Live data from Hacker News

The battle for the world’s most powerful cyberweapon

nytimes.com

61–70 of 87 posts

Re: The battle for the world’s most powerful cyberweapon

#62
post #7

Earlier quoted context omitted.

But how would that basically clone my phone's content on their servers? (Which is claimed in the article) it must be some kind of weakness within the system, with some entry point other than some 'cookie'

> it must be some kind of weakness within the system You can assume there are many such weaknesses. Nothing is perfectly secure. Nuclear weapons plans are stolen, RSA's crypto keys were stolen ... your phone isn't protected on that level. Security is about raising the cost for an attacker beyond the value to that attacker: if you have data perceived to be worth $1M, make it cost $10M to steal it. But the cost to the…

They could think I am a terrorist and I am not even aware until I put a food in their country. I can't know, as I only have a marginal understanding what they think terrorism is.

Re: The battle for the world’s most powerful cyberweapon

#64

How is it that we can't have an OS that stops such things? I'm of the opinion that the NSA must have a long running covert program to discourage the adoption of secure operating systems. Multilevel Secure Operating Systems have existed since the 1980s, yet most people haven't even heard of them.

There's insufficient motivation for OS creators. It's possible to compile C code with various hardening options and pay a few percent overhead for it, but it remains almost entirely in the realm of academia... Except for the Xbox. Someone hacking an Xbox would lose _Microsoft_ money through piracy, which hurts their bottom line! As a result, the Xbox runs a type 1 hypervisor with various compiler hardening options li…

Maybe we should use Xbox instead of phones for secure communication?

Re: The battle for the world’s most powerful cyberweapon

#65
If you are interested in a detailed account of the cyberarms race, check out "This Is How They Tell Me the World Ends: The Cyberweapons Arms Race" by New York Times reporter Nicole Perlroth. While the books tends to get a tad repetitive after a while, and definitely skirts many of the technicalities, its definitely provides a lot of insight into the underground zero-day exploits markets and the cyberarms race that we are in right now.

https://www.amazon.com/This-They-Tell-World-Ends/dp/16355760...

Re: The battle for the world’s most powerful cyberweapon

#66

Why is the FBI paying to get Pegasus? Doesn't the US have NSA to do this kind of hacks or find no click zero days in Android/iPhone and share the zero days with the FBI? Or why hasn't someone try to trick NSO to hack a monitored phone and find out the zero day? I am having these questions because every time I hear about NSO there is this question in my head "What is so special about NSO?". I see 2017, 2018, etc. how…

NSO doesn't ask to see your warrant...

Re: The battle for the world’s most powerful cyberweapon

#67
post #29

Earlier quoted context omitted.

The NSA does have an organization devoted to developing these sorts of attacks that make the NSO group look like a bunch of kindergarteners as evidenced by the Snowden leaks. The CIA also, independently of the NSA, has an organization that develops these sorts of attacks that make the NSO group also look like a bunch of kindergarteners as evidenced by the Vault 7 leaks. Almost without a doubt, the FBI, DHS, US Navy,…

> The CIA also, independently of the NSA, has an organization that develops these sorts of attacks that make the NSO group also look like a bunch of kindergarteners as evidenced by the Vault 7 leaks. Have you actually looked at the Vault 7 leaks? There’s nothing there far beyond the capabilities of a NSO-type actor. NSO is at the level of a nation state, but so are all the nation states. It’s easy to think that funne…

My hunch is that size is harming MS and Google. I bet smaller companies, more focused and with the same budget would achieve more.

Re: The battle for the world’s most powerful cyberweapon

#68
post #27

Earlier quoted context omitted.

Which hardening options are Apple ignoring? I would have thought the standard types of ones (debian's default) would also be set on macos/ios, eg https://help.apple.com/xcode/mac/current/#/devf87a2ac8f From what I can tell all NSO's rigmarole of making a virtual machine in the PDF parser is to work around the existing mitigations. I guess they could also turn on asan etc in production but that's more than a few perce…

I don‘t know anything about the benefits of these options but if the tradeoff is only a slowdown of the device this should be an option given to the user. Maybe even payed for („hardened version“ at buy time) or through a subscription.

Just an anecdote but I use GrapheneOS on my phone. It's a security focused OS based on Android AOSP with in particular a secure memory allocation function.

The whole OS feels much slower than regular Google Android, Osmand (map app) is barely usable (on a Pixel 4XL which isn't a low end phone by any means).

So I don't think we can discount how much slower a device will be with a more secure OS. It might be invisible on desktops, but certainly not on mobile.

Re: The battle for the world’s most powerful cyberweapon

#69

Just imagine if we had a key escrow or other backdoor like FBI asked for. If governments were made up of 99.9% very honest people, hundreds of untrustworthy individuals would still have enormous power ready to be abused.

We already have a form of key escrow in the form of public PKI infra/root CAs, etc.

We also have a certificate transparency system to detect misissuance, and some precedent for economically ruining CAs who break the public's trust.

I'm not sure what would happen, though, if someone claimed that a CA had issued a certificate for their domain without permission. Assuming they could detect this and get the certificate revoked quickly, any attack could at least be stopped (after the damage had potentially already been done).

You're right, though, that there's little incentive for a government to not use "legal" methods to subvert a CA within its jurisdiction, and accuse the complaining site owner of false-flag attacking their own domain for media attention, or some other excuse.

If anything, I'm surprised that a government hasn't tried to poison-the-well of this system by creating a few boy-who-cried-wolf scenarios already.

Re: The battle for the world’s most powerful cyberweapon

#70

I always find it amusing when a particular software artifact is treated as some kind of powerful weapon in itself, and not just the codification of some really smart people's ideas on the current state of the art in some domain. The number of people on earth that can do this kind of stuff would fit in football stadium. The people are the weapon, not the specific executable.

I mean that’s kind of the definition of a weapon. The atomic bomb was also just the codification of some ideas into a physical machine.
Post reply on HN