Live data from Hacker News

The battle for the world’s most powerful cyberweapon

nytimes.com

71–80 of 87 posts

Re: The battle for the world’s most powerful cyberweapon

#71

Why is the FBI paying to get Pegasus? Doesn't the US have NSA to do this kind of hacks or find no click zero days in Android/iPhone and share the zero days with the FBI? Or why hasn't someone try to trick NSO to hack a monitored phone and find out the zero day? I am having these questions because every time I hear about NSO there is this question in my head "What is so special about NSO?". I see 2017, 2018, etc. how…

Law enforcement is not NSA's job. They have no reason to help FBI here.

Re: The battle for the world’s most powerful cyberweapon

#72

I always find it amusing when a particular software artifact is treated as some kind of powerful weapon in itself, and not just the codification of some really smart people's ideas on the current state of the art in some domain. The number of people on earth that can do this kind of stuff would fit in football stadium. The people are the weapon, not the specific executable.

I mean that’s kind of the definition of a weapon. The atomic bomb was also just the codification of some ideas into a physical machine.

>The atomic bomb was also just the codification of some ideas into a physical machine.

No, it wasn't. It was the product of the entire industrial capacity of the United States. The amount of Deuterium required for a fission bomb took years of labor by hundreds of thousands of people to produce. The "ideas" were worthless without the physical infrastructure and industrial capacity to carry out the construction.

Software, on the other hand, requires nothing more than really really smart people and a $200 laptop.

Re: The battle for the world’s most powerful cyberweapon

#73
post #50
post #48

Earlier quoted context omitted.

.

Thank you for the reply. I was actually only expecting an answer to 1 or 2 of them rather than all of them. 2 and 3 were more questions on the business side of (expenditure on staff finding exploits / expected number to find per year) rather than raw expenses and 4 was more a monetary return rather than a ROI, but thank you for all the answers nonetheless. Just for clarification, am I correctly understanding your ans…

I think it's funny that you were able to exploit someone working in the industry into giving up information they shouldn't have merely by stating your speculation as fact.

Who needs 0-days when you have Cunningham's Law[1]?

I'm just trolling, but it apparently did happen here. :)

1: https://meta.wikimedia.org/wiki/Cunningham%27s_Law

Re: The battle for the world’s most powerful cyberweapon

#74

Earlier quoted context omitted.

I don‘t know anything about the benefits of these options but if the tradeoff is only a slowdown of the device this should be an option given to the user. Maybe even payed for („hardened version“ at buy time) or through a subscription.

Just an anecdote but I use GrapheneOS on my phone. It's a security focused OS based on Android AOSP with in particular a secure memory allocation function. The whole OS feels much slower than regular Google Android, Osmand (map app) is barely usable (on a Pixel 4XL which isn't a low end phone by any means). So I don't think we can discount how much slower a device will be with a more secure OS. It might be invisible…

If the secure OS had the same development velocity as the OEM profit OS, the secure OS would be much better optimized than it currently is and likely much much more secure, too.

Android and iOS are optimized in general and for example Google or Samsung also optimize and distribute it for specific hardware. GrapheneOS is not well funded and has little influence in hardware development. The development of Graphene from AOSP is pretty much guaranteed to de-optimize it in the short term.

While there is little about mobile that would cause a secure OS to be noticably slower, much less mature software with many fewer deployments is expectedly less optimized.

Re: The battle for the world’s most powerful cyberweapon

#75
Not often we get to witness such a clear spread of a new technological evil in, what, half a generation? The potential this industry has to inexpensively damage nascent democracies and justice efforts is astounding.

They've 'democratised' the coup d'état and the absolute cover-up.

Shame on all of them.

Re: The battle for the world’s most powerful cyberweapon

#76

Earlier quoted context omitted.

> Afaik, neither of these things has been proven. It's not even clear (at least to me) what a proof of "difficulty" would look like. You would have to prove that no mathematical process could exist that was capable of (for example) factoring a composite number N in less than M steps (where M is a function of N), and prove that each step has some minimum energy or time requirement, to ground the "difficulty" in terms…

It would be a reduction of discrete-log/factorization to some algorithm with known lower bounds on runtime/space for a given probability of success.

