Live data from Hacker News

iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

appleinsider.com

21–30 of 177 posts

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#21
post #8

Earlier quoted context omitted.

Please stop using the term "paranoid" to describe those who desire personal privacy.

There is a degree to where you are actually paranoid though, otherwise we wouldn't have that word. If you are this paranoid, you shouldn't be carrying an electronic device.

It's not paranoia when it's true. While most people value the convenience of conventional phones calls and default messaging applications over true privacy, those who prefer privacy aren't being paranoid. Companies are monitoring communication to increase ad revenue; government are monitoring communication to catch criminals, enable industrial espionage, and suppress dissent. It's only paranoia if it's delusional. We know that we're being spied on, even if we're not being individually targeted. Even democracies that supposedly value freedom engage in widespread surveillance in direct violation of their own laws.

I'm in the camp of pragmatic resistance to surveillance. I use browser plugins to block ads and cookies where it doesn't get in the way of reaching the content I want; I use Signal for messaging even though almost none of my recipients do; I disable location services except for things like Maps that actually need to know where I am; I turn off all the spyware I know about that's built into operating systems; etc. I'm not a tin-foil-hat-wearer; I'm not doing anything illegal that I need to hide; I'm just trying to push back in a small way against the erosion of privacy and rights that permeates everything electronic.

But the parent isn't paranoid. They really are watching. And we shouldn't be so complacent.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#22

I dated a journalist once. She used some random free app for phone calls because recording calls isn't built into iOS and she needed to record calls. I suggested a small device for her to plug her headphones through, but she declined. I'm sure there's a few journalists out there that take cybersecurity seriously, but I'd wager the vast majority are pretty trivially monitored.

But it also depends on what kind of journalism they're doing, right? Not all report on criminal activity, or on investigating the government. It's kinda like threat-models, no need to be super secure if your work brings no risks to you, your organisation, or those you come in contact with.

Agreed. The parent comment makes a ridiculous extrapolation.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#23

Earlier quoted context omitted.

There is a degree to where you are actually paranoid though, otherwise we wouldn't have that word. If you are this paranoid, you shouldn't be carrying an electronic device.

It's not paranoia when it's true. While most people value the convenience of conventional phones calls and default messaging applications over true privacy, those who prefer privacy aren't being paranoid. Companies are monitoring communication to increase ad revenue; government are monitoring communication to catch criminals, enable industrial espionage, and suppress dissent. It's only paranoia if it's delusional. We…

Yes, but if you are that paranoid and worried about it, the fact remains you should not carry an electronic device.

This person is so paranoid, that they believe that a cyberweapon developed by a private company in Israel that uses previously-unknown bugs in the most sandboxed messaging system you can get on a phone are going to be deployed against them, so they should not use the calling, texting, or any other "phone-like" functionalities of a phone.

They then distrust that the End to End Encryption is in-fact End to End, and then think that using Signal or something is more secure, when if a bug in a system more sandboxed than Signal was found (iMessage, which has BlastDoor which Signal does not have), it is more than likely that Signal has it's own zero-days in it, so you shouldn't be using that either.

That's paranoid, and if you are that paranoid (which, maybe you have a reason to be), your solution isn't well thought-through. You shouldn't be using a phone if you can help it.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#24
post #8

Earlier quoted context omitted.

Please stop using the term "paranoid" to describe those who desire personal privacy.

There is a degree to where you are actually paranoid though, otherwise we wouldn't have that word. If you are this paranoid, you shouldn't be carrying an electronic device.

No, that's not what paranoid means. Your statement is simply incorrect and your use of the word is derogatory.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#25
post #8

Earlier quoted context omitted.

Please stop using the term "paranoid" to describe those who desire personal privacy.

It is paranoid for the average person to think they're sufficiently interesting to be a surveillance target.

Everyone in the global west (and China, and Russia) is subject to mass surveillance. That's documented fact, not paranoia.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#26
post #14

Time for a cyber security focused smartphone?

That's a little silly. The iPhone is a "cyber security focused smartphone" and Apple has billions in R&D money going into its phone. That's a nice thing to say but it doesn't really mean much unless you have some way to achieve that in a way that Apple's vast resources can't.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#27
post #9

Earlier quoted context omitted.

Nope, because they get escrowed by the other end of the iMessage conversation. Also, the whole point of disabling iMessage (in this thread) is to close the iMessage-related zero click exploits described in TFA.

The other end of the conversation escrows the key on any messenger. Otherwise how would you read the message? Unless you consider Snapchat, but that's not End to End Encrypted. And are you really sure that Signal or your preferred messengers don't also have Zero-Click exploits? After all, they aren't sandboxed to the degree iMessage is with BlastDoor.

Snapchat claims to be end to end encrypted, last I looked.

Signal does not escrow endpoint keys in an iCloud Backup, so your first statement is incorrect.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#28

I dated a journalist once. She used some random free app for phone calls because recording calls isn't built into iOS and she needed to record calls. I suggested a small device for her to plug her headphones through, but she declined. I'm sure there's a few journalists out there that take cybersecurity seriously, but I'd wager the vast majority are pretty trivially monitored.

Apple really doesn't help them. the marketing (lying) that iOS is secure is pretty intense.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#29
Apple needs to make it possible for users to choose other ways of sending and receiving messages and listening to music, or of choosing not to do either of those things if they don't want to. Obviously, you can currently install and use other applications that provide the same functionality, but you cannot uninstall or disable defaults.

The most shocking experience to me in trying to evaluate the Mac ecosystem when they released the M1 and I bought a Macbook Air is being in meetings where I'm using bluetooth headphones, take the headphones off and put them back on, and music.app automatically opens and comes to the foreground of my desktop. There is no supported way of disabling this user-hostile anti-feature. I look on Google and StackOverflow and all of the suggestions for how to disable it dating back to 2014 or whenever no longer work. Apparently, the likely answer is turn off System Integrity Projection, reboot, rename or remove the file containing the application launcher, turn SIP back on, and hope that doesn't break anything else and hope Apple doesn't revert your changes on the next system update.

That did not seem worth it. The fact that Apple Music can and has been used as an attack vector makes it even worse that it is so tightly integrated with the audio subsystem of the hardware as to take over your device thanks to movements you are making in the physical real world even when you may not be touching the device at all.

I just can't understand what the thought process was in making this a default behavior, let alone one that cannot be disabled.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#30
post #2

This coupled along with the fact that iMessage's E2EE has been backdoored by the non-E2EE iCloud Backup key escrow is a good argument for leaving iMessage, FaceTime, and iCloud all turned off on a device. I go one step further and leave the SIM card out, which means the SMS vulnerability path is closed too.

But then you are using SMS, which your cell carrier can absolutely see and intercept because it's decrypted. So in either case... turn off native messaging and use Signal or something if you are paranoid. You aren't really using the "phone" part anymore, so buy an iPod touch or something. Also, iMessage is fully E2E if you disable iCloud Backup. Which can easily do in Settings.

No, then you use gpg email or xmpp.
Post reply on HN