Live data from Hacker News

Apple alerts users in 92 nations to mercenary spyware attacks

techcrunch.com

111–120 of 301 posts

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#111
post #96

It's probably far worse with Android users that Google is not disclosing. I'm seriously considering changing to Apple after this. Not that its secure but that they are willing to go to this length to communicate it.

> I'm seriously considering changing to Apple after this.

Ironically that may be worse for you. iMessage is probably a critical step in 60% (or more) of these exploits, and the various unicode/pdf etc rendering engines are responsible in many exploits. Android's open-source nature likely means that a lot of these things are found by security researchers first. Don't forget that zerodium still pays more for an android 0-day than an iOS 0-day.

Plus, the huge variability between Samsung/Google/Moto/Huawei etc makes it triply hard for a single exploit to be successful.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#112

"Mercenary spyware attacks, such as those using Pegasus from the NSO Group, are exceptionally rare and vastly more sophisticated than regular cybercriminal activity or consumer malware" So, maybe even provoking an Apple warning to those targets could also be part of a sophisticated operation. These targets react or have to react in a certain way. Instigate to lure people out of hiding and entice them to react, even i…

>What do these targeted people do then? Switching phones? When you can get a $130 Motorola that has better security... Yes. Since the 2018 iphone crack by the FBI, I am shocked anyone uses their iphone for secrets.

The 2018 crack that one can foil by picking a decent passphrase instead of a 4-digit number?

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#113

There’s a reddit thread by somebody who got one of these: https://old.reddit.com/r/iphone/comments/1c10jai/i_have_rece... The interesting thing IMO is they claim to just be some random college student. Which seems believable because if they were a real secret squirrel I guess they wouldn’t ask reddit about it, haha. I wonder if the hackers are targeting people based on phone numbers or something. (I could imagine a c…

"random college student" I think there's a misunderstanding on what constitutes a valid or ideal target for state sponsored (or "mercenary") attackers. Simply working at a research lab, industrial manufacturer, power station, tech company or knowing a certain professor can put you on a target list.

Well dang I work in a research lab and I didn’t get an email.

I’m just going to assume my research is so interesting that they sent the real badasses after me, somebody that Apple can’t catch. The truth is too ego-shattering.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#114

"Mercenary spyware attacks, such as those using Pegasus from the NSO Group, are exceptionally rare and vastly more sophisticated than regular cybercriminal activity or consumer malware" So, maybe even provoking an Apple warning to those targets could also be part of a sophisticated operation. These targets react or have to react in a certain way. Instigate to lure people out of hiding and entice them to react, even i…

>What do these targeted people do then? Switching phones? When you can get a $130 Motorola that has better security... Yes. Since the 2018 iphone crack by the FBI, I am shocked anyone uses their iphone for secrets.

Is there a modern smartphone or cellphone the fbi, cia, nsa any nation state can not hack ?

I can guarantee you the fbi can also hack a $130 motorolla.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#115
post #65

Earlier quoted context omitted.

> Is there any company as big as Apple with so many major security issues? To be fair, does any Android device alert you to a compromise like this?

Android is more secure, especially in recent history. You can even see it in 0 day bounties. Don't pay attention to Samsung though, that company is probably the Apple equivalent of android.

The number of public bounties for a system seems orthogonal to the number of actual vulnerabilities in a system. Of course, vulnerabilities exist independent of the existence of a bounty for them.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#116
post #106
post #101

Earlier quoted context omitted.

Are you a journalist or high profile target? If not, this notification isn't for the average person.

Why is it hard to see that while he may not be a target for any sort of state sponsored attack, it’s a bellwether of apples stance on security. I really, really don’t think he meant he was switching to Apple because he’s a CIA spy stationed in Moscow.

> CIA spy stationed in Moscow.

Чёрт побери!

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#117
post #96

It's probably far worse with Android users that Google is not disclosing. I'm seriously considering changing to Apple after this. Not that its secure but that they are willing to go to this length to communicate it.

> I'm seriously considering changing to Apple after this. Ironically that may be worse for you. iMessage is probably a critical step in 60% (or more) of these exploits, and the various unicode/pdf etc rendering engines are responsible in many exploits. Android's open-source nature likely means that a lot of these things are found by security researchers first. Don't forget that zerodium still pays more for an android…

you changed my mind successfully thank you

but what about dumb phones from late 2000s like my Samsung Alias 2? what kind of sick bastard would make zero days for this

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#118

Earlier quoted context omitted.

"random college student" I think there's a misunderstanding on what constitutes a valid or ideal target for state sponsored (or "mercenary") attackers. Simply working at a research lab, industrial manufacturer, power station, tech company or knowing a certain professor can put you on a target list.

Well dang I work in a research lab and I didn’t get an email. I’m just going to assume my research is so interesting that they sent the real badasses after me, somebody that Apple can’t catch. The truth is too ego-shattering.

For now

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#119
post #96

It's probably far worse with Android users that Google is not disclosing. I'm seriously considering changing to Apple after this. Not that its secure but that they are willing to go to this length to communicate it.

> I'm seriously considering changing to Apple after this. Ironically that may be worse for you. iMessage is probably a critical step in 60% (or more) of these exploits, and the various unicode/pdf etc rendering engines are responsible in many exploits. Android's open-source nature likely means that a lot of these things are found by security researchers first. Don't forget that zerodium still pays more for an android…

> Don't forget that zerodium still pays more for an android 0-day than an iOS 0-day.

A random Internet search gives iOS 30% market share to Android's 70% [1], which could also explain the higher price.

[1] https://www.statista.com/statistics/272698/global-market-sha...

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#120
post #37
post #20

Earlier quoted context omitted.

On the Apple Support page here: https://support.apple.com/en-in/102174 In the screenshot it says the threat notification was sent "via email and iMessage", so it would not be displayed in any different way on your phone, which I also find surprising. I definitely wouldn't expect to receive something like this as an Email, and I have turned off iMessage.

Just out of curiosity why would you have imessage turned off?

iMessage has been one of the most successful delivery vector for these spyware attacks.

So, if you think you are a likely target of a state sponsored attack, best thing you can do on an Apple device is to turn on lockdown mode, turn off iCloud and iMessage, stop using keychain, use only a yubikey for all authentication, and restrict yourself to a limited number of essential apps on your primary device and use a dedicated burner device for all your throwaway browsing and communications, and erase/reset that device after every session. And still, assume everything you say and do online is fully compromised, because there are always system vulnerabilities that haven't been made known yet ('zero-day' attacks) and are being used to compromise highly targeted individuals. In the end, it is a very convoluted cat and mouse game.

Post reply on HN