Live data from Hacker News

iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

appleinsider.com

91–100 of 177 posts

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#91
post #24

Earlier quoted context omitted.

No, that's not what paranoid means. Your statement is simply incorrect and your use of the word is derogatory.

Only if you say so. There is a degree of rational fear, rational expectation of being tracked. Your degree of fear though is irrational unless you are, in fact, a journalist in an authoritarian state. You are saying that you are so paranoid, you don't trust iMessage to be End-to-End Encrypted because it has zero-click exploits developed as part of a cyberweapon that is explicitly targeted against high-profile journal…

> Your degree of fear though is irrational unless you are, in fact, a journalist in an authoritarian state.

You are putting words in OP's mouth. OP never said he was fearful, only that he didn't want to be tracked.

Someone friendly could follow me around in real life and watch what I'm doing - and keep suggesting products to me based on getting to know me. I'm not going to be afraid but I am going to be freaking annoyed, and feel like my privacy is violated when he says he isn't going away.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#92
post #74

Earlier quoted context omitted.

Only if you say so. There is a degree of rational fear, rational expectation of being tracked. Your degree of fear though is irrational unless you are, in fact, a journalist in an authoritarian state. You are saying that you are so paranoid, you don't trust iMessage to be End-to-End Encrypted because it has zero-click exploits developed as part of a cyberweapon that is explicitly targeted against high-profile journal…

No, he is right that you are using bad words because you disagree. I wouldn't have added this but the thread just keeps going. Just because someone want to be as secure as possible while using their electronic devices and you think they are being extreme doesn't mean that they are being paranoid. It has nothing to do with being paranoid. It could simply be because it is fun to try and secure your devices or to gather…

> It could simply be because it is fun to try and secure your devices or to gather knowledge on how to do so

It could be the case, absolutely. But the OP doesn't sound like their having fun, they are in earnest.

> do not trust for a second that iMessage is securely E2EE

Ask a security expert, and they will tell you it has been verified by just about everyone who has inspected it that this is, in fact, the case, including the EFF. But it is proprietary code, not open, which is a downfall.

> are saved unencrypted to iCloud

And can be turned off with the flip of a switch in Settings if that's something you are worried about. For most people who aren't OP-sec (like my Grandma), having all of her messages deleted because someone stole her phone isn't worth it.

> "buggy parsing on data that strangers push to your phone?!"

Yes... Except that every other secure messenger also does the exact same thing. And they don't have BlastDoor sandboxing like iMessage does. Yes, BlastDoor has flaws, but at least it's there unlike other messengers which don't sandbox.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#93
post #27

Earlier quoted context omitted.

Snapchat claims to be end to end encrypted, last I looked. Signal does not escrow endpoint keys in an iCloud Backup, so your first statement is incorrect.

This is false. Snapchat has "snaps" protected, but text messages and group messages are not end to end encrypted. Also, Signal putting your escrow keys in iCloud? I don't think you know what you are talking about. You can set iMessage to not put your keys in iCloud like I said above by turning off iCloud Backup which makes it fully End-to-End with your own key on your device, just like Signal. If you are worried abou…

>You can set iMessage to not put your keys in iCloud like I said above by turning off iCloud Backup which makes it fully End-to-End

"Fully" smells like a weasel word here. Either it is E2EE or it isn't. iMesssage isn't by default from what you are saying and if it requires the other end to also turn off icloud backup before it is E2EE then I'd go as far as stating that it is a completely useless attempt to be E2EE. In fact I'd argue Apple is full of sh*t if they actually ever stared that it is E2EE (but I have no idea if they did).

Comparing Signal to such a mess is... well at a minimum it is disingenuous.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#94

Earlier quoted context omitted.

