Live data from Hacker News

Finnish diplomats’ phones infected with NSO Group Pegasus spyware

bleepingcomputer.com

61–70 of 113 posts

Re: Finnish diplomats’ phones infected with NSO Group Pegasus spyware

#61

Although I'm certainly no celebrity / important likely target of hackers, I'm interested in this just because recently I've gotten paranoid about my financial accounts (after a company I used to work for finally went public and I was fortunate to cash out an amount of $). When hackers use such exploits, do they then basically have something like remote control over your phone, and can start exfiltrating data / manipu…

When I received a huge amount of cash some years ago, my outlook changed completely. The first thing to do was to split the money in order not to keep everything in one basket. I choose banks with unvieldy, problematic protection schemes that are awkward to use. And I set up a dedicated old laptop for banking (which still works).

My biggest paranoia wasn't about remote access though. I was really afraid someone could counterfeit my ID and just cash out as much as they could get away with. Fortunately, it hasn't happened to me.

Re: Finnish diplomats’ phones infected with NSO Group Pegasus spyware

#62

Although I'm certainly no celebrity / important likely target of hackers, I'm interested in this just because recently I've gotten paranoid about my financial accounts (after a company I used to work for finally went public and I was fortunate to cash out an amount of $). When hackers use such exploits, do they then basically have something like remote control over your phone, and can start exfiltrating data / manipu…

Give written instructions to your bank requiring them know to engage in transactions over a certain amount without a certain set of verification procedures (for example a call back with a prearranged password for any wire was one that I had with my old bank), and have them acknowledge receipt in writing as well. In the unlikely/unfortunate event that your money is stolen - recouping from the financial institution will be more straightforward if they didn’t follow procedures and you can prove it.

Re: Finnish diplomats’ phones infected with NSO Group Pegasus spyware

#63
post #34

Earlier quoted context omitted.

Make sure your big $$$ are not available easily. Find a bank/brokerage that will actually do their job verifying you before they dispense your money. You are not able to defend yourself from targeted attacks. Period. It is one thing to try to defend from attacks of opportunity (ie. viruses, ransomware, etc.) and another from people who actually know their job and for some reason find yourself attractive target. Thus,…

Putnam investments are really hard to get money out of. For example, I tried to cash in an annuity, and it required a medallion certificate by another bank. A medallion certificate is like a notary but is only done by another bank.

Depends how motivated the attackers are. They can try to find another bank with weaker rules, perhaps open an account there first.

I needed one of those things, and shopped around for a bit. And while all the big names would refuse, had waiting periods, fees, other requirements, a local credit union gave me one after signing up for a savings account immediately with a minimal or no fee.

Re: Finnish diplomats’ phones infected with NSO Group Pegasus spyware

#64

Although I'm certainly no celebrity / important likely target of hackers, I'm interested in this just because recently I've gotten paranoid about my financial accounts (after a company I used to work for finally went public and I was fortunate to cash out an amount of $). When hackers use such exploits, do they then basically have something like remote control over your phone, and can start exfiltrating data / manipu…

I have a separate phone specifically used for banking (since banks require me to install their 2fa app on my phone) and have a unique sim card that I only use for banks.

It's not 100% foolproof I guess but at least it reduces my risk.

Re: Finnish diplomats’ phones infected with NSO Group Pegasus spyware

#65
post #7

Earlier quoted context omitted.

Contrary to popular belief, iPhones and Android phones have really poor security and new exploits are discovered all the time. So a properly formatted text message is all that's required these days. It's like in the dotcom days when 90% of the web was open to SQL injection.

Meanwhile, they take 30% cut from developers and force everyone to buy a new phone every year. Microsoft monopolization of Windows is a child play in comparison to this phone racket.

My iPhone 7 is a handmedown that I got 3 years ago. I see no reason to upgrade until it A) dies or B) stops receiving security updates, at which point I’ll probably just get another handmedown from someone who likes new things more than I do.

Re: Finnish diplomats’ phones infected with NSO Group Pegasus spyware

#66
post #40

Earlier quoted context omitted.

>And your comment is just antisemitic. It's dangerous tossing that term around. There is enough real antisemitism in the world, and it's a real problem, we don't need to make-pretend extra. Critisism of the state of Israel does not equate antisemitism.

Quoted post unavailable.

ok, I'll expand on this quickly:

1. The state of Israel is the only state in the area where both Jews and Arabs are welcome and have a place in government and legislative bodies. Much of the "legitimate criticism" of Israel isn't directed at the Arabs in Israel it seems to I claim thinly veiled hate against the Jewish part of the population.

2. If one argues that it is against the Jewish part of the population because they dominate then one cannot say it is against the state of Israel only because then the difference doesn't mean anything.

Re: Finnish diplomats’ phones infected with NSO Group Pegasus spyware

#68

What about patching the vulnerabilities rather than running around with anger? We can sue the hell out of them and convince the Israeli government to ban them altogether but this is obviously doomed to repeat, somebody will inevitably take the place sooner or later, legally or illegally.

Patching won't help, if you are diplomat, that has to use communication towers in a country, that is spying on you. Also, phone OS all allow incoming of sms, that are not visible - because that is how they are built. Those messages are there for technical reasons and that is also making them easy to exploit.

Also, Israeli government simply can't forbid their companies to do, what US companies are not forbidden to do, because that option is only available to totalitarian states.

Patching is not an issue here, but your ability to take your own(and if you are a really lucky - then others) government by balls and squeeze hard, if they do this stuff. If you do not have ability to get government by balls, then government is squeezing your balls already.

Re: Finnish diplomats’ phones infected with NSO Group Pegasus spyware

#69

NSO is just the one that sells a fully weaponized product but many companies out there are capable of selling you exploits with similar capabilities. Like Zerodium,Immunity Inc etc etc

so much this. the discussion around NSO (specifically in Israel this past week) has become so exhausting

NSO marketing enjoy the fact they are shown as some super powered company who has been able and always will be able to get full control of every phone on earth. One dramatic news investigation showed exclusive video of NSO branded server racks[1] in an African country. Who cares about the servers? All pegasus needs is an internet connection, you could probably run it from a Chromebook

As the NSO 0-day bank has changed over the years, so have their capabilities. The NSO of 3 years ago is not the same as today and is not the same as the 2023 version. These 0-days might be known at 100 other companies with less aggressive marketing arms

[1] https://twitter.com/newsisrael13/status/1483887597025992716

Re: Finnish diplomats’ phones infected with NSO Group Pegasus spyware

#70

I propose that any article like this don't refer to it as "NSO spyware", but instead refer to it as "Israeli spyware". The reality is that while NSO Group is a private company, it has deep links to the Israeli government and generally doesn't allow it's services to be used against the interests of the Israeli state. Hiding behind a corporate name to maintain Israel's reputation in international media isn't really oka…

> doesn't allow it's services to be used against the interests of the Israeli state

All countries have export laws to prevent local companies from using their services and products against the country's interests.

Post reply on HN