Live data from Hacker News

Apple alerts users in 92 nations to mercenary spyware attacks

techcrunch.com

131–140 of 301 posts

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#131
post #16

There’s a reddit thread by somebody who got one of these: https://old.reddit.com/r/iphone/comments/1c10jai/i_have_rece... The interesting thing IMO is they claim to just be some random college student. Which seems believable because if they were a real secret squirrel I guess they wouldn’t ask reddit about it, haha. I wonder if the hackers are targeting people based on phone numbers or something. (I could imagine a c…

That person already got targeted last summer. I doubt they are as uninteresting as they believe/claim to be.

You'd be surprised. A college student in an interesting field is an interesting target. Doesn't mean he's done anything nefarious or even shady.

Industrial espionage is a thing.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#132
post #12

Pegasus and NSO. (Edit: of course I'm flagged for this. Surprise surprise)

You're being downvoted because you made a three-word comment that adds nearly nothing to the discussion on a site that hopes to entice meaningful discourse. Trying to play the victim on top of that is just silly.

[dead]

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#133
post #58
post #37

Earlier quoted context omitted.

Just out of curiosity why would you have imessage turned off?

iMessage histories are backed up in the nightly automatic non-e2ee iCloud Backup, effectively backdooring iMessage’s “end to end encryption” by escrowing the plaintext to a not-endpoint. Apple can read approximately everyone’s iMessages out of their backups. It’s not private or secure, and claiming it is end to end encrypted is misleading almost to the point of being actually false.

[dead]

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#134
post #38

Earlier quoted context omitted.

Interesting use of language on your part as well- what makes the NSO Group spyware illegal ?

The DMCA, in the US. Other statutes in other markets. Hacking computers is pretty prima facie criminal everywhere. It's true that there are inter-jurisdictional edge cases (cracking an iPhone in India via an attack from Israel probably isn't illegal in the USA,etc...) which allows NSO to operate more freely than we'd like. But no one seriously claims this is legal activity anywhere in particular, just that we can't c…

The CFAA is the broadest and most relevant US statute regarding computer hacking. But yes, international computer hackers typically operate outside of the jurisdictional reach of their targets.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#135
post #118

Earlier quoted context omitted.

Well dang I work in a research lab and I didn’t get an email. I’m just going to assume my research is so interesting that they sent the real badasses after me, somebody that Apple can’t catch. The truth is too ego-shattering.

For now

So may different ways to read that, haha

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#136

Note that "mercenary spyware" is the politically correct term Apple chose for "state-sponsored attacker" because Modi complained that Apple was exposing them for using illegal NSO Group spyware.

Well, supreme court ordered panel investigation into this spyware scandal didn't find any evidence of actual spyware. So there's that. Also, if government wants to investigate someone, they have so many powerful ways to do that (and they actually do that). So, it's not clear to me what need they have to go spy on people via NSO tools. And surely, if they were building large datacenters to do massive spying like some TLAs do in 5eyes countries, we would know about it. So, no, this isn't the local government but a foreign government (which doesn't have detention powers in another country) that's likely to use remote hacking methods to coerce people in another country. We saw this with leaked data dumps from recent hacks by the not so friendly neighbors on India's many citizen databases (like retirement provident fund systems etc).

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#137
post #58

Earlier quoted context omitted.

iMessage histories are backed up in the nightly automatic non-e2ee iCloud Backup, effectively backdooring iMessage’s “end to end encryption” by escrowing the plaintext to a not-endpoint. Apple can read approximately everyone’s iMessages out of their backups. It’s not private or secure, and claiming it is end to end encrypted is misleading almost to the point of being actually false.

This is the same behavior as SMS if you have enabled “Messages backup.” If backup is not enabled you will not have a copy of iMessages stored in iCloud (though all compatible and configured devices will still receive messages). This can be changed by opting in to the e2ee iCloud data service “Advanced Data Protection.”

Nope. Even opting into ADP, your iMessage conversations will still be backed up to Apple without e2ee - just from the non-ADP phones of all the people you iMessage with instead of your own phone.

iMessages are backed up in duplicate - once on the sender and once on the receiver. You can only control e2ee for half of it, so your conversations are still under surveillance unless everyone you message with has also turned on ADP.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#139

Earlier quoted context omitted.

>What do these targeted people do then? Switching phones? When you can get a $130 Motorola that has better security... Yes. Since the 2018 iphone crack by the FBI, I am shocked anyone uses their iphone for secrets.

Is there a modern smartphone or cellphone the fbi, cia, nsa any nation state can not hack ? I can guarantee you the fbi can also hack a $130 motorolla.

Nothing is un-hackable if you know how to properly use a $5 wrench.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#140

There’s a reddit thread by somebody who got one of these: https://old.reddit.com/r/iphone/comments/1c10jai/i_have_rece... The interesting thing IMO is they claim to just be some random college student. Which seems believable because if they were a real secret squirrel I guess they wouldn’t ask reddit about it, haha. I wonder if the hackers are targeting people based on phone numbers or something. (I could imagine a c…

"random college student" I think there's a misunderstanding on what constitutes a valid or ideal target for state sponsored (or "mercenary") attackers. Simply working at a research lab, industrial manufacturer, power station, tech company or knowing a certain professor can put you on a target list.

NSO was targeting something like 40k people just in mexico. It's entirely possible that this was an accidental targeting because they have a similar name or email to a target.
Post reply on HN