Live data from Hacker News

UK Government Officials Infected with Pegasus

citizenlab.ca

111–120 of 381 posts

Re: UK Government Officials Infected with Pegasus

#111

I'm surprised this isn't a major diplomatic incident between the UK and Israel too, since the Israeli intelligence company was supposedly "closely monitoring how their customers were using the software" or akin to that. Like, yeah, blame the UAE mostly for this but let's also have a discussion about why this was sold to anyone who would pay with no oversight at all. Western countries need to do better.

Politics... If russia did that, they would be treated a lot differently than israel or eg. USA.

> If russia did that, they would be treated a lot differently than israel or eg. USA.

Russia poisoned multiple British nationals with chemical and radioactive weapons on British soil and got away with it scot-free.

https://www.bbc.com/news/uk-51722301

Re: UK Government Officials Infected with Pegasus

#112
post #7

I'm curious about the threat modelling of those high level officials. With all these hacking going on, if feels like it's not been a consideration. Pegasus claims iOS and Android hacking capabilities, one would expect more specialised communications being used at that level. Car companies provide specialised vehicles for governmental use, I would have expected to see specialised iOS or Android devices at least. Nothi…

My headcanon at this point is that the spymasters know about the security binary[0], and have decided that the threat of going dark is worse than the threat of getting pwned with their own NOBUS[1] exploits. Better to have everyone be vulnerable.

I do know at one point Apple had special Korean iPhone SKUs with no physical camera installed, I have no clue if those are still being made. Samsung probably did the same thing. The problem is that, aside from just removing hardware, there's no particular special software configuration that you can do to make the device more secure. Every good idea out there is either already being done on the consumer versions of these devices, or is an optional feature you can already enable on a stock device with MDM software. The security on phones is already pretty good, albeit at the cost of freedom for enthusiasts and tinkerers.

[0] Binary as in gender, not as in untrusted.

[1] US intelligence term that stands for "NObody But US" and is equivalent to "0day".

Re: UK Government Officials Infected with Pegasus

#113
post #40

Earlier quoted context omitted.

There's so much that's factually wrong with this comment I don't know where to start. 1. The UK does have a Bill of Rights (It's different in England and Scotland). The English one pre-dates the US Bill of rights by a century[0]. 2. It does have a constitution, but not a written constitution in the American sense[1]. 3. The Queen doesn't nominate Bishops; she rubber stamps nominations by a committee who are approved…

I stopped reading around: "Protestants may have arms for their defence suitable to their conditions and as allowed by law;" and something about (only) Ireland repealed it in [1]. In [2] it says, quite straight faced, that "The Constitution of the United Kingdom or British constitution comprises the written and unwritten arrangements that establish the United Kingdom of Great Britain and Northern Ireland as a politica…

> Britain does not have a written constitution but it is followed (how?)

Perhaps this is just a tacit admission that writing the rules on a piece of paper changes nothing. People follow the rules as a kind of collective consensus. Writing them down in one place wouldn’t change that.

Re: UK Government Officials Infected with Pegasus

#114
post #104

This is a bit of a tangent but I think reports like these strengthen the argument against electronic voting. There's basically no way of building a secure electronic voting system that can beat the security and auditability properties of old school pen and paper voting.

Yeah, not like there's any sort of transparent way to audit a public chain of data blocks representing votes associated with an anonymous certificates that would allow end users (verified with registration cards and authorized with their mobile device biometrics) to check their votes were recorded correctly and for 3rd parties to easily audit the vote totals. That's a problem that hasn't been solved at all by the cur…

Being able to easily validate what individual people voted for is exactly the opposite of what you want in a voting system, as it make vote buying/selling trivial. I suggest looking into the huge list of previous electoral fraud for all the different kind of attacks that need to be defended against: https://en.wikipedia.org/wiki/Electoral_fraud

Re: UK Government Officials Infected with Pegasus

#115
post #107

This is a bit of a tangent but I think reports like these strengthen the argument against electronic voting. There's basically no way of building a secure electronic voting system that can beat the security and auditability properties of old school pen and paper voting.

