Earlier quoted context omitted.
The big difference here is the Message app on Android is just a normal app whereas imessage is bundled deep in the OS with tons of private apis
I don’t understand why people keep bringing this up when it has no functional relevance to how secure it is
Apple alerts users in 92 nations to mercenary spyware attacks
221–230 of 301 posts
Re: Apple alerts users in 92 nations to mercenary spyware attacks
#222Earlier quoted context omitted.
> I'm seriously considering changing to Apple after this. Ironically that may be worse for you. iMessage is probably a critical step in 60% (or more) of these exploits, and the various unicode/pdf etc rendering engines are responsible in many exploits. Android's open-source nature likely means that a lot of these things are found by security researchers first. Don't forget that zerodium still pays more for an android…
Apple specifically acknowledges this and has Lockdown Mode to address it. If you care about security you should enable it. Of course you’ll not be able to watch YouTube videos, but you’ll be safer.
Re: Apple alerts users in 92 nations to mercenary spyware attacks
#223Earlier quoted context omitted.
Well dang I work in a research lab and I didn’t get an email. I’m just going to assume my research is so interesting that they sent the real badasses after me, somebody that Apple can’t catch. The truth is too ego-shattering.
Look to your left. Look to your right. Both of those people are working for a foreign government. At least one of them does not know it. Trust no one.
Re: Apple alerts users in 92 nations to mercenary spyware attacks
#224Earlier quoted context omitted.
> I'm seriously considering changing to Apple after this. Ironically that may be worse for you. iMessage is probably a critical step in 60% (or more) of these exploits, and the various unicode/pdf etc rendering engines are responsible in many exploits. Android's open-source nature likely means that a lot of these things are found by security researchers first. Don't forget that zerodium still pays more for an android…
you changed my mind successfully thank you but what about dumb phones from late 2000s like my Samsung Alias 2? what kind of sick bastard would make zero days for this
If we’re talking about having the microphone tapped etc, I don’t think anyone would still be developing 0-days for such old phones. If you want to be safer (assuming fear of old software having unpatched vulnerabilities) Nokia launched a dumb phone not too long ago.
However… GSM networks and cell tower level tracking is much harder/almost impossible to escape short of throwing away your phone. SMSes can be hijacked, hostile agents can force downgrade the connection to 3G/2g to break encryption (iirc, please correct me if wrong), and your location is generally known to your service provider and Uncle Sam.
Plus… the SIM card is its own mini computer, and lots of the firmware between that and the telephony modules is proprietary and closed source. If you’re familiar with intel ME you have an idea of what I’m talking about.
Honestly, if you’re not a journalist going after big names, or a top CEO/president etc you likely don’t need to worry about any of these. But if you are, or just want to be privacy conscious, your best bet is to never use cell towers and only use Wi-Fi/internet from public or untraceable places; along with Wi-Fi calling for telephony. Btw I’m not sure but I think Google fi and a few carriers/MVNOs offer virtual numbers, which can be a good first step for privacy.
Re: Apple alerts users in 92 nations to mercenary spyware attacks
#225There’s a reddit thread by somebody who got one of these: https://old.reddit.com/r/iphone/comments/1c10jai/i_have_rece... The interesting thing IMO is they claim to just be some random college student. Which seems believable because if they were a real secret squirrel I guess they wouldn’t ask reddit about it, haha. I wonder if the hackers are targeting people based on phone numbers or something. (I could imagine a c…
Everyone's thinking academic secrets but have they engaged in activism in any way shape or form? Being able to take activists and discredit them is an amazing ability. I would not at all be surprised if the xz compression backdoor was an attempt by a certain government to gain the ability to discredit anyone that is against them in anyway.
Re: Apple alerts users in 92 nations to mercenary spyware attacks
#226It's probably far worse with Android users that Google is not disclosing. I'm seriously considering changing to Apple after this. Not that its secure but that they are willing to go to this length to communicate it.
>It's probably far worse with Android users that Google is not disclosing. [citation needed]
Re: Apple alerts users in 92 nations to mercenary spyware attacks
#227Earlier quoted context omitted.
[flagged]
[flagged]
Re: Apple alerts users in 92 nations to mercenary spyware attacks
#228Earlier quoted context omitted.
iMessage histories are backed up in the nightly automatic non-e2ee iCloud Backup, effectively backdooring iMessage’s “end to end encryption” by escrowing the plaintext to a not-endpoint. Apple can read approximately everyone’s iMessages out of their backups. It’s not private or secure, and claiming it is end to end encrypted is misleading almost to the point of being actually false.
That has nothing to do with turning it on or off since the same happens with SMS.
Apple makes privacy claims about iMessage including 'Apple can’t decrypt the data.', which is notably false in this (common) scenario, and requires a large asterisk on those claims, IMO bordering on making them unethical, period.
Re: Apple alerts users in 92 nations to mercenary spyware attacks
#229"Mercenary spyware attacks, such as those using Pegasus from the NSO Group, are exceptionally rare and vastly more sophisticated than regular cybercriminal activity or consumer malware" So, maybe even provoking an Apple warning to those targets could also be part of a sophisticated operation. These targets react or have to react in a certain way. Instigate to lure people out of hiding and entice them to react, even i…
Apple:
"If you have received an Apple threat notification We strongly suggest you enlist expert help, such as the rapid-response emergency security assistance provided by the Digital Security Helpline at the nonprofit Access Now. Apple threat notification recipients can contact the Digital Security Helpline 24 hours a day, seven days a week through their website. Outside organizations do not have any information about what caused Apple to send a threat notification, but they can assist targeted users with tailored security advice."
https://support.apple.com/en-lamr/102174
Amnesty International:
"The Access Now Helpline and other Security Lab civil society partners are also equipped to support individuals who have received these Apple notifications."
https://securitylab.amnesty.org/latest/2024/04/apple-threat-...
Re: Apple alerts users in 92 nations to mercenary spyware attacks
#230There’s a reddit thread by somebody who got one of these: https://old.reddit.com/r/iphone/comments/1c10jai/i_have_rece... The interesting thing IMO is they claim to just be some random college student. Which seems believable because if they were a real secret squirrel I guess they wouldn’t ask reddit about it, haha. I wonder if the hackers are targeting people based on phone numbers or something. (I could imagine a c…
E: Thread: https://old.reddit.com/r/iphone/comments/1c10jai/i_have_rece...