Live data from Hacker News

Apple will notify users about state-sponsored cybersecurity threats

support.apple.com

131–140 of 166 posts

Re: Apple will notify users about state-sponsored cybersecurity threats

#131
post #130

they'll only do it if the US government allows them to. Like it or not, if they go against three-letter-agencies in the US, high ranked apple employees will spend years in jail based on the rulings of secret courts where all of your rights are irrelevant. The moment the cia says the word "terrorism", all your rights are gone regardless of how wrong the investigators might be. They can literally declare you guilty wit…

> they are on the same level as the ccp

Nonsense.

Re: Apple will notify users about state-sponsored cybersecurity threats

#132

Earlier quoted context omitted.

Yeah, we were doing that, so the response was to just shrug. Without a lot more context it's hard to know what your reaction should be to something like that.

A lack of context is kind of the problem here. What we need are specific method details, including origination addresses. There may be times when only most of that info is helpful, but withholding is always the opposite of helpful.

Except for future users targeted by those same attackers, for whom it is immensely helpful that they aren't being tipped off

Re: Apple will notify users about state-sponsored cybersecurity threats

#133

I see a lot of people in the comments conflating legal requests and attacks. Regardless of your opinion on either of those issues, they are different things.

NSA surveillance is illegal. Will we be notified?

If Apple learns of NSA surveillance of a specific individual... maybe? Beyond that what are you suggesting they do, send an alert to everyone in the US that the NSA might be spying on them?

Re: Apple will notify users about state-sponsored cybersecurity threats

#134
post #107
post #81

Earlier quoted context omitted.

>How can the user know Read the document of the original top post (the document from Apple). The answer to your question is right there in the document.

That does nothing to verify authenticity within iMessage itself, creating the opportunity for abuse and impersonation I outlined in my other comment in this thread. A simple solution to this problem would be a "verified" indicator for users to know that the iMessage did in fact originate from Apple, without them having to first know that such a support document exists.

Some of these scam messages, being tailored to individuals and not necessarily sent in bulk, do in fact come from technically valid Apple IDs that have been created for the purpose by the scammer. So they would show your little verified indicator just fine, so it doesn’t help.

And they did post the solution in the document. It’s an out of band verification. Pretty tried and true solution.

Re: Apple will notify users about state-sponsored cybersecurity threats

#135

Earlier quoted context omitted.

Because the NSO group definitely used iMessage to communicate with one another...

This is more likely targeting phishing messages coming from NSO Group to victims, rather than communication between NSO members.

Not even phishing, NSO had a zero-click iMessage exploit (so they could just send a message to their victims and then hack their iPhones remotely).

Re: Apple will notify users about state-sponsored cybersecurity threats

#138

Earlier quoted context omitted.

Can you provide citation for this? Also how they are different from any other tech company? My MacBooks security keys are not trivial to acquire because they aren’t in icloud. In some of the countries in five eyes nations, you don’t have a choice about cooperating or not. But what do 5 eyes have to do with Chinese users?

> Can you provide citation for this? Apple's cooperation with PRISM[0] is well documented[1], but if you want to find the particularly damning details you'll need to do your own research. The dust has settled since the Snowden revelations, and many mentions of the program have been sterilized. > Also how they are different from any other tech company? It's not. But the claim that Apple puts extra effort into protecti…

I'd like to discuss with you in Good faith. But your points seem to be made in bad faith.

PRISM wasn't really a cooperative program, it was a highjacking of the internet backbone wasn't it? Your citation doesn't confirm any kind of cooperation.

I didn't really make any claim about Apple doing extra, I was challenging the idea that they some how do worse. They seem to play as fair as you can in the given political environments across the various nations they work in.

Not knowing what kind of keys or encryption I use on my device, I'm not sure you can make any reasonable comment on what I think, or what the US wants me to think. MacBooks don't force any particular type of crypto, you can kind of do whatever you like. Are you referring to something in particular?

Domestic data sovereignty is not unique to china. A number of countries ask for that. I agree it's not ideal, and mandated backdoors (which Countries like Australia have) add to the problem here. Google don't service the Chinese market directly, Microsoft have in country storage, as do Yahoo, so not sure your point there. "Every other big tech company"? Tencent/Alibaba are obviously also in china. I'm not sure what the alternative to compliance with countries laws are. Do you think it's better if companies do not obey local laws?

A lot of countries are "Known abusers of human rights"... if you made a prerequisite of not working with those countries, you'd be out of business pretty quick. Agree that's not ideal... but it is the reality.

Re: Apple will notify users about state-sponsored cybersecurity threats

#139
post #130

they'll only do it if the US government allows them to. Like it or not, if they go against three-letter-agencies in the US, high ranked apple employees will spend years in jail based on the rulings of secret courts where all of your rights are irrelevant. The moment the cia says the word "terrorism", all your rights are gone regardless of how wrong the investigators might be. They can literally declare you guilty wit…

There's a difference between a warrant with a gag order and noticing that someone is trying to hack into a user's account.

I see no reason to think Apple will want to stay silent about an attacker trying to hack a user's account just because they might stay silent about warrants with gag orders.

Post reply on HN