Live data from Hacker News

Apple will notify users about state-sponsored cybersecurity threats

support.apple.com

71–80 of 166 posts

Re: Apple will notify users about state-sponsored cybersecurity threats

#71
post #15

I see a lot of pessimism in the comments. But I think this is a great step in the right direction. Other companies should take note. More of this, please!

I think you can spot when your phone has been hacked, for example the mobile phone carriers can spot the traffic and slow down the communication making it obvious things are not working properly. Take using the AirBnB app, you put in a criteria, the results come back then the spooky hackers wipe the results and give you a list of their "safehouse" Airbnb locations meaning all you can do is book into one of their safe houses. The fact you see the AirBnB results get wiped and then slowly other results not really matching your criteria appearing should tell you, you could be booking into a safe house.

Dating apps/websites is another way to get into a relationship with "undercover" investigators and I dont think most people are aware that any crime ever committed since birth can be prosecuted so as no one can predict what legislation might be hitting the books in the future, it might be hard to keep your nose clean.

I think most people are aware of dodgy text messages which tends to be the start of malware entering your phone.

Re: Apple will notify users about state-sponsored cybersecurity threats

#72
post #22

I know of one case of a Polish prosecutor who does not obey (do not want to bend the law) Zbigniew Ziobro, who is both the minister of justice and the prosecutor general. She received a notification from Apple just today. Source: https://mobile.twitter.com/e_wrzosek/status/1463551631648251...

Is it concerning to any security people with more knowledge than me that this is sent via iMessage?!

Re: Apple will notify users about state-sponsored cybersecurity threats

#73
post #22

I know of one case of a Polish prosecutor who does not obey (do not want to bend the law) Zbigniew Ziobro, who is both the minister of justice and the prosecutor general. She received a notification from Apple just today. Source: https://mobile.twitter.com/e_wrzosek/status/1463551631648251...

Is it concerning to any security people with more knowledge than me that this is sent via iMessage?!

iMessage is extremely secure and utilizes end-to-end encryption, why is this concerning to you?

Re: Apple will notify users about state-sponsored cybersecurity threats

#74
post #26

Earlier quoted context omitted.

Apple is like the last company in that space to do this. Google has had these warnings since 2012. Facebook, Microsoft and Twitter since 2015. (I agree that it's great that Apple is finally doing this. But it seems entirely par for the course for them to be a decade late and still get the credit.)

I have never seen any warnings from Google or Facebook if I automate against my own accounts, and dumping the data. Only on sign-in attempts. That kind of warning is very limited, and Apple also have them. It seems like Apple now have introduced ‘honey pots’ and other techniques to discover if there already is someone with access to your account/device, and that is a big deal and good news. And something I have never…

The warning is for government-sponsored attacks, not any kind of automation.

https://blog.google/threat-analysis-group/updates-about-gove...

Re: Apple will notify users about state-sponsored cybersecurity threats

#75
post #73

Earlier quoted context omitted.

Is it concerning to any security people with more knowledge than me that this is sent via iMessage?!

iMessage is extremely secure and utilizes end-to-end encryption, why is this concerning to you?

And it has spam problems: https://www.wired.com/2014/08/apples-imessage-is-being-taken...

The problem is authenticity and authority, not encryption. How can the user know this message really came from Apple and not a spammer?

Re: Apple will notify users about state-sponsored cybersecurity threats

#76
post #15

I see a lot of pessimism in the comments. But I think this is a great step in the right direction. Other companies should take note. More of this, please!

Google's been doing this since at least 2012 http://arstechnica.com/information-technology/2012/06/google...

Re: Apple will notify users about state-sponsored cybersecurity threats

#77

Earlier quoted context omitted.

Gmail does it https://blog.google/threat-analysis-group/updates-about-gove...

Yeah, I loved having my work gmail account peppered with a giant red banner warmomg "THIS ACCOUNT IS THE TARGET OF STATE SPONSORED HACKERS". That was fun. We didn't really know how to respond or attempt to mitigate such a warning so, left it ignored.

Respond by using 2fa if you weren't already, not signing into the account from untrusted devices, checking OAuth grants for apps you don't recognize, not using same pw elsewhere

Re: Apple will notify users about state-sponsored cybersecurity threats

#79
post #75
post #73

Earlier quoted context omitted.

iMessage is extremely secure and utilizes end-to-end encryption, why is this concerning to you?

And it has spam problems: https://www.wired.com/2014/08/apples-imessage-is-being-taken... The problem is authenticity and authority, not encryption. How can the user know this message really came from Apple and not a spammer?

[deleted]

Re: Apple will notify users about state-sponsored cybersecurity threats

#80
post #75
post #73

Earlier quoted context omitted.

iMessage is extremely secure and utilizes end-to-end encryption, why is this concerning to you?

And it has spam problems: https://www.wired.com/2014/08/apples-imessage-is-being-taken... The problem is authenticity and authority, not encryption. How can the user know this message really came from Apple and not a spammer?

That article is seven years old and in no way reflects current reality. In fact it has never reflected my own experience or that of anyone I know, where iMessage spam has been near enough to non-existent.

And even if there were a spam problem, the risk is mostly on the upside anyway. It would only be an issue if iMessage got a reputation for flooding people with admonishments to take security seriously, purportedly from Apple.

Post reply on HN