Live data from Hacker News

Apple alerts users in 92 nations to mercenary spyware attacks

techcrunch.com

81–90 of 301 posts

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#81
post #54

Earlier quoted context omitted.

When I have to point to something when I say I doubt manufacturing will ever come back to the west, I point to the fact we can't manufacture the simplest of things ourselves anymore. Thanks Delta Airlines, whose metal nametags are literally just cut sheets of aluminum with some paint on them and are still Made in China. Someone seriously wants to tell me we can manufacture bleeding edge tech when we can't even cut an…

That's just weird. the US is definitely a lower cost country than Norway yet my youngest son works for a company here in Norway that does quite a lot of business making metal and plastic tags of various kinds with text engraved, printed, or laser cut. As far as I know most of the machinery is made in Europe, mostly Germany, again generally higher cost than the US. So I find it difficult to believe that it can't be do…

My guess is that it's likely cultural.

Cost cutting seems to be done much more deeply in the US than in Europe. For example, economy class on all North American airlines is rather miserable, while most European non budget carriers have a better experience in economy.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#82
post #52

Earlier quoted context omitted.

It’s “true” if you, as the GP seems to intend to, define “country” to be “state that is sovereign in the sense of a principal subject of international law”. This is, to say the least, not the only definition of a “country” (and is also among the definitions of “nation”.)

"Country" definitely does not mean "sovereign states" in English. And I do mean "English" because in the UK, England, Scotland and Wales are officially considered "countries" by the UK government...

If you care, you definitely need to specify what you mean, e.g. the British gameshow "Pointless" has a catch phrase:

"And by 'country' we mean a sovereign state that is a member of the UN in its own right"

So if you're asked for "country names ending in land" on the show they'll invariably remind you of the definition and you ought to then know Scotland is plain wrong, whereas Ireland is a reasonable although obvious (so not "Pointless") attempt to answer.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#83
post #51

Is this spyware possible due to engineering flaws in Apple products?

Check out Darknet diaries podcast on the NSO group. NSO group likely pays over $100k USD to hackers that have a good zero day for iphone.

https://darknetdiaries.com/episode/100/

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#84

There’s a reddit thread by somebody who got one of these: https://old.reddit.com/r/iphone/comments/1c10jai/i_have_rece... The interesting thing IMO is they claim to just be some random college student. Which seems believable because if they were a real secret squirrel I guess they wouldn’t ask reddit about it, haha. I wonder if the hackers are targeting people based on phone numbers or something. (I could imagine a c…

"random college student" I think there's a misunderstanding on what constitutes a valid or ideal target for state sponsored (or "mercenary") attackers. Simply working at a research lab, industrial manufacturer, power station, tech company or knowing a certain professor can put you on a target list.

It could also be an accidental misidentification - maybe OP has the same name as someone they actually wanted to target, or their phone number or email address is very similar to someone they wanted to target.

Or, it could be an intentional misidentification - maybe OP has a friend who was picked up by whatever east european security services, and provided OPs name as some kind of co-conspirator in something OP's friend was into.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#85
post #80

Earlier quoted context omitted.

I spend way too much time on HN, and having seen how often flags are abused or simply used too liberally, I think they are way too over powered. A lot of good discussion gets killed by flags right it of the gate. Sometimes it gets vouched and redeemed, but the vast majority of the time the damage is done and that comment or story languishes in obscurity.

The comment doesn't really say anything and the commenter is not saying they edited the comment to make it just non-substantive rather than non-substantive and inflammatory.

Excellent point. Thank you!

I would hope people aren't using flags for low-value comments, but you make a great point that it could have been edited to remove something that was deserving of a flag.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#86
post #65

Earlier quoted context omitted.

> Is there any company as big as Apple with so many major security issues? To be fair, does any Android device alert you to a compromise like this?

Android is more secure, especially in recent history. You can even see it in 0 day bounties. Don't pay attention to Samsung though, that company is probably the Apple equivalent of android.

>Android is more secure, especially in recent history. You can even see it in 0 day bounties.

This needs citations, and more than just referencing 0-day bounties.

0-day bounties are an incredibly weak signal in regards to security posture.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#87

"Mercenary spyware attacks, such as those using Pegasus from the NSO Group, are exceptionally rare and vastly more sophisticated than regular cybercriminal activity or consumer malware" So, maybe even provoking an Apple warning to those targets could also be part of a sophisticated operation. These targets react or have to react in a certain way. Instigate to lure people out of hiding and entice them to react, even i…

>What do these targeted people do then? Switching phones? When you can get a $130 Motorola that has better security... Yes. Since the 2018 iphone crack by the FBI, I am shocked anyone uses their iphone for secrets.

I doubt a 6 year old phone with outdated OS will be more secure than an up to date iPhone

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#88
post #22

Note that "mercenary spyware" is the politically correct term Apple chose for "state-sponsored attacker" because Modi complained that Apple was exposing them for using illegal NSO Group spyware.

The power of language, where "state-sponsored" too accurately directs the population's attention to their government but where mercenary is vague and non-aiming - where a simple change in language is enough to quell that ire and attention of authoritarians; or should I say authoritarian behaviour to not out them directly as authoritarians?

So you're saying that non authoritarian governments do not sponsor or do themselves the spying / attacks?

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#89
post #80

Earlier quoted context omitted.

I spend way too much time on HN, and having seen how often flags are abused or simply used too liberally, I think they are way too over powered. A lot of good discussion gets killed by flags right it of the gate. Sometimes it gets vouched and redeemed, but the vast majority of the time the damage is done and that comment or story languishes in obscurity.

The comment doesn't really say anything and the commenter is not saying they edited the comment to make it just non-substantive rather than non-substantive and inflammatory.

[deleted]

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#90
post #58
post #37

Earlier quoted context omitted.

Just out of curiosity why would you have imessage turned off?

iMessage histories are backed up in the nightly automatic non-e2ee iCloud Backup, effectively backdooring iMessage’s “end to end encryption” by escrowing the plaintext to a not-endpoint. Apple can read approximately everyone’s iMessages out of their backups. It’s not private or secure, and claiming it is end to end encrypted is misleading almost to the point of being actually false.

This is the same behavior as SMS if you have enabled “Messages backup.” If backup is not enabled you will not have a copy of iMessages stored in iCloud (though all compatible and configured devices will still receive messages).

This can be changed by opting in to the e2ee iCloud data service “Advanced Data Protection.”

Post reply on HN