Live data from Hacker News

U.S. State Department phones hacked with Israeli company spyware

reuters.com

41–50 of 651 posts

Re: U.S. State Department phones hacked with Israeli company spyware

#41

Is there a timetable when Apple plans to stop using memory-unsafe languages to avoid memory-bugs? If not, how can the amount of zero-days stop with constant development?

biggest issue here isn't memory safety but the dumpster fire of imessage format that calls out to privileged parts of the system

Which is exploitable primarily it by memory safety exploits.

Will it make attacks impossible? Probably not totally. But it might raise the cost of the attack by an order of magnitude or more and certain classes of vulnerabilities might disappear completely.

Re: U.S. State Department phones hacked with Israeli company spyware

#42

> NSO Group said in a statement on Thursday that it did not have any indication their tools were used but canceled the relevant accounts and would investigate based on the Reuters inquiry. Why would they cancel accounts without knowledge of wrongdoing?

And simultaneusly: - not have any indication their tools were used - canceled the relevant accounts Which "relevant" accounts if NSO's tools weren't used?

I think it's pretty clear by now that they have 100% visibility into the entire exploitation chain for all of their customers. Their "official statements" mean nothing.

Re: U.S. State Department phones hacked with Israeli company spyware

#43
post #26

>In a public response, NSO has said its technology helps stop terrorism and that they've installed controls to curb spying against innocent targets. For example, NSO says its intrusion system cannot work on phones with U.S. numbers beginning with the country code +1. So the point is to stop terrorism and to do that they've immediately ruled that all Americans aren't terrorists. That doesn't seem like a good metric of…

So I just have to buy a US phone to evade detection from NSO? And why didn't that logic work for US State Dept phones? I'm honestly of the opinion there is nothing that NSO can say that isn't outright lying. This isn't a normal company in anyway.

>And why didn't that logic work for US State Dept phones

They had Ugandan numbers, as they lived in Uganda.

Re: U.S. State Department phones hacked with Israeli company spyware

#45

>In a public response, NSO has said its technology helps stop terrorism and that they've installed controls to curb spying against innocent targets. For example, NSO says its intrusion system cannot work on phones with U.S. numbers beginning with the country code +1. So the point is to stop terrorism and to do that they've immediately ruled that all Americans aren't terrorists. That doesn't seem like a good metric of…

> the point is to stop terrorism and to do that they've immediately ruled that all Americans aren't terrorists

The alleged point is to sell software that stops terrorism. Pissing off America is a good way to stop being able to sell your software.

Re: U.S. State Department phones hacked with Israeli company spyware

#46
I don't understand the focus on NSO in these stories. If U.S State Department personnel in Uganda were shot from an M-16, would the headline mention "an American arms manufacturer"? No, because it's ridiculous.

For better or worse, NSO's product is a weapon. How is it any different from an M-16? Where is the outrage towards the people who used this weapon against the State Department?

Re: U.S. State Department phones hacked with Israeli company spyware

#47

Is there a timetable when Apple plans to stop using memory-unsafe languages to avoid memory-bugs? If not, how can the amount of zero-days stop with constant development?

no question that imessage, email parsers, etc that do third party untrusted network type interactions SHOULD be memory safe. But of course they are not, and apple in particular LARDS these formats down with a million features.

Re: U.S. State Department phones hacked with Israeli company spyware

#48

>In a public response, NSO has said its technology helps stop terrorism and that they've installed controls to curb spying against innocent targets. For example, NSO says its intrusion system cannot work on phones with U.S. numbers beginning with the country code +1. So the point is to stop terrorism and to do that they've immediately ruled that all Americans aren't terrorists. That doesn't seem like a good metric of…

Reminds me of how some ransomware looks for if your default keyboard language is Russian. If so then it exits, doing nothing.

OK, so the best way to protect privacy is to get US-based phone number and install Russian keyboard as a default.

Re: U.S. State Department phones hacked with Israeli company spyware

#49

I don't understand the focus on NSO in these stories. If U.S State Department personnel in Uganda were shot from an M-16, would the headline mention "an American arms manufacturer"? No, because it's ridiculous. For better or worse, NSO's product is a weapon. How is it any different from an M-16? Where is the outrage towards the people who used this weapon against the State Department?

It's my understanding that NSO runs centralized command and control servers that their "clients" are granted access to, for both the on-device payload installation and also data exfiltration.

They do not give the software to their clients to go use somewhere in the world fully independently (self hosted payload dropper, C&C, etc)

They're a direct participant in the network traffic. Unlike a dumb purely offline piece of hardware like a M4 rifle or similar.

Post reply on HN