Does having a paper trail generated exactly after voting help? This is the system that's followed in India. I tried to think of ways it could fail but it seemed pretty fool proof as far as I can think. I'm pretty sure I might have missed some corner case

If you're going to have a paper trail for an electronic system, then why not just use the paper system?

It's like there's a pro-electronic movement that's looking for every excuse to move to electronic...

Ok, so we go electronic. We put in all these extra checks and balances to account for it's downsides. It runs well. People start questioning the need for the checks and balances, since it's so full-proof. So we remove the checks and balances.

For the people that complain about the staffing requirements for a paper-based election: it's a feature, not a bug. The sheer number of people involved make it virtually impossible to rig an election.

Re: UK Government Officials Infected with Pegasus

#116

Earlier quoted context omitted.

Why would that be surprising? I haven't heard about Yemen being outraged at France for selling weapons to the UAE for example. Western countries can't do better, it's how the world has and always will operate.

I've not heard about France but Yemen has definitely been outraged at Britain for selling weapons to Saudi Arabia...

No post body was provided.

Re: UK Government Officials Infected with Pegasus

#117
post #14

Earlier quoted context omitted.

> And what were GCHQ, MI6 and NCSC doing to protect our prime-minister at this time? Nobody is perfect - but there are people who blatantly ignore ITSEC best practices and are therefore almost unprotectable.

> Nobody is perfect - but there are people who blatantly ignore ITSEC best practices and are therefore almost unprotectable This is tangential to this story however. Even people who follow best practices can get owned when ex-Mossad/8200 agents armed with dozens of zero days and millions of dollars come after them.

No post body was provided.

Re: UK Government Officials Infected with Pegasus

#118
post #15

Earlier quoted context omitted.

I would be shocked if people couldn't find an RCE in an early 2000s flip phone. I had a friend who had hers since 2010 and MMS crashed it all the time.

Attack surface reduction is the important part. I’m not in disagreement with what you said, but if you took a modern iPhone and removed all capabilities other than sending and receiving phone calls, it would be much more secure than one which supports mms, email, browsing, etc.

Are you sure having a phone in your phone is a good idea? Phone calls are a significant source of attacks now, even if none of those attacks exploit a vulnerability in the phone software. As far as I'm concerned, the only point in having a dial-able phone number is to ensure I'm still eligible for car warranty scams and 2FA code harvesting attacks.

Re: UK Government Officials Infected with Pegasus

#119
post #62

I'm surprised this isn't a major diplomatic incident between the UK and Israel too, since the Israeli intelligence company was supposedly "closely monitoring how their customers were using the software" or akin to that. Like, yeah, blame the UAE mostly for this but let's also have a discussion about why this was sold to anyone who would pay with no oversight at all. Western countries need to do better.

The current home secretary, Priti Patel, was forced to resign from her previous (lesser) role as Minister for International Development for secretly (and thus illegally) meeting with Israeli diplomats. https://www.bbc.co.uk/news/uk-politics-41923007 It is completely unsurprising that there is little care shown by our government.

Doesn't the fact that she had to resign point to the opposite conclusion, namely that these governments are distinct entities with sometimes conflicting interests?

Re: UK Government Officials Infected with Pegasus

#120

Earlier quoted context omitted.

There are others who would know more about this than I do, but a few reasons come to mind: 1. NSO almost certainly has more than one exploit chain at a time. While this would burn one of their exploits, it wouldn’t put them out of business or eliminate the ability for them to get RCE on phones in general. 2. Vendors already have bug bounty programs with established award ceilings. These exploits are almost always far…

Vendors may be more incentivised to intentionally kill the Pegasus business model, which would have immeasurable PR value if executed well.

Then another one pops up. Fact is, the market is there. It's not too dissimilar how after the silk road was taken down 10 others came up in its place.

Markets for exploits are unfortunately here to stay.

Post reply on HN