Live data from Hacker News

The battle for the world’s most powerful cyberweapon

nytimes.com

1–10 of 87 posts

Re: The battle for the world’s most powerful cyberweapon

#5
post #2

They always talk about phone numbers, does that mean without a number I am safe from that attack?

I would bet they have a semi-persistent "non-logged user session cookies" to track you. Just like every other Advertising/publisher does already.

basically instead of "Credit card purchase -> phone number -> person ID" they would use "credit card purchase -> semi-persistent hash -> person ID"

Re: The battle for the world’s most powerful cyberweapon

#7
post #2

They always talk about phone numbers, does that mean without a number I am safe from that attack?

I would bet they have a semi-persistent "non-logged user session cookies" to track you. Just like every other Advertising/publisher does already. basically instead of "Credit card purchase -> phone number -> person ID" they would use "credit card purchase -> semi-persistent hash -> person ID"

But how would that basically clone my phone's content on their servers? (Which is claimed in the article) it must be some kind of weakness within the system, with some entry point other than some 'cookie'

Re: The battle for the world’s most powerful cyberweapon

#8
Why is the FBI paying to get Pegasus? Doesn't the US have NSA to do this kind of hacks or find no click zero days in Android/iPhone and share the zero days with the FBI? Or why hasn't someone try to trick NSO to hack a monitored phone and find out the zero day? I am having these questions because every time I hear about NSO there is this question in my head "What is so special about NSO?". I see 2017, 2018, etc. how can someone have zero days for years and no one copy the zero day or fix the zero day? Why I don't hear about NSO competition? Does it have competition?

Re: The battle for the world’s most powerful cyberweapon

#9
post #7

Earlier quoted context omitted.

I would bet they have a semi-persistent "non-logged user session cookies" to track you. Just like every other Advertising/publisher does already. basically instead of "Credit card purchase -> phone number -> person ID" they would use "credit card purchase -> semi-persistent hash -> person ID"

But how would that basically clone my phone's content on their servers? (Which is claimed in the article) it must be some kind of weakness within the system, with some entry point other than some 'cookie'

I had the same question, and this article seems to at least attempt to answer this question referring to an ongoing legal case by several tech companies against NSO. Essentially, they're leveraging exploits in various apps (iMessage, WhatsApp, Gmail, etc) commonly found on phones to infect the end user.

So in essence, they're selling limited time exploits to load malware and I guess having to constantly find new exploits to sell. Hell of a business model for sure.

https://www.occrp.org/en/the-pegasus-project/how-does-pegasu...

Re: The battle for the world’s most powerful cyberweapon

#10
post #7

Earlier quoted context omitted.

But how would that basically clone my phone's content on their servers? (Which is claimed in the article) it must be some kind of weakness within the system, with some entry point other than some 'cookie'

I had the same question, and this article seems to at least attempt to answer this question referring to an ongoing legal case by several tech companies against NSO. Essentially, they're leveraging exploits in various apps (iMessage, WhatsApp, Gmail, etc) commonly found on phones to infect the end user. So in essence, they're selling limited time exploits to load malware and I guess having to constantly find new expl…

That sounds horrible, but thanks for the link!

In that case it can't be as perfect as they claim, except they have a huge list of apps to target what very well could be the case.

Edit:// Oh

> including Gmail, Facebook, WhatsApp, FaceTime, Viber, WeChat, Telegram, Apple’s built-in messaging and email apps, and others.

Post reply on HN