Live data from Hacker News

A Saudi woman's iPhone revealed hacking around the world

reuters.com

71–80 of 184 posts

Re: A Saudi woman's iPhone revealed hacking around the world

#72
post #63
post #60

Earlier quoted context omitted.

You're really cavalier about whether widespread hacks happen. See any of the text message attacks from the past decade.

Except we don't live in the past decade anymore. Even though people are still sometimes reluctant to updates ("it only made my device slow!"), We made significant progress on patch distribution. In the past a bug in the SMS stack could be mass exploited and still not getting fixed anytime soon. Not anymore. These bugs cost $10k~$100k now and once you mass-exploit it, they are gone.

> Except we don't live in the past decade anymore.

You do know that is a terible attitude for a real-world security posture meant to protect non-theoretical people's property and information against actual exploits?

> In the past a bug in the SMS stack could be mass exploited and still not getting fixed anytime soon. Not anymore.

While you may wish for patches to always take care of exploits before any phones are compromised, that's not much more than wishful thinking. You assume that all 0day exploits are both known and fixed immediately. That is 100% false.

Re: A Saudi woman's iPhone revealed hacking around the world

#73
post #28

Earlier quoted context omitted.

Which is why the only safe way to operate is assume anything that is susceptible to outside data is already compromised - and so run them in sandboxes.

That's not a solution. You're just piping the outside data into your sandbox; it can have bugs too.

This is why I run a 1-task only Windows VM inside a Linux VM on a Mac. Ain’t nobody ripping through x3 0-days for my chats.

Re: A Saudi woman's iPhone revealed hacking around the world

#74
post #28

Earlier quoted context omitted.

Which is why the only safe way to operate is assume anything that is susceptible to outside data is already compromised - and so run them in sandboxes.

That's not a solution. You're just piping the outside data into your sandbox; it can have bugs too.

There's no such thing as a perfect solution, only solutions that improve a bad situation.

Re: A Saudi woman's iPhone revealed hacking around the world

#76

How come the company that made Pegasus is being sanctioned, but the government that used Pegasus to abduct, kill, and then dismember a dissident - isn't?

The simple answer is that to the people that really matter in decisions like that, those in the intelligence and the state departments of countries like the US, software like Pegasus is an important tool in staying ahead of adversaries. And in order to do its job effectively, it’s best if people don’t know about it. Pegasus may be sanctioned, but another company will make a product to takes its place and the game will start again. A similar argument can be made in favour of keeping the Saudis on side; they are useful for what they can do to help attain the foreign policy goals of the US and it’s allies. Those goals are mostly related to making sure the US continues to have access to all the stuff they need to stay on top of the geopolitical tree

Re: A Saudi woman's iPhone revealed hacking around the world

#77
post #54
post #51

Why doesn’t Apple have a team doing what Citizens Lab does, instead of victims contacting a third party? Also, I wonder if Google Pixel is more secure?

Because Animoji was more important. Incase anyone was wondering, yes the amount they spent on that particular feature vastly eclipsed their spend on the kinds of teams that could have caught this.

To be fair, Animoji probably sell more phones that protection against State-backed adversaries.

Re: A Saudi woman's iPhone revealed hacking around the world

#78
post #49

Isn't the walled garden and locked down OS/hardware supposed to prevent these things?

Only provably correct software would prevent such things. A walled garden could make it simpler to enforce that only software proved correct can be installed, but without the proof, it does not guarantee much,,only makes certain things less probable. Writing provably correct software us now a rare and expensive engineering feat. Most consumer OSes have nothing of thus sort, sadly. And I mean just the limited set of s…

Formal correctness proofs are both unattainable and insufficient. We don't know how to do it at the required scale, and it doesn't save us from flawed formal specifications, we'll have the bugs in the formal requirements instead of in the code.

There are more cost efficient and proven ways to effectively address these kinds of vulnerabilities, like limiting complexity, using programming language features to eliminate classes of bugs, using other verifiable engineering disciplines, and compartmentalisation. Proofs also have their place locally in verifying small components. But making this commercially viable would large numbers of customers and users who are willing to make big compromises in functionality, features, third party apps etc.

Re: A Saudi woman's iPhone revealed hacking around the world

#80
post #76

How come the company that made Pegasus is being sanctioned, but the government that used Pegasus to abduct, kill, and then dismember a dissident - isn't?

The simple answer is that to the people that really matter in decisions like that, those in the intelligence and the state departments of countries like the US, software like Pegasus is an important tool in staying ahead of adversaries. And in order to do its job effectively, it’s best if people don’t know about it. Pegasus may be sanctioned, but another company will make a product to takes its place and the game wil…

How does it help to stay ahead of adversaries when they're selling it to basically everyone including most adversaries?
Post reply on HN