Live data from Hacker News

iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

appleinsider.com

111–120 of 177 posts

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#111
post #14

Time for a cyber security focused smartphone?

Those are always targeted extra hard since they tend to be used by criminals. See the recent "encrypted phones" (Encrochat, Anom, ...) If you really care about security maybe it's better to get a really dumb 4G phone and share it's connection with a Linux small form tablet (but not running Android). Of course, inconvenient as hell, but much more secure, especially since you are not running the iOS/Android mono-cultur…

I don’t think ootb Linux is more secure than Android or iOS. You don’t even have simple sandboxing between apps.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#112

there are apparently 50k names in that list, last I've checked they confirmed ~180 journalists are among them. spying on journalists is atrocious, but who are the other 49.800?

They're releasing more names including, "lawyers, human rights defenders, religious figures, academics, businesspeople, diplomats, senior government officials and heads of state"

From: https://www.theguardian.com/news/2021/jul/18/huge-data-leak-...

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#113
post #48
post #17

Earlier quoted context omitted.

Would it actually have more resources that say Apple? I think if Apple can not do it, I am unsure if anyone else could. All supposedly secure smart phones are not, but they are at least obscure. I think that one should probably buy an Apple (at least they control everything rather than the cobbled together android clones) and disable basically everything except exactly what is needed. At least that reduces the surfac…

Apple can do it (create a security focused phone), it just isn't anywhere near what they want to do. The instant security (or privacy for that matter) gets in the way of profit for Apple they will back away.

Agreed, Apple has made a commercial decision here not to win against NSO-level adversaries. NSO is clearly winning the war (on the available evidence), presumably by investing more in security research / buying exploits. Sure, they put in *enough* effort to be secure in general - they prefer to keep outrageous profit margins rather than do more. Apple is perfectly comfortable with this balance:

> "Attacks like the ones described are highly sophisticated, cost millions of dollars to develop, often have a short shelf life, and are used to target specific individuals,” it said. “While that means they are not a threat to the overwhelming majority of our users, we continue to work tirelessly to defend all our customers, and we are constantly adding new protections for their devices and data." https://www.theguardian.com/news/2021/jul/19/how-does-apple-...

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#114

Earlier quoted context omitted.

> the marketing (lying) that iOS is secure is pretty intense. I don't see how it's lying. If you are going to consider that iOS is not secure because they got owned by a couple 0 days, then by that definition there isn't a secure piece of software on the planet.

iOS exploits are paying less than Android - http://zerodium.com/program.html . Based on supply and demand it would appear that iOS is less secure right?

True, and many many good researchers boast the Android security compared to iOS, thanks to Google and Samsung (mostly) since many years now (https://onezero.medium.com/is-android-getting-safer-than-ios...).

But as a *platform* I am intimately convinced that iOS is far more secure than Android... I agree that a few apps have been authorised by Apple to be published on the App Store, but when it happens to the Play Store it is not only one or two apps... it is mostly 5 to 10 apps developed by the same developer and which contain *the same* flaws.

Also, as demonstrated AdGuard a few years now (https://adguard.com/en/blog/popular-android-apps-are-stealin...), it is way easier to extract user informations from random apps on Android than iOS. However the Android API has been improved since two years now (and Android 12 is better than ever to secure user informations).

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#115
post #71

Earlier quoted context omitted.

You could do far better than iOS. Worse though is that it encourages very poor infosec because when it's profitable for Apple and often makes doing things correctly difficult or impossible.

I suppose you have examples to propose?

It makes checking the hygiene of apps you use impossible, building them from source artificially difficult and expensive and pushes users towards services with serious flaws like icloud backup.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#116

Apple needs to make it possible for users to choose other ways of sending and receiving messages and listening to music, or of choosing not to do either of those things if they don't want to. Obviously, you can currently install and use other applications that provide the same functionality, but you cannot uninstall or disable defaults. The most shocking experience to me in trying to evaluate the Mac ecosystem when t…

I think that might just be a bug. Or maybe something in your headphones is causing it to send a "play" command through Bluetooth? That will open the Music app if you have nothing playing already.

Given that the headphones cannot know if there's an app playing already, this should be configurable in the OS: i.e. allow selecting which app (or no one) to launch when receiving a Play command

Only allowing their own app to be associated with the default audio player is anti-competitive, at the very least

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#117
post #17
post #14

Time for a cyber security focused smartphone?

Would it actually have more resources that say Apple? I think if Apple can not do it, I am unsure if anyone else could. All supposedly secure smart phones are not, but they are at least obscure. I think that one should probably buy an Apple (at least they control everything rather than the cobbled together android clones) and disable basically everything except exactly what is needed. At least that reduces the surfac…

iOS seems the worst solution, like you are forced to used Apple web engine so a bug or zero day in that engine will own all users. Apple would need to give the users the ability to uninstall preinstalled stuff and replaced them with safer or better alternatives.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#118

Apple needs to make it possible for users to choose other ways of sending and receiving messages and listening to music, or of choosing not to do either of those things if they don't want to. Obviously, you can currently install and use other applications that provide the same functionality, but you cannot uninstall or disable defaults. The most shocking experience to me in trying to evaluate the Mac ecosystem when t…

> where I'm using bluetooth headphones, take the headphones off and put them back on, and music.app automatically opens and comes to the foreground of my desktop I think your bluetooth headphones are sending a play command to your device when it's connected. I'm sure it's annoying, but I think your macbook is doing the right thing here.

I’m almost positive that this is what’s happening. With a pair of Sony XM3’s and various Apple devices I’ve never seen this behavior.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#119

An intelligence agency cannot have the following properties simultaneously: (1) The ability to detect espionage from China and Russia (2) The inability to access journalists' phones If you want an intel agency to be able to thwart Chinese intelligence activities, you can't also publicly state you won't be looking closely into members of a profession who act a lot like spies.

We understand that the intelligence agencies can and do monitor a number of people associated with hostile foreign governments. For example, this is believed to be how "Tucker Carlson got surveilled by the CIA" -- he is believed to have contacted a surveilled Russian agent to discuss interviews with the Russian president.

This is called "incidental collection" and it's a touchy subject for sure.

But this subject is different than the DoJ directly surveilling journalists who leak, which is a problem, and governments surveilling their own citizens directly, not incidentally.

We can and should hold our government(s) to a standard of effective fire-walling of acceptable intelligence gathering and holding them accountable when they go beyond to surveil citizens directly, or indirectly through spying agreements.

We can make sure that the people who surveil Chinese or Russian "diplomats" are totally different than the people who execute search warrants against our citizens, and expect there to be zero crossover there.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#120
post #48

Earlier quoted context omitted.

Apple can do it (create a security focused phone), it just isn't anywhere near what they want to do. The instant security (or privacy for that matter) gets in the way of profit for Apple they will back away.

Apple is actually not in the business of selling the data of their users. They will also risk aggravating large players in favor of improved privacy. A recent example: App Tracking Transparency [1] which makes tracking an opt-in feature to be requested from the user. To no one's surprise users are happily declining when made this offer. Companies like Facebook aren't too happy about it. [2] [1] https://www.apple.com/…

Privacy and security are related, but distinct. Apple has been pushing privacy, but we're talking about security here. Typically the tradeoffs around increasing security have to do with user experience, something Apple typically does not like to compromise on.
Post reply on HN