Live data from Hacker News

ICE Has a $2M Contract for Spyware That Can Hack Phones Without a Click

military.com

51–60 of 60 posts

Re: ICE Has a $2M Contract for Spyware That Can Hack Phones Without a Click

#51
post #45
post #34

Earlier quoted context omitted.

Indeed. But when the rubber meets the road, even our community has trouble standing behind people taking direct action to disrupt ICE activities. eg: https://news.ycombinator.com/item?id=48727750

Tech in general (including HN) skews right wing. The era of the countercultural social rebel is long over. Now it's largely just people who have the bag defending the status quo and a whole bunch more people who think they'll one day be holding the bag so are defending the status quo. Tech companies are now fundamentally just defense contractors. There are an awful lot of people who don't hate opression. They simply…

This is perhaps one of the more disappointing aspects of the collapse of the 'old internet' and its replacement with the venture capital backed enshittification engine that it is now. Tech people used to be mostly people who were curious about things. That might not be a selector for 'good' person but it's at least a selector against the kind of brutally effective banal corporate evil that so dominates the space today.

Re: ICE Has a $2M Contract for Spyware That Can Hack Phones Without a Click

#52

>Citizen Lab helped WhatsApp identify and block an active Graphite zero-click exploit in late 2024. How to get murdered by a private equity firm in one easy step.

They’ve been doing this for a while. And actually there’s a pretty great episode of darknet diaries that talks about how they were directly targeted by 8200 agents (taken out to dinner in New York IIRC). They were trying to find dirt on the guy.

I think the days of nation-corps openly initiating tolerated if not fully legal 'police actions' against people sufficiently disruptive to quarterly results is probably in our not too distant future. A couple generations, at most.

Re: ICE Has a $2M Contract for Spyware That Can Hack Phones Without a Click

#53
post #38

> The most dangerous infections require no mistake by the target. A zero-click attack works because phones automatically inspect incoming messages and files before displaying them. It’s zero click but it needs an entry point, do we know the entry point? Yes of course! It’s the phone number!! I hope now you know why they keep phone numbers as a mean of identification, all the big tech and advancement in protocols and…

> "It’s zero click but it needs an entry point, do we know the entry point? Yes of course! It’s the phone number!!" Sort of, but not really. iMessage, Whatsapp, Signal, etc are the actual entry point. You can use some of those services without a phone number and having your phone number tied to a different device isn't going to protect you. If you had none of those on your phone most of these attacks wouldn't work. >…

> Sort of, but not really. iMessage, Whatsapp, Signal, etc are the actual entry point.

You are missing the point, the phone number is what links your identity in real life with the digital one, say you have WhatsApp and only was registered with an email, that email is hard or impossible to link it to you compared to a phone number. This is not about a vulnerability on an app but the points where it’s easy to send something remotely on someone’s phone to have click or zero click attack, knowing it’s them and it’s their phone.

> Cell modems don't have their "own gnss", nor would it be needed to track people.

Nope, the triangulation method is the old school way, aka old cell phones, new phones send the exact location from the gnss, and cell modems have built in gnss, just grab a quectel and send an AT command after connecting the antennas and you will get precise location, I personally used it in some projects before. Read more about the gnss sent by your phone here, which apple is trying to stop in recent phones.

https://an.dywa.ng/carrier-gnss.html

Re: ICE Has a $2M Contract for Spyware That Can Hack Phones Without a Click

#54
post #9

So NSA Wiretapping is illegal but ICE is ok? This administration is so wantonly criminal.

Wait, since when has the NSA stopped collecting data? That assumption is new to me.

It is statutorily unlawful for NSA and foreign-facing intelligence agencies to target Americans for spying except for in certain specific conditions. This law has long been ignored, but it is on the books.

Re: ICE Has a $2M Contract for Spyware That Can Hack Phones Without a Click

#55
post #53

Earlier quoted context omitted.

