Live data from Hacker News

Apple will notify users about state-sponsored cybersecurity threats

support.apple.com

11–20 of 166 posts

Re: Apple will notify users about state-sponsored cybersecurity threats

#14
"If Apple discovers activity consistent with a state-sponsored attack"

I am really interested in understanding more about a "state-sponsored attack" as someone who works in Ops and has experience in CyberSec. All these years working in the industry and I had no idea you could identify an "attack" that easily.

Re: Apple will notify users about state-sponsored cybersecurity threats

#16
post #14

"If Apple discovers activity consistent with a state-sponsored attack" I am really interested in understanding more about a "state-sponsored attack" as someone who works in Ops and has experience in CyberSec. All these years working in the industry and I had no idea you could identify an "attack" that easily.

See also: Apple sues NSO Group to curb the abuse of state-sponsored spyware (apple.com) https://news.ycombinator.com/item?id=29320986

Re: Apple will notify users about state-sponsored cybersecurity threats

#17
post #14

"If Apple discovers activity consistent with a state-sponsored attack" I am really interested in understanding more about a "state-sponsored attack" as someone who works in Ops and has experience in CyberSec. All these years working in the industry and I had no idea you could identify an "attack" that easily.

For a company with the resources of Apple? I'd imagine their Threat Hunting/Identification and classification systems are top notch. There are a number of know taxonomies for different attacks around and I'm quite sure Apple has some automation around identifying those attacks. It even addresses that many will be false positives. Example taxonomy: https://us-cert.cisa.gov/CISA-National-Cyber-Incident-Scorin...

Re: Apple will notify users about state-sponsored cybersecurity threats

#18

Why do I get the feeling that if the state is China, then it won't get reported as such. I assume their supply chain is more important.

China has their own iCloud servers and keys, from what I understand they're happy enough with that.

Re: Apple will notify users about state-sponsored cybersecurity threats

#19
post #8
post #3

Earlier quoted context omitted.

Also if the state if USA...

https://www.apple.com/legal/transparency/us.html Contains the canary: “To date, Apple has not received any orders for bulk data.”

that appears to only be connected to requests under those specific acts.

Otherwise, given their involvement in the PRISM program [1] I don't see how we can take that canary seriously.

[1] https://en.wikipedia.org/wiki/PRISM_(surveillance_program)

Re: Apple will notify users about state-sponsored cybersecurity threats

#20
post #14

"If Apple discovers activity consistent with a state-sponsored attack" I am really interested in understanding more about a "state-sponsored attack" as someone who works in Ops and has experience in CyberSec. All these years working in the industry and I had no idea you could identify an "attack" that easily.

Where do you see the word 'easily' in Apple's statement?

If the complaint is that attribution is sometimes sketchy, so? Sometimes it isn't.

Post reply on HN