Live data from Hacker News

iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

appleinsider.com

31–40 of 177 posts

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#32
post #24

Earlier quoted context omitted.

There is a degree to where you are actually paranoid though, otherwise we wouldn't have that word. If you are this paranoid, you shouldn't be carrying an electronic device.

No, that's not what paranoid means. Your statement is simply incorrect and your use of the word is derogatory.

Only if you say so.

There is a degree of rational fear, rational expectation of being tracked. Your degree of fear though is irrational unless you are, in fact, a journalist in an authoritarian state.

You are saying that you are so paranoid, you don't trust iMessage to be End-to-End Encrypted because it has zero-click exploits developed as part of a cyberweapon that is explicitly targeted against high-profile journalists. You then think using Signal or something is more secure, even though if this was pulled off in iMessage (more sandboxed than any other messenger security-wise), your other messengers probably are also flawed and you shouldn't use any of them.

In fact, you shouldn't use a mobile device. And maybe for your situation, that is right and rational. But for most people, it's not.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#33

I dated a journalist once. She used some random free app for phone calls because recording calls isn't built into iOS and she needed to record calls. I suggested a small device for her to plug her headphones through, but she declined. I'm sure there's a few journalists out there that take cybersecurity seriously, but I'd wager the vast majority are pretty trivially monitored.

I see your point, however, having worked in newsrooms - it really is about their beat and their threat-model. My organization covers a wide range of beats and folks covering national security or other sensitive topics have an entirely different workflow compared to those covering, e.g. housing.

I think being responsive to their needs and building trust will go much further. Also, designing a one-size fits all model will just mean that your reporters will either ignore the guidance or find a way to work around it.

For instance, the most recent credible threat we have had against one of our reporters wasn't a state-level actor, but rather folks on the internet (trivially) finding their address and doxing/harassing them and their family. No amount of technology hygiene will change the fact that voter registrations are public records.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#34
post #9

Earlier quoted context omitted.

Nope, because they get escrowed by the other end of the iMessage conversation. Also, the whole point of disabling iMessage (in this thread) is to close the iMessage-related zero click exploits described in TFA.

The other end of the conversation escrows the key on any messenger. Otherwise how would you read the message? Unless you consider Snapchat, but that's not End to End Encrypted. And are you really sure that Signal or your preferred messengers don't also have Zero-Click exploits? After all, they aren't sandboxed to the degree iMessage is with BlastDoor.

[deleted]

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#35
post #14

Time for a cyber security focused smartphone?

Simple solution: just use "dumb phones" or burners

No non-open source "smart" phone is going to be secure enough. If you never store your data on your phone, you are safe from these hacks. Now you have to just protect from physical attacks :)

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#36
post #6
post #2

This coupled along with the fact that iMessage's E2EE has been backdoored by the non-E2EE iCloud Backup key escrow is a good argument for leaving iMessage, FaceTime, and iCloud all turned off on a device. I go one step further and leave the SIM card out, which means the SMS vulnerability path is closed too.

Should probably also dig an underground bunker and collect cans of sardines to last for decades.

Canned food has a surprisingly short shelf life. Sealed containers of dry beans and rice are the way to go.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#37
post #27

Earlier quoted context omitted.

The other end of the conversation escrows the key on any messenger. Otherwise how would you read the message? Unless you consider Snapchat, but that's not End to End Encrypted. And are you really sure that Signal or your preferred messengers don't also have Zero-Click exploits? After all, they aren't sandboxed to the degree iMessage is with BlastDoor.

Snapchat claims to be end to end encrypted, last I looked. Signal does not escrow endpoint keys in an iCloud Backup, so your first statement is incorrect.

This is false. Snapchat has "snaps" protected, but text messages and group messages are not end to end encrypted.

Also, Signal putting your escrow keys in iCloud? I don't think you know what you are talking about. You can set iMessage to not put your keys in iCloud like I said above by turning off iCloud Backup which makes it fully End-to-End with your own key on your device, just like Signal.

If you are worried about the other party having their conversations being backed up, tell them to disable iCloud Backup. If you are this worried about the privacy of your communications, hopefully the other party would be as well.

And Signal and any other E2E messenger is absolutely storing copies of your key on the recipient's phone, just like iMessage would. If it didn't, there'd be no way to verify that a message was sent from the same sender.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#38
An intelligence agency cannot have the following properties simultaneously:

(1) The ability to detect espionage from China and Russia (2) The inability to access journalists' phones

If you want an intel agency to be able to thwart Chinese intelligence activities, you can't also publicly state you won't be looking closely into members of a profession who act a lot like spies.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#39

Apple needs to make it possible for users to choose other ways of sending and receiving messages and listening to music, or of choosing not to do either of those things if they don't want to. Obviously, you can currently install and use other applications that provide the same functionality, but you cannot uninstall or disable defaults. The most shocking experience to me in trying to evaluate the Mac ecosystem when t…

I also have bluetooth headphones I use with a mac, and that’s never happened to me. Is it a new thing with the M1 machines or something?

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#40
post #14

Time for a cyber security focused smartphone?

Those are always targeted extra hard since they tend to be used by criminals. See the recent "encrypted phones" (Encrochat, Anom, ...)

If you really care about security maybe it's better to get a really dumb 4G phone and share it's connection with a Linux small form tablet (but not running Android).

Of course, inconvenient as hell, but much more secure, especially since you are not running the iOS/Android mono-culture, so for anyone to target you it would require customized service.

Post reply on HN