When are governments going to finally realize that voice calls, text, and maybe plaintext email are enough for work phones? Is playing Candy Crush on your work phone really a mission-critical cyberpriority? All the high-security executive/legislative people (at least in the US) have two phones: the personal phone and the work phone. Whoever made the decision for the work phones to be "smart" needs to be fired. The ol…
Finnish diplomats’ phones infected with NSO Group Pegasus spyware
101–110 of 113 posts
Re: Finnish diplomats’ phones infected with NSO Group Pegasus spyware
#102I propose that any article like this don't refer to it as "NSO spyware", but instead refer to it as "Israeli spyware". The reality is that while NSO Group is a private company, it has deep links to the Israeli government and generally doesn't allow it's services to be used against the interests of the Israeli state. Hiding behind a corporate name to maintain Israel's reputation in international media isn't really oka…
Sounds reasonable. But we have to be fair. We should start referring to Google as "American data gatherers" and Meta as "American efforts to improve lives by showing more relevant ads to people"/s. Don't pretend that they don't both have deep links in American politics.
Not as "scary" because they aren't selling exploits to nation states and instead spying on their users/the internet.
Ike wasn't wrong.
Re: Finnish diplomats’ phones infected with NSO Group Pegasus spyware
#103Earlier quoted context omitted.
Ah, i see SMS and account insecurity has increased the telecom’s revenue. The security lapses will only get worse.
That's entirely true, but then again, that second sim card costs me 20 usd a year, so it's a cheap insurance.
Re: Finnish diplomats’ phones infected with NSO Group Pegasus spyware
#104Earlier quoted context omitted.
Any reasonably complex piece of software will have vulnerabilities. In other words, vulnerabilities are not a variable for the security equation, they are a constant. When designing something, vulnerabilities will exist. Generally, vulnerabilities, on their own, are not a great indication of how security is prioritized internally in any company.
When security researchers report SERIOUS security bugs to the manufacturers, as happened again and again the last years, without them acknowledging or fixing them for many months then I think it's safe to say they don't really care about security. You can go and talk about complex software and that vulnerabilities will always exists how much you want, but there is no excuse for these big companies to not fix major bu…
I’m not okay with anyone at all having it, so maybe if everyone could have it, the industry would have to get their shit together and actually patch the exploits.
Re: Finnish diplomats’ phones infected with NSO Group Pegasus spyware
#105Although I'm certainly no celebrity / important likely target of hackers, I'm interested in this just because recently I've gotten paranoid about my financial accounts (after a company I used to work for finally went public and I was fortunate to cash out an amount of $). When hackers use such exploits, do they then basically have something like remote control over your phone, and can start exfiltrating data / manipu…
Stop using debit cards. Only use credit cards. Pay them via positive pay from the 3rd account.
Stop using pull. Only use push. Only target the 3rd account with positive pay as the source of funds.
You should look at family office setups anyway. It used to be something that was done at 100M level but these days the services became cheap enough that it makes sense at 10M level.
[0] Switch to a bank that supports positive pay for all electronic transactions.
Re: Finnish diplomats’ phones infected with NSO Group Pegasus spyware
#106Although I'm certainly no celebrity / important likely target of hackers, I'm interested in this just because recently I've gotten paranoid about my financial accounts (after a company I used to work for finally went public and I was fortunate to cash out an amount of $). When hackers use such exploits, do they then basically have something like remote control over your phone, and can start exfiltrating data / manipu…
Give written instructions to your bank requiring them know to engage in transactions over a certain amount without a certain set of verification procedures (for example a call back with a prearranged password for any wire was one that I had with my old bank), and have them acknowledge receipt in writing as well. In the unlikely/unfortunate event that your money is stolen - recouping from the financial institution wil…
Re: Finnish diplomats’ phones infected with NSO Group Pegasus spyware
#107Earlier quoted context omitted.
If you care about this, consider using a security-oriented OS on desktop based on hardware virtualization: https://qubes-os.org . In this case, if you use your phone only to confirm the transactions (as the second factor), you should be safe enough.
If you are super paranoid, ask your bank to disable all remote access to your account and go into the branch in person when you want to do something.
Re: Finnish diplomats’ phones infected with NSO Group Pegasus spyware
#108Although I'm certainly no celebrity / important likely target of hackers, I'm interested in this just because recently I've gotten paranoid about my financial accounts (after a company I used to work for finally went public and I was fortunate to cash out an amount of $). When hackers use such exploits, do they then basically have something like remote control over your phone, and can start exfiltrating data / manipu…
The ideal attacker would find a way to silently steal a credential (e.g. session cookie) from your phone, then use it on a different device. That's not going to be something that makes a lot of noise on your device itself.
Re: Finnish diplomats’ phones infected with NSO Group Pegasus spyware
#109Earlier quoted context omitted.
Quoted post unavailable.
I don't doubt that some hide their hate behind that, but that does not mean that all critisism of Israel is "hidden antisemitism". Interpreting what peoples "real feelings" are from such a small post is pretty complicated, and since antisemitism is very serious you should not throw those accusations around easily. I can't see anything antisemitic in the post you called antisemitic. What is it actually you think was a…
We agree. Reread my post and it should be clear as I write "too many", not "everyone" or anything like that.
> I can't see anything antisemitic in the post you called antisemitic. What is it actually you think was antisemitic about it?
I didn't say that. It was a response to the generic wording of that post. Edit: Above I replied to your reply to to throw8932894. Are you confusing me for throw8932894?
Re: Finnish diplomats’ phones infected with NSO Group Pegasus spyware
#110Earlier quoted context omitted.
Depends how motivated the attackers are. They can try to find another bank with weaker rules, perhaps open an account there first. I needed one of those things, and shopped around for a bit. And while all the big names would refuse, had waiting periods, fees, other requirements, a local credit union gave me one after signing up for a savings account immediately with a minimal or no fee.
> Depends how motivated the attackers are. They can try to find another bank with weaker rules, perhaps open an account there first. That isn't really incentivized in this case. Assuming by medallion certificate they meant "medallion signature guarantee" [0] as established by SEC Rule 17 Ad-15 [1], a core part of the system there is that the financial institution granting it accepts liability for any forgery, up to a…
Some smaller credit unions or local banks are less rigorous it seems and that incentivizes whoever wants to steal the money to go there with a fake ID, bills, etc.
> What prefix though?
F. Still a nice chunk of money for someone to steal. I guess, what I was surprised about was how different the rules were. Some quite strict, at large institutions, some pretty lax.
> How did you check out in terms of signup (long history as resident? local connections?)?
Called around and visited a few banks in the area. Not sure if / how they checked the history as a resident? There was no prior relationship with that particular credit union. As you say, perhaps behind the scene they did a rather thorough background check, but it just didn't feel that way at all based on the context.