Live data from Hacker News

Finnish diplomats’ phones infected with NSO Group Pegasus spyware

bleepingcomputer.com

91–100 of 113 posts

Re: Finnish diplomats’ phones infected with NSO Group Pegasus spyware

#91
post #89

Earlier quoted context omitted.

> How can you prove that this is more secure against state level actors than iOS which have billions (?) of users? By comparing the number of exploits? Qubes relies on Xen, which is used by very big targets, so should be under constant attacks. Qubes uses hardware (VT-d) virtualization, which AFAIK was last time broken by the Qubes founder in 2003: https://en.wikipedia.org/wiki/Blue_Pill_(software) .

> By comparing the number of exploits? Qubes relies on Xen, which is used by very big targets, so should be under constant attacks This is often giving quite misleading conclusions based on what I just said - iOS for example is much more popular and heavily tested - of course the amount of exploits is much larger, because it is also much more interesting target as many are using it. How many people are using phones/l…

> Xen is commonly used on server side - not by those guys who are holding the interesting stuff on their personal devices.

AFAIK server side is often even more interesting for hackers as it's connected to big money.

Re: Finnish diplomats’ phones infected with NSO Group Pegasus spyware

#92
post #63

Earlier quoted context omitted.

Putnam investments are really hard to get money out of. For example, I tried to cash in an annuity, and it required a medallion certificate by another bank. A medallion certificate is like a notary but is only done by another bank.

Depends how motivated the attackers are. They can try to find another bank with weaker rules, perhaps open an account there first. I needed one of those things, and shopped around for a bit. And while all the big names would refuse, had waiting periods, fees, other requirements, a local credit union gave me one after signing up for a savings account immediately with a minimal or no fee.

>Depends how motivated the attackers are. They can try to find another bank with weaker rules, perhaps open an account there first.

That isn't really incentivized in this case. Assuming by medallion certificate they meant "medallion signature guarantee" [0] as established by SEC Rule 17 Ad-15 [1], a core part of the system there is that the financial institution granting it accepts liability for any forgery, up to a specified prefix amount (and the transaction will be rejected if the stamp isn't enough to cover the transaction amount). So if they "find another bank with weaker rules" who gets them to issue a stamp for a few hundred grand they are on the hook for that loss.

As a result, it's actually taken pretty seriously at least for significant amounts of money. This specific area isn't one where the guarantor gets to shrug their shoulders about it. Since they're going to be on the hook for hundreds of thousands to millions if they get it wrong, you need to be a known, established customer to even try, go in person, and someone higher level is absolutely going to looking at it personally. And even if an attacker did get past all that, the whole point is the one being attacked still hasn't lost anything.

>a local credit union gave me one after signing up for a savings account immediately with a minimal or no fee.

What prefix though? How did you check out in terms of signup (long history as resident? local connections?)? Lots of stuff goes on behind the scenes. An F alpha prefix ($100k surety, credit union) isn't the same thing as a Z ($14 million surety).

----

0: https://www.mybanktracker.com/blog/investing/medallion-signa...

1: https://www.law.cornell.edu/cfr/text/17/240.17Ad-15

Re: Finnish diplomats’ phones infected with NSO Group Pegasus spyware

#93

Earlier quoted context omitted.

If you care about this, consider using a security-oriented OS on desktop based on hardware virtualization: https://qubes-os.org . In this case, if you use your phone only to confirm the transactions (as the second factor), you should be safe enough.

If you are super paranoid, ask your bank to disable all remote access to your account and go into the branch in person when you want to do something.

This might be too high level of paranoia for me (and I run Qubes as a daily driver).

Re: Finnish diplomats’ phones infected with NSO Group Pegasus spyware

#94
post #89

Earlier quoted context omitted.

> How can you prove that this is more secure against state level actors than iOS which have billions (?) of users? By comparing the number of exploits? Qubes relies on Xen, which is used by very big targets, so should be under constant attacks. Qubes uses hardware (VT-d) virtualization, which AFAIK was last time broken by the Qubes founder in 2003: https://en.wikipedia.org/wiki/Blue_Pill_(software) .

> By comparing the number of exploits? Qubes relies on Xen, which is used by very big targets, so should be under constant attacks This is often giving quite misleading conclusions based on what I just said - iOS for example is much more popular and heavily tested - of course the amount of exploits is much larger, because it is also much more interesting target as many are using it. How many people are using phones/l…

I would argue that iOS is more dangerous because we can be fairly certain that it's not only vulnerable to exploits like Pegasus, but also phones home to FIVE EYES on a regular basis. Qubes is vulnerable to neither of these attacks, and it's architecture is explicitly designed to isolate all components of the system with hardened hypervisor technology used by the most high-security servers in the world. For the most part, you don't even have to trust the device you're running Qubes on; the isolation technology is that robust.

Re: Finnish diplomats’ phones infected with NSO Group Pegasus spyware

#95

Although I'm certainly no celebrity / important likely target of hackers, I'm interested in this just because recently I've gotten paranoid about my financial accounts (after a company I used to work for finally went public and I was fortunate to cash out an amount of $). When hackers use such exploits, do they then basically have something like remote control over your phone, and can start exfiltrating data / manipu…

Arguing from first principles, the first step in detecting a problem is to know your device's baseline operation. This means knowing the bevvy of processes that are running, the resources they use, and the messages they send and to which hosts. With this baseline, you can now see if something is going wrong - a process you don't recognize, connecting to hosts you don't recognize, and so on. Of course, this is also th…

>In terms of capability, I speculate that the best an attacker can achieve is a sticky, privileged process that accepts arbitrary commands at runtime, which can be used to read the disk, analyze other running processes, install and exfil sensor data, etc.

