Live data from Hacker News

When Trump Phones Friends, the Chinese and the Russians Listen and Learn

nytimes.com

91–97 of 97 posts

Re: When Trump Phones Friends, the Chinese and the Russians Listen and Learn

#91
post #45

This article mentions that restoring an iphone from backup also risks transferring any malware. What would be the way to restore an iphone: would restore data from icloud also risk malware infection if the phone had it? (E.g. syncing calendars, imessages, health data, etc, all of which can use icloud sync) Referring to regular iphones here, not the president's custom phone

For backed up data to carry a piece of malware, they'd have to exploit a zero-day bug in iOS or in the associated app. That's possible in theory, but those have been rare, and once iOS or the app gets fixed, the exploit in the data is neutralized. Looking at a list of known iOS malware [1] I don't offhand see any tools that manage to install themselves through exploits in non-jailbroken iOS or exploits normal App Sto…

Great summary, thanks! So basically, exploits are possible on extremely high value targets like the president, but apart from that there are basically no malware worried for updated, non-jailbroken iphones.

I'd been curious about this since reading about NSO Pegasus and their SMS method. Is this likely in the "zero day, high value target category"?

I've never properly seen an explanation of how it's supposed to work.

https://thehackernews.com/2018/07/iphone-hacking-spyware.htm...

Re: When Trump Phones Friends, the Chinese and the Russians Listen and Learn

#92
> what arguments tend to sway him and to whom he is inclined to listen — to keep a trade war with the United States from escalating further.

So, maybe it's a good thing he's using his iPhone.

How difficult would it be to develop something like an iPhone One for the president and other high officials?

> His Twitter phone can connect to the internet only over a Wi-Fi connection

There was a lot of criticism regarding him using Twitter with regards to computer safety. I would think that the CIA or Secret Service approaches Twitter in such a case and tries to work out a custom solution to make extra sure the account isn't vulnerable to tampering. Like 2FA where he gets the pins from an assistant or something like that.

Re: When Trump Phones Friends, the Chinese and the Russians Listen and Learn

#93
post #92

> what arguments tend to sway him and to whom he is inclined to listen — to keep a trade war with the United States from escalating further. So, maybe it's a good thing he's using his iPhone. How difficult would it be to develop something like an iPhone One for the president and other high officials? > His Twitter phone can connect to the internet only over a Wi-Fi connection There was a lot of criticism regarding hi…

German government has/had iPhone Ones. Didn't stop allies from eavesdropping.

Re: When Trump Phones Friends, the Chinese and the Russians Listen and Learn

#94

Earlier quoted context omitted.

The president can declassify anything he wants to, merely by speaking it to someone else. He's the only person in or out of the government who can do this. So, not impeachable. Impeachable would be when the former Secretary of State did not exercise care when handling classified information. The relevant statute does not require intent - only lack of care. It is interesting that all the push back by governments to ke…

>Impeachable would be when the former Secretary of State did not exercise care when handling classified information Its remarkable that some people are still keeping up this charade, 3.5 years after it was revealed and 2 years after it was put to rest. C'mon, man. It's intellectual dishonesty. Apparently we judge a former SoS by the rules of cricket and the President by the rules of Calvinball.

Charade? She sent and received classified emails:

https://www.factcheck.org/2016/07/clintons-handling-of-class...

Here's the relevant statute:

https://www.law.cornell.edu/uscode/text/18/793

    (f) Whoever, being entrusted with or having lawful possession or control of any document, writing, code book, signal book, sketch, photograph, photographic negative, blueprint, plan, map, model, instrument, appliance, note, or information, relating to the national defense, (1) through gross negligence permits the same to be removed from its proper place of custody or delivered to anyone in violation of his trust, or to be lost, stolen, abstracted, or destroyed, or (2) having knowledge that the same has been illegally removed from its proper place of custody or delivered to anyone in violation of its trust, or lost, or stolen, abstracted, or destroyed, and fails to make prompt report of such loss, theft, abstraction, or destruction to his superior officer—
   
    Shall be fined under this title or imprisoned not more than ten years, or both.

Re: When Trump Phones Friends, the Chinese and the Russians Listen and Learn

#95

Earlier quoted context omitted.

>Impeachable would be when the former Secretary of State did not exercise care when handling classified information Its remarkable that some people are still keeping up this charade, 3.5 years after it was revealed and 2 years after it was put to rest. C'mon, man. It's intellectual dishonesty. Apparently we judge a former SoS by the rules of cricket and the President by the rules of Calvinball.

Charade? She sent and received classified emails: https://www.factcheck.org/2016/07/clintons-handling-of-class... Here's the relevant statute: https://www.law.cornell.edu/uscode/text/18/793 (f) Whoever, being entrusted with or having lawful possession or control of any document, writing, code book, signal book, sketch, photograph, photographic negative, blueprint, plan, map, model, instrument, appliance, note, or inf…

https://warontherocks.com/2016/07/why-intent-not-gross-negli...

> Even though the plain language of the statute reads “gross negligence,” the Supreme Court has essentially rewritten the statue to require intent to sustain a conviction.

https://law.stackexchange.com/questions/11432/why-might-titl...

Re: When Trump Phones Friends, the Chinese and the Russians Listen and Learn

#96
post #91

Earlier quoted context omitted.

For backed up data to carry a piece of malware, they'd have to exploit a zero-day bug in iOS or in the associated app. That's possible in theory, but those have been rare, and once iOS or the app gets fixed, the exploit in the data is neutralized. Looking at a list of known iOS malware [1] I don't offhand see any tools that manage to install themselves through exploits in non-jailbroken iOS or exploits normal App Sto…

Great summary, thanks! So basically, exploits are possible on extremely high value targets like the president, but apart from that there are basically no malware worried for updated, non-jailbroken iphones. I'd been curious about this since reading about NSO Pegasus and their SMS method. Is this likely in the "zero day, high value target category"? I've never properly seen an explanation of how it's supposed to work.…

Pegasus is listed in that exploit wiki link I posted above and they link to some technical documents about it.

Re: When Trump Phones Friends, the Chinese and the Russians Listen and Learn

#97
post #91

Earlier quoted context omitted.

Great summary, thanks! So basically, exploits are possible on extremely high value targets like the president, but apart from that there are basically no malware worried for updated, non-jailbroken iphones. I'd been curious about this since reading about NSO Pegasus and their SMS method. Is this likely in the "zero day, high value target category"? I've never properly seen an explanation of how it's supposed to work.…

Pegasus is listed in that exploit wiki link I posted above and they link to some technical documents about it.

Oh thanks, so they’re all patched and it only works against older iphones/non-updated iphones.
Post reply on HN