The battle for the world’s most powerful cyberweapon
1–10 of 87 posts
Re: The battle for the world’s most powerful cyberweapon
#2Re: The battle for the world’s most powerful cyberweapon
#3Re: The battle for the world’s most powerful cyberweapon
#4Re: The battle for the world’s most powerful cyberweapon
#5They always talk about phone numbers, does that mean without a number I am safe from that attack?
basically instead of "Credit card purchase -> phone number -> person ID" they would use "credit card purchase -> semi-persistent hash -> person ID"
Re: The battle for the world’s most powerful cyberweapon
#6Janek's Box?
Re: The battle for the world’s most powerful cyberweapon
#7They always talk about phone numbers, does that mean without a number I am safe from that attack?
I would bet they have a semi-persistent "non-logged user session cookies" to track you. Just like every other Advertising/publisher does already. basically instead of "Credit card purchase -> phone number -> person ID" they would use "credit card purchase -> semi-persistent hash -> person ID"
Re: The battle for the world’s most powerful cyberweapon
#8Re: The battle for the world’s most powerful cyberweapon
#9Earlier quoted context omitted.
I would bet they have a semi-persistent "non-logged user session cookies" to track you. Just like every other Advertising/publisher does already. basically instead of "Credit card purchase -> phone number -> person ID" they would use "credit card purchase -> semi-persistent hash -> person ID"
But how would that basically clone my phone's content on their servers? (Which is claimed in the article) it must be some kind of weakness within the system, with some entry point other than some 'cookie'
So in essence, they're selling limited time exploits to load malware and I guess having to constantly find new exploits to sell. Hell of a business model for sure.
https://www.occrp.org/en/the-pegasus-project/how-does-pegasu...
Re: The battle for the world’s most powerful cyberweapon
#10Earlier quoted context omitted.
But how would that basically clone my phone's content on their servers? (Which is claimed in the article) it must be some kind of weakness within the system, with some entry point other than some 'cookie'
I had the same question, and this article seems to at least attempt to answer this question referring to an ongoing legal case by several tech companies against NSO. Essentially, they're leveraging exploits in various apps (iMessage, WhatsApp, Gmail, etc) commonly found on phones to infect the end user. So in essence, they're selling limited time exploits to load malware and I guess having to constantly find new expl…
In that case it can't be as perfect as they claim, except they have a huge list of apps to target what very well could be the case.
Edit:// Oh
> including Gmail, Facebook, WhatsApp, FaceTime, Viber, WeChat, Telegram, Apple’s built-in messaging and email apps, and others.