The worst-case scenario would be if the attacker somehow manages to rewrite your motherboard and/or SSD's firmware with a malicious firmware. And even if you reinstall your OS - he still manages to re-install the rootkit afterwards. I've only read about such type of malware but never have I seen or heard of anything like that in the wild.

Re: Finnish diplomats’ phones infected with NSO Group Pegasus spyware

#96
post #92
post #63

Earlier quoted context omitted.

Depends how motivated the attackers are. They can try to find another bank with weaker rules, perhaps open an account there first. I needed one of those things, and shopped around for a bit. And while all the big names would refuse, had waiting periods, fees, other requirements, a local credit union gave me one after signing up for a savings account immediately with a minimal or no fee.

> Depends how motivated the attackers are. They can try to find another bank with weaker rules, perhaps open an account there first. That isn't really incentivized in this case. Assuming by medallion certificate they meant "medallion signature guarantee" [0] as established by SEC Rule 17 Ad-15 [1], a core part of the system there is that the financial institution granting it accepts liability for any forgery, up to a…

Yes, exactly I meant medallion signature guarantee thank you sorry I didn't use exact terminology.

Re: Finnish diplomats’ phones infected with NSO Group Pegasus spyware

#97
post #58

I think it would be good hygiene to completely reset phones every year or half-year. Now, if it were common practice, I guess the exploits would get around that too (or they already do?)

I'm curious how many of the known exploits today would persist past a "restore from backup" via iCloud. To be truly successful, would you need to take no history from your pre-reset phone forward?

Re: Finnish diplomats’ phones infected with NSO Group Pegasus spyware

#98

Earlier quoted context omitted.

ok, I'll expand on this quickly: 1. The state of Israel is the only state in the area where both Jews and Arabs are welcome and have a place in government and legislative bodies. Much of the "legitimate criticism" of Israel isn't directed at the Arabs in Israel it seems to I claim thinly veiled hate against the Jewish part of the population. 2. If one argues that it is against the Jewish part of the population becaus…

Genuinely asking, my understanding is that Israel the government considers itself a primarily Jewish ethnostate with policies in place to evict Arabs from their lands in order to put Jewish people in there. My understanding is that this is where a lot of criticism and advocacy for Palestine comes from. In that case, in order to criticize the treatment of Palestinians, one would be criticizing a policy that benefits p…

Remember that while I feel sorry for both parts I'm heavily biased so don't accept anything I write at face value but check it. On the other hand, unlike mainstream media and many who "support the Palestinian[1] cause" I'll be up front about it and ask you to verify yourself without referring you to more heavily biased sources.

> with policies in place to evict Arabs from their lands in order to put Jewish people in there.

I cannot defend everything Israel does but the last time I can remember there was a lot of fuzz on HN about evicting Arabs to give land to Israelis it was about giving back land to the families whos property was stolen and given to Arabs in the brief time where Jordan occupied it.

Also remember that there used to be a whole lot of Jews in the lands surrounding Israel. These partially moved voluntarily, partially where driven out harshly.

Meanwhile Arabs got to stay in Israel[2].

In fact more Jews were moved into Israel from surrounding countries than Arabs expelled from Israel so theoretically, if Arabs wanted, they could have given the properties of the Jews that fled from their countries to the Arabs that came from Israel.

That didn't happen as the Arabs never accepted UNs plan. So the neighbouring countries put their relatives in camps while waiting to "shove the Jews into the sea", Israel welcomed their own people and got them integrated with homes and a place to work. As time went by I think it became convenient to keep them there as a chess pawn.

[1]: I consequently use the word Arabs except here. There has never been a country named Palestine, just a Roman administrative province and later a fiction fueled by crafty journalists that saw that the story about small Israel against the Arab world would put Israel in a good light while "big" Israel (it is the size of a small county in Norway) against the poor "Palestinians"[3] in the camps.

[2]: Part of this seems to be a cynical plot by the Israelis. They asked them to stay I understand because if they all left, all the neighbouring countries could just walk in and shoot everything that lived.

[3]: Actually Arabs, just living inside the borders of the small part that UN/UK gave to the Jewish part of the population.

PS: Again, I'm heavily biased. I write to make you see it from my side. I have been caught in factual errors before. When that happen and I can verify it I have apologized and I try to not repeat those mistakes, again unlike mainstream journalists.

Re: Finnish diplomats’ phones infected with NSO Group Pegasus spyware

#99

Earlier quoted context omitted.

> if your computer is compromised while doing it, you can still lose it. The hardware wallet itself has a screen, and requires you to confirm your transactions, so generally not true

Just for people who don’t know, it’s shows relevant data regarding the transaction: Sum, currency, target address. Now, if you verify that data, you are safe… if the original address was correct. But as we are talking about a sophisticated targeted attack, where did you get the original address from? Because if it was your phone or your computer, we are back to step one, as that might already be manipulated.

[deleted]

Re: Finnish diplomats’ phones infected with NSO Group Pegasus spyware

#100
post #40

Earlier quoted context omitted.

>And your comment is just antisemitic. It's dangerous tossing that term around. There is enough real antisemitism in the world, and it's a real problem, we don't need to make-pretend extra. Critisism of the state of Israel does not equate antisemitism.

Quoted post unavailable.

I don't doubt that some hide their hate behind that, but that does not mean that all critisism of Israel is "hidden antisemitism". Interpreting what peoples "real feelings" are from such a small post is pretty complicated, and since antisemitism is very serious you should not throw those accusations around easily. I can't see anything antisemitic in the post you called antisemitic. What is it actually you think was antisemitic about it?
Post reply on HN