Live data from Hacker News

iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

appleinsider.com

41–50 of 177 posts

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#41
Just because it was only used to target journalists, supposedly, does not mean someone could not also target random individuals. I doubt NSO has such control over their customers that the uses can't be expanded to almost anything, like blackmail, theft and harassment.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#42

Apple needs to make it possible for users to choose other ways of sending and receiving messages and listening to music, or of choosing not to do either of those things if they don't want to. Obviously, you can currently install and use other applications that provide the same functionality, but you cannot uninstall or disable defaults. The most shocking experience to me in trying to evaluate the Mac ecosystem when t…

I also have bluetooth headphones I use with a mac, and that’s never happened to me. Is it a new thing with the M1 machines or something?

Haven't seen this either. Both my wife and I are on M1 MacBooks.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#43
post #14

Time for a cyber security focused smartphone?

I agree. To break apart from the Android/Apple world, surely a team of people could disrupt the ecosystem. It wasn't that long ago that flip phones were state of the art. Somewhere in between then and now, we passed all the barriers to lose privacy. BlackBerry, blackphone didn't succeed to be profitable, but perhaps that was not the right time. Perhaps privacy was not so completely lost yet, to be relevant to the public. Perhaps there is enough of a market to sustain that model?

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#44

Apple needs to make it possible for users to choose other ways of sending and receiving messages and listening to music, or of choosing not to do either of those things if they don't want to. Obviously, you can currently install and use other applications that provide the same functionality, but you cannot uninstall or disable defaults. The most shocking experience to me in trying to evaluate the Mac ecosystem when t…

I also have bluetooth headphones I use with a mac, and that’s never happened to me. Is it a new thing with the M1 machines or something?

Nope, I’ve never had this happen to me on my M1 machine, Bluetooth or 3,5mm headphones. If you don’t have another media app focussed or active, pressing a media control button/key will open Music iirc.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#45

I dated a journalist once. She used some random free app for phone calls because recording calls isn't built into iOS and she needed to record calls. I suggested a small device for her to plug her headphones through, but she declined. I'm sure there's a few journalists out there that take cybersecurity seriously, but I'd wager the vast majority are pretty trivially monitored.

But it also depends on what kind of journalism they're doing, right? Not all report on criminal activity, or on investigating the government. It's kinda like threat-models, no need to be super secure if your work brings no risks to you, your organisation, or those you come in contact with.

That's a fair point, although bad actors will also wait around for years for your work to become more interesting/relevant, if they think there's a chance of it.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#46
post #14

Time for a cyber security focused smartphone?

That's a little silly. The iPhone is a "cyber security focused smartphone" and Apple has billions in R&D money going into its phone. That's a nice thing to say but it doesn't really mean much unless you have some way to achieve that in a way that Apple's vast resources can't.

The silly thing is that Apple advertises their phone as something cyber security focused, when it can be totally pwned in so many ways.

And you don't need Apple's resources to make something better, just a more secure phone would have much worse UX. Just some examples for a much more secure phone, where you dont need Apple's budget:

- Runs some barebones Linux with minimal packages. An SMS app is an SMS app, not something that makes HTTP requests.

- app store is very heavily vetted

- forced updates, you can't dismiss update notifications.

- minimal attack interface, no smart connection features or accessories.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#47
post #14

Time for a cyber security focused smartphone?

That's a little silly. The iPhone is a "cyber security focused smartphone" and Apple has billions in R&D money going into its phone. That's a nice thing to say but it doesn't really mean much unless you have some way to achieve that in a way that Apple's vast resources can't.

> ave some way to achieve that in a way that Apple's vast resources can't.

I think "can't" here runs up against "choose not to". So far as we can tell opsec tends to be a pain in the ass in ways that are fundamental, not a problem with tools. Apple, like any other consumer focused company, doesn't lose focus of this.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#48
post #17
post #14

Time for a cyber security focused smartphone?

Would it actually have more resources that say Apple? I think if Apple can not do it, I am unsure if anyone else could. All supposedly secure smart phones are not, but they are at least obscure. I think that one should probably buy an Apple (at least they control everything rather than the cobbled together android clones) and disable basically everything except exactly what is needed. At least that reduces the surfac…

Apple can do it (create a security focused phone), it just isn't anywhere near what they want to do. The instant security (or privacy for that matter) gets in the way of profit for Apple they will back away.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#49
post #5
post #3

Earlier quoted context omitted.

Then you could just as well get a iPod touch or iPad mini.

Neither of those has a vibrate motor to let me know about notifications. They also can't be used to pair to an Apple Watch. I know this because I used to carry an iPad Mini in my pants pocket.

I just wanna know how big are your pants pockets

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#50
post #46

Earlier quoted context omitted.

That's a little silly. The iPhone is a "cyber security focused smartphone" and Apple has billions in R&D money going into its phone. That's a nice thing to say but it doesn't really mean much unless you have some way to achieve that in a way that Apple's vast resources can't.

The silly thing is that Apple advertises their phone as something cyber security focused, when it can be totally pwned in so many ways. And you don't need Apple's resources to make something better, just a more secure phone would have much worse UX. Just some examples for a much more secure phone, where you dont need Apple's budget: - Runs some barebones Linux with minimal packages. An SMS app is an SMS app, not some…

You just pwned yourself.

- Forced Updates? The FBI takes over the update server, forcibly sends out an update that sends all messages to the FBI immediately, and there's no way to stop it. That suggestion is idiotic. Or even better, install Pegasus on all the phones, have them be quietly reporting back to home for a few weeks, with journalists having no way to prevent updating.

- You forgot Hardware Root of Trust and Secure Enclave, like on an iPhone. Otherwise, the FBI can install a tool which just guesses PINs over and over while resetting the PIN attempts counter. It is not possible to build this protection in software only. You need chip-level hardware, and only iPhones in Fall 2020 and later have the Enclave set up to block repeated PIN attempts even if Apple-signed code is loaded. No other phone is safe from their own manufacturer like that.

Post reply on HN