Live data from Hacker News

U.S. State Department phones hacked with Israeli company spyware

reuters.com

261–270 of 651 posts

Re: U.S. State Department phones hacked with Israeli company spyware

#261
post #198
post #189

Is anyone working on a microkernel design for privacy-sensitive devices (like phones) that would prevent outright this class of kernel-level arbitrary code execution exploits? We're stuck with iOS and Android for the foreseeable future, but is there hope that we'll get this right some day? Actually, would a microkernel design even be sufficient? Given that hackers exploit deserialization, memory safety, and variable…

Many of the kernel issues exploited in iOS are caused indirectly by its microkernel architecture, namely, the use of "ports" for kernel to kernel and kernel to user land IPC. For example: https://bugs.chromium.org/p/project-zero/issues/detail?id=21... . Microkernel vs monolithic kernel has little to do with this, IMO. The main issues are asynchronous complexity and memory safety. Also, a lot of your most sensitive da…

And the userland is the worst possible combination of technology imaginable for this purpose - a memory unsafe language with a ton of magic dynamic features. You get the horrible serialization issues from Java & Ruby with the same old heap, stack and integer overflows we've come to love in C and mix in some of the runtime control flow from C++.

Re: U.S. State Department phones hacked with Israeli company spyware

#262

This is a typical "shadow government" symptom. You have forces working within the government that 1) have their own agendas; 2) have connection to international communities, usually military-intelligence ones; 3) have almost zero regulation; 4) even many high ranking government officials don't know about them because they are brotherhood-like closed circles. This reminds me of Operation Gladio or Propaganda Due but d…

There is nothing supporting the theory or conclusion

Re: U.S. State Department phones hacked with Israeli company spyware

#264

This is a typical "shadow government" symptom. You have forces working within the government that 1) have their own agendas; 2) have connection to international communities, usually military-intelligence ones; 3) have almost zero regulation; 4) even many high ranking government officials don't know about them because they are brotherhood-like closed circles. This reminds me of Operation Gladio or Propaganda Due but d…

Implying that Israeli spying on the US is some fringe "shadow government" sub-group of the Israeli government is strange given a long, long history of high profile Israeli spying incidents against the US. https://en.wikipedia.org/wiki/Lawrence_Franklin_espionage_sc... https://en.wikipedia.org/wiki/Jonathan_Pollard https://en.wikipedia.org/wiki/Ben-Ami_Kadish https://en.wikipedia.org/wiki/Jack_Parsons_(rocket_engineer…

The US spies on its European allies all the time, and I'm sure they spy on Israel too, so that's not super surprising.

As for the USS Liberty, some do argue that it was intentional, but both the Israelis and Americans ended up agreeing that it was a mistake. The US is no stranger to such mistakes either, even more egregious ones like when they killed close to 300 civilians aboard a regular passenger flight following an approved route and in contact with ATC (Iran Air 655).

In the end both the US and Israel are amoral states that act only according to their economic and strategic interests and I feel that this unites them. I wish it didn't, though.

Re: U.S. State Department phones hacked with Israeli company spyware

#265

Earlier quoted context omitted.

The USS Liberty incident happened 52 years ago. >because they didn't like that we were watching them That is the American conspiracy theorist interpretation of the incident that (understandably) also gained traction among a few of the survivors. The Israelis disagree. It was most likely a case of mistaken identity. Just like friendly fire incidents. Friendly fire incidents happen all the time, including between US fo…

The survivors said that the pilots were waving at them before they carried out the attack

can you provide the source?

Re: U.S. State Department phones hacked with Israeli company spyware

#266
post #242

Earlier quoted context omitted.

Maybe stop funding them, for a start? Congressional oversight used to be a thing. Snowden showed the NSA lied to congress. No heads rolled.

I can believe there are shadow organizations that lack oversight. In fact, it seems likely. But that these shadow organizations are maintaining power by surveiling and blackmailing congress people is a whole other ballgame and seems highly unlikely to me. For one, it's likely that not every Congressperson has some deep dark secret that makes them blackmail-able. And pissing off the only group of people that could cut…

> For one, it's likely that not every Congressperson has some deep dark secret that makes them blackmail-able.

I'd be more than willing to bet that they do. "If you give me six lines written by the hand of the most honest of men, I will find something in them which will hang him." and that only covers "honest" men who wouldn't have illegal coordination with PACs, bribes with lobbyists, personal communications filled with racism, or evidence of sexual activities that might upset their base. When "6 lines" becomes a record of everything you've ever done online, all of your communications, your GPS coordinates and the data of anyone around you it's going to get easier to find a noose around your neck.

Even if there managed to exist a single person in congress who wasn't screwing over the American people somehow for personal gain, or didn't have some skeleton in their closet they didn't want exposed to voters/campaign contributors when a group is capable of compromising your system and inserting whatever offensive material they want to use against you it's incentive enough to back off.

Re: U.S. State Department phones hacked with Israeli company spyware

#267
post #228

Earlier quoted context omitted.

Imagine how much society would improve if all the dirt got aired. Hiding this information is trading the wellbeing of the country for the NSA's own internal goals and power.

> Imagine how much society would improve if all the dirt got aired. Depends on the dirt. Some of it might be private and personal stuff, such as infidelity. That type of stuff, while blackmailable, doesn't really benefit the public much.

The public's elected representatives being easily blackmailable is obviously of great concern to the public, I don't know why you're downplaying this.

Re: U.S. State Department phones hacked with Israeli company spyware

#269
post #189

Is anyone working on a microkernel design for privacy-sensitive devices (like phones) that would prevent outright this class of kernel-level arbitrary code execution exploits? We're stuck with iOS and Android for the foreseeable future, but is there hope that we'll get this right some day? Actually, would a microkernel design even be sufficient? Given that hackers exploit deserialization, memory safety, and variable…

The Intel ME runs a microkernel but it is still exploitable (even if you "clean" it).

SEL4 and Fuchsia seem to have a security focus, but whether that results in real world difficult to exploit devices is unclear.

Re: U.S. State Department phones hacked with Israeli company spyware

#270

Earlier quoted context omitted.

> that remains to be seen Oh man, for purely comical purposes I would love to see NSO actually believe that.

In principle, America could drop Hellfire R9X sword missiles through the cars of every NSO employee. In practice, would American politicians have the nerve to go to war with NSO, when NSO probably infected all their phones years ago? How much dirt do they have on American politicians?

So you think because NSO breached a few state department phones that they have the deep dirt on every sitting congress member?
Post reply on HN