Earlier quoted context omitted.
...or I could just use a truly-secure option that doesn't destroy my personal security model. Owning an iDevice presents a considerable security risk to my current setup.
There is no such thing as a "truly-secure option." As anyone truly concerned about security will tell you. You will be forced to make compromises somewhere unless you want to live under a rock in the desert. You can't drive without a State ID, can't get a home loan without credit, can't work without a Social Security Number except under limited circumstances, can't make money without reporting to the IRS, and so on.…
iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones
121–130 of 177 posts
Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones
#122Earlier quoted context omitted.
I did help desk support at a news agency. We were constantly cleaning up malware from journalists computers... The journalists were constantly downloading all sorts of sketchy files as part of their job. Basically, if you're leaking state secrets / embarrassing repressive governments, don't leave a digital trail that can be traced back to you. Just assume everyone (especially journalists on national security or human…
Yes! In our newsroom (which isn't perfect by any means) - I have been testing using Qubes for really sensitive/untrusted documents. We also open un-trusted documents (from e.g. FOIA responses) on a machine live-booting from a CD. However, it adds enough friction (especially with remote work) that it's hard to get it right 100% of the time. If you want to share really sensitive documents, one way to ensure proper hand…
Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones
#123Apple needs to make it possible for users to choose other ways of sending and receiving messages and listening to music, or of choosing not to do either of those things if they don't want to. Obviously, you can currently install and use other applications that provide the same functionality, but you cannot uninstall or disable defaults. The most shocking experience to me in trying to evaluate the Mac ecosystem when t…
Unfortunately it's not built in, but I think it's your headphones doing something nonstandard because my Sony XM4s and AirPods do not fire this behavior when I put them in.
Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones
#124Earlier quoted context omitted.
Apple really doesn't help them. the marketing (lying) that iOS is secure is pretty intense.
Perfectly secure computers are an oxymoron. They don’t exist. iOS is the least worst mobile option and it’s ridiculous to say Apple is lying about security if any exploits are found, ever. If you look at e.g. how messaging works in iOS 14 [0] you’ll see that they do in fact work on making secure systems. But parsing and memory safety are hard. Like, really hard. The fact that NSO found exploits doesn’t mean Apple is…
Absolutely, but creating a platform the encourages or forces users to do the wrong thing is a regression from where we were ten years ago.
>iOS is the least worst mobile option
No. Devices running a FOSS operating system like the Pinephone are the least worst mobile option, people don't like it because it's not sexy and it's currently very inconvenient. The rest of the options are so bad that you're probably better off without a mobile phone at all.
RE: iMessage
You have everyone using exactly the same messaging client, so you have one piece of software to exploit and now you can attack everyone. The extreme lack of diversity makes these sorts of complex exploits much more profitable.
>iOS is pretty damn secure
Sure, if you don't do anything with it. But it encourages users to download unaditable closed apps and reassures them that doing so is totally safe despite the fact that most of them are using 3rd party telemetry services run by data brokers.
Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones
#125An intelligence agency cannot have the following properties simultaneously: (1) The ability to detect espionage from China and Russia (2) The inability to access journalists' phones If you want an intel agency to be able to thwart Chinese intelligence activities, you can't also publicly state you won't be looking closely into members of a profession who act a lot like spies.
We understand that the intelligence agencies can and do monitor a number of people associated with hostile foreign governments. For example, this is believed to be how "Tucker Carlson got surveilled by the CIA" -- he is believed to have contacted a surveilled Russian agent to discuss interviews with the Russian president. This is called "incidental collection" and it's a touchy subject for sure. But this subject is d…
Yes, that happens all of the time but one difference here with Tucker is he was deliberately "unmasked." Normally when an American is caught up in foreign surveillance, their identity is blocked out or masked, "incidental collection" as you said. Someone purposefully unmasked it. And someone purposefully leaked it. The same thing was done to General Flynn.
https://en.wikipedia.org/wiki/Unmasking_by_U.S._intelligence...
Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones
#126Earlier quoted context omitted.
I think that might just be a bug. Or maybe something in your headphones is causing it to send a "play" command through Bluetooth? That will open the Music app if you have nothing playing already.
