Live data from Hacker News

Apple alerts users in 92 nations to mercenary spyware attacks

techcrunch.com

181–190 of 301 posts

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#181
post #21

Earlier quoted context omitted.

Sci-Fi Author: In my book I invented the Torment Nexus as a cautionary tale Tech Company: At long last, we have created the Torment Nexus from classic sci-fi novel Don't Create The Torment Nexus https://twitter.com/AlexBlechman/status/1457842724128833538

To be fair, somebody will always decide what you wrote was a warning and they should fear it, even if you specifically intended a utopia, just as people insist on rooting for and even imitating the bad guys from stories because they misunderstood "cool" as "good". Example: Some people think San Junipero, the one positive Black Mirror episode with an actual Happily Ever After romantic ending is a dystopian vision. Som…

Okay, yeah. But even from a pretty hardcore moral relativist POV...

> "mercenary spyware", AI war targeting, and death drones

Are not super easy to justify. Like, sure some people obviously think those ought to be a thing, but those people are dicks.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#182
post #18

If I got a message that said: “Apple detected that you are being targeted by a mercenary spyware attack that is trying to remotely compromise the iPhone associated with your Apple ID -xxx-,” it wrote in the warning to affected customers." I would assume it's fake, part of some phishing scam. How can we know something like this is real? I'd be even more likely to think it's fake if it looks different than all the othe…

As long as it doesn't have any links to click or try to force you to login to something, it just sounds like information to me. If my bank sent me something about Credit Card fraud I would be very skeptical if it had a big "CLICK HERE TO LOGIN" type of thing. But if it was just info, and maybe ended with "Contact your local branch to learn more", but no links, no phone numbers, etc. I would be less skeptical.

This is, I think, a valuable heuristic. Anything but the most complex and long-term scam always includes some call to action, nearly always URGENT and IMMEDIATE (so as not to give you a chance to think about it or research it).

A notification that is ONLY a notification about something is very unlikely to be malicious (though could certainly be erroneous). My bank will send me a concerning email or SMS about suspicious activity that needs to be reviewed or confirmed, but because they know it's a vector for attack their specifically ask you to call them at their published number listed on your card.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#183
post #101
post #96

It's probably far worse with Android users that Google is not disclosing. I'm seriously considering changing to Apple after this. Not that its secure but that they are willing to go to this length to communicate it.

Are you a journalist or high profile target? If not, this notification isn't for the average person.

Or if you are adjacent to a high profile target, working in the same company as a high profile target, working at a company that is contracted to a high profile target, friend of a friend of a high profile target.... And so on.

Sure, the average person probably doesn't need this (although as another comment pointed out, HN isn't quite representative of the average)... But the net is a hell of a lot wider than just journalists.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#184

Earlier quoted context omitted.

> I'm seriously considering changing to Apple after this. Ironically that may be worse for you. iMessage is probably a critical step in 60% (or more) of these exploits, and the various unicode/pdf etc rendering engines are responsible in many exploits. Android's open-source nature likely means that a lot of these things are found by security researchers first. Don't forget that zerodium still pays more for an android…

> Plus, the huge variability between Samsung/Google/Moto/Huawei etc makes it triply hard for a single exploit to be successful. That variability is a double-edged sword. Manufacturer-added Android bundleware is notorious for being shoddily built and could easily represent added points of ingress. Which is why I wish it were practical to replace OEM Android versions with GrapheneOS/CalyxOS or similar on the latest dev…

GrapheneOS and I think CalyxOS runs just fine on the latest Pixel devices. From what I see it is quite up to date most of the times.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#185
post #96

It's probably far worse with Android users that Google is not disclosing. I'm seriously considering changing to Apple after this. Not that its secure but that they are willing to go to this length to communicate it.

>It's probably far worse with Android users that Google is not disclosing.

[citation needed]

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#186
post #95
post #86

Earlier quoted context omitted.

> Android is more secure, especially in recent history. You can even see it in 0 day bounties. This needs citations, and more than just referencing 0-day bounties. 0-day bounties are an incredibly weak signal in regards to security posture.

Pricing, and for more than zero days here: https://zerodium.com/program.html

Pricing of 0-days has very little correlation with the security of something, if any correlation.

I'm not sure what the "and for more" you are referencing. The site lists prices, an FAQ, and events. None of that supports the argument made by parent comment.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#187
post #37

Earlier quoted context omitted.

Just out of curiosity why would you have imessage turned off?

iMessage has been one of the most successful delivery vector for these spyware attacks. So, if you think you are a likely target of a state sponsored attack, best thing you can do on an Apple device is to turn on lockdown mode, turn off iCloud and iMessage, stop using keychain, use only a yubikey for all authentication, and restrict yourself to a limited number of essential apps on your primary device and use a dedic…

So it's not just me :-D

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#188
post #101

Earlier quoted context omitted.

Are you a journalist or high profile target? If not, this notification isn't for the average person.

Or if you are adjacent to a high profile target, working in the same company as a high profile target, working at a company that is contracted to a high profile target, friend of a friend of a high profile target.... And so on. Sure, the average person probably doesn't need this (although as another comment pointed out, HN isn't quite representative of the average)... But the net is a hell of a lot wider than just jo…

Years ago I worked for a non-profit in an office building in San Francisco. My office neighbors were Google, the US Secret Service and, I shit you not, China Daily (a major news outlet run by the Chinese Communist party).

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#190
post #38

Earlier quoted context omitted.

Interesting use of language on your part as well- what makes the NSO Group spyware illegal ?

The DMCA, in the US. Other statutes in other markets. Hacking computers is pretty prima facie criminal everywhere. It's true that there are inter-jurisdictional edge cases (cracking an iPhone in India via an attack from Israel probably isn't illegal in the USA,etc...) which allows NSO to operate more freely than we'd like. But no one seriously claims this is legal activity anywhere in particular, just that we can't c…

The point I'm hearing in the parent post is more like that many of the state actors using such attacks against domestic targets actually may be legally allowed to do so, if they have passed laws which permit their own security services to use such software on their residents' phones.

Even in USA that likely could be legal with an appropriate court warrant, and many other countries have more permissive constitutions.

Post reply on HN