Live data from Hacker News

iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

appleinsider.com

151–160 of 177 posts

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#151
post #85

I wonder if there is a way to disable iMessage and iTunes usage. With windows server I used to have a target of balance in any attack footprint.. if Microsoft provided the OS, the component services that the server exists to provide should always try to be third party software (db, web server, etc) to try and minimize one type of escalation vulnerabilities… while possibly opening up to another, hopefully less worse s…

You can use a NextDNS configuration profile at https://apple.nextdns.io and a NextDNS account to block the device communicating with many Apple services.

A good way to disable iMessage and iTunes, though, is to simply not have an Apple ID. (This prevents the install of applications via the App Store, however.) You can of course set up the device with no Apple ID and then only add the Apple ID to the App Store (and not iTunes or iMessage/FaceTime/iCloud). This is what I do.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#152

I dated a journalist once. She used some random free app for phone calls because recording calls isn't built into iOS and she needed to record calls. I suggested a small device for her to plug her headphones through, but she declined. I'm sure there's a few journalists out there that take cybersecurity seriously, but I'd wager the vast majority are pretty trivially monitored.

> I dated a journalist once. She used some random free app for phone calls because recording calls isn't built into iOS and she needed to record calls. I suggested a small device for her to plug her headphones through, but she declined.

Sounds like she dodged a potential honeypot and surveillance attempt.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#154

Earlier quoted context omitted.

> No. Devices running a FOSS operating system like the Pinephone are the least worst mobile option, people don't like it because it's not sexy and it's currently very inconvenient. The rest of the options are so bad that you're probably better off without a mobile phone at all. There's nothing about FOSS that makes something secure, and building secure software is so hard and expensive that my guess is that you need…

> There's nothing about FOSS that makes something secure, and building secure software is so hard and expensive that my guess is that you needs the sponsorship of a government of major corporation to do so. Some FOSS does have such sponsorships, but a lot doesn't The F/OSS community has a weird collective amnesia about exploits that rubs me the wrong way -- just because someone can look at it doesn't mean that someon…

> The F/OSS community has a weird collective amnesia about exploits that rubs me the wrong way...

If you repeat something frequently enough, a lot of people will regard it as true. And a lot of people are extremely reluctant to reevaluate their judgements after they've made them, even in light of new information.

IIRC, the "FOSS is more secure" refrain started in the 90s/00s, when security was an afterthought even at companies like Microsoft and Apple and Linux was unusual enough to fly under the radar when there were a lot of big, high-profile worms circulating. But since then some closed-source commercial software has gotten much more secure, and FOSS has gotten more popular, but remains plagued by important projects that get by on shoestring resources.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#155
post #130

Earlier quoted context omitted.

> No. Devices running a FOSS operating system like the Pinephone are the least worst mobile option, people don't like it because it's not sexy and it's currently very inconvenient Just because it's FOSS doesn't mean it's secure. If your problem is privacy then sure, the PinePhone is the least worst mobile option. If your problem is security I don't see how a phone that doesn't have hardware embedded key manager is a…

>Just because it's FOSS doesn't mean it's secure. Right, but it does mean you won't be forced to do things the wrong way because it makes Apple money. >hardware embedded key manager This means keeping copies of keys unencrypted (or encrypted with a key on the same device which is effectively the same) on the device. You're just a couple exploits away from sharing the keys at that point so many people argue that these…

[deleted]

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#156
post #28

Earlier quoted context omitted.

Apple really doesn't help them. the marketing (lying) that iOS is secure is pretty intense.

Perfectly secure computers are an oxymoron. They don’t exist. iOS is the least worst mobile option and it’s ridiculous to say Apple is lying about security if any exploits are found, ever. If you look at e.g. how messaging works in iOS 14 [0] you’ll see that they do in fact work on making secure systems. But parsing and memory safety are hard. Like, really hard. The fact that NSO found exploits doesn’t mean Apple is…

iOS exploits are cheaper than Android exploits because iOS exploits are so plentiful[1][2].

[1] https://www.theregister.com/2020/05/14/zerodium_ios_flaws/

[2] http://zerodium.com/program.html

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#157
post #87

Earlier quoted context omitted.

It's not paranoia when it's true. While most people value the convenience of conventional phones calls and default messaging applications over true privacy, those who prefer privacy aren't being paranoid. Companies are monitoring communication to increase ad revenue; government are monitoring communication to catch criminals, enable industrial espionage, and suppress dissent. It's only paranoia if it's delusional. We…

> I disable location services except for things like Maps that actually need to know where I am Fun fact: having systemwide location services on, even if you don't enable it for any apps, means that your location is sent in realtime to Apple/Google at all times (via Wi-Fi triangulation data). It's not just passive GPS reception. If you want actual location privacy, you'll want to leave location services off systemwid…

There is a way around this. If you use an Android distribution with UnifiedNlp (part of microG) and without Google Play Services, you can install only the location providers that you want to use for Wi-Fi and cell tower triangulation. Google would not be monitoring your location queries. Provider options include:

- OpenCellID (offline): https://f-droid.org/en/packages/org.gfd.gsmlocation/

- Radiocells.org (optionally offline): https://f-droid.org/en/packages/org.openbmap.unifiedNlp/

- Déjà Vu (offline cache using Wi-Fi and cellular data): https://f-droid.org/en/packages/org.fitchfamily.android.deja...

- Mozilla Location Services (online): https://f-droid.org/en/packages/org.microg.nlp.backend.ichna...

UnifiedNlp is preinstalled on Android distributions that include microG. CalyxOS is the only one of these that supports relocking the bootloader with the developers' key:

https://calyxos.org

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#158
post #91

Earlier quoted context omitted.

> Your degree of fear though is irrational unless you are, in fact, a journalist in an authoritarian state. You are putting words in OP's mouth. OP never said he was fearful, only that he didn't want to be tracked. Someone friendly could follow me around in real life and watch what I'm doing - and keep suggesting products to me based on getting to know me. I'm not going to be afraid but I am going to be freaking anno…

Not wanting to be tracked is fine. I'm trying to say his game-plan for not being tracked is immensely flawed. He thinks a nation-state weapon could be used against him, so switch to a third-party messenger which doesn't do the same degree of sandboxing for security. What could go wrong? If you are worried about a threat that is that niche, and will almost certainly be patched soon, you shouldn't be using any messenge…

IMO you are putting words in their mouth and misrepresenting what OP was saying.

OP wasn't talking just about the pegasus attack, they were talking about the key escrow not being held under end to end encryption on iCloud. That's not going to be patched any time soon, and there are other messengers which don't do this.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#159
post #147
post #140

Earlier quoted context omitted.

> average joe > building them from source An average joe doesn't even know what 'build from source' means

We could have taught people such things, but there’s no profit in that. We want to maximize the number of people using our devices and our software, so that we get richer, even if it means putting some fraction of these users in grave danger. That’s simply negligence. That it’s distributed across an entire industry doesn’t change the ethics. Selling people tools that put them at risk is much different than sharing fo…

Some things you say make sense, but suggesting that “people” can/should learn how to build from source is simply nonsense. Heck if I had to build my OS I’d stick to a feature phone instead.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#160
post #8

Earlier quoted context omitted.

Please stop using the term "paranoid" to describe those who desire personal privacy.

It is paranoid for the average person to think they're sufficiently interesting to be a surveillance target.

We aren't in the 1970's. It's cheap and easy to do dragnet surveillance, and it costs a fraction of a cent to store text communications and to perform speech-to-text on audio and video.

You don't have to be interesting, you just need to exist to be caught up in the dragnet.

Post reply on HN