But could there ever be a guarantee that no more efficient algorithm could be found? I agree that, given an algorithm, you can reason about the runtime/space/probability requirements that it places on an implementation, but you also have to contend with different models of computation.

According to Wikipedia, the "quantum complexity-theoretic Church–Turing thesis" states that: "A quantum Turing machine can efficiently simulate any realistic model of computation."[0] but even assuming this is true, and that we could build a practical general purpose quantum computer, the word "efficiently" here only means "up to polynomial-time reductions", and I don't think we can know in advance what polynomial-time reductions could be discovered.

[0] https://en.wikipedia.org/wiki/Church%E2%80%93Turing_thesis#V...

Re: The battle for the world’s most powerful cyberweapon

#77

Earlier quoted context omitted.

> Afaik, neither of these things has been proven. It's not even clear (at least to me) what a proof of "difficulty" would look like. You would have to prove that no mathematical process could exist that was capable of (for example) factoring a composite number N in less than M steps (where M is a function of N), and prove that each step has some minimum energy or time requirement, to ground the "difficulty" in terms…

Something like this? https://en.m.wikipedia.org/wiki/Halting_problem

We can prove that it is a logical impossibility for some algorithm to exist, but I don't think we can say, given an algorithm with a certain set of steps, that there isn't an equivalent algorithm that requires fewer steps.

Also, "steps" here would have to be measured in terms of operations on a physical machine (or at least an idealised perfectly efficient physical machine), but different architectures would allow different operations, and that's before we start considering different models of computation.

Re: The battle for the world’s most powerful cyberweapon

#78

Earlier quoted context omitted.

We already have a form of key escrow in the form of public PKI infra/root CAs, etc.

We also have a certificate transparency system to detect misissuance, and some precedent for economically ruining CAs who break the public's trust. I'm not sure what would happen, though, if someone claimed that a CA had issued a certificate for their domain without permission. Assuming they could detect this and get the certificate revoked quickly, any attack could at least be stopped (after the damage had potential…

Remember that rogue driver signed by a “leaked” cert?

Things like that are a lot more useful than fooling someone about some silly website.

Updates to your OS or secure apps (lmao) funded by the abc soup (Signal and Free Radio Asia, read up) could be signed by the government.

For the greater good, citizen.

Re: The battle for the world’s most powerful cyberweapon

#79

Earlier quoted context omitted.

We also have a certificate transparency system to detect misissuance, and some precedent for economically ruining CAs who break the public's trust. I'm not sure what would happen, though, if someone claimed that a CA had issued a certificate for their domain without permission. Assuming they could detect this and get the certificate revoked quickly, any attack could at least be stopped (after the damage had potential…

Remember that rogue driver signed by a “leaked” cert? Things like that are a lot more useful than fooling someone about some silly website. Updates to your OS or secure apps (lmao) funded by the abc soup (Signal and Free Radio Asia, read up) could be signed by the government. For the greater good, citizen.

Does Chrome do certificate transparency on its own updates?

Re: The battle for the world’s most powerful cyberweapon

#80

Earlier quoted context omitted.

We also have a certificate transparency system to detect misissuance, and some precedent for economically ruining CAs who break the public's trust. I'm not sure what would happen, though, if someone claimed that a CA had issued a certificate for their domain without permission. Assuming they could detect this and get the certificate revoked quickly, any attack could at least be stopped (after the damage had potential…

Remember that rogue driver signed by a “leaked” cert? Things like that are a lot more useful than fooling someone about some silly website. Updates to your OS or secure apps (lmao) funded by the abc soup (Signal and Free Radio Asia, read up) could be signed by the government. For the greater good, citizen.

Apps and OSes shouldn't (and don't need to) make their security dependent on the web PKI. Linux distros come with their own public keys, for example, which are used to check the signatures on package updates.

Things have got a bit worse recently, with the Google Play Store requiring app developers to let it build and sign the packages itself[0], but I suppose the argument is that if you don't trust Alphabet with the app signing keys, you shouldn't trust it with the signing keys for the OS updates you download.

(If your Android updates are signed by keys controlled by an entity other than Alphabet, then you can presumably use an alternative app repo too).

[0] https://www.theregister.com/2021/07/01/android_app_bundle/

Post reply on HN