Live data from Hacker News

The NSA Reportedly Has Total Access To The Apple iPhone

forbes.com

11–20 of 212 posts

Re: The NSA Reportedly Has Total Access To The Apple iPhone

#11
This is from a very old version of iOS (2007). We don't know if this is still true.

Regardless, I can say for a fact that there are exploits for all cell phone platforms. iOS exploits are by far the hardest to find. An iOS remote execution 0day will easily fetch $250k. I've seen one go for $600k. For an Android remote exec 0day, you're looking at closer to $50k.

Even if the NSA doesn't have these on hand, they can certainly purchase them.

Re: The NSA Reportedly Has Total Access To The Apple iPhone

#12
Honestly, I don't really care. The NSA can read whatever they want of mine. I've heard the arguments about how you should care, even if you don't have anything to hide. And I find them persuasive on one level and simultaneously unengaging on another. By contrast, the parallels to fascist Italy and Nazi Germany and living in a turnkey fascist state are most unpersuasive.

The one argument against what I've written that has been made that I think is worthy of highlighting is that there are people around the world who are risking their lives under totalitarian regimes. People's smug responses and ad hominem detract from this important point, which could be helpful to others outside of HN in better understanding the issue.

Your downvotes will not persuade me or anyone else with my views. They do demonstrate that some are committed partisans on this issue. I appreciate some of the clear, unemotional arguments that have been made, however.

Re: The NSA Reportedly Has Total Access To The Apple iPhone

#13

Humm... I was going to buy the new iPhone, this changed my mind. Maybe I should just get a feature phone instead.

All cell phone OSs are compromised to some degree. If Apple's claims about their crypto were auditable, I would say that iOS is the best from a security standpoint.

Re: The NSA Reportedly Has Total Access To The Apple iPhone

#14
So here is a complete anecdotal suspicion:

I have had the iPhone since the first day of release. I have gone through 16 physical devices over that period (due to me breaking them a lot and going through several employers where I had never purchased my own phone since (well before) it was released). I am currently, for the first time in a long time, on my own personal device; an iPhone 4.

I upgraded it to iOS7 when it was available. The device is a slow POS and I want to stab my eyes out when I use it....

However; there is a behavior that I have only personally noticed recently: (Please tell me if you see the same thing)

Whenever I transition between literally ANY screen, I see a quick BLINK of the screen - in the same anim that you would see when you take a screenshot.

So I am wondering "Is my phone taking a screen cap of EVERY switch/transition I make? WHY"

Now, I know that iOS does do screen caps of things so that when you are switching in various ways that it already has a cache of the last state of that screen in order to thumbnail the previous view... BUT I understood this to be limited to certain circumstances. Currently I am noticing it on pretty much ANY transition.

Even if this is the actual, "Normal", my suspicion is that this fact can be used to entirely rebuild an entire session of activity for a user through their entire interactions. Even if you just grab these screens which are used at a system level - a great deal could be inferred from just these workflow screen caps.

Re: The NSA Reportedly Has Total Access To The Apple iPhone

#15
post #11

This is from a very old version of iOS (2007). We don't know if this is still true. Regardless, I can say for a fact that there are exploits for all cell phone platforms. iOS exploits are by far the hardest to find. An iOS remote execution 0day will easily fetch $250k. I've seen one go for $600k. For an Android remote exec 0day, you're looking at closer to $50k. Even if the NSA doesn't have these on hand, they can ce…

Why isn't Apple (or some other consumer group) in that market buying up the 0days? I want to see the price of 0days that compromise any longitudinal user information above $10 million.

Idea: 0day markets are legalised [1]. Regulators require companies keep the average price of their 0days above a threshold or attach a warning to their product and marketing materials. This aligns the security interests of consumers with companies while incentivising companies and researchers to build secure products.

[1] A license to the 0day (but not the 0day itself) would be freely traded for a duration after which the company would have the option to (a) buy it at some price or (b) release it to the public, retaining full liability for any consequences (last holder of the license gets a percentage cut of any fines or legal awards).

Re: The NSA Reportedly Has Total Access To The Apple iPhone

#16
post #5

Humm... I was going to buy the new iPhone, this changed my mind. Maybe I should just get a feature phone instead.

All the phones are exploited. I doubt it matters.

Perhaps, but with a feature phone there's much less for the eavesdroppers to see.

Re: The NSA Reportedly Has Total Access To The Apple iPhone

#17
post #3

Spiegel source: http://www.spiegel.de/international/world/how-the-nsa-spies-...

Hm, now I'm paranoid re the little "special teams" that article mentions that intercepts the mail package and plugs in whatever doodad the NSA has into the phone, and then sends it along to the customer...my new iPhone had a fingerprint smudge on the screen plastic protector packaging that I otherwise attributed to some overworked Foxconn employee but now I have half a mind it was some NSA agent after 1 too many pizzas....

Re: The NSA Reportedly Has Total Access To The Apple iPhone

#18

Humm... I was going to buy the new iPhone, this changed my mind. Maybe I should just get a feature phone instead.

There's always "that guy" who makes this comment. We should start giving out "StackOverFlow style badges".

The sad fact is that it doesn't matter how secure your phone is because there's a weaker link in your security chain. You...

Re: The NSA Reportedly Has Total Access To The Apple iPhone

#19
post #11

This is from a very old version of iOS (2007). We don't know if this is still true. Regardless, I can say for a fact that there are exploits for all cell phone platforms. iOS exploits are by far the hardest to find. An iOS remote execution 0day will easily fetch $250k. I've seen one go for $600k. For an Android remote exec 0day, you're looking at closer to $50k. Even if the NSA doesn't have these on hand, they can ce…

Why isn't Apple (or some other consumer group) in that market buying up the 0days? I want to see the price of 0days that compromise any longitudinal user information above $10 million. Idea: 0day markets are legalised [1]. Regulators require companies keep the average price of their 0days above a threshold or attach a warning to their product and marketing materials. This aligns the security interests of consumers wi…

Apple being Apple, they wouldn't tell you. But I'm sure someone in there is thinking it. They did hire Geohot after his jailbreak...

Re: The NSA Reportedly Has Total Access To The Apple iPhone

#20
post #11

This is from a very old version of iOS (2007). We don't know if this is still true. Regardless, I can say for a fact that there are exploits for all cell phone platforms. iOS exploits are by far the hardest to find. An iOS remote execution 0day will easily fetch $250k. I've seen one go for $600k. For an Android remote exec 0day, you're looking at closer to $50k. Even if the NSA doesn't have these on hand, they can ce…

>I've seen one go for $600k.

Without revealing the actual site/method/whatever; can you please explain how the 0day exploit market works?

I can make basic assumptions that it is deep-web-forums/TOR/Whatever... but can you enlighten me as to how one might go about selling/buying such an exploit?

Post reply on HN