Live data from Hacker News

ICE Has a $2M Contract for Spyware That Can Hack Phones Without a Click

military.com

41–50 of 60 posts

Re: ICE Has a $2M Contract for Spyware That Can Hack Phones Without a Click

#41

> Graphite belongs to the same category of commercial surveillance technology as Pegasus, the better-known spyware developed by NSO Group. Both are classified as mercenary spyware, meaning private companies develop and sell them to government intelligence and law enforcement agencies. This buries the lede a bit. These companies play their part in trans-national organized crime networks, spanning countries like the US…

What is ICE doing besides immigration control?

They're the leading agency in the US involved in stopping human trafficking and child exploitation. Unfortunately the good work they do is being overshadowed by the other nonsensical shit.

Re: ICE Has a $2M Contract for Spyware That Can Hack Phones Without a Click

#42

> Graphite belongs to the same category of commercial surveillance technology as Pegasus, the better-known spyware developed by NSO Group. Both are classified as mercenary spyware, meaning private companies develop and sell them to government intelligence and law enforcement agencies. This buries the lede a bit. These companies play their part in trans-national organized crime networks, spanning countries like the US…

there are many if these companies and toolkits. too many to mention. more than 150 countries spend over 10M a year on _offensive_ cyber. generally making use of such toolkits if they lack inhouse capabilities, which is pretty much all of those countries because the people creating the capabilities will refuse to work for them, so they can sell their tools.

Yup, but here is the rub: you and me can't buy the real stuff. You have to be a professional law breaker, which means you are in organized crime (don't forget the white collar guys), or you are working for Intelligence, in whatever capacity, in whatever oversight. The problem is that for offensive surveillance organizations the line between crime and work gets blurred quickly. That is why I am not too enthusiastic that our Dutch intelligence agency will receive offensive capabilities as well. Information is power, and you will soon end up with an organization that feels limited by oversight, but that also can easily accumulate means to evade such oversight. Bonus points if people from those kinds of organizations find their way in legislative branches or overseeing powers.

This has been a process of decades. Also surveillance, cybercrime and business do connect. If you look at the history of capital flows in the US, you will see a massive shift of capital from military has been redirected to the surveillance industry. If you would cut out surveillance from the USA economy, things would look quite different. The stock market is heavily skewed towards companies with this business model. As food for thought, think about what the GDP looks like without Apple, Google, Anthropic, OpenAI etc. To give an example of just one facet, Meta alone makes billions on crime each year [1] and will fight toot and nail anyone who dares to threaten their business model of addiction and privacy violation. To continue down this path against the interests of the public, these companies feel confident enough to try their hands at dangerous games [2], of which history teaches us that will always end in tears, because zero-sum is in the end a hunger game.

[1] https://www.reuters.com/investigations/meta-is-earning-fortu...

[2] https://abc45.com/news/nation-world/big-tech-ceos-attend-tru...

Re: ICE Has a $2M Contract for Spyware That Can Hack Phones Without a Click

#43
post #38

> The most dangerous infections require no mistake by the target. A zero-click attack works because phones automatically inspect incoming messages and files before displaying them. It’s zero click but it needs an entry point, do we know the entry point? Yes of course! It’s the phone number!! I hope now you know why they keep phone numbers as a mean of identification, all the big tech and advancement in protocols and…

> "It’s zero click but it needs an entry point, do we know the entry point? Yes of course! It’s the phone number!!"

Sort of, but not really. iMessage, Whatsapp, Signal, etc are the actual entry point. You can use some of those services without a phone number and having your phone number tied to a different device isn't going to protect you. If you had none of those on your phone most of these attacks wouldn't work.

> phone modems has their own gnss and they send location to the towers all the time

Cell modems don't have their "own gnss", nor would it be needed to track people. Cell signal triangulation is what the mobile networks utilize. It is mainly used to help provide location data to emergency services and is accurate enough with three or more towers. They can also do it with two, but then it's a less accurate positioning, with the user's location being in the overlap of the two cells.

Re: ICE Has a $2M Contract for Spyware That Can Hack Phones Without a Click

#44
post #40

Earlier quoted context omitted.

