Live data from Hacker News

Apple will notify users about state-sponsored cybersecurity threats

support.apple.com

81–90 of 166 posts

Re: Apple will notify users about state-sponsored cybersecurity threats

#81
post #75
post #73

Earlier quoted context omitted.

iMessage is extremely secure and utilizes end-to-end encryption, why is this concerning to you?

And it has spam problems: https://www.wired.com/2014/08/apples-imessage-is-being-taken... The problem is authenticity and authority, not encryption. How can the user know this message really came from Apple and not a spammer?

>How can the user know

Read the document of the original top post (the document from Apple).

The answer to your question is right there in the document.

Re: Apple will notify users about state-sponsored cybersecurity threats

#82

So something like PRISM that targets everybody won't trigger a warning?

I doubt it. Keep in mind this will only work for non-court-gag-ordered instances. If the US subpoenas Apple about an individual they won't be allowed to notify them. I have no idea how this applies to other countries. I think this is more like: "We noticed unusual API usage and we don't have a gag order so whatever it is, it's not likely to be good"

To be fair, a subpoena isn't a cyberattack. But yes, this will be mostly of value of people being targeted by governments that are not the USA or best buddies with the USA.

Re: Apple will notify users about state-sponsored cybersecurity threats

#83

Earlier quoted context omitted.

Can you provide citation for this? Also how they are different from any other tech company? My MacBooks security keys are not trivial to acquire because they aren’t in icloud. In some of the countries in five eyes nations, you don’t have a choice about cooperating or not. But what do 5 eyes have to do with Chinese users?

You shouldn't argue with @smoldesu, he has a history of trying to troll and spread FUD about Apple at every possible opportunity, even on completely unrelated topics. It's so ridiculous, a complaint about it is the #1 result on Google if you type "smoldesu" in. They also are not typically the most factual of complaints but they aren't interested in corrections. Beats me why the mods haven't sent warnings.

Thank you for your crack forensic work, this guy seems like a really reprehensible character, it's a wonder that his throwaway troll account has accrued so much karma and even regularly commented on a variety of topics to avoid arousing suspicion. After some more OSINT (open source intelligence for my fellow Redditors out there) we even discovered that he had accounts on other sites, where he also espoused original opinions and fresh takes. We'll do our best to stamp out any intellectually stimulating conversations in the future to ensure that Apple threads don't accidentally cause readers to think about the product they use.

Re: Apple will notify users about state-sponsored cybersecurity threats

#84
post #75

Earlier quoted context omitted.

And it has spam problems: https://www.wired.com/2014/08/apples-imessage-is-being-taken... The problem is authenticity and authority, not encryption. How can the user know this message really came from Apple and not a spammer?

That article is seven years old and in no way reflects current reality. In fact it has never reflected my own experience or that of anyone I know, where iMessage spam has been near enough to non-existent. And even if there were a spam problem, the risk is mostly on the upside anyway. It would only be an issue if iMessage got a reputation for flooding people with admonishments to take security seriously, purportedly f…

Meanwhile apple has added iMessage apps[1], that you can add to your iMessage and there recently were a few iMessage exploits including a zero-click one[2].

[1] https://support.apple.com/en-us/HT206906

[2] https://9to5mac.com/2021/07/19/zero-click-imessage-exploit/

Re: Apple will notify users about state-sponsored cybersecurity threats

#87
post #69

Earlier quoted context omitted.

From a pragmatic user's point of view, that would look just like "Apple didn't happen to notice that I was a target of state-sponsored activity". Recent headlines do not suggest that Apple's cyberdefenses are all that great against state-sponsored stuff. From a more philosophical point of view - expecting a large corporation to go mano a mano on your behalf, against a major state security organization...that's right…

And yet, in the contact tracing case both Apple and Google refused to give data and control to EU governments. I believe the contact tracing app was used against protesters in rallies about BLM though, by the FBI IIRC.

Source? Pretty bold claim to just toss out with an IIRC.

First, I haven't seen any indictments of any BLM rioters. Note when I say rioters I'm not including protesters but those who set fires and harmed people.

Second, while I'm against contact tracing apps in general for the reason they can be abused, I don't think they would be needed by LE given their ability to setup string rays, drones, and monitor social media.

Most of the BLM rioters and Antifa terrorists are known. Raz Simone is still free although he setup CHAZ, passed out rifles, and extorted public officials with political demands while claiming public land allowing 6 people to be killed under his "security".

Re: Apple will notify users about state-sponsored cybersecurity threats

#88
post #77

Earlier quoted context omitted.

Yeah, I loved having my work gmail account peppered with a giant red banner warmomg "THIS ACCOUNT IS THE TARGET OF STATE SPONSORED HACKERS". That was fun. We didn't really know how to respond or attempt to mitigate such a warning so, left it ignored.

Respond by using 2fa if you weren't already, not signing into the account from untrusted devices, checking OAuth grants for apps you don't recognize, not using same pw elsewhere

Yeah, we were doing that, so the response was to just shrug. Without a lot more context it's hard to know what your reaction should be to something like that.

Re: Apple will notify users about state-sponsored cybersecurity threats

#90
post #73

Earlier quoted context omitted.

Is it concerning to any security people with more knowledge than me that this is sent via iMessage?!

iMessage is extremely secure and utilizes end-to-end encryption, why is this concerning to you?

Aren't iMessages backed up to icloud that does not have end to end encryption.
Post reply on HN