> "It’s zero click but it needs an entry point, do we know the entry point? Yes of course! It’s the phone number!!" Sort of, but not really. iMessage, Whatsapp, Signal, etc are the actual entry point. You can use some of those services without a phone number and having your phone number tied to a different device isn't going to protect you. If you had none of those on your phone most of these attacks wouldn't work. >…

> Sort of, but not really. iMessage, Whatsapp, Signal, etc are the actual entry point. You are missing the point, the phone number is what links your identity in real life with the digital one, say you have WhatsApp and only was registered with an email, that email is hard or impossible to link it to you compared to a phone number. This is not about a vulnerability on an app but the points where it’s easy to send som…

> say you have WhatsApp and only was registered with an email, that email is hard or impossible to link it to you

I mean, this simply isn't the case. Email is very noisy and leaves tons of evidence all over the internet.

> new phones send the exact location from the gnss, and cell modems have built in gnss, just grab a quectel and send an AT command after connecting the antennas and you will get precise location

The link you provided states the GNSS for the cell modem is GPS (or one of the other non-US systems). You said disabling GPS on the phone doesn't change this. Are you saying the modem has a second, secret GPS antenna? Or does it use some other global navigation system that isn't GPS?

The post also directly mentions GPS and triangulation:

> According to news sources, it routinely collects information from cellular companies and identifies the location of all phones through cellular antenna triangulation and GPS data

GNSS is just a blanket term for GPS-like systems, which is a passive system for identifying where you are on the planet.

Re: ICE Has a $2M Contract for Spyware That Can Hack Phones Without a Click

#56

> Graphite belongs to the same category of commercial surveillance technology as Pegasus, the better-known spyware developed by NSO Group. Both are classified as mercenary spyware, meaning private companies develop and sell them to government intelligence and law enforcement agencies. This buries the lede a bit. These companies play their part in trans-national organized crime networks, spanning countries like the US…

> I cannot unsee this from the massive purges in the military, rooting out the most competent leadership. Structural coherence issues aside, is this some sort of a joke, or just thinly veiled personal bias presented as fact?

[dead]

Re: ICE Has a $2M Contract for Spyware That Can Hack Phones Without a Click

#57
post #9

Earlier quoted context omitted.

Wait, since when has the NSA stopped collecting data? That assumption is new to me.

It is statutorily unlawful for NSA and foreign-facing intelligence agencies to target Americans for spying except for in certain specific conditions. This law has long been ignored, but it is on the books.

It’s orthogonal. Whether legal or not you know they have the data.

I think most people were glad authorities were using flock and cell tower data to backtrack and arrest folks involved in the Jan riots. They didn’t push back then cuz they didn’t have the vision to see that it would just grow bigger and get used more commonly almost quotidian. And it will by this admin and by the opposing admins. They all love having data at their disposal. Heck, Congress did nothing about being spied on by our intelligence services.

Re: ICE Has a $2M Contract for Spyware That Can Hack Phones Without a Click

#58
post #53

Earlier quoted context omitted.

> Sort of, but not really. iMessage, Whatsapp, Signal, etc are the actual entry point. You are missing the point, the phone number is what links your identity in real life with the digital one, say you have WhatsApp and only was registered with an email, that email is hard or impossible to link it to you compared to a phone number. This is not about a vulnerability on an app but the points where it’s easy to send som…

> say you have WhatsApp and only was registered with an email, that email is hard or impossible to link it to you I mean, this simply isn't the case. Email is very noisy and leaves tons of evidence all over the internet. > new phones send the exact location from the gnss, and cell modems have built in gnss, just grab a quectel and send an AT command after connecting the antennas and you will get precise location The…

> Email is very noisy and leaves tons of evidence all over the internet.