Only if you say so. There is a degree of rational fear, rational expectation of being tracked. Your degree of fear though is irrational unless you are, in fact, a journalist in an authoritarian state. You are saying that you are so paranoid, you don't trust iMessage to be End-to-End Encrypted because it has zero-click exploits developed as part of a cyberweapon that is explicitly targeted against high-profile journal…

That's absolutely not paranoia, so I'd suggest you leave GP alone instead of burning karma and making yourself look like a fool.

Name-calling and blind assertions ("it's not because it's not!") is not a good-faith response.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#95

I dated a journalist once. She used some random free app for phone calls because recording calls isn't built into iOS and she needed to record calls. I suggested a small device for her to plug her headphones through, but she declined. I'm sure there's a few journalists out there that take cybersecurity seriously, but I'd wager the vast majority are pretty trivially monitored.

But it also depends on what kind of journalism they're doing, right? Not all report on criminal activity, or on investigating the government. It's kinda like threat-models, no need to be super secure if your work brings no risks to you, your organisation, or those you come in contact with.

You can get to the criminal activity or government investigation journalists through the more "trivial" journalists if they work in the same company.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#96
post #28

I dated a journalist once. She used some random free app for phone calls because recording calls isn't built into iOS and she needed to record calls. I suggested a small device for her to plug her headphones through, but she declined. I'm sure there's a few journalists out there that take cybersecurity seriously, but I'd wager the vast majority are pretty trivially monitored.

Apple really doesn't help them. the marketing (lying) that iOS is secure is pretty intense.

>the marketing (lying) that iOS is secure is pretty intense.

I don't see how it's lying. If you are going to consider that iOS is not secure because they got owned by a couple 0 days, then by that definition there isn't a secure piece of software on the planet.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#97
post #71

Earlier quoted context omitted.

To be fair it's probably the most secure environment for the average Joe, you're just saying that it's not perfectly secure, which would be impossible in this world.

You could do far better than iOS. Worse though is that it encourages very poor infosec because when it's profitable for Apple and often makes doing things correctly difficult or impossible.

I suppose you have examples to propose?

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#98
post #80

Earlier quoted context omitted.

The other end of the conversation escrows the key on any messenger. Otherwise how would you read the message? Unless you consider Snapchat, but that's not End to End Encrypted. And are you really sure that Signal or your preferred messengers don't also have Zero-Click exploits? After all, they aren't sandboxed to the degree iMessage is with BlastDoor.

>"BlastDoor is a great step, to be sure, but it's pretty lame to just slap sandboxing on iMessage and hope for the best. How about: "don't automatically run extremely complex and buggy parsing on data that strangers push to your phone?!" https://twitter.com/billmarczak/status/1416801514685796352

Except that almost every other secure messenger is guilty of the same thing. And they don't sandbox at all, whereas BlastDoor at least tries to.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#99

Apple needs to make it possible for users to choose other ways of sending and receiving messages and listening to music, or of choosing not to do either of those things if they don't want to. Obviously, you can currently install and use other applications that provide the same functionality, but you cannot uninstall or disable defaults. The most shocking experience to me in trying to evaluate the Mac ecosystem when t…

>where I'm using bluetooth headphones, take the headphones off and put them back on, and music.app automatically opens and comes to the foreground of my desktop

I think your bluetooth headphones are sending a play command to your device when it's connected. I'm sure it's annoying, but I think your macbook is doing the right thing here.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#100
post #89

Earlier quoted context omitted.

There is no such thing as a "truly-secure option." As anyone truly concerned about security will tell you. You will be forced to make compromises somewhere unless you want to live under a rock in the desert. You can't drive without a State ID, can't get a home loan without credit, can't work without a Social Security Number except under limited circumstances, can't make money without reporting to the IRS, and so on.…

> can't work without a Social Security Number except under limited circumstances Something like 96% of human beings don't have a social security number. Many of them work.

Like the nation you live in doesn't have its own Tax Authority with information on you, and doesn't have its own ID Number you need to use for working.

The technicals are different, the point is the same.

Post reply on HN