Live data from Hacker News

Apple will notify users about state-sponsored cybersecurity threats

support.apple.com

61–70 of 166 posts

Re: Apple will notify users about state-sponsored cybersecurity threats

#61

Earlier quoted context omitted.

Can you provide citation for this? Also how they are different from any other tech company? My MacBooks security keys are not trivial to acquire because they aren’t in icloud. In some of the countries in five eyes nations, you don’t have a choice about cooperating or not. But what do 5 eyes have to do with Chinese users?

> Can you provide citation for this? Apple's cooperation with PRISM[0] is well documented[1], but if you want to find the particularly damning details you'll need to do your own research. The dust has settled since the Snowden revelations, and many mentions of the program have been sterilized. > Also how they are different from any other tech company? It's not. But the claim that Apple puts extra effort into protecti…

> Apple's cooperation with PRISM[0] is well documented[1]

Neither of your links documents any kind of cooperation, let alone documenting it well.

Re: Apple will notify users about state-sponsored cybersecurity threats

#62

Earlier quoted context omitted.

Apple claims in their lawsuit that they have over 100 false iCloud accounts that were created, and is confident in their identities to the degree they are going to use them for standing to prove that NSO signed a legal agreement in the lawsuit. In which case, NSO f!@#ed up and left iCloud Messages Backup enabled, which stores unencrypted copies of the End-to-End messages and makes it trivial for Apple to alert any pe…

Because the NSO group definitely used iMessage to communicate with one another...

This is more likely targeting phishing messages coming from NSO Group to victims, rather than communication between NSO members.

Re: Apple will notify users about state-sponsored cybersecurity threats

#63

Earlier quoted context omitted.

Can you provide citation for this? Also how they are different from any other tech company? My MacBooks security keys are not trivial to acquire because they aren’t in icloud. In some of the countries in five eyes nations, you don’t have a choice about cooperating or not. But what do 5 eyes have to do with Chinese users?

> Can you provide citation for this? Apple's cooperation with PRISM[0] is well documented[1], but if you want to find the particularly damning details you'll need to do your own research. The dust has settled since the Snowden revelations, and many mentions of the program have been sterilized. > Also how they are different from any other tech company? It's not. But the claim that Apple puts extra effort into protecti…

I shouldn't be arguing with the trolls - but in case anyone was curious about these (nonsense) allegations:

Your links do not document cooperation with PRISM other than that the NSA believed they got information from them, which is very different. For all we know, it could have been the NSA abusing an API endpoint. Also, it said that it got lots of stuff like email, address, and so on when all of these services were combined which made it PRISM.

For all we know, it could have been checking the emails from Apple (because of FaceTime), getting address from Facebook, using address to look up other info on LinkedIn, and so forth. If anything, PRISM shows NSA abuse of services more than intentional compliance.

> definitely more secure devices you could be using.

I hate that I have to say this, but Linux phones are not more secure. They do have a company they don't phone-home to, but if a Linux phone was found on the side of the road, I have no doubt that the NSA would find a way in (unlike the iPhone, which as lately as the Rittenhouse trial, the latest model has not been cracked and the government ultimately struck a deal with the defense for a PIN code).

Linux phones are only secure by obscurity in that less research has been done on them and they are less common - but if government agencies were (or are) putting some research cash into them, I would not be surprised if they burst open from a million attacks that iPhones and Androids have found and fixed over the last decade.

> It's no coincidence that MacBooks force you to use NIST-designed crypto

Stop being conspiratorial - almost everyone, including many companies outside the US, use Curve25519 or P-256, and a big reason why is that the algorithm is very fast to calculate while being reasonably secure, which is a plus for fast encryption. Also, nobody has seriously alleged that Curve25519 is backdoor, unlike Dual_EC_DRBG which was suspect almost immediately. Also, NIST did not invent Dual_EC_DRBG. The NSA did and submitted it to NIST as a standard which NIST reluctantly accepted.

> Shied away from that kind of compliance with a known abuser of human rights

Yes - but Microsoft, Google, etc still make their phones in the same factories, and the reason they didn't hand over the server keys was because they don't really offer any services in China. Google doesn't work in China, and Microsoft's involvement is minor and China doesn't care because Windows doesn't encrypt data unless you have the Pro version and it's switched on. Also, your bias is showing in your use of Apple "happily" complying. How do you know that?

I can go on.

Re: Apple will notify users about state-sponsored cybersecurity threats

#65
post #7

I'm surprised to see protection against state sponsored attacks implemented by a company as big as Apple. Is any other 'mainstream' company offering a similar feature? Warrant canary [0] comes to mind, but that is usually a message to all users, as opposed to notifying an individual user. [0]: https://en.wikipedia.org/wiki/Warrant_canary

> by a company as big as Apple Would smaller company stand a chance against very much any state? If men in suits taken a CEO of a big company for "a talk" in the forest there would be a lot of fuss in the media, whereas small company would probably be scared to bits and never said a word.

A talk in the forest is for poor countries like Belarus. Rich countries just call their local SEC and IRS.

Re: Apple will notify users about state-sponsored cybersecurity threats

#66
post #26
post #15

I see a lot of pessimism in the comments. But I think this is a great step in the right direction. Other companies should take note. More of this, please!

Apple is like the last company in that space to do this. Google has had these warnings since 2012. Facebook, Microsoft and Twitter since 2015. (I agree that it's great that Apple is finally doing this. But it seems entirely par for the course for them to be a decade late and still get the credit.)

I have never seen any warnings from Google or Facebook if I automate against my own accounts, and dumping the data. Only on sign-in attempts. That kind of warning is very limited, and Apple also have them.

It seems like Apple now have introduced ‘honey pots’ and other techniques to discover if there already is someone with access to your account/device, and that is a big deal and good news. And something I have never seen from any of the other big companies.

Re: Apple will notify users about state-sponsored cybersecurity threats

#67
post #14

"If Apple discovers activity consistent with a state-sponsored attack" I am really interested in understanding more about a "state-sponsored attack" as someone who works in Ops and has experience in CyberSec. All these years working in the industry and I had no idea you could identify an "attack" that easily.

I believe it has to do with phishing attempts by known tools (NSO’s Pegasus). If anyone has the resources to fend them off, fingerprint them, etc it is Apple, Microsoft and Google.

Re: Apple will notify users about state-sponsored cybersecurity threats

#69

What if it is illegal to do so?

From a pragmatic user's point of view, that would look just like "Apple didn't happen to notice that I was a target of state-sponsored activity". Recent headlines do not suggest that Apple's cyberdefenses are all that great against state-sponsored stuff. From a more philosophical point of view - expecting a large corporation to go mano a mano on your behalf, against a major state security organization...that's right…

And yet, in the contact tracing case both Apple and Google refused to give data and control to EU governments. I believe the contact tracing app was used against protesters in rallies about BLM though, by the FBI IIRC.
Post reply on HN