Live data from Hacker News

The battle for the world’s most powerful cyberweapon

nytimes.com

11–20 of 87 posts

Re: The battle for the world’s most powerful cyberweapon

#11

Why is the FBI paying to get Pegasus? Doesn't the US have NSA to do this kind of hacks or find no click zero days in Android/iPhone and share the zero days with the FBI? Or why hasn't someone try to trick NSO to hack a monitored phone and find out the zero day? I am having these questions because every time I hear about NSO there is this question in my head "What is so special about NSO?". I see 2017, 2018, etc. how…

Paying is the key. NSA doing it for FBI would generate no profit for anyone. Given various loopholes exploiting arrangements between allied security services, I'd not be surprised if NSA were a source of 0days for NSO.

Re: The battle for the world’s most powerful cyberweapon

#12

Why is the FBI paying to get Pegasus? Doesn't the US have NSA to do this kind of hacks or find no click zero days in Android/iPhone and share the zero days with the FBI? Or why hasn't someone try to trick NSO to hack a monitored phone and find out the zero day? I am having these questions because every time I hear about NSO there is this question in my head "What is so special about NSO?". I see 2017, 2018, etc. how…

the competition for NSO within the US would be traditional defense contractors: raytheon, l3harris, etc.

One can make much more money with the DoD than the DoJ.

Re: The battle for the world’s most powerful cyberweapon

#14
post #7

Earlier quoted context omitted.

I would bet they have a semi-persistent "non-logged user session cookies" to track you. Just like every other Advertising/publisher does already. basically instead of "Credit card purchase -> phone number -> person ID" they would use "credit card purchase -> semi-persistent hash -> person ID"

But how would that basically clone my phone's content on their servers? (Which is claimed in the article) it must be some kind of weakness within the system, with some entry point other than some 'cookie'

> it must be some kind of weakness within the system

You can assume there are many such weaknesses. Nothing is perfectly secure. Nuclear weapons plans are stolen, RSA's crypto keys were stolen ... your phone isn't protected on that level. Security is about raising the cost for an attacker beyond the value to that attacker: if you have data perceived to be worth $1M, make it cost $10M to steal it.

But the cost to the defender is relatively high. There is no way your phone, whatever you use, is perfectly secure; there is no way every app on your phone is perfectly secure; the cost would be astromical to the vendors. There are endless possible holes.

The question is, what is the perceived value of the contents of your phone? Are you the Secretary of Defense or the CEO of a Fortune 100 company? An international terrorist? If they really want you, they've got you (unless you pay for some serious personnel). They could just replace your phone with an identical one containing a little extra hardware, for example.

But your phone almost certainly isn't perceived to have that level of value.

Re: The battle for the world’s most powerful cyberweapon

#17

The most powerful cyberweapon is making sure every human understands an inkling of number theory

So everyone's invented their own cryptography. Great! I'll just buffer-overflow the TCP stack and let myself in; then I can read all their messages after they've decrypted them.

Rock, meet paper.

Re: The battle for the world’s most powerful cyberweapon

#18
post #11

Why is the FBI paying to get Pegasus? Doesn't the US have NSA to do this kind of hacks or find no click zero days in Android/iPhone and share the zero days with the FBI? Or why hasn't someone try to trick NSO to hack a monitored phone and find out the zero day? I am having these questions because every time I hear about NSO there is this question in my head "What is so special about NSO?". I see 2017, 2018, etc. how…

Paying is the key. NSA doing it for FBI would generate no profit for anyone. Given various loopholes exploiting arrangements between allied security services, I'd not be surprised if NSA were a source of 0days for NSO.

I would 100% be surprised if NSO was being supplied with vulnerabilities from government agencies. If anything it is likely to be the other way around.

Re: The battle for the world’s most powerful cyberweapon

#20
How is it that we can't have an OS that stops such things?

I'm of the opinion that the NSA must have a long running covert program to discourage the adoption of secure operating systems.

Multilevel Secure Operating Systems have existed since the 1980s, yet most people haven't even heard of them.

Post reply on HN