Live data from Hacker News

The NSA Reportedly Has Total Access To The Apple iPhone

forbes.com

101–110 of 212 posts

Re: The NSA Reportedly Has Total Access To The Apple iPhone

#101
"one question has been paramount for privacy advocates: How do we, as a society, balance the need for security against the rights to privacy and freedom? "

I hear this fallacy question again an again. It implies that giving total power to gobertment is "security". It is not.

Giving total control to Stalin meant hundred of millions of Russians got murdered in terror, giving total power to Hitler or Mussolini from democracies meant the total destruction of Germany and Italy with millions dead.

Re: The NSA Reportedly Has Total Access To The Apple iPhone

#102
post #82

Aren't we missing a critical point here?? > "The initial release of DROPOUTJEEP will focus on installing the implant via closed access methods." [2007] OK, we knew this much already. I remember seeing a number of stories on how law enforcement can pull data off an iPhone, etc. Not really much new here. > "A remote installation capability will be pursued for a future release" Here is the interesting bit. You don't put…

" iCloud allows Apple to install and run code directly on your device remotely." I dont understand this? so far as I am aware, apple has always been able to install and run code directly on your device remotely. what am I missing?

That they let spies run arbitrary code on your phone too.

Re: The NSA Reportedly Has Total Access To The Apple iPhone

#103
post #56

Ha, I wonder what this will do to acceptance of Apple products inside DoD's (well govt in general). Many agencies and military branches love them some new cool toys and have been pushing for their inclusion. Now revealing that Apple security can so seemingly easily be compromised, will they still allow or advise use of Apple products on government's own networks?

I thought the largest take away from all these leaks was that various branches of government, even within the military and intelligence communities, routinely deploy solutions that are known to be insecure?

Re: The NSA Reportedly Has Total Access To The Apple iPhone

#104
post #82

Aren't we missing a critical point here?? > "The initial release of DROPOUTJEEP will focus on installing the implant via closed access methods." [2007] OK, we knew this much already. I remember seeing a number of stories on how law enforcement can pull data off an iPhone, etc. Not really much new here. > "A remote installation capability will be pursued for a future release" Here is the interesting bit. You don't put…

" iCloud allows Apple to install and run code directly on your device remotely." I dont understand this? so far as I am aware, apple has always been able to install and run code directly on your device remotely. what am I missing?

Features - iCloud is just an extension of the stuff that was on iOS already. Previously you had preinstalled apps as part of the rom that could run in the background etc, and you had apps that you could download that ran sandboxed and had to have an icon, etc. iCloud allows direct access to the filesystem remotely. iCloud also now has routing support to assign you to different Apple servers, etc. All of these features would make it trivial for the NSA to put their own special server in at the iCloud data centers and redirect specific people onto it without them knowing.

So while it would have been theoretically possible for the NSA to do it before iCloud, iCloud makes it actually practical to do it without subverting the whole iOS team.

Re: The NSA Reportedly Has Total Access To The Apple iPhone

#105
post #95

Now the talk he gave was interesting, laying out some known and some new facts about the surveillance and automated attack capabilities of the NSA, particularity interesting is the targeting of infrastructure and their traffic injection systems. And he is right to make the point, that its particularly despicable that they actively sabotage infrastructure security, something everyone on this planet has to suffer from.…

> force backdoors

unlikely

> they are legally bound to publicly lie about it

source?

Re: The NSA Reportedly Has Total Access To The Apple iPhone

#106
post #11

This is from a very old version of iOS (2007). We don't know if this is still true. Regardless, I can say for a fact that there are exploits for all cell phone platforms. iOS exploits are by far the hardest to find. An iOS remote execution 0day will easily fetch $250k. I've seen one go for $600k. For an Android remote exec 0day, you're looking at closer to $50k. Even if the NSA doesn't have these on hand, they can ce…

Why isn't Apple (or some other consumer group) in that market buying up the 0days? I want to see the price of 0days that compromise any longitudinal user information above $10 million. Idea: 0day markets are legalised [1]. Regulators require companies keep the average price of their 0days above a threshold or attach a warning to their product and marketing materials. This aligns the security interests of consumers wi…

Many vendors do this covertly through HP (with ZDI) and other intermediaries. The problem is the government will always pay more, or even offer to let you sell it back to the vendor and buy it from you (in the case of things that are difficult to field upgrade like routers).