That’s correct, but email aren’t as linked to your real identity as how it’s the case with a phone number, knowing someone’s phone you can: deliver zero click zero day through an SMS, know their precise location, know their personal information as that number mostly used in government/banks/insurance/etc., plus real time data (listed below), so effectively knowing all that in a click on some aggregator (plantir?), the email isn’t as easy, while it’s not secure and never will be, it doesn’t provide that accurate information quickly about someone without extra steps, assuming it wasn’t a burner email anyway.

> The link you provided states the GNSS for the cell modem is GPS (or one of the other non-US systems). You said disabling GPS on the phone doesn't change this. Are you saying the modem has a second, secret GPS antenna? Or does it use some other global navigation system that isn't GPS?

I am aware what gnss is, and nope nope to both. Ok, let me explain, disabling the location services in your phone will not prevent your carrier from knowing your location, that will disable the OS/apps levels, but the gnss is embedded within your modem, with a firmware you don’t control or know. When you click the disable buttons you only prevent the OS of getting the location data, not the modem, and even if you happen (impossible) to open the hardware and cut the wires of the embedded gnss, the carrier can still estimate your location. Only when you stops the carrier connection is when you are truly not tracked, airplane mode is being the easiest but other means exist.

Per the link I shared before (also this if you need more details), 5G’s LTE Positioning Protocol LPP explicitly permits a network location server to ask a phone for GNSS measurements or a GNSS-derived location estimate.

https://www.etsi.org/deliver/etsi_ts/137300_137399/137355/16... (pages 214 to 230)

The modem firmware is proprietary and can’t prove it doesn’t share the location once you disable it, in fact, the reason why apple is disabling it in their own modems at hardware level proves it can’t be disabled on a software. Also, both android and apple say that basically just because you have location disabled doesn’t mean your location isn’t known for emergencies.

https://support.apple.com/en-us/102515

https://support.google.com/android/answer/9319337?hl=en

Even so, with location disabled, at hardware level, the carrier can still use: serving cell and sector to know your location, the timing of roundtrip RTT and time advance TA angle of arrival AoA and the usual suspect RSRP/RSRQ, signal strength and radio metrics, tower tilateration (canada admit using that for emergency https://crtc.gc.ca/eng/phone/911/can.htm), and positioning signals E-CID and OTDOA.

All of that won’t be an issue if you are not connected to the carrier, and to be connected you need a sim card, and that means you have a phone number, see how much you get exposed by only having a phone number, real time data or historical personal record? It’s why it’s still required in all services under the disguise of preventing spam or 2FA. Bottom line: don’t trust a service that requires a phone number, try to always have your phone disconnected from carrier by at least airplane mode, or better measures.

Re: ICE Has a $2M Contract for Spyware That Can Hack Phones Without a Click

#59
post #11
post #6

for people that don't understand how bad ICE is, here is a brief selection of _recent_ news about ICE, this isn't even like the product of an extensive search Ice buys shock gloves https://www.pbs.org/newshour/nation/a-perfect-tool-for-abuse... ICE doesn't pay hospital bills: https://www.sfchronicle.com/politics/article/ice-detainee-me... DOJ blocked federal prosecution of ICE agent in shooting: https://www.propublic…

> ICE Deports Milo Yiannopoulos, to settle some intra-MAGA feud This is probably the one valid thing they did. He's truly vile [1]. He's also illustrative of how most undocumented people aren't "sneaking across the border" as the media claims but are simply visa overstayers. Still, Laura Loomer shouldn't have the power to advance his deportation. The story goes that he was in removal proceedings and he didn't show up…

Nothing important was lost in the night of the long knives, either, in terms of the victims.. just the rule of law.

Re: ICE Has a $2M Contract for Spyware That Can Hack Phones Without a Click

#60
post #29

Ehud Baraj, wasn't he a close confidante of Epstein?

I assume you mean Ehud Barak? Surely not, or I would have heard about it in the US media for sure.

The media in the US doesn't cover all the Epstein associates for some reason.

But he is. For example:

https://www.aljazeera.com/news/2026/2/13/former-israeli-pm-b...

Post reply on HN