They reuse the same zero-days across multiple countries and agencies; Israelis are very efficient at doing business.

Ok, so they can amortize expense and scarcity. But if they are reusing exploits, why isn't WhatsApp or the phone OS patched? I'm confused how they can be known functional infections, used multiple times, and then not get checked by the vendors? Even not be thwarted by some incidental app-patch. WhatsApp and Signal must know of this, don't they have some AI tools to fuzz and fix?

A lot of these exploits don't survive an update, power cycling, etc. Some, if they're done well, may also clean up after themselves.

Doing digital forensics on a restrictive mobile device (like an iphone or decent android phone) is difficult.

> WhatsApp and Signal must know of this, don't they have some AI tools to fuzz and fix?

Sure, but it's not a simple thing. That's why these exploits can go for millions. If it was easy to "fuzz and fix" these exploits would be worth nothing.

Re: ICE Has a $2M Contract for Spyware That Can Hack Phones Without a Click

#45
post #34
post #6

for people that don't understand how bad ICE is, here is a brief selection of _recent_ news about ICE, this isn't even like the product of an extensive search Ice buys shock gloves https://www.pbs.org/newshour/nation/a-perfect-tool-for-abuse... ICE doesn't pay hospital bills: https://www.sfchronicle.com/politics/article/ice-detainee-me... DOJ blocked federal prosecution of ICE agent in shooting: https://www.propublic…

Indeed. But when the rubber meets the road, even our community has trouble standing behind people taking direct action to disrupt ICE activities. eg: https://news.ycombinator.com/item?id=48727750

Tech in general (including HN) skews right wing. The era of the countercultural social rebel is long over. Now it's largely just people who have the bag defending the status quo and a whole bunch more people who think they'll one day be holding the bag so are defending the status quo. Tech companies are now fundamentally just defense contractors.

There are an awful lot of people who don't hate opression. They simply hate being oppressed. And those are two very different things.

This claim probably upsets a bunch of people who don't want to think of themselves as right wing. They'll point to rainbow flags in their bios at the same time they're the most NIMBY people in the Bay Area and they basically want homeless people to just die.

Re: ICE Has a $2M Contract for Spyware That Can Hack Phones Without a Click

#46

Earlier quoted context omitted.

there are many if these companies and toolkits. too many to mention. more than 150 countries spend over 10M a year on _offensive_ cyber. generally making use of such toolkits if they lack inhouse capabilities, which is pretty much all of those countries because the people creating the capabilities will refuse to work for them, so they can sell their tools.

Yup, but here is the rub: you and me can't buy the real stuff. You have to be a professional law breaker, which means you are in organized crime (don't forget the white collar guys), or you are working for Intelligence, in whatever capacity, in whatever oversight. The problem is that for offensive surveillance organizations the line between crime and work gets blurred quickly. That is why I am not too enthusiastic th…

a lot of these companies sell to people with money. its just that ordinary folks cant afford million dollar contracts.

there are varying degrees ofc. not everyone is NSO group or such ex intelligence folks. many sell licenses to red teams and security service providers (and law enforcement in some cases).

private intelligence companies use such tooling to gather information on individuals for business and private customers too.

a lot of toolkits also allow to just add your own exploits via scripting etc. so you can get exploits in 1 place and tooling in another etc.

there are laws, but those are not everywhere, and its unclear whos dealin to who in a lot of cases

Re: ICE Has a $2M Contract for Spyware That Can Hack Phones Without a Click

#47

Earlier quoted context omitted.

there are many if these companies and toolkits. too many to mention. more than 150 countries spend over 10M a year on _offensive_ cyber. generally making use of such toolkits if they lack inhouse capabilities, which is pretty much all of those countries because the people creating the capabilities will refuse to work for them, so they can sell their tools.

