Live data from Hacker News

iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

appleinsider.com

71–80 of 177 posts

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#71
post #28

Earlier quoted context omitted.

Apple really doesn't help them. the marketing (lying) that iOS is secure is pretty intense.

To be fair it's probably the most secure environment for the average Joe, you're just saying that it's not perfectly secure, which would be impossible in this world.

You could do far better than iOS. Worse though is that it encourages very poor infosec because when it's profitable for Apple and often makes doing things correctly difficult or impossible.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#72
post #17

Earlier quoted context omitted.

Would it actually have more resources that say Apple? I think if Apple can not do it, I am unsure if anyone else could. All supposedly secure smart phones are not, but they are at least obscure. I think that one should probably buy an Apple (at least they control everything rather than the cobbled together android clones) and disable basically everything except exactly what is needed. At least that reduces the surfac…

Plenty of people have "beaten" Apple for security, though oftentimes these hardened phone OSes are only secure through obscurity.

Who?

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#73

Apple needs to make it possible for users to choose other ways of sending and receiving messages and listening to music, or of choosing not to do either of those things if they don't want to. Obviously, you can currently install and use other applications that provide the same functionality, but you cannot uninstall or disable defaults. The most shocking experience to me in trying to evaluate the Mac ecosystem when t…

> I just can't understand what the thought process was in making this a default behavior, let alone one that cannot be disabled.

I do not get the bluetooth-automatically-starts Apple Music behavior.

I haven't tried but I just checked the iMessages preferences and you can disable being contacted via your phone number or email addresses, with check boxes for each. As Macs don't have phone numbers I think this would work? I do use apple messages (which is why I didn't try disabling it), but use WhatsApp and signal more than I use the default.

I have no idea how good the mac's security might be, just pointing out my experience.

I agree that Apple could do better with eliminating their bundled apps, but I use third party calendar, address book, reminders, photo, etc with no issues. And I hear quite a few people are willing to use chrome (ugh) as their default browser and safari doesn't get in the way.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#74
post #24

Earlier quoted context omitted.

No, that's not what paranoid means. Your statement is simply incorrect and your use of the word is derogatory.

Only if you say so. There is a degree of rational fear, rational expectation of being tracked. Your degree of fear though is irrational unless you are, in fact, a journalist in an authoritarian state. You are saying that you are so paranoid, you don't trust iMessage to be End-to-End Encrypted because it has zero-click exploits developed as part of a cyberweapon that is explicitly targeted against high-profile journal…

No, he is right that you are using bad words because you disagree. I wouldn't have added this but the thread just keeps going.

Just because someone want to be as secure as possible while using their electronic devices and you think they are being extreme doesn't mean that they are being paranoid. It has nothing to do with being paranoid. It could simply be because it is fun to try and secure your devices or to gather knowledge on how to do so in case you need to apply the skill-set at work or a thousand other reasons.

>you don't trust iMessage to be End-to-End Encrypted

I don't secure my devices as GP does but I also do not trust for a second that iMessage is securely E2EE. It is not something you hear rarely if talking about the topic, in fact it is very common argument on HN that iMessage messages are saved unencrypted to iCloud.

>this was pulled off in iMessage (more sandboxed than any other messenger security-wise)

That is almost the opposite opinion of iMessage than what was posted by researchers yesterday on HN (well, Twitter originally). In fact they stated:

>"BlastDoor is a great step, to be sure, but it's pretty lame to just slap sandboxing on iMessage and hope for the best. How about: "don't automatically run extremely complex and buggy parsing on data that strangers push to your phone?!"

In short, Paranoid is misused a lot like this. Just like Schizophrenia (it is often used about having multiple personalities or many opinions that clashes, but neither is correct usage).

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#75
post #35

Earlier quoted context omitted.

Simple solution: just use "dumb phones" or burners No non-open source "smart" phone is going to be secure enough. If you never store your data on your phone, you are safe from these hacks. Now you have to just protect from physical attacks :)

CopperheadOS is an open source OS that builds on Android and can be used on the Pixel devices. I've found it to be quite secure.

Didn't CopperheadOS shut down years ago? The developer, Daniel Micay, now develops GrapheneOS.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#76
post #14

Time for a cyber security focused smartphone?

These apparently exist in the criminal underworld (see the FBI's recent sting using such a project) and for state security organizations (developed by major defense contractors, afaik).

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#77
post #48
post #17

Earlier quoted context omitted.

Would it actually have more resources that say Apple? I think if Apple can not do it, I am unsure if anyone else could. All supposedly secure smart phones are not, but they are at least obscure. I think that one should probably buy an Apple (at least they control everything rather than the cobbled together android clones) and disable basically everything except exactly what is needed. At least that reduces the surfac…

Apple can do it (create a security focused phone), it just isn't anywhere near what they want to do. The instant security (or privacy for that matter) gets in the way of profit for Apple they will back away.

Apple is actually not in the business of selling the data of their users. They will also risk aggravating large players in favor of improved privacy. A recent example: App Tracking Transparency [1] which makes tracking an opt-in feature to be requested from the user. To no one's surprise users are happily declining when made this offer. Companies like Facebook aren't too happy about it. [2]

[1] https://www.apple.com/newsroom/2021/01/data-privacy-day-at-a...

[2] https://www.inc.com/jason-aten/apples-privacy-update-is-turn...

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#78

Earlier quoted context omitted.

Then buy an iPhone, and turn off iCloud Backup in Settings, it's not hard to do. Then your iMessages are fully E2E Encrypted.

...or I could just use a truly-secure option that doesn't destroy my personal security model. Owning an iDevice presents a considerable security risk to my current setup.

There is no such thing as a "truly-secure option." As anyone truly concerned about security will tell you.

You will be forced to make compromises somewhere unless you want to live under a rock in the desert. You can't drive without a State ID, can't get a home loan without credit, can't work without a Social Security Number except under limited circumstances, can't make money without reporting to the IRS, and so on. It's entirely about what compromises you want to make, and the tradeoffs therein.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#79

Earlier quoted context omitted.

Plenty of people have "beaten" Apple for security, though oftentimes these hardened phone OSes are only secure through obscurity.

Who?

The parent post is saying that many of these "secure phones" are, on paper, secure - but that's because companies like the NSO Group don't give them much attention. If they did become the focus of attention, they'd probably burst from a thousand leaks.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#80
post #9

Earlier quoted context omitted.

Nope, because they get escrowed by the other end of the iMessage conversation. Also, the whole point of disabling iMessage (in this thread) is to close the iMessage-related zero click exploits described in TFA.

The other end of the conversation escrows the key on any messenger. Otherwise how would you read the message? Unless you consider Snapchat, but that's not End to End Encrypted. And are you really sure that Signal or your preferred messengers don't also have Zero-Click exploits? After all, they aren't sandboxed to the degree iMessage is with BlastDoor.

>"BlastDoor is a great step, to be sure, but it's pretty lame to just slap sandboxing on iMessage and hope for the best. How about: "don't automatically run extremely complex and buggy parsing on data that strangers push to your phone?!"

https://twitter.com/billmarczak/status/1416801514685796352

Post reply on HN