Earlier quoted context omitted.
Would it actually have more resources that say Apple? I think if Apple can not do it, I am unsure if anyone else could. All supposedly secure smart phones are not, but they are at least obscure. I think that one should probably buy an Apple (at least they control everything rather than the cobbled together android clones) and disable basically everything except exactly what is needed. At least that reduces the surfac…
Apple can do it (create a security focused phone), it just isn't anywhere near what they want to do. The instant security (or privacy for that matter) gets in the way of profit for Apple they will back away.
iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones
61–70 of 177 posts
Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones
#62I dated a journalist once. She used some random free app for phone calls because recording calls isn't built into iOS and she needed to record calls. I suggested a small device for her to plug her headphones through, but she declined. I'm sure there's a few journalists out there that take cybersecurity seriously, but I'd wager the vast majority are pretty trivially monitored.
Apple really doesn't help them. the marketing (lying) that iOS is secure is pretty intense.
Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones
#63I dated a journalist once. She used some random free app for phone calls because recording calls isn't built into iOS and she needed to record calls. I suggested a small device for her to plug her headphones through, but she declined. I'm sure there's a few journalists out there that take cybersecurity seriously, but I'd wager the vast majority are pretty trivially monitored.
I see your point, however, having worked in newsrooms - it really is about their beat and their threat-model. My organization covers a wide range of beats and folks covering national security or other sensitive topics have an entirely different workflow compared to those covering, e.g. housing. I think being responsive to their needs and building trust will go much further. Also, designing a one-size fits all model w…
I don't envy your challenge. Security must make it more expensive to the attacker than it's worth. Even the housing reporter's data could be highly valuable; with inside knowledge, someone could make a killing on real estate. The value of the national security beat information is astronomical.
I don't grasp why, with all the news about breaches, reporters still don't care.
Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones
#64Earlier quoted context omitted.
Simple solution: just use "dumb phones" or burners No non-open source "smart" phone is going to be secure enough. If you never store your data on your phone, you are safe from these hacks. Now you have to just protect from physical attacks :)
CopperheadOS is an open source OS that builds on Android and can be used on the Pixel devices. I've found it to be quite secure.
Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones
#65Time for a cyber security focused smartphone?
Would it actually have more resources that say Apple? I think if Apple can not do it, I am unsure if anyone else could. All supposedly secure smart phones are not, but they are at least obscure. I think that one should probably buy an Apple (at least they control everything rather than the cobbled together android clones) and disable basically everything except exactly what is needed. At least that reduces the surfac…
Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones
#66I dated a journalist once. She used some random free app for phone calls because recording calls isn't built into iOS and she needed to record calls. I suggested a small device for her to plug her headphones through, but she declined. I'm sure there's a few journalists out there that take cybersecurity seriously, but I'd wager the vast majority are pretty trivially monitored.
But it also depends on what kind of journalism they're doing, right? Not all report on criminal activity, or on investigating the government. It's kinda like threat-models, no need to be super secure if your work brings no risks to you, your organisation, or those you come in contact with.
Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones
#67Earlier quoted context omitted.
No, that's not what paranoid means. Your statement is simply incorrect and your use of the word is derogatory.
Only if you say so. There is a degree of rational fear, rational expectation of being tracked. Your degree of fear though is irrational unless you are, in fact, a journalist in an authoritarian state. You are saying that you are so paranoid, you don't trust iMessage to be End-to-End Encrypted because it has zero-click exploits developed as part of a cyberweapon that is explicitly targeted against high-profile journal…
Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones
#68I dated a journalist once. She used some random free app for phone calls because recording calls isn't built into iOS and she needed to record calls. I suggested a small device for her to plug her headphones through, but she declined. I'm sure there's a few journalists out there that take cybersecurity seriously, but I'd wager the vast majority are pretty trivially monitored.
I did help desk support at a news agency. We were constantly cleaning up malware from journalists computers... The journalists were constantly downloading all sorts of sketchy files as part of their job. Basically, if you're leaking state secrets / embarrassing repressive governments, don't leave a digital trail that can be traced back to you. Just assume everyone (especially journalists on national security or human…
However, it adds enough friction (especially with remote work) that it's hard to get it right 100% of the time.
If you want to share really sensitive documents, one way to ensure proper handling of your documents is to use a service like SecureDrop [0] which for e.g. only accepts submissions over Tor and requires the use of a secure viewing station [1] (air-gapped machine live-booting Tails w coreboot rom + webcam/networking card physically removed) to decrypt/access leaks.
That being said, I don't think there's a perfect tech-only solution because nothing is stopping folks handling it carelessly after they access the file.
[0] https://securedrop.org/directory/center-public-integrity/
Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones
#69An intelligence agency cannot have the following properties simultaneously: (1) The ability to detect espionage from China and Russia (2) The inability to access journalists' phones If you want an intel agency to be able to thwart Chinese intelligence activities, you can't also publicly state you won't be looking closely into members of a profession who act a lot like spies.
Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones
#70Earlier quoted context omitted.
Neither of those has a vibrate motor to let me know about notifications. They also can't be used to pair to an Apple Watch. I know this because I used to carry an iPad Mini in my pants pocket.
Then buy an iPhone, and turn off iCloud Backup in Settings, it's not hard to do. Then your iMessages are fully E2E Encrypted.