Yup, but here is the rub: you and me can't buy the real stuff. You have to be a professional law breaker, which means you are in organized crime (don't forget the white collar guys), or you are working for Intelligence, in whatever capacity, in whatever oversight. The problem is that for offensive surveillance organizations the line between crime and work gets blurred quickly. That is why I am not too enthusiastic th…

> That is why I am not too enthusiastic that our Dutch intelligence agency will receive offensive capabilities as well

AIVD[0] has had world renowned offensive cyber capabilities for a long time now. They punch _way_ above their weight class, equalling and maybe surpassing the capabilities of countries like Russia, although Russia throws more people at it so they end up with a broader overall impact. It's actually really, really impressive what they've accomplished. You should be proud of it. For example of some of their good work: https://www.zdnet.com/article/dutch-spies-tipped-off-nsa-tha...

"When hackers operating next to Moscow’s Red Square launched an attack against the Democratic Party in 2015, someone was watching. And that someone, according to new reports, was the Dutch General Intelligence and Security Service (AIVD).

Netherlands newspaper de Volkskrant and the public broadcaster NOS reported on Thursday evening that AIVD hackers had penetrated the Russian operation back in the summer of 2014."

More here: https://www.washingtonpost.com/news/worldviews/wp/2018/01/26...

[0] https://english.aivd.nl/

Re: ICE Has a $2M Contract for Spyware That Can Hack Phones Without a Click

#48

Earlier quoted context omitted.

Yup, but here is the rub: you and me can't buy the real stuff. You have to be a professional law breaker, which means you are in organized crime (don't forget the white collar guys), or you are working for Intelligence, in whatever capacity, in whatever oversight. The problem is that for offensive surveillance organizations the line between crime and work gets blurred quickly. That is why I am not too enthusiastic th…

> That is why I am not too enthusiastic that our Dutch intelligence agency will receive offensive capabilities as well AIVD[0] has had world renowned offensive cyber capabilities for a long time now. They punch _way_ above their weight class, equalling and maybe surpassing the capabilities of countries like Russia, although Russia throws more people at it so they end up with a broader overall impact. It's actually re…

  > It's actually really, really impressive what they've accomplished. You should be proud of it. 
No doubts about that, they are world class. But they are seeking to reduce oversight, and they succeed at that politically. The last government, a (far) right wing coalition of highly ineffective parties and personalities, with Schoof as so-called `neutral` prime minister had laid the ground work. Schoof had been director-general of the NCTV, in his roles he was connected to intelligence services. Unsurprisingly, in the short lifetime of his cabinet he managed to reduce oversight.

This is a moral hazard. Nations should implement a very clear rule: when you have served in the intelligence service community, you cannot partake in politics. The intel branch should be firewalled off from the democratic branches.

A good overview from a big dutch tech site: https://tweakers.net/reviews/15236/aivd-en-mivd-lijken-hun-z...

Re: ICE Has a $2M Contract for Spyware That Can Hack Phones Without a Click

#49
post #38

> The most dangerous infections require no mistake by the target. A zero-click attack works because phones automatically inspect incoming messages and files before displaying them. It’s zero click but it needs an entry point, do we know the entry point? Yes of course! It’s the phone number!! I hope now you know why they keep phone numbers as a mean of identification, all the big tech and advancement in protocols and…

If you don't use third party messaging services your phone number is not necessarily an entry point. Your particular device could have an sms 0day, but it's less universally applicable.

Re: ICE Has a $2M Contract for Spyware That Can Hack Phones Without a Click

#50

Earlier quoted context omitted.

Yup, but here is the rub: you and me can't buy the real stuff. You have to be a professional law breaker, which means you are in organized crime (don't forget the white collar guys), or you are working for Intelligence, in whatever capacity, in whatever oversight. The problem is that for offensive surveillance organizations the line between crime and work gets blurred quickly. That is why I am not too enthusiastic th…

a lot of these companies sell to people with money. its just that ordinary folks cant afford million dollar contracts. there are varying degrees ofc. not everyone is NSO group or such ex intelligence folks. many sell licenses to red teams and security service providers (and law enforcement in some cases). private intelligence companies use such tooling to gather information on individuals for business and private cus…

  > private intelligence companies use such tooling to gather information on individuals for business and private customers too.
Yes, that is a very scary. These weapons are being used against journalists and politicians threatening personal business interests.
Post reply on HN