Live data from Hacker News

The NSA Reportedly Has Total Access To The Apple iPhone

forbes.com

91–100 of 212 posts

Re: The NSA Reportedly Has Total Access To The Apple iPhone

#91

Earlier quoted context omitted.

They are a subset of random people, and one OP is less concerned about having his credentials than random people as a whole.

an interesting question GP raises... Who would you be more worried about having access to your email account and why? a. NSA b. a random criminal (unaffiliated with government) For me, the answer is not even close, but I'm more interested in understanding how others on HN process this.

In cases like these you have to evaluate the probability of something bad happening times the magnitude of the harm (essentially the expected value). The NSA can do much more damage (excluding the fact that they can do similar damage even without having this information) than a random lowly criminal, however the likelihood they'll target a boring person such as me is much lower. So for me I'd be more worried about b. Of course, ideally I would rather not have to worry about either.

Re: The NSA Reportedly Has Total Access To The Apple iPhone

#92
post #45
post #11

This is from a very old version of iOS (2007). We don't know if this is still true. Regardless, I can say for a fact that there are exploits for all cell phone platforms. iOS exploits are by far the hardest to find. An iOS remote execution 0day will easily fetch $250k. I've seen one go for $600k. For an Android remote exec 0day, you're looking at closer to $50k. Even if the NSA doesn't have these on hand, they can ce…

Seriously? Apple fanboys feel the need to try to defend Apple by saying that their competitors are worse? Wake the fuck up! This isn't about Apple. It's about an out of control military that's spying on all of us and threatening our way of life and our livelihoods.

I know very well why this hurts Apple fans so much:

It has been Apple's strategy all along to get you to buy literally everything from them. Their USP was to have it all integrated.

Problem is: Once you understand that at least 1 peace of your integrated platform is foul, your whole equipment "looses value" for you, because it's now less integrated.

It's a similar strategy to how banks have been protecting themselves: Be/remain "too big to fail", meaning: Become so big that, when your bottom line is under attack (by whatever market forces), the whole society suffers. Thus, society will protect you, no matter how you behave.

Re: The NSA Reportedly Has Total Access To The Apple iPhone

#93
post #37

Honestly, I don't really care. The NSA can read whatever they want of mine. I've heard the arguments about how you should care, even if you don't have anything to hide. And I find them persuasive on one level and simultaneously unengaging on another. By contrast, the parallels to fascist Italy and Nazi Germany and living in a turnkey fascist state are most unpersuasive. The one argument against what I've written that…

I completely disagree, but I have voted you up. You represent normal people. Those of us who care are the weirdos. I've given up. Whats the point? Frankly, if I knew I needed actual privacy, I'd not use anything electronic, and go olde skool. That's all I need to know now. I've told everyone I know and / or care about. Its now up to them. Get used to it, Big Brother has been here for a while, is staying, and will get…

I wrote you a sticky note encrypted with a Caesar-cipher based on the one published in the 1964 Encyclopedia Britannica. I affixed it to the door of the first stall of the men's bathroom of the 3rd floor of the engineering building. Please reply by February 7th 2014, as the final meeting is scheduled for October 2014 and there is barely time to coordinate with Eagle, Moe, and Fixie. Given the custodial hazards of stall-based sticky note networking there will be a follow-up note soon. -- exxegoexsrgi

Re: The NSA Reportedly Has Total Access To The Apple iPhone

#94
post #34

Earlier quoted context omitted.

>I've seen one go for $600k. Without revealing the actual site/method/whatever; can you please explain how the 0day exploit market works? I can make basic assumptions that it is deep-web-forums/TOR/Whatever... but can you enlighten me as to how one might go about selling/buying such an exploit?

It's not really a huge secret. I'm sure you could do a little digging and find out what's what. But that said, here's a run-down of the market: There are lone ranger types and small groups that churn out a few exploits. These guys (the small groups) go through trusted middlemen (usually via encrypted email), who buy the exploits at a discount. Now the middleman has a collection of 0days that he can sell to establishe…

I can smell a Hollywood movie potential here. "0day the Movie"

Re: The NSA Reportedly Has Total Access To The Apple iPhone

#95
Now the talk he gave was interesting, laying out some known and some new facts about the surveillance and automated attack capabilities of the NSA, particularity interesting is the targeting of infrastructure and their traffic injection systems. And he is right to make the point, that its particularly despicable that they actively sabotage infrastructure security, something everyone on this planet has to suffer from.

