Live data from Hacker News

Apple alerts users in 92 nations to mercenary spyware attacks

techcrunch.com

291–300 of 301 posts

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#291

Earlier quoted context omitted.

No. Most exploits target iMessage because everyone has it installed.

There's plenty of normal apps built-in, iOS isn't very modular. But none of those are not as deeply integrated as imessage.

Ok, but you still haven’t explained how this means it is any less secure. Can you point to exploits that take advantage of the system integration it has?

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#292

Earlier quoted context omitted.

Neither is correlated to how secure something is?

Yes it is

Despite you feeling smug about it, the economics of the zero day market are far more complex than you think they are.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#293

Earlier quoted context omitted.

There's plenty of normal apps built-in, iOS isn't very modular. But none of those are not as deeply integrated as imessage.

Ok, but you still haven’t explained how this means it is any less secure. Can you point to exploits that take advantage of the system integration it has?

It's less secure because it's not using the same sandbox used by billions of apps.

> Can you point to exploits that take advantage of the system integration it has?

Sure, the last pegasus attack on the image codec would not have worked on Android.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#294
post #288

Earlier quoted context omitted.

Users want their messages and iMessaged nudes to be private from Apple and warrantless FBI snooping. Presently, they aren’t.

Pretty sure Apple requires a warrant to decrypt those.

You are incorrect.

https://en.m.wikipedia.org/wiki/PRISM

From the front page of the Times today, they are renewing the law that says they have to do it without a warrant (FISA Section 702, aka PRISM).

https://www.nytimes.com/2024/04/12/us/politics/surveillance-...

You’ll note that this is regularly and frequently used by the FBI against domestic users (such as BLM protesters). Apple processes these FISA demands on over 70,000 user accounts every year, and the number is increasing. (That’s just the count for the warrantless FISA stuff - search warrants are a different (larger) figure.)

They also expanded it to allow them to search Apple’s data on people entering the US as visitors.

> The House also passed several other significant amendments. They included allowing the Section 702 program to be used to gather intelligence on foreign narcotics trafficking organizations and to vet potential foreign visitors to the United States; empowering certain congressional leaders to observe classified hearings before a court that oversees national-security surveillance; and expanding the types of companies with access to foreign communications that can be required to participate in the program.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#295

Earlier quoted context omitted.

Ok, but you still haven’t explained how this means it is any less secure. Can you point to exploits that take advantage of the system integration it has?

It's less secure because it's not using the same sandbox used by billions of apps. > Can you point to exploits that take advantage of the system integration it has? Sure, the last pegasus attack on the image codec would not have worked on Android.

You mean the WebP vulnerability in code that literally everyone shared? That one?

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#296

There’s a reddit thread by somebody who got one of these: https://old.reddit.com/r/iphone/comments/1c10jai/i_have_rece... The interesting thing IMO is they claim to just be some random college student. Which seems believable because if they were a real secret squirrel I guess they wouldn’t ask reddit about it, haha. I wonder if the hackers are targeting people based on phone numbers or something. (I could imagine a c…

Everyone's thinking academic secrets but have they engaged in activism in any way shape or form? Being able to take activists and discredit them is an amazing ability. I would not at all be surprised if the xz compression backdoor was an attempt by a certain government to gain the ability to discredit anyone that is against them in anyway.

How often is that being done in the modern age of social media? I don't think "activists" are very important or dangerous to governments anywhere.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#297
post #230

Earlier quoted context omitted.

In that thread someone asserted he received the first message after traveling to/through Cyprus E: Thread: https://old.reddit.com/r/iphone/comments/1c10jai/i_have_rece...

There's some significant geopolitical intrigue surrounding Cyprus -- probably the most obvious are its partition between between Turkey and Greece and its use as a tax haven by Russian oligarchs.

There's also "equipment" on Cyprus. I know a fiber-optic specialist who spent some time there working on a Five Eyes project for the UK.

See, e.g.: https://en.wikipedia.org/wiki/Akrotiri_and_Dhekelia

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#298

Earlier quoted context omitted.

The Permutation City reference is irrelevant to San Junipero. I never made the claim that the entities in the simulation were not sentient. I made the claim that they aren't "you." These are very different things. I haven't seen the newer seasons. But looking at the synopsis on wiki (Beyond the Sea?), this is a very different scenario. Permutation City might be a better one to look at for what I'm getting at. Remembe…

> I made the claim that they aren't "you." These are very different things. I understand what you're claiming, as I pointed out under this understanding your current existence is already terrifying. Not just when you fall asleep, but even moment by moment the underpinning compute substrate is repaired and replaced and yet it feels as though this is an ongoing experience, there's no reason Yorkie experiences this any…

That was not clear from the prior conversation. Lost in translation I guess.

Sure, we can go into sleep and is reality even real. But it's a bit different when we're talking about a specific reality we know is not real and the point I'm getting at is that we know that version of you is for sure 100% with no uncertainty not you. Since both entities can exist simultaneously and independently. Which is an entirely different construct than say dying in your sleep and being replaced because there's not multiple entities with shared experiences existing at the same time. What I'm pointing to is this so yeah there's clearly miscommunication when you're talking about an even more abstract concept.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#299

How can Pegasus and NSO still be allowed to exist? I know they are an Israeli corporation, but even then has there been action against them from the Israeli government? This is basically rogue state behavior

> How can Pegasus and NSO still be allowed to exist?

Because the entities that have the power to outlaw them are their biggest customers.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#300
post #119

Earlier quoted context omitted.

> I'm seriously considering changing to Apple after this. Ironically that may be worse for you. iMessage is probably a critical step in 60% (or more) of these exploits, and the various unicode/pdf etc rendering engines are responsible in many exploits. Android's open-source nature likely means that a lot of these things are found by security researchers first. Don't forget that zerodium still pays more for an android…

> Don't forget that zerodium still pays more for an android 0-day than an iOS 0-day. A random Internet search gives iOS 30% market share to Android's 70% [1], which could also explain the higher price. [1] https://www.statista.com/statistics/272698/global-market-sha...

That's worldwide, though. I think a target is more likely to reside in e.g. the US (where iOS usage is >50%) than in Africa.
Post reply on HN