Live data from Hacker News

Finnish diplomats’ phones infected with NSO Group Pegasus spyware

bleepingcomputer.com

31–40 of 113 posts

Re: Finnish diplomats’ phones infected with NSO Group Pegasus spyware

#31

Although I'm certainly no celebrity / important likely target of hackers, I'm interested in this just because recently I've gotten paranoid about my financial accounts (after a company I used to work for finally went public and I was fortunate to cash out an amount of $). When hackers use such exploits, do they then basically have something like remote control over your phone, and can start exfiltrating data / manipu…

The capabilities depend on the specific exploit but if you're dealing with something like Pegasus, the answer is yes to almost all those questions.

> I wonder if there is some resource where people can read about how to detect and avoid such exploits and protect against them?

Protecting against the cutting edge of current nation-state attacks [1] is... well, it's not impossible but it's up there. Just don't be important/interesting enough to catch their wrath is the TL;DR.

That said, see: https://docs.mvt.re/en/latest/introduction/

[1]: https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...

Re: Finnish diplomats’ phones infected with NSO Group Pegasus spyware

#32
post #7

Earlier quoted context omitted.

Contrary to popular belief, iPhones and Android phones have really poor security and new exploits are discovered all the time. So a properly formatted text message is all that's required these days. It's like in the dotcom days when 90% of the web was open to SQL injection.

It’s not at all like in the dotcom days. Unlike SQL injections, these aren’t low skill attacks that can be mounted by skiddies.

You are right in that these attacks takes more skills or a little bit of money, so in that regard it's not the same.

But in multiple ways I think it's the same; like that it's obvious that security is still not a priority when building the software and that you as a user have to assume that the platforms are compromised.

Re: Finnish diplomats’ phones infected with NSO Group Pegasus spyware

#33

Although I'm certainly no celebrity / important likely target of hackers, I'm interested in this just because recently I've gotten paranoid about my financial accounts (after a company I used to work for finally went public and I was fortunate to cash out an amount of $). When hackers use such exploits, do they then basically have something like remote control over your phone, and can start exfiltrating data / manipu…

Someone who has access to Pegasus is not going after finances. I had modest amount of ethereum on my PC, was hacked, but I still had control over my wallet. If you have $1M+ it should not be tied to your sim card, GMail account etc... If you use the same device to access your bank accounts, and to browse internet or receive messages, you are like an idiot who does not do backups!

So you mean for example, you keep your Authenticator app on a device completely separate from your phone / disconnected from the internet?

Re: Finnish diplomats’ phones infected with NSO Group Pegasus spyware

#34

Although I'm certainly no celebrity / important likely target of hackers, I'm interested in this just because recently I've gotten paranoid about my financial accounts (after a company I used to work for finally went public and I was fortunate to cash out an amount of $). When hackers use such exploits, do they then basically have something like remote control over your phone, and can start exfiltrating data / manipu…

Make sure your big $$$ are not available easily. Find a bank/brokerage that will actually do their job verifying you before they dispense your money.

You are not able to defend yourself from targeted attacks. Period.

It is one thing to try to defend from attacks of opportunity (ie. viruses, ransomware, etc.) and another from people who actually know their job and for some reason find yourself attractive target.

Thus, the best way to respond is to not make yourself attractive target in the first place and if you need to have attractive things somewhere -- separate them from everything else.

Re: Finnish diplomats’ phones infected with NSO Group Pegasus spyware

#35

Earlier quoted context omitted.

Someone who has access to Pegasus is not going after finances. I had modest amount of ethereum on my PC, was hacked, but I still had control over my wallet. If you have $1M+ it should not be tied to your sim card, GMail account etc... If you use the same device to access your bank accounts, and to browse internet or receive messages, you are like an idiot who does not do backups!

So you mean for example, you keep your Authenticator app on a device completely separate from your phone / disconnected from the internet?

2FA is a good option for securing your centralized accounts. But unfortunately, if you're logged in on your phone and your phone is hacked, well, it's still game over.

For crypto currencies it may help to store them on a hardware wallet, since accessing your money will require explicit interaction. But, as far as I understand (please correct me, not up to date with the security mechanisms of hardware wallets), if your computer is compromised while doing it, you can still lose it.

Re: Finnish diplomats’ phones infected with NSO Group Pegasus spyware

#36

Earlier quoted context omitted.

Someone who has access to Pegasus is not going after finances. I had modest amount of ethereum on my PC, was hacked, but I still had control over my wallet. If you have $1M+ it should not be tied to your sim card, GMail account etc... If you use the same device to access your bank accounts, and to browse internet or receive messages, you are like an idiot who does not do backups!

In that case, the majority of the people in the world with more than $1MM are idiots.

The advantage of centralized services tied to your clear identity is that they do some diligence to ensure the person accessing your account is actually you. You (often) even have a reasonable recourse to undo things that have been done fraudulently.

Re: Finnish diplomats’ phones infected with NSO Group Pegasus spyware

#37

Earlier quoted context omitted.

No, they use zero-day exploits in common media formats. The spy sends you a message containing an image or pdf, your device parses it, is exploited, and then removes the message, before there ever is a notification about it. You will never know that it ever happened. For example, see FORCEDENTRY, which is one of theirs, and the technical deep dive of it is about the most amazing piece of technical writing released la…

I can't believe that all text messages aren't stored somewhere on the NSA (or equiv.) server (so it should be easy to quickly find the zero-day after a single attack). They probably just aren't motivated enough to expose the zero-days associated with it.

Why would the NSA be motivated to find these vulnerabilities? They already have access to Pegasus :-)

... you don't think they're interested in closing them, do you?

Re: Finnish diplomats’ phones infected with NSO Group Pegasus spyware

#38

When are governments going to finally realize that voice calls, text, and maybe plaintext email are enough for work phones? Is playing Candy Crush on your work phone really a mission-critical cyberpriority? All the high-security executive/legislative people (at least in the US) have two phones: the personal phone and the work phone. Whoever made the decision for the work phones to be "smart" needs to be fired. The ol…

Is there some overview about what phones governments use in high-securitiy contexts? It would be interesting to see what they consider secure, since that's probably informed by their own capabilities. Last time I checked Obama was using a BlackBerry.

Re: Finnish diplomats’ phones infected with NSO Group Pegasus spyware

#39
post #20

Earlier quoted context omitted.

Quoted post unavailable.

What? That comment wasn’t even made by me.

I apologize. It seems that you entered your comment right where the other comment was moments before. I saw your comment already grayed due to downvotes and since the previous comment gained some downvotes, I wrongly assumed that it was edited.

The original comment was made by the user iqanq. Once again, I'm sorry.

Re: Finnish diplomats’ phones infected with NSO Group Pegasus spyware

#40

Earlier quoted context omitted.

> If you use the same device to access your bank accounts, and to browse internet or receive messages, you are like an idiot who does not do backups! Using ones phone for banking, internet, and sms is completely normal. Saying that 99.9999999999999999% of the world population that owns smartphones is an idiot isn't helpful. The idiots are the governments of the world that haven't sanctioned Israel for allowing the co…

Quoted post unavailable.

>And your comment is just antisemitic.

It's dangerous tossing that term around. There is enough real antisemitism in the world, and it's a real problem, we don't need to make-pretend extra. Critisism of the state of Israel does not equate antisemitism.

Post reply on HN