The people cranking out high volumes of exploits for the customer are sitting on huge multi-year contracts worth tens if not hundreds of millions of dollars. They don't want to go play in some utopian regulated marketplace, they just want to make money and protect America.

Re: The NSA Reportedly Has Total Access To The Apple iPhone

#107
post #102

Earlier quoted context omitted.

" iCloud allows Apple to install and run code directly on your device remotely." I dont understand this? so far as I am aware, apple has always been able to install and run code directly on your device remotely. what am I missing?

That they let spies run arbitrary code on your phone too.

We don't know that, we also don't know whether Google or Microsoft or any of the other phone or phone OS vendors 'let' the NSA do any of this. Even if the NSA had inside help, it may have been via individual Apple (Google, MS, etc) employees without Apple's knowledge, or ex-Apple engineers contracted by the NSA. In fact the later would be a much more useful approach for the NSA since it would minimize the number of people who knew it was going on and could therefore leak about it or interfere with the capability.

Re: The NSA Reportedly Has Total Access To The Apple iPhone

#108
post #11

This is from a very old version of iOS (2007). We don't know if this is still true. Regardless, I can say for a fact that there are exploits for all cell phone platforms. iOS exploits are by far the hardest to find. An iOS remote execution 0day will easily fetch $250k. I've seen one go for $600k. For an Android remote exec 0day, you're looking at closer to $50k. Even if the NSA doesn't have these on hand, they can ce…

>I've seen one go for $600k. Without revealing the actual site/method/whatever; can you please explain how the 0day exploit market works? I can make basic assumptions that it is deep-web-forums/TOR/Whatever... but can you enlighten me as to how one might go about selling/buying such an exploit?

I just went to a security conference and started asking around among friends. It's like asking around a high school who sells weed, everyone kinda knows but they don't talk about it openly.

You'll get introduced to someone who has a small security firm and from their LinkedIn page you can see they have a pretty vague but interesting past. Ask for a shit ton of money.

Did the guy spend 8 years at a british aerospace company before going into consulting? GCHQ. 5 years at the "Department of Defense"? NSA. High school drop out? Chinese or Russians.

Re: The NSA Reportedly Has Total Access To The Apple iPhone

#109

Earlier quoted context omitted.

" iCloud allows Apple to install and run code directly on your device remotely." I dont understand this? so far as I am aware, apple has always been able to install and run code directly on your device remotely. what am I missing?

Features - iCloud is just an extension of the stuff that was on iOS already. Previously you had preinstalled apps as part of the rom that could run in the background etc, and you had apps that you could download that ran sandboxed and had to have an icon, etc. iCloud allows direct access to the filesystem remotely. iCloud also now has routing support to assign you to different Apple servers, etc. All of these feature…

I am sorry, I dont think that makes much sense.

Apple has had remote access to the file system forever - an early use of it was to remove apps that had certain kinds of legal issues from the phones of those who had purchased it.

iCloud is simply remote file storage, and not all applications use it anyway - if the NSA wants access to my phone, achieving access to my iCloud account is a pretty poor second best.

Re: The NSA Reportedly Has Total Access To The Apple iPhone

#110
post #82

Aren't we missing a critical point here?? > "The initial release of DROPOUTJEEP will focus on installing the implant via closed access methods." [2007] OK, we knew this much already. I remember seeing a number of stories on how law enforcement can pull data off an iPhone, etc. Not really much new here. > "A remote installation capability will be pursued for a future release" Here is the interesting bit. You don't put…

> "Obviously with iOS devices having ports closed and being behind NAT, the NSA can't exploit them remotely."

This is a pretty limited view of remote exploits. It could easily be a browser-based exploit for example, with the payload as part of an image served by an ad, thus not requiring any open ports.

I cannot imagine the NSA waited for iCloud to get access to iPhones.

Post reply on HN