Live data from Hacker News

Apple alerts users in 92 nations to mercenary spyware attacks

techcrunch.com

211–220 of 301 posts

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#211
post #179

Earlier quoted context omitted.

Look to your left. Look to your right. Both of those people are working for a foreign government. At least one of them does not know it. Trust no one.

If this is sarcasm, I love it. If you're serious then I don't.

I think it must be, it is a re-spin of a common “toxic STEM professor” meme.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#212

Earlier quoted context omitted.

The article omitted it, but the message says to update iOS to the latest software and enable its lockdown mode.

Right. That's a "turn it off and turn it on again" tech support answer.

I disagree: I'd expect they would have discovered the exploit and delivered and update to patch it, and lock down mode is not standard usage by normal users.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#213
post #9

There’s a reddit thread by somebody who got one of these: https://old.reddit.com/r/iphone/comments/1c10jai/i_have_rece... The interesting thing IMO is they claim to just be some random college student. Which seems believable because if they were a real secret squirrel I guess they wouldn’t ask reddit about it, haha. I wonder if the hackers are targeting people based on phone numbers or something. (I could imagine a c…

Well the they might be just a college student, but they could have a relationship with the actual target in some way. And if it's part of a complex operation they could be trying some indirect approaches.

> Well the they might be just a college student, but they could have a relationship with the actual target in some way.

People who are "just" college students often are the sons and daughters of people who could be targeted. Not to mention people in their social circles.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#214

Earlier quoted context omitted.

Why would a college student be an interesting target simply for being a college student in an interesting field? If they work at an interesting company or something like that I would understand, but the knowledge that is accessible in colleges is not some super secret stuff or am I missing something?

The conversation here is focussing on industrial espionage, but that's only one use case for this kind of active measure. An association with an opposition political party could easily get one on a surveillance list.

We've had this problem quite a bit in Australia.

Chinese students attending protests have had their families back home warned.

Personally know friends this has happened to.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#215
post #94

Earlier quoted context omitted.

aren't using flags for low-value comments They could, and if you ask me, they should. They gum up threads and often start meta discussions about exactly how low-value they are. Many are even explicitly listed in the guidelines - snark, tropes and memes, 'broke the back button', shallow putdowns, etc. Righteously flaggable, one and all.

I agree regarding snark, and pretty much anything that criticizes the person rather than the ideas. But one person's tropes and memes are often somebody else's current belief/position, especially if they are part of today's lucky 10,000[1]. What (in your opinion) is the purpose of the down-vote button? [1]: https://xkcd.com/1053/

But one person's tropes and memes are often somebody else's current belief/position

In a site with the ostensible goal of 'curious conversation', that's not really good enough - it's not the job of your potential interlocutors to figure out what sincere, reasoned beliefs and positions hide behind the throwaway trope line. If you want to have a conversation, it's on you to try to converse. There are lots of other places where the trope line is fine - from the group chat with friends or colleagues to twitter. But those places work in different ways.

What (in your opinion) is the purpose of the down-vote button?

It's a way to say 'this comment is misranked'. There are lots of reasons to feel a comment is misranked - including simple disagreement.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#216
post #202

Earlier quoted context omitted.

The point I'm hearing in the parent post is more like that many of the state actors using such attacks against domestic targets actually may be legally allowed to do so, if they have passed laws which permit their own security services to use such software on their residents' phones. Even in USA that likely could be legal with an appropriate court warrant, and many other countries have more permissive constitutions.

> Even in USA that likely could be legal with an appropriate court warrant Can you expand upon this? I'm not particularly familiar but it doesn't seem right. Obviously LEO agencies are allowed to subpoena private information, but can they legally use exploits with a warrant? Are there recorded examples of this? [Based on your reference to warrants, I guess I'm excluding the NSA or other supposed state-level spy agenc…

I'm not a lawyer and the proper answer is likely state-dependent, but why not?

It's well established that with an appropriate warrant, LEO have always been able to come into your house without telling you and add hidden surveillance bugs to listen on your communications; they have always been allowed to physically modify or replace your phone (e.g. physical phone wiretaps a century ago); Electronic Communications Privacy Act reasserts that this applies also to electronic surveillance and digital communications; so (as a non-expert) I don't really see why that wouldn't apply to smartphone exploits as well. We do see exploits being applied to devices in LEO possession (e.g. https://www.theverge.com/2021/4/14/22383957/fbi-san-bernadin... for one random example) to recover evidence.

The main restriction is the constitutional limits of 4th amendment which requires specific warrants for each case - which is a significant practical obstacle, so the circumstances in which warrantless wiretapping is permitted (e.g. by PATRIOT act) is a contentious issue; however, it's not relevant if a proper warrant is obtained.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#217
post #206

Earlier quoted context omitted.

I'm in Europe, I haven't encountered anyone in my life who has used iMessage (everyone uses WhatsApp, now also Telegram/Signal), so I don't really have a use for it, when I wanted to try the weird AR emoji / heartbeat reaction message things with my partner we noticed we both had iMessage turned off, I guess it's like a setting that maybe we skipped during the phone setup? Not sure if it's on by default for some peop…

Where in Europe is that? Surprising to me (Swedish).

I've lived in Germany and the UK, I guess I wrongly assumed it was like this everywhere in Europe. Might also be related to the social environment.

I am noticing, the social circle I am currently in has now largely moved to Telegram, whereas in other places it's 100% WhatsApp.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#218

There’s a reddit thread by somebody who got one of these: https://old.reddit.com/r/iphone/comments/1c10jai/i_have_rece... The interesting thing IMO is they claim to just be some random college student. Which seems believable because if they were a real secret squirrel I guess they wouldn’t ask reddit about it, haha. I wonder if the hackers are targeting people based on phone numbers or something. (I could imagine a c…

Everyone's thinking academic secrets but have they engaged in activism in any way shape or form? Being able to take activists and discredit them is an amazing ability. I would not at all be surprised if the xz compression backdoor was an attempt by a certain government to gain the ability to discredit anyone that is against them in anyway.

what activists are running sshd?

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#219
post #61
post #51

Is this spyware possible due to engineering flaws in Apple products?

Technically, yes? But there has never ever been non-trivial software that has been completely free of such defects. In other words (in my opinion), iOS is probably better than most other platforms against this type of attack.

"In other words" doesn't make sense here.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#220
post #119

Earlier quoted context omitted.

> I'm seriously considering changing to Apple after this. Ironically that may be worse for you. iMessage is probably a critical step in 60% (or more) of these exploits, and the various unicode/pdf etc rendering engines are responsible in many exploits. Android's open-source nature likely means that a lot of these things are found by security researchers first. Don't forget that zerodium still pays more for an android…

> Don't forget that zerodium still pays more for an android 0-day than an iOS 0-day. A random Internet search gives iOS 30% market share to Android's 70% [1], which could also explain the higher price. [1] https://www.statista.com/statistics/272698/global-market-sha...

You raise a good point, however iirc the values of the 2 oses were the same for a long time in the past.
Post reply on HN