Live data from Hacker News

Pegasus spyware found on journalists’ phones, French intelligence confirms

theguardian.com

91–100 of 101 posts

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#91

Is there no regulatory or compliance requirements for surveillance software? Instead of blaming the victims of pegasus, we should focus our attention on the lack of actions from key policymakers and regulatory bodies. It is not possible for every individual to be a technical expert when it comes to malware removal, but we can reduce the likelihood of misusing surveillance software by creating an ethical framework aro…

Not having your system locked down would be the first problem that needs solving if you want to combat malware.

Forget regulatory compliance, we didn't get safe http traffic or disk encryption by listening to policy makers. That isn't a general indictment, they just are too slow and their motivation is compromised on the topic of surveillance.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#92

Is there no regulatory or compliance requirements for surveillance software? Instead of blaming the victims of pegasus, we should focus our attention on the lack of actions from key policymakers and regulatory bodies. It is not possible for every individual to be a technical expert when it comes to malware removal, but we can reduce the likelihood of misusing surveillance software by creating an ethical framework aro…

> Is there no regulatory or compliance requirements for surveillance software? Nope! It's not even clear if Pegasus and its employees broke any laws. (Though I would love to see CFAA and copyright law tested against this.) Optimistically, this might be the wake-up call to change that.

We have a lot of laws against dragnet surveillance. They didn't help at all as there is no consequence of breaking them.

Even if they are found guilty, policy makers have noticed that this too hasn't any effect at all. They just need to craft an exception et voilà it is allegedly legal.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#93

Earlier quoted context omitted.

It's pretty much what we have in China now.

To the positive spin for China, they tend to target only their fellow citizens and have some internal coherency and moral. NSO is an Israeli national problem that sells the spying capabilities to the highest bidding crook dictator around the world.

> positive spin for China

> moral

Which moral?

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#94
post #79

Earlier quoted context omitted.

No, but when they appear, _you can fix them_.

Are there actual hard numbers on whether open-to-all-eyes is beneficial at all scales? For example, do public eyes actually catch and did more Linux bugs than three letter agencies? And would this situation be worse if Linux were a very well funded, closed source Windows? I’m ignorant on whether the open source security mantra is founded upon religion or evidence.

Although they do contribute, believing three letter agencies wouldn't try to leave backdoors is certainly the former.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#95
How would I factory reset and then cold boot my phone?

I'm very noob wrt firmware and rootkits and even CPU microcode. My understanding is some kind of factory reset is no longer feasible. And certainly no longer verifiable.

--

Ages ago, I proposed that electronic voting machines (tabulators) boot from CD-ROM. Device's ROM would only have bare minimum boot loader. Imagine some super minimal embedded controller, zero unnecessary features. Mount a CD, run the optical scanner, a few buttons, 2 line LCD panel, dot matrix printer.

Assume 2000s best practices election administration. Scantron style ballots, precinct-based poll sites, tabulation occurs the moment polls close, tabulated results posted publicly.

These CD-ROMs would then by secured, as much as possible, thru physical chain of custody. Just like all other election artifacts. They'd also contain snapshot of entire source and toolchain and election data, so any one could inspect them, reproduce the builds, verify the dataset, etc.

My jurisdiction had 100s of poll sites. Instead of programming each ballot scanner, they'd burn CD-ROMs.

Any way.

I mention this because I think such simplistic view of secured computing is no longer feasible. And to consider all the things we'd have to give up to return such a world.

Could I put a phone's entire dev stack onto some WORM media and then reimage the device? What would that even look like?

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#96

How would I factory reset and then cold boot my phone? I'm very noob wrt firmware and rootkits and even CPU microcode. My understanding is some kind of factory reset is no longer feasible. And certainly no longer verifiable. -- Ages ago, I proposed that electronic voting machines (tabulators) boot from CD-ROM. Device's ROM would only have bare minimum boot loader. Imagine some super minimal embedded controller, zero…

You can't really be sure about your device, even after a supposed reset. Lenovo, for one, had a way to reinstall its bloat/spyware on its laptops, even after you reinstalled Windows yourself.

https://en.wikipedia.org/wiki/Lenovo#Lenovo_Service_Engine

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#97

Earlier quoted context omitted.

