Live data from Hacker News

UK Government Officials Infected with Pegasus

citizenlab.ca

131–140 of 381 posts

Re: UK Government Officials Infected with Pegasus

#131

This is a bit of a tangent but I think reports like these strengthen the argument against electronic voting. There's basically no way of building a secure electronic voting system that can beat the security and auditability properties of old school pen and paper voting.

Generally a lot of voting security experts advocate for paper ballots with electronic counting. It is very robust, efficient, has great fallback, and lots of systems available to keep secure.

This is what a lot of states get wrong, with the voting machine itself being the gateway to entering your vote and having it read. For the machines in my Georgia county, it prints a paper ballot that you drop it into a counting/scanner machine, but the issue is that the only thing on the paper is a QR code that is likely encrypted (nothing readable when scanned with a standard QR reader), so there really isn't a way to verify that the paper you got actually matched what you entered into the ballot machine.

The ideal system is: ballot machine entry -> prints paper ballot scantron style, so the only information the scanner will see is what you've verified is correct -> scanner reads it and enters it into their database while also saving the paper.

Re: UK Government Officials Infected with Pegasus

#132

This is a bit of a tangent but I think reports like these strengthen the argument against electronic voting. There's basically no way of building a secure electronic voting system that can beat the security and auditability properties of old school pen and paper voting.

Generally a lot of voting security experts advocate for paper ballots with electronic counting. It is very robust, efficient, has great fallback, and lots of systems available to keep secure.

I think the problem is who builds it. I wouldn’t trust election software that wasn’t open source with a lot of eyeballs on it. Diebold wasn’t exactly a shining example to set. Preferably a non profit organization backing it and then having it adopted as a standard. I just don’t see that happening in the US where voter obstruction is part of at least one party’s strategy.

Re: UK Government Officials Infected with Pegasus

#133

This is a bit of a tangent but I think reports like these strengthen the argument against electronic voting. There's basically no way of building a secure electronic voting system that can beat the security and auditability properties of old school pen and paper voting.

I do not think so (my opinion, I may be wrong here).

Paper ballots (pen and paper) are susceptible to more rigging. Government officials can directly change the results by deliberately miscounting the results. It is seen in many countries where corruption is very high in the election commission. In these places, elected candidates, voters, 'pro-democracy' individuals advocate for electronic voting (Electronic Voting Machine, EVM.)

Recently, we saw the images and videos from the recent Belarus Lukashenk elections, where the officials just threw out paper ballots. In Pakistan, to curb voter fraud by paper ballots the previous Imran Khan (PTI) Government tried to install electronic voting equipments at locations particularly in rural areas where voter fraud was at a really high rate.

The ruling Government can use its state power to influence the outcome of elections. By pen and paper, the actual voting happens in a 'democratic way', but, the counting is left to individuals which will commit voter fraud.

Whereas, in electronic voting, 'Code Is Law, every single vote is counted properly. To curb the cons/disadvantages of electronic voting, which are

a.) The underlying code can be tweaked by the ruling government to give them an advantage in the counting.

b.) Voter fraud can be committed by abusing the actual hardware of the voting machine.

To solve this particular problem, the Election Commission of India (ECI) recently tried to bring some new changes. It majorly includes, having paper proof along with electronic proof called as VVPAT (Voter Verifiable Paper Audit Trail). The way it happens is:- When you cast your vote to a candidate 'C', the machine will print a slip with the proof of your vote to candiate 'C'.

So, if the opposition party alleges that voter fraud happened with the tampering of EVM, the election commission (or an independent third party, or the opposition candidate himself on his own) can then do a recount based on the VVPAT slips and cross-check the results per booth (per EVM).

Re: UK Government Officials Infected with Pegasus

#134
post #57

I'm surprised this isn't a major diplomatic incident between the UK and Israel too, since the Israeli intelligence company was supposedly "closely monitoring how their customers were using the software" or akin to that. Like, yeah, blame the UAE mostly for this but let's also have a discussion about why this was sold to anyone who would pay with no oversight at all. Western countries need to do better.

> I'm surprised this isn't a major diplomatic incident between the UK and Israel too Are you really surprised? I'd be surprised if the UK and its media made a fuss about it. Certainly we won't be making a fuss about it here in the US that's for sure. I'd imagine russia and china wishes they had 1/10th the influence that israel has in the US/UK. Say what you want about israel, but for such a tiny country, it punches f…

When 11 US diplomats in Uganda turned up with NSO Pegasus Malware on their phones, the US government responded by listing NSO as a covered Entity and forbidding any US company from buying or selling with it without express permission of the USG- Dell can't sell them monitors or laptops without the State Department publishing written, specific permission. Several US congresspersons advocated for even harsher response (Global Magnitsky Sanctions, which would, AIUI, basically cut them off from the dollar and their employees from traveling to the US). The US reserves the right to do that later.

