Live data from Hacker News

UK Government Officials Infected with Pegasus

citizenlab.ca

21–30 of 381 posts

Re: UK Government Officials Infected with Pegasus

#21
post #15

The question is then what phone exists that is immune from this? A flip phone? A Nokia 1011? I might be completely misinformed but seems like SIM card and the underlying OS is vector. What happens if I use a cell phone from late 90s and early 2000s? What is there to hack with those flip phones? JavaME over the wire? What if the cell phone dates even further? Legitimately curious what options is there. Could If you ar…

I would be shocked if people couldn't find an RCE in an early 2000s flip phone. I had a friend who had hers since 2010 and MMS crashed it all the time.

If you're talking about flip phones and trying to protect against an eavesdropper of a phone call or SMS, then there's no point. The network that these phones used is full of holes already https://en.wikipedia.org/wiki/Signalling_System_No._7#Protoc...

Re: UK Government Officials Infected with Pegasus

#22
As appalling as this intrusion is, I can't help but feel there is some measure of propriety that it should be done to a nation taking advantage of its impressive technological legacy to eavesdrop on most transatlantic communications, and scheming and hacking to subvert the communication infrastructure of friendly countries. Not that "what goes around comes around" is going to fix anything in this regard...

Re: UK Government Officials Infected with Pegasus

#23
This is a bit of a tangent but I think reports like these strengthen the argument against electronic voting. There's basically no way of building a secure electronic voting system that can beat the security and auditability properties of old school pen and paper voting.

Re: UK Government Officials Infected with Pegasus

#24
post #7

I'm curious about the threat modelling of those high level officials. With all these hacking going on, if feels like it's not been a consideration. Pegasus claims iOS and Android hacking capabilities, one would expect more specialised communications being used at that level. Car companies provide specialised vehicles for governmental use, I would have expected to see specialised iOS or Android devices at least. Nothi…

Time to revamp the black berry.

Re: UK Government Officials Infected with Pegasus

#25
post #17
post #4

Earlier quoted context omitted.

Ironically, the fact that it's not playing out as a major dust-up in public will probably only further contribute to conspiratorial thinking in re: the Israeli gov't.

Quoted post unavailable.

Numbers?

Re: UK Government Officials Infected with Pegasus

#26

And what were GCHQ, MI6 and NCSC doing to protect our prime-minister at this time? We have a problem in democratic nations. I've written about it here [1]. Bruce Schneier has also addressed it in his own way. Our lack of any framework for civic cybersecurity is a disgrace. People in future ages will look back on our time as a wild-west. A solution can only come from a ground-up awareness through education. [1] http:/…

The Johnson government has been widely but toothlessly criticized for using WhatsApp on personal devices to conduct affairs of state (and deleting messages, failing to hand over messages to investigations, etc.). My personal opinion is that they don't care too much about this type of thing (being hacked by UAE, etc.), and are preoccupied with more selfish matters. It can be quite profitable to be the butler to Gulf, Russian, and UK billionaires.

Re: UK Government Officials Infected with Pegasus

#27

And what were GCHQ, MI6 and NCSC doing to protect our prime-minister at this time? We have a problem in democratic nations. I've written about it here [1]. Bruce Schneier has also addressed it in his own way. Our lack of any framework for civic cybersecurity is a disgrace. People in future ages will look back on our time as a wild-west. A solution can only come from a ground-up awareness through education. [1] http:/…

>And what were GCHQ, MI6 and NCSC doing to protect our prime-minister at this time?

Preparing an advertising campaign against E2E encryption: https://www.engadget.com/the-uk-government-is-reportedly-pla...

Re: UK Government Officials Infected with Pegasus

#28
post #19
post #8

Earlier quoted context omitted.

The realpolitik of it is that Johnson some weeks ago went to the Saudis hat in hand asking for oil after they've stopped responding to phone calls from POTUS . Last year: The Saudi crown prince, Mohammed bin Salman, warned Boris Johnson in a text message that UK-Saudi Arabian relations would be damaged if the British government failed to intervene to “correct” the Premier League’s “wrong” decision not to allow a £300…

Some context/background to the deal the sale has been stalled for more than a year at that point , the league had decided arbitrarily to put a fitness check and delay(not reject) the deal. Roman, usmanov (minority holder ) and Abu Dhabi sovereign fund are current owners of major clubs before Saudi Arabia . The stalling and later approval has nothing to do with concerns of sportswashing (PL has sold out any morality t…

> Disclaimer : I am a Newcastle fan

As-salamu alaykum

I reckon the fans of rival clubs will absolutely terrorize you with taunting going forth.

Re: UK Government Officials Infected with Pegasus

#29

The question is then what phone exists that is immune from this? A flip phone? A Nokia 1011? I might be completely misinformed but seems like SIM card and the underlying OS is vector. What happens if I use a cell phone from late 90s and early 2000s? What is there to hack with those flip phones? JavaME over the wire? What if the cell phone dates even further? Legitimately curious what options is there. Could If you ar…

No technology is entirely secure today, we haven't built it in a provably secure way

The most secure today is probably a Pixel 6 running a secure messaging app with a limited attack surface, no image support, no emoji, etc. Removing all the standard apps including the browser and Webview engine would significantly help.

If you could switch an iPhone into a secure mode which removed large chunks of messaging functionality then it would be the preferred option.

Post reply on HN