Live data from Hacker News

iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

appleinsider.com

51–60 of 177 posts

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#51

I dated a journalist once. She used some random free app for phone calls because recording calls isn't built into iOS and she needed to record calls. I suggested a small device for her to plug her headphones through, but she declined. I'm sure there's a few journalists out there that take cybersecurity seriously, but I'd wager the vast majority are pretty trivially monitored.

I did help desk support at a news agency. We were constantly cleaning up malware from journalists computers... The journalists were constantly downloading all sorts of sketchy files as part of their job. Basically, if you're leaking state secrets / embarrassing repressive governments, don't leave a digital trail that can be traced back to you. Just assume everyone (especially journalists on national security or human rights beats) have been hacked.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#52
post #14

Time for a cyber security focused smartphone?

That's a little silly. The iPhone is a "cyber security focused smartphone" and Apple has billions in R&D money going into its phone. That's a nice thing to say but it doesn't really mean much unless you have some way to achieve that in a way that Apple's vast resources can't.

The Iphone have never been a "cyber security focused smartphone" unless you define security being in focus while it is at least a few steps down from profit, design, and usability.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#53

Apple needs to make it possible for users to choose other ways of sending and receiving messages and listening to music, or of choosing not to do either of those things if they don't want to. Obviously, you can currently install and use other applications that provide the same functionality, but you cannot uninstall or disable defaults. The most shocking experience to me in trying to evaluate the Mac ecosystem when t…

I think that might just be a bug. Or maybe something in your headphones is causing it to send a "play" command through Bluetooth? That will open the Music app if you have nothing playing already.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#54
> However, it is unlikely that Pegasus will be a problem for the vast majority of iPhone users. While the tool is used as intended against criminals by governments, the attacks against innocent people are seemingly against those who could be critics to a regime, including journalists and human rights activists.

Attacks against the freedom of others and critics of government are a much larger threat to ordinary people than if they were surveilled themselves.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#55
post #2

This coupled along with the fact that iMessage's E2EE has been backdoored by the non-E2EE iCloud Backup key escrow is a good argument for leaving iMessage, FaceTime, and iCloud all turned off on a device. I go one step further and leave the SIM card out, which means the SMS vulnerability path is closed too.

But then you are using SMS, which your cell carrier can absolutely see and intercept because it's decrypted. So in either case... turn off native messaging and use Signal or something if you are paranoid. You aren't really using the "phone" part anymore, so buy an iPod touch or something. Also, iMessage is fully E2E if you disable iCloud Backup. Which can easily do in Settings.

This

>you are using SMS

doesn't fit with this from GP

>leave the SIM card out

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#56

Apple needs to make it possible for users to choose other ways of sending and receiving messages and listening to music, or of choosing not to do either of those things if they don't want to. Obviously, you can currently install and use other applications that provide the same functionality, but you cannot uninstall or disable defaults. The most shocking experience to me in trying to evaluate the Mac ecosystem when t…

> , or of choosing not to do either of those things if they don't want to. Obviously, you can currently install and use other applications that provide the same functionality, but you cannot uninstall or disable defaults.

With Apple Configurator you can disable Music and Messages. It’s not the most user-friendly method, but it is possible.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#57

I dated a journalist once. She used some random free app for phone calls because recording calls isn't built into iOS and she needed to record calls. I suggested a small device for her to plug her headphones through, but she declined. I'm sure there's a few journalists out there that take cybersecurity seriously, but I'd wager the vast majority are pretty trivially monitored.

But it also depends on what kind of journalism they're doing, right? Not all report on criminal activity, or on investigating the government. It's kinda like threat-models, no need to be super secure if your work brings no risks to you, your organisation, or those you come in contact with.

Journalists from celebrity gossip reporters to foreign affairs correspondents needs to take security seriously. Even gossip journalists receive information from sources that ranges from information that would get the source fired or blacklisted to put in jail (e.g. LA sheriffs leaking celebrity photos).

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#58
post #14

Time for a cyber security focused smartphone?

Those are always targeted extra hard since they tend to be used by criminals. See the recent "encrypted phones" (Encrochat, Anom, ...) If you really care about security maybe it's better to get a really dumb 4G phone and share it's connection with a Linux small form tablet (but not running Android). Of course, inconvenient as hell, but much more secure, especially since you are not running the iOS/Android mono-cultur…

But then you are vulnerable to physical attacks. You don't have hardware root of trust, so installing a PIN-guessing tool is easy. Extracting the encrypted data for attacking it on a computer outside the phone is also easy.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#59
post #46

Earlier quoted context omitted.

That's a little silly. The iPhone is a "cyber security focused smartphone" and Apple has billions in R&D money going into its phone. That's a nice thing to say but it doesn't really mean much unless you have some way to achieve that in a way that Apple's vast resources can't.

The silly thing is that Apple advertises their phone as something cyber security focused, when it can be totally pwned in so many ways. And you don't need Apple's resources to make something better, just a more secure phone would have much worse UX. Just some examples for a much more secure phone, where you dont need Apple's budget: - Runs some barebones Linux with minimal packages. An SMS app is an SMS app, not some…

In that case, you would still need to trust the mostly proprietary drivers and hardware. And if you aggressively remove features, I guess the question becomes why you would even need a phone. Maybe for some use cases it would be better to simply use a laptop.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#60
post #35
post #14

Time for a cyber security focused smartphone?

Simple solution: just use "dumb phones" or burners No non-open source "smart" phone is going to be secure enough. If you never store your data on your phone, you are safe from these hacks. Now you have to just protect from physical attacks :)

CopperheadOS is an open source OS that builds on Android and can be used on the Pixel devices. I've found it to be quite secure.
Post reply on HN