Live data from Hacker News

The NSA Reportedly Has Total Access To The Apple iPhone

forbes.com

71–80 of 212 posts

Re: The NSA Reportedly Has Total Access To The Apple iPhone

#71
post #48

Earlier quoted context omitted.

who are these NSA people that aren't also random people?

They are a subset of random people, and one OP is less concerned about having his credentials than random people as a whole.

an interesting question GP raises...

Who would you be more worried about having access to your email account and why?

  a. NSA
  b. a random criminal (unaffiliated with government)
For me, the answer is not even close, but I'm more interested in understanding how others on HN process this.

Re: The NSA Reportedly Has Total Access To The Apple iPhone

#72
post #59

Earlier quoted context omitted.

If you were the NSA, would you be taking screenshots just as the target was /switching/ apps, instead of taking them while they're using it? Oh, he's opened Mail, take a screenshot of Mail's splash screen while it's loading, now don't do anything. Oh, he's done using the app, quick, take a screenshot of his empty inbox before the app switches to Candy Crush. Not to mention that the screen flash while a screenshot is…

I am not talking about the "NSA taking screen shots" -- I am talking about the iOS taking screenshots... this is just a "nice feature" that any phone tapper/hacker (like the NSA) could exploit. My question is: Does the iOS device, in fact, take a screenshot of every single transition? everyone seems to miss my question, thus I must be posing it poorly. What I said again, simply, was that: I knew that some transitions…

Ah, i see what you mean. I think you are correct in that iOS takes a screenshot of pretty much every transition, but i'm willing to bet that it has nothing to do with the screen flashes as it should be automatic and in the background. The screen flashes are UX features for user controlled screenshots. I believe the screenshots of each application's state before transition has to be stored somewhere and if someone manages to access them, some damage could be done, but at the same time, not that much. I don't know exactly how the screenshots are queued up (is there 1 screenshot for each application? If i open the app again and navigate to another view and transition out, is the first screenshot overwritten?)

Apologies, your initial comment sounded like you thought you were being targeted by the NSA or something.

Re: The NSA Reportedly Has Total Access To The Apple iPhone

#73
post #54

Honestly, I don't really care. The NSA can read whatever they want of mine. I've heard the arguments about how you should care, even if you don't have anything to hide. And I find them persuasive on one level and simultaneously unengaging on another. By contrast, the parallels to fascist Italy and Nazi Germany and living in a turnkey fascist state are most unpersuasive. The one argument against what I've written that…

Imagine the abuses of J. Edgar Hoover or Richard Nixon, except amplified with today's tech. "It always seemed like President Nixon's campaign was one step ahead of us, almost as if they were reading our email...but nobody ever broke into our hotel suite or anything so it's all just speculation." Edit: brainfart as pointed out by jeremyswank.

I guess you probably mean J. Edgar Hoover, a former head of the FBI.

Re: The NSA Reportedly Has Total Access To The Apple iPhone

#75
post #45
post #11

This is from a very old version of iOS (2007). We don't know if this is still true. Regardless, I can say for a fact that there are exploits for all cell phone platforms. iOS exploits are by far the hardest to find. An iOS remote execution 0day will easily fetch $250k. I've seen one go for $600k. For an Android remote exec 0day, you're looking at closer to $50k. Even if the NSA doesn't have these on hand, they can ce…

Seriously? Apple fanboys feel the need to try to defend Apple by saying that their competitors are worse? Wake the fuck up! This isn't about Apple. It's about an out of control military that's spying on all of us and threatening our way of life and our livelihoods.

Your comment would be of more value if you removed your "Apple fanboy" rant and made a point about the government being out of control.

Re: The NSA Reportedly Has Total Access To The Apple iPhone

#76
post #27

Earlier quoted context omitted.

Why isn't Apple (or some other consumer group) in that market buying up the 0days? I want to see the price of 0days that compromise any longitudinal user information above $10 million. Idea: 0day markets are legalised [1]. Regulators require companies keep the average price of their 0days above a threshold or attach a warning to their product and marketing materials. This aligns the security interests of consumers wi…

I like the idea. I would donate towards a more secure AOSP. Unfortunately, no matter how much you sure up your phone's OS, there is still a massive, gaping hole in the form of the baseband processor. Until we have phones where the baseband is a tightly regulated slave processor, accessible only through a low-privelege mechanism (like a USB port), we can't really hope to have truly secure phones anyway.

Could you elaborate on this? -- I don't know anything about the issues of baseband processors on mobile phones (or even what they are) but it sounds interesting.

Re: The NSA Reportedly Has Total Access To The Apple iPhone

#77

Couldn't this be accomplished simply by creating apps that deal with contacts, photos, camera, etc. and then having users download and accept the permissions themselves. For example, imagine that any one of the contact or calendar management apps where you "Allow xxxxx to access your contacts" was produced by the NSA under the guise of an innovative startup.

Not quite: for example, iOS doesn't allow apps to access the SMS database.

In light of recent leaks, it's still pretty obvious: think a repackaging of OTA jailbreaks (like jailbreakme from the iPhone OS 3 era) plus Foxacid.

You could make jailbreakme not display a dialog or install Cydia, and the user wouldn't notice anything except their phone got warm for awhile and has a newly opened port for SSH.

Re: The NSA Reportedly Has Total Access To The Apple iPhone

#78
post #21

Earlier quoted context omitted.

Why isn't Apple (or some other consumer group) in that market buying up the 0days? I want to see the price of 0days that compromise any longitudinal user information above $10 million. Idea: 0day markets are legalised [1]. Regulators require companies keep the average price of their 0days above a threshold or attach a warning to their product and marketing materials. This aligns the security interests of consumers wi…

Because then Apple would be promoting and adding money to a market it does not want developed and also probably engaging in illegal transactions.

No, Google sort of does this with their bug bounties for Chrome.

Re: The NSA Reportedly Has Total Access To The Apple iPhone

#79
post #19

Earlier quoted context omitted.

Why isn't Apple (or some other consumer group) in that market buying up the 0days? I want to see the price of 0days that compromise any longitudinal user information above $10 million. Idea: 0day markets are legalised [1]. Regulators require companies keep the average price of their 0days above a threshold or attach a warning to their product and marketing materials. This aligns the security interests of consumers wi…

Apple being Apple, they wouldn't tell you. But I'm sure someone in there is thinking it. They did hire Geohot after his jailbreak...

Doesn't matter if any of this is true or not, it's the perception that counts.

I'm quite interested to see what, if anything, Tim Cook will do or say to reassure the faithful.

"Apple is erasing discussions on this topic at their support forum, right now the whole forum is shut down for a complete cleanup."

http://forums.appleinsider.com/t/161398/nsa-worked-on-iphone...

Re: The NSA Reportedly Has Total Access To The Apple iPhone

#80
post #32

Not only is the slide from 2008, but it also says it requires "close access methods" and "remote installation will be pursued for a future release." In other words, they need physical access to your device. If we think that the NSA can't compromise a device after gaining physical access, well then I think we should be scared about the competence of the NSA. I don't have the patience to watch Appelbaum's hour long tal…

"physical access", or "we'll run a jailbreak tool and set the 'hidden' property of the Cydia app to true"
Post reply on HN