli company spyware

#224
post #78
post #22

Earlier quoted context omitted.

Seriously, they're pretty much the Mark Zuckerberg of their industry.

I‘d rather compare Zuckerberg to the Sackler family who knew how addictive and harmful their painkiller Oxycotin was, yet ignoring all evicence, making billions of dollars. Zuckerberg knows how bad Facebook and Instagram is, how harmful to individuals and society alike, yet ignoring that and making billions. Edit: Replaced „social media“ with „Facebook and Instagram“

Why did you feel the need for the edit? I would agree with the blanket use of social media. Twitter is no better. Do we know enough about the inner working of TikTok to know they aren't doing similar?

Re: U.S. State Department phones hacked with Israeli company spyware

#225

This is a typical "shadow government" symptom. You have forces working within the government that 1) have their own agendas; 2) have connection to international communities, usually military-intelligence ones; 3) have almost zero regulation; 4) even many high ranking government officials don't know about them because they are brotherhood-like closed circles. This reminds me of Operation Gladio or Propaganda Due but d…

Implying that Israeli spying on the US is some fringe "shadow government" sub-group of the Israeli government is strange given a long, long history of high profile Israeli spying incidents against the US. https://en.wikipedia.org/wiki/Lawrence_Franklin_espionage_sc... https://en.wikipedia.org/wiki/Jonathan_Pollard https://en.wikipedia.org/wiki/Ben-Ami_Kadish https://en.wikipedia.org/wiki/Jack_Parsons_(rocket_engineer…

The USS Liberty incident happened 52 years ago.

>because they didn't like that we were watching them

That is the American conspiracy theorist interpretation of the incident that (understandably) also gained traction among a few of the survivors. The Israelis disagree.

It was most likely a case of mistaken identity. Just like friendly fire incidents. Friendly fire incidents happen all the time, including between US forces in the recent Iraq and Afghanistan conflict.

Re: U.S. State Department phones hacked with Israeli company spyware

#226

I thought the exploited holes were patched by iOS at some point. How are these phones still getting hacked?

In past exploits were used for jailbreaking. Now they can be sold for 6 figures. The incentive to report vulnerabilities or even use them casually for jailbreaking has gone way down. I think the only way would be for Apple to offer 6 figure pay outs for the exploits. Maybe they could get a tax write off.

Re: U.S. State Department phones hacked with Israeli company spyware

#227
post #189

Is anyone working on a microkernel design for privacy-sensitive devices (like phones) that would prevent outright this class of kernel-level arbitrary code execution exploits? We're stuck with iOS and Android for the foreseeable future, but is there hope that we'll get this right some day? Actually, would a microkernel design even be sufficient? Given that hackers exploit deserialization, memory safety, and variable…

Yep, a number of people are, myself included. OSDev channels have a few people who talk about it. The Fuchsia folks are around, too, and are quite friendly people. They probably have the most hopeful chance of a widespread release, though admittedly I worry about the affiliation with Google getting in the way of pro-consumerism. Just my opinion though.

Re: U.S. State Department phones hacked with Israeli company spyware

#228

Earlier quoted context omitted.

Maybe stop funding them, for a start? Congressional oversight used to be a thing. Snowden showed the NSA lied to congress. No heads rolled.

Imagine all the dirt the NSA has on congress.

Imagine how much society would improve if all the dirt got aired.

Hiding this information is trading the wellbeing of the country for the NSA's own internal goals and power.

Re: U.S. State Department phones hacked with Israeli company spyware

#229

Earlier quoted context omitted.

Wow! You found one instance of the US spying on a friendly government. That totally justifies NSO leasing spyware to authoritarian third world regimes! Carry on folks, nothing to see here.

It doesn't justify it, but if we're going to take a stance against spyware, we have to take a stance against all spyware. That includes the home-rolled stuff that the NSA pushes out to Apple and Google.

No, we don’t.

Re: U.S. State Department phones hacked with Israeli company spyware

#230

I don't understand the focus on NSO in these stories. If U.S State Department personnel in Uganda were shot from an M-16, would the headline mention "an American arms manufacturer"? No, because it's ridiculous. For better or worse, NSO's product is a weapon. How is it any different from an M-16? Where is the outrage towards the people who used this weapon against the State Department?

> For better or worse, NSO's product is a weapon. How is it any different from an M-16? Where is the outrage towards the people who used this weapon against the State Department?

It is highly unlikely that NSO group actually gives out their exploits, based on what we know about previous exploitations that have become known. It's more like they offer an interface to execute their exploits on a given target. The fact that they can block entities from using their service, after having had access to it (like they supposedly did in this case), very strongly supports this hypothesis. Hence they're offering a service, to use weapons for (or rather, in the name of) some (government) entity that pays them money to do so.

Imagine bombing-as-a-service, as an instance. That's much more like it, and your argument doesn't hold in that case.

Post reply on HN