Live data from Hacker News

Apple alerts users in 92 nations to mercenary spyware attacks

techcrunch.com

161–170 of 301 posts

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#161

There’s a reddit thread by somebody who got one of these: https://old.reddit.com/r/iphone/comments/1c10jai/i_have_rece... The interesting thing IMO is they claim to just be some random college student. Which seems believable because if they were a real secret squirrel I guess they wouldn’t ask reddit about it, haha. I wonder if the hackers are targeting people based on phone numbers or something. (I could imagine a c…

A government that stoops to civil rights crimes but doesn't attach a good percentage of its fear to student movements is kind of oblivious to history as it pertains to its own miserable survival.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#162
post #37

Earlier quoted context omitted.

Just out of curiosity why would you have imessage turned off?

iMessage has been one of the most successful delivery vector for these spyware attacks. So, if you think you are a likely target of a state sponsored attack, best thing you can do on an Apple device is to turn on lockdown mode, turn off iCloud and iMessage, stop using keychain, use only a yubikey for all authentication, and restrict yourself to a limited number of essential apps on your primary device and use a dedic…

> assume everything you say and do online is fully compromised

This is the way.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#163
post #96

It's probably far worse with Android users that Google is not disclosing. I'm seriously considering changing to Apple after this. Not that its secure but that they are willing to go to this length to communicate it.

Wait... Apple has the worst security record of any of the FAANG companies and you are switching to them because they admitted a security issue after the fact? What? Is this just regular Apple fanboy-ism?

i changed my mind after somebody reminded me Android is more secure and harder to hack due to diversity in hardware

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#164

Earlier quoted context omitted.

I don’t see how the bounties back this up?

Supply and demand.

The bounties look like they have fairly comparable distribution, and just knowing the dollar figures doesn't really tell much about either supply or demand. Your inference requires that knowledge.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#165
post #24
post #21

Earlier quoted context omitted.

Sci-Fi Author: In my book I invented the Torment Nexus as a cautionary tale Tech Company: At long last, we have created the Torment Nexus from classic sci-fi novel Don't Create The Torment Nexus https://twitter.com/AlexBlechman/status/1457842724128833538

Same goes for certain types of lead characters in things like American Psycho, Fight Club, Mad Men and Wolf of Wall St. These are seen as aspirational instead of cautionary tales.

There was a recent article in NYT about Grand Theft Auto and the author mentions that their friends became a little more racist after playing it as kids. My takeaway was that these forms of media aren't for children because they probably won't understand that it's satire. Then I realized that many adults don't understand that it's satire either.

Edit: article in question: https://www.nytimes.com/2024/01/25/arts/grand-theft-auto-isl...

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#166

There’s a reddit thread by somebody who got one of these: https://old.reddit.com/r/iphone/comments/1c10jai/i_have_rece... The interesting thing IMO is they claim to just be some random college student. Which seems believable because if they were a real secret squirrel I guess they wouldn’t ask reddit about it, haha. I wonder if the hackers are targeting people based on phone numbers or something. (I could imagine a c…

[flagged]

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#167
post #96

It's probably far worse with Android users that Google is not disclosing. I'm seriously considering changing to Apple after this. Not that its secure but that they are willing to go to this length to communicate it.

> I'm seriously considering changing to Apple after this. Ironically that may be worse for you. iMessage is probably a critical step in 60% (or more) of these exploits, and the various unicode/pdf etc rendering engines are responsible in many exploits. Android's open-source nature likely means that a lot of these things are found by security researchers first. Don't forget that zerodium still pays more for an android…

I do not believe the android Messages application is open source. I believe AOSP contains something very barebones. It has been a lot of years, am I incorrect?

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#168

Earlier quoted context omitted.

You'd be surprised. A college student in an interesting field is an interesting target. Doesn't mean he's done anything nefarious or even shady. Industrial espionage is a thing.

Why would a college student be an interesting target simply for being a college student in an interesting field? If they work at an interesting company or something like that I would understand, but the knowledge that is accessible in colleges is not some super secret stuff or am I missing something?

The conversation here is focussing on industrial espionage, but that's only one use case for this kind of active measure. An association with an opposition political party could easily get one on a surveillance list.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#169
post #101
post #96

It's probably far worse with Android users that Google is not disclosing. I'm seriously considering changing to Apple after this. Not that its secure but that they are willing to go to this length to communicate it.

Are you a journalist or high profile target? If not, this notification isn't for the average person.

You don't need to be a journalist. I think many tech workers are oblivious to how juicy and obvious a target we are. Most of us publish a detailed target on our own back via LinkedIn, or our company's website About Us and Clients pages.

Long ago, I co-founded a tiny startup. We had some high profile clients. I was dumb enough to put those clients on our site. I also used to be dumb enough to have a public social media profile, in my name.

I was already somewhat security aware, but one day I almost fell for a spear phishing email. Someone created a gmail account 1 character different from my gf's gmail. They sent me a well worded, but simple email along the lines of "Hey baby, check this out!" and URL shortened link. She happened to be next to me, and I said to her "Hey, what's this?" "What? I didn't send that!" I then opened it in a VM and saw that it resolved to something.ru.

It was a combo of identifying the juicy client of ours, seeing my name as co-founder, finding me on FB, finding my gf in my profile, getting her email, etc.

I then got to learn fun new terms like threat modeling.

Is it possible that someone might think that you have ssh access to a server on an interesting network? You are a target.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#170

There’s a reddit thread by somebody who got one of these: https://old.reddit.com/r/iphone/comments/1c10jai/i_have_rece... The interesting thing IMO is they claim to just be some random college student. Which seems believable because if they were a real secret squirrel I guess they wouldn’t ask reddit about it, haha. I wonder if the hackers are targeting people based on phone numbers or something. (I could imagine a c…

Everyone's thinking academic secrets but have they engaged in activism in any way shape or form?

Being able to take activists and discredit them is an amazing ability. I would not at all be surprised if the xz compression backdoor was an attempt by a certain government to gain the ability to discredit anyone that is against them in anyway.

Post reply on HN