But.. I don't even know where to begin, its not only that we need to convince a large portion of the US population that living in a dystopian total surveillance state is actually not something to thrive for, we can't even begin to discuss those issues in any meaningful way when people have not the slightest clue whats really going on, even if leaks like this occur that outline frightening and utterly insane surveillance and attack capabilities nobody is going to explain it to them (not that anyone cares anyways).

The NSA developed and deployed a global system that enables them to do DPI on the whole internet traffic, analyze that traffic, inject traffic, attack every system through countless vulnerabilities and backdoors and all of that automated, not only against their “targets” but also against any infrastructure they are interested in.

They have secret laws, can force companies to work with them, force backdoors and not only are the US companies not allowed to talk about those things, they are legally bound to publicly lie about it.

So yeah they can hack every iPhone on this planet, and turn it into a silent listening device, among many many many other things, is that really what we should be talking about?

Re: The NSA Reportedly Has Total Access To The Apple iPhone

#96
post #32

Not only is the slide from 2008, but it also says it requires "close access methods" and "remote installation will be pursued for a future release." In other words, they need physical access to your device. If we think that the NSA can't compromise a device after gaining physical access, well then I think we should be scared about the competence of the NSA. I don't have the patience to watch Appelbaum's hour long tal…

Much of Jacob's presentation echoes many of the articles he (and others) had published in Der Spiegel earlier that day, going into a little more into the technical aspects (to the extent they are known and/or can be inferred.) While you may skip out the talk, at least look over the articles. While Jacob's style may rub you wrong, the issues are there regardless, and impatience is hardly a justifiable excuse.

On another note, if you are aware of Jacob misleading on any matter, it would be nice pointing that out directly. He is an activist that has done everything from helping with on-the-ground infrastructure deployments in war-torn areas, working on and advocating for Tor, speaking in front of the EU council… Casting doubt on his integrity without highlighting relevant facts is a way of distracting from the actual issues under discussion.

Re: The NSA Reportedly Has Total Access To The Apple iPhone

#97
post #32

Not only is the slide from 2008, but it also says it requires "close access methods" and "remote installation will be pursued for a future release." In other words, they need physical access to your device. If we think that the NSA can't compromise a device after gaining physical access, well then I think we should be scared about the competence of the NSA. I don't have the patience to watch Appelbaum's hour long tal…

>I don't have the patience to watch Appelbaum's hour long talk, but unless he has something far more impressive than these documents then he's just another activist who will willfully mislead in order to advance his cause.

The fact that you cherry picked a obvious example, and even downplayed its singificance -- plus fact that you were quick to call him an "activist" (nay, "another activist", how their pesky multitudes annoy you), tells more about you than about him or the talk.

Re: The NSA Reportedly Has Total Access To The Apple iPhone

#98

Honestly, I don't really care. The NSA can read whatever they want of mine. I've heard the arguments about how you should care, even if you don't have anything to hide. And I find them persuasive on one level and simultaneously unengaging on another. By contrast, the parallels to fascist Italy and Nazi Germany and living in a turnkey fascist state are most unpersuasive. The one argument against what I've written that…

Disagree completely but upvoted because it's an opinion that I think should be seen. Your comments effectively represent the 99.999% of the population that doesn't pay attention to any of this, except to what small amount they're fed via "paranoid" tech friends (and they all wear tinfoil hats, so whatever), nightly news and 60 minutes.

Re: The NSA Reportedly Has Total Access To The Apple iPhone

#100
post #82

Aren't we missing a critical point here?? > "The initial release of DROPOUTJEEP will focus on installing the implant via closed access methods." [2007] OK, we knew this much already. I remember seeing a number of stories on how law enforcement can pull data off an iPhone, etc. Not really much new here. > "A remote installation capability will be pursued for a future release" Here is the interesting bit. You don't put…

" iCloud allows Apple to install and run code directly on your device remotely."

I dont understand this? so far as I am aware, apple has always been able to install and run code directly on your device remotely.

what am I missing?

Post reply on HN