Live data from Hacker News

iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

appleinsider.com

81–90 of 177 posts

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#81
post #8

Earlier quoted context omitted.

Please stop using the term "paranoid" to describe those who desire personal privacy.

There is a degree to where you are actually paranoid though, otherwise we wouldn't have that word. If you are this paranoid, you shouldn't be carrying an electronic device.

Paranoia is an irrational suspicion that you are being watched.

If you just don't want to be watched, either by people or algorithms, and have a rational understanding of what tracking/surveillance you are under, and you are actually not paranoid.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#83
post #48

Earlier quoted context omitted.

Apple can do it (create a security focused phone), it just isn't anywhere near what they want to do. The instant security (or privacy for that matter) gets in the way of profit for Apple they will back away.

Or maybe it's because they're doing their best to make every iPhone the security-focused phone, while not doing anything that would anger the FBI enough to try to pass legislation. When you are that big of a company, the things you can get away with are much more restricted than a small company.

They have already angered the FBI quite a lot during the 2016 San Bernadino case and made their position on the matter clear:

https://www.apple.com/customer-letter/

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#84
post #18
post #14

Time for a cyber security focused smartphone?

https://grapheneos.org ?

Yeah, GrapheneOS needs a hardware manufacturing partner.

Anyone who thinks they're up to the task (bulletproof?) should contact them.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#85
I wonder if there is a way to disable iMessage and iTunes usage.

With windows server I used to have a target of balance in any attack footprint.. if Microsoft provided the OS, the component services that the server exists to provide should always try to be third party software (db, web server, etc) to try and minimize one type of escalation vulnerabilities… while possibly opening up to another, hopefully less worse set of holes.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#86

I dated a journalist once. She used some random free app for phone calls because recording calls isn't built into iOS and she needed to record calls. I suggested a small device for her to plug her headphones through, but she declined. I'm sure there's a few journalists out there that take cybersecurity seriously, but I'd wager the vast majority are pretty trivially monitored.

I see your point, however, having worked in newsrooms - it really is about their beat and their threat-model. My organization covers a wide range of beats and folks covering national security or other sensitive topics have an entirely different workflow compared to those covering, e.g. housing. I think being responsive to their needs and building trust will go much further. Also, designing a one-size fits all model w…

Well, she wrote about scary stuff. Murderers, etc. Feature stories for one of the few fact checked Canadian magazines left. Some stuff in The Atlantic about politics.

Was she getting leaks from NSA staffers? No. But it does feel kinda silly to me that journalists, generally speaking, have insecure setups by default. But I get it, it's a hard industry to squeeze a living out of these days.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#87

Earlier quoted context omitted.

There is a degree to where you are actually paranoid though, otherwise we wouldn't have that word. If you are this paranoid, you shouldn't be carrying an electronic device.

It's not paranoia when it's true. While most people value the convenience of conventional phones calls and default messaging applications over true privacy, those who prefer privacy aren't being paranoid. Companies are monitoring communication to increase ad revenue; government are monitoring communication to catch criminals, enable industrial espionage, and suppress dissent. It's only paranoia if it's delusional. We…

> I disable location services except for things like Maps that actually need to know where I am

Fun fact: having systemwide location services on, even if you don't enable it for any apps, means that your location is sent in realtime to Apple/Google at all times (via Wi-Fi triangulation data). It's not just passive GPS reception.

If you want actual location privacy, you'll want to leave location services off systemwide on your smartphone, and consider getting an offline GPS receiver device. Good car satnav devices from China are like $60 now, and include continent-wide maps, though you lose realtime traffic info, being offline.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#88

Apple needs to make it possible for users to choose other ways of sending and receiving messages and listening to music, or of choosing not to do either of those things if they don't want to. Obviously, you can currently install and use other applications that provide the same functionality, but you cannot uninstall or disable defaults. The most shocking experience to me in trying to evaluate the Mac ecosystem when t…

I also have bluetooth headphones I use with a mac, and that’s never happened to me. Is it a new thing with the M1 machines or something?

It happens to me every time I connect my QC35s to a 2018 MacBook Pro. It's extremely annoying.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#89

Earlier quoted context omitted.

...or I could just use a truly-secure option that doesn't destroy my personal security model. Owning an iDevice presents a considerable security risk to my current setup.

There is no such thing as a "truly-secure option." As anyone truly concerned about security will tell you. You will be forced to make compromises somewhere unless you want to live under a rock in the desert. You can't drive without a State ID, can't get a home loan without credit, can't work without a Social Security Number except under limited circumstances, can't make money without reporting to the IRS, and so on.…

> can't work without a Social Security Number except under limited circumstances

Something like 96% of human beings don't have a social security number. Many of them work.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#90
post #28

I dated a journalist once. She used some random free app for phone calls because recording calls isn't built into iOS and she needed to record calls. I suggested a small device for her to plug her headphones through, but she declined. I'm sure there's a few journalists out there that take cybersecurity seriously, but I'd wager the vast majority are pretty trivially monitored.

Apple really doesn't help them. the marketing (lying) that iOS is secure is pretty intense.

iOS is currently the least worst mobile solution as a daily driver for the majority of people who are users before techies.

It doesn’t mean it’s good enough but I’d be curious to hear your ideas for what could work as easily for the masses.

Post reply on HN