MSM editors are a little tech literate these days but they have no authority on the matter. Any other contenders?
The battle for the world’s most powerful cyberweapon
61–70 of 87 posts
Re: The battle for the world’s most powerful cyberweapon
#62Earlier quoted context omitted.
But how would that basically clone my phone's content on their servers? (Which is claimed in the article) it must be some kind of weakness within the system, with some entry point other than some 'cookie'
> it must be some kind of weakness within the system You can assume there are many such weaknesses. Nothing is perfectly secure. Nuclear weapons plans are stolen, RSA's crypto keys were stolen ... your phone isn't protected on that level. Security is about raising the cost for an attacker beyond the value to that attacker: if you have data perceived to be worth $1M, make it cost $10M to steal it. But the cost to the…
Re: The battle for the world’s most powerful cyberweapon
#63After reading the title I thought this article was about the Intel Management Engine.
Re: The battle for the world’s most powerful cyberweapon
#64How is it that we can't have an OS that stops such things? I'm of the opinion that the NSA must have a long running covert program to discourage the adoption of secure operating systems. Multilevel Secure Operating Systems have existed since the 1980s, yet most people haven't even heard of them.
There's insufficient motivation for OS creators. It's possible to compile C code with various hardening options and pay a few percent overhead for it, but it remains almost entirely in the realm of academia... Except for the Xbox. Someone hacking an Xbox would lose _Microsoft_ money through piracy, which hurts their bottom line! As a result, the Xbox runs a type 1 hypervisor with various compiler hardening options li…
Re: The battle for the world’s most powerful cyberweapon
#65https://www.amazon.com/This-They-Tell-World-Ends/dp/16355760...
Re: The battle for the world’s most powerful cyberweapon
#66Why is the FBI paying to get Pegasus? Doesn't the US have NSA to do this kind of hacks or find no click zero days in Android/iPhone and share the zero days with the FBI? Or why hasn't someone try to trick NSO to hack a monitored phone and find out the zero day? I am having these questions because every time I hear about NSO there is this question in my head "What is so special about NSO?". I see 2017, 2018, etc. how…
Re: The battle for the world’s most powerful cyberweapon
#67Earlier quoted context omitted.
The NSA does have an organization devoted to developing these sorts of attacks that make the NSO group look like a bunch of kindergarteners as evidenced by the Snowden leaks. The CIA also, independently of the NSA, has an organization that develops these sorts of attacks that make the NSO group also look like a bunch of kindergarteners as evidenced by the Vault 7 leaks. Almost without a doubt, the FBI, DHS, US Navy,…
> The CIA also, independently of the NSA, has an organization that develops these sorts of attacks that make the NSO group also look like a bunch of kindergarteners as evidenced by the Vault 7 leaks. Have you actually looked at the Vault 7 leaks? There’s nothing there far beyond the capabilities of a NSO-type actor. NSO is at the level of a nation state, but so are all the nation states. It’s easy to think that funne…
Re: The battle for the world’s most powerful cyberweapon
#68Earlier quoted context omitted.
Which hardening options are Apple ignoring? I would have thought the standard types of ones (debian's default) would also be set on macos/ios, eg https://help.apple.com/xcode/mac/current/#/devf87a2ac8f From what I can tell all NSO's rigmarole of making a virtual machine in the PDF parser is to work around the existing mitigations. I guess they could also turn on asan etc in production but that's more than a few perce…
I don‘t know anything about the benefits of these options but if the tradeoff is only a slowdown of the device this should be an option given to the user. Maybe even payed for („hardened version“ at buy time) or through a subscription.
The whole OS feels much slower than regular Google Android, Osmand (map app) is barely usable (on a Pixel 4XL which isn't a low end phone by any means).
So I don't think we can discount how much slower a device will be with a more secure OS. It might be invisible on desktops, but certainly not on mobile.
Re: The battle for the world’s most powerful cyberweapon
#69Just imagine if we had a key escrow or other backdoor like FBI asked for. If governments were made up of 99.9% very honest people, hundreds of untrustworthy individuals would still have enormous power ready to be abused.
We already have a form of key escrow in the form of public PKI infra/root CAs, etc.
I'm not sure what would happen, though, if someone claimed that a CA had issued a certificate for their domain without permission. Assuming they could detect this and get the certificate revoked quickly, any attack could at least be stopped (after the damage had potentially already been done).
You're right, though, that there's little incentive for a government to not use "legal" methods to subvert a CA within its jurisdiction, and accuse the complaining site owner of false-flag attacking their own domain for media attention, or some other excuse.
If anything, I'm surprised that a government hasn't tried to poison-the-well of this system by creating a few boy-who-cried-wolf scenarios already.
Re: The battle for the world’s most powerful cyberweapon
#70I always find it amusing when a particular software artifact is treated as some kind of powerful weapon in itself, and not just the codification of some really smart people's ideas on the current state of the art in some domain. The number of people on earth that can do this kind of stuff would fit in football stadium. The people are the weapon, not the specific executable.