> However, it is unlikely that Pegasus will be a problem for the vast majority of iPhone users. While the tool is used as intended against criminals by governments, the attacks against innocent people are seemingly against those who could be critics to a regime, including journalists and human rights activists. Attacks against the freedom of others and critics of government are a much larger threat to ordinary people…
iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones
161–170 of 177 posts
Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones
#162Time for a cyber security focused smartphone?
Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones
#163Earlier quoted context omitted.
We understand that the intelligence agencies can and do monitor a number of people associated with hostile foreign governments. For example, this is believed to be how "Tucker Carlson got surveilled by the CIA" -- he is believed to have contacted a surveilled Russian agent to discuss interviews with the Russian president. This is called "incidental collection" and it's a touchy subject for sure. But this subject is d…
> For example, this is believed to be how "Tucker Carlson got surveilled by the CIA" -- he is believed to have contacted a surveilled Russian agent to discuss interviews with the Russian president. Yes, that happens all of the time but one difference here with Tucker is he was deliberately "unmasked." Normally when an American is caught up in foreign surveillance, their identity is blocked out or masked, "incidental…
How could an analyst understand the conversation without knowing both parties?
My understanding is that some 10,000 legal unmaskings occur per year, and Gen Flynn and Tucker's unmasking were both routine, legal, and integral to analyzing the intelligence
When one considers the litany of crimes the disgraced lunatic Flynn committed, it's no wonder he got caught up in collection and that his identity was important to understanding the collection!
Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones
#164Apple needs to make it possible for users to choose other ways of sending and receiving messages and listening to music, or of choosing not to do either of those things if they don't want to. Obviously, you can currently install and use other applications that provide the same functionality, but you cannot uninstall or disable defaults. The most shocking experience to me in trying to evaluate the Mac ecosystem when t…
Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones
#165Earlier quoted context omitted.
Perfectly secure computers are an oxymoron. They don’t exist. iOS is the least worst mobile option and it’s ridiculous to say Apple is lying about security if any exploits are found, ever. If you look at e.g. how messaging works in iOS 14 [0] you’ll see that they do in fact work on making secure systems. But parsing and memory safety are hard. Like, really hard. The fact that NSO found exploits doesn’t mean Apple is…
iOS exploits are cheaper than Android exploits because iOS exploits are so plentiful[1][2]. [1] https://www.theregister.com/2020/05/14/zerodium_ios_flaws/ [2] http://zerodium.com/program.html
Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones
#166Earlier quoted context omitted.
It makes checking the hygiene of apps you use impossible, building them from source artificially difficult and expensive and pushes users towards services with serious flaws like icloud backup.
> average joe > building them from source An average joe doesn't even know what 'build from source' means
Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones
#167Earlier quoted context omitted.
>"BlastDoor is a great step, to be sure, but it's pretty lame to just slap sandboxing on iMessage and hope for the best. How about: "don't automatically run extremely complex and buggy parsing on data that strangers push to your phone?!" https://twitter.com/billmarczak/status/1416801514685796352
Except that almost every other secure messenger is guilty of the same thing. And they don't sandbox at all, whereas BlastDoor at least tries to.
Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones
#168Earlier quoted context omitted.
Apple can do it (create a security focused phone), it just isn't anywhere near what they want to do. The instant security (or privacy for that matter) gets in the way of profit for Apple they will back away.
Apple is actually not in the business of selling the data of their users. They will also risk aggravating large players in favor of improved privacy. A recent example: App Tracking Transparency [1] which makes tracking an opt-in feature to be requested from the user. To no one's surprise users are happily declining when made this offer. Companies like Facebook aren't too happy about it. [2] [1] https://www.apple.com/…
However I do believe that Apple is only doing what you describe as a PR move. At the same time Apple fight other's advertising and tracking they are strengthening their own version of this. That users get something good out of it is strictly a side-effect. Promoting Apple because of this is in my opinion worse than promoting Facebook for their behaviour as they don't try to sell it as "protecting their users" as far as I know. Using an Apple phone is likely better than one Facebook had its hands on but the thinking and ethics behind is worse in an Apple product as they are successfully being extremely disingenuous towards their users about protecting their privacy.
Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones
#169Earlier quoted context omitted.
Or maybe it's because they're doing their best to make every iPhone the security-focused phone, while not doing anything that would anger the FBI enough to try to pass legislation. When you are that big of a company, the things you can get away with are much more restricted than a small company.
They have already angered the FBI quite a lot during the 2016 San Bernadino case and made their position on the matter clear: https://www.apple.com/customer-letter/
Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones
#170I dated a journalist once. She used some random free app for phone calls because recording calls isn't built into iOS and she needed to record calls. I suggested a small device for her to plug her headphones through, but she declined. I'm sure there's a few journalists out there that take cybersecurity seriously, but I'd wager the vast majority are pretty trivially monitored.
I see your point, however, having worked in newsrooms - it really is about their beat and their threat-model. My organization covers a wide range of beats and folks covering national security or other sensitive topics have an entirely different workflow compared to those covering, e.g. housing. I think being responsive to their needs and building trust will go much further. Also, designing a one-size fits all model w…