Given that the headphones cannot know if there's an app playing already, this should be configurable in the OS: i.e. allow selecting which app (or no one) to launch when receiving a Play command Only allowing their own app to be associated with the default audio player is anti-competitive, at the very least
Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones
#127Earlier quoted context omitted.
I also have bluetooth headphones I use with a mac, and that’s never happened to me. Is it a new thing with the M1 machines or something?
It happens to me every time I connect my QC35s to a 2018 MacBook Pro. It's extremely annoying.
Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones
#128Earlier quoted context omitted.
Perfectly secure computers are an oxymoron. They don’t exist. iOS is the least worst mobile option and it’s ridiculous to say Apple is lying about security if any exploits are found, ever. If you look at e.g. how messaging works in iOS 14 [0] you’ll see that they do in fact work on making secure systems. But parsing and memory safety are hard. Like, really hard. The fact that NSO found exploits doesn’t mean Apple is…
>Perfectly secure computers are an oxymoron. They don’t exist. Absolutely, but creating a platform the encourages or forces users to do the wrong thing is a regression from where we were ten years ago. >iOS is the least worst mobile option No. Devices running a FOSS operating system like the Pinephone are the least worst mobile option, people don't like it because it's not sexy and it's currently very inconvenient. T…
Just because it's FOSS doesn't mean it's secure. If your problem is privacy then sure, the PinePhone is the least worst mobile option. If your problem is security I don't see how a phone that doesn't have hardware embedded key manager is a step up. It's not like the Linux Kernel, and whatever messenger you do decide to use is free from zero-days either.
>But it encourages users to download unaditable closed apps and reassures them that doing so is totally safe despite the fact that most of them are using 3rd party telemetry services run by data brokers.
And for the very same reason your bicycle is safer than a car because it doesn't encourage you to drive 75mph. I agree the world might be a lot better if we "return to monkey" but I don't think anarcho-primitivism is a solution.
Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones
#129Earlier quoted context omitted.
Perfectly secure computers are an oxymoron. They don’t exist. iOS is the least worst mobile option and it’s ridiculous to say Apple is lying about security if any exploits are found, ever. If you look at e.g. how messaging works in iOS 14 [0] you’ll see that they do in fact work on making secure systems. But parsing and memory safety are hard. Like, really hard. The fact that NSO found exploits doesn’t mean Apple is…
>Perfectly secure computers are an oxymoron. They don’t exist. Absolutely, but creating a platform the encourages or forces users to do the wrong thing is a regression from where we were ten years ago. >iOS is the least worst mobile option No. Devices running a FOSS operating system like the Pinephone are the least worst mobile option, people don't like it because it's not sexy and it's currently very inconvenient. T…
The flip side is the lack of diversity makes patching easy. Good luck pushing an update patching a 0-day affecting 3-4 Android versions to 60% of devices.
Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones
#130Earlier quoted context omitted.
>Perfectly secure computers are an oxymoron. They don’t exist. Absolutely, but creating a platform the encourages or forces users to do the wrong thing is a regression from where we were ten years ago. >iOS is the least worst mobile option No. Devices running a FOSS operating system like the Pinephone are the least worst mobile option, people don't like it because it's not sexy and it's currently very inconvenient. T…
> No. Devices running a FOSS operating system like the Pinephone are the least worst mobile option, people don't like it because it's not sexy and it's currently very inconvenient Just because it's FOSS doesn't mean it's secure. If your problem is privacy then sure, the PinePhone is the least worst mobile option. If your problem is security I don't see how a phone that doesn't have hardware embedded key manager is a…
Right, but it does mean you won't be forced to do things the wrong way because it makes Apple money.
>hardware embedded key manager
This means keeping copies of keys unencrypted (or encrypted with a key on the same device which is effectively the same) on the device. You're just a couple exploits away from sharing the keys at that point so many people argue that these make things worse and not better.
>It's not like the Linux Kernel, and whatever messenger you do decide to use is free from zero-days either.
Sure but you can't even guess at which messenger I use. Attacking me means taking expensive professional time and focusing it on one person. As for zero days in the kernel, they seem to appear less often than for iOS but I could be missing some.
>anarcho-primitivism
There's nothing more primitive than flinging binary artifacts around the way you do on closed OSes. The FOSS OS approach where knowledgeable people protect those who aren't knowledgeable (without restricting their rights) is a significantly more advanced social structure.