To the positive spin for China, they tend to target only their fellow citizens and have some internal coherency and moral. NSO is an Israeli national problem that sells the spying capabilities to the highest bidding crook dictator around the world.

> To the positive spin for China, they tend to target only their fellow citizens and have some internal coherency and moral. This is a terribly disturbing comment to me, who cares that they "tend to only target their citizens?"

If I had to choose, I'd go with China, at least they believe in something.

NSO looms like modern version of mercenaries, selling 'raid and pillage as a service'. It's like spanish conquistadors, kill and steal anything law does not protect.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#98
post #85
post #79

Earlier quoted context omitted.

Are there actual hard numbers on whether open-to-all-eyes is beneficial at all scales? For example, do public eyes actually catch and did more Linux bugs than three letter agencies? And would this situation be worse if Linux were a very well funded, closed source Windows? I’m ignorant on whether the open source security mantra is founded upon religion or evidence.

Classical FUD. > For example, do public eyes actually catch and did more Linux bugs than three letter agencies? Is it so important, who found a bug? TLA can find a bug, and then it has a choice: TLA can use it to spy on other countries, or TLA can fix it to protect their own country. Your TLA may choose to leave your country unprotected, but it is the problem of your country.

Sorry, not an attempt at FUD. As I wrote, I’m entirely ignorant on whether there is hard evidence one way or another on the topic.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#99
post #58

Earlier quoted context omitted.

>But if that imessage vulnerability was FOSS and you could flash your own image 1. the vulnerability wasn't FOSS. It was kept under wraps because otherwise it would get discovered and apple would patch it 2. what makes you think that amateurs working in their free time can patch 0days faster than the vendors themselves?

Because these "amateurs" build all the essential tools we rely on today. That wasn't Apple. I cannot really believe what crap I have to read here. Vendor lock in is a huge factor for insecurity in software.

Amateurs behind what essential tools? Tell me a tool and a name. I've been thinking hard for 10 minutes and every FOSS tool I used the past week has highly regarded and well payed professionals behind it.

Maybe in 1995 it was like that, it's not now.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#100
post #59
post #56

Earlier quoted context omitted.

A depressing thought experiment a professor once posited many years ago....Hitler comes to power in the internet era and now has state of the art tools to find people of certain traits, vs manpower and spies to discover them. Ability to go through your entire lives digital footprint. Every picture. Every video you've created, or viewed on a website. Every location you've visited, how long you were there, and who was…

We have all that, just without Hitler in power. At least in the US anyway, the government has access, should it become necessary, to a comprehensive catalog of your activities and communications. It's just that they should get a warrant before accessing it, which I'm not naive enough to believe that they do in all cases. The ship already sailed on the whole "ubiquitous gaze" thing.

> I've heard quite a lot of people that talk about post-privacy, and they talk about it in terms of feeling like, you know, it's too late, we're done for, there's just no possibility for privacy left anymore and we just have to get used to it. And this is a pretty fascinating thing, because it seems to me that you never hear a feminist say that we're post-consent because there is rape. And why is that? The reason is that it's bullshit.

> We can't have a post-privacy world until we're post-privilege. So when we cave in our autonomy, then we can sort of say, "well, okay, we don't need privacy anymore, in fact we don't have privacy anymore, and I'm okay with that." Realistically though people are not comfortable with that. Because, if you only look at it from a position of privilege, like, say, white man on a stage, then yeah, maybe post-privacy works out okay for those people. But if you have ever not been, or if you are currently not, a white man with a passport from one of the five good nations in the world, it might not really work out well for you, and in fact it might be designed specifically such that it will continue to not work out well for you, because the structures themselves produce these inequalities.

> So when you hear someone talk about post-privacy, I think it's really important to engage them about their own privilege in the system and what it is they are actually arguing for.

-- Jacob Appelbaum, http://www.youtube.com/watch?v=Y3h46EbqhPo&t=7m46s

Post reply on HN