So the US has responded, quite forcefully, to people much lower on the food chain being hacked by Pegasus.

See: https://arstechnica.com/information-technology/2021/12/the-s...

Re: UK Government Officials Infected with Pegasus

#135
post #40

Earlier quoted context omitted.

There's so much that's factually wrong with this comment I don't know where to start. 1. The UK does have a Bill of Rights (It's different in England and Scotland). The English one pre-dates the US Bill of rights by a century[0]. 2. It does have a constitution, but not a written constitution in the American sense[1]. 3. The Queen doesn't nominate Bishops; she rubber stamps nominations by a committee who are approved…

I stopped reading around: "Protestants may have arms for their defence suitable to their conditions and as allowed by law;" and something about (only) Ireland repealed it in [1]. In [2] it says, quite straight faced, that "The Constitution of the United Kingdom or British constitution comprises the written and unwritten arrangements that establish the United Kingdom of Great Britain and Northern Ireland as a politica…

> Britain does not have a written constitution but it is followed (how?),

Pretty much the same as in the US/Australia/etc where written constitutions exist: the courts strike down unconstitutional laws or acts.

Re: UK Government Officials Infected with Pegasus

#136

I'm surprised this isn't a major diplomatic incident between the UK and Israel too, since the Israeli intelligence company was supposedly "closely monitoring how their customers were using the software" or akin to that. Like, yeah, blame the UAE mostly for this but let's also have a discussion about why this was sold to anyone who would pay with no oversight at all. Western countries need to do better.

Maybe certain interest group within UK is working with certain interest group in Israel and "borrowed" Pegasus to use against other interest group(s).

Actually Yes Minster joked about surveillance put on certain ministers. Can watch for fun. Sitcoms nowadays rarely talk about political issues.

Re: UK Government Officials Infected with Pegasus

#137

Earlier quoted context omitted.

Attack surface reduction is the important part. I’m not in disagreement with what you said, but if you took a modern iPhone and removed all capabilities other than sending and receiving phone calls, it would be much more secure than one which supports mms, email, browsing, etc.

Are you sure having a phone in your phone is a good idea? Phone calls are a significant source of attacks now, even if none of those attacks exploit a vulnerability in the phone software. As far as I'm concerned, the only point in having a dial-able phone number is to ensure I'm still eligible for car warranty scams and 2FA code harvesting attacks.

You’re right, my point was surface reduction, not that one tech is more or less vulnerable than others

Re: UK Government Officials Infected with Pegasus

#138

Earlier quoted context omitted.

Vendors may be more incentivised to intentionally kill the Pegasus business model, which would have immeasurable PR value if executed well.

Then another one pops up. Fact is, the market is there. It's not too dissimilar how after the silk road was taken down 10 others came up in its place. Markets for exploits are unfortunately here to stay.

The models are different. Silk Road has millions of sellers and millions of buyers; Pegasus has a very small set of both, who would be more difficult to connect with. It probably won’t kill it, but will create a harder to leverage profit model

Re: UK Government Officials Infected with Pegasus

#139
post #62

I'm surprised this isn't a major diplomatic incident between the UK and Israel too, since the Israeli intelligence company was supposedly "closely monitoring how their customers were using the software" or akin to that. Like, yeah, blame the UAE mostly for this but let's also have a discussion about why this was sold to anyone who would pay with no oversight at all. Western countries need to do better.

The current home secretary, Priti Patel, was forced to resign from her previous (lesser) role as Minister for International Development for secretly (and thus illegally) meeting with Israeli diplomats. https://www.bbc.co.uk/news/uk-politics-41923007 It is completely unsurprising that there is little care shown by our government.

[deleted]

Re: UK Government Officials Infected with Pegasus

#140

Earlier quoted context omitted.

Generally a lot of voting security experts advocate for paper ballots with electronic counting. It is very robust, efficient, has great fallback, and lots of systems available to keep secure.

The issue is verification - how do you verify the elctronic count was accurate? And if you're going to manually count it to verify the electronic count, then why have the electronic count in the first place?

Do a manual count for a random sample plus all tight races and in case of any suspicions or challenges.
Post reply on HN