Earlier quoted context omitted.
That article is seven years old and in no way reflects current reality. In fact it has never reflected my own experience or that of anyone I know, where iMessage spam has been near enough to non-existent. And even if there were a spam problem, the risk is mostly on the upside anyway. It would only be an issue if iMessage got a reputation for flooding people with admonishments to take security seriously, purportedly f…
Meanwhile apple has added iMessage apps[1], that you can add to your iMessage and there recently were a few iMessage exploits including a zero-click one[2]. [1] https://support.apple.com/en-us/HT206906 [2] https://9to5mac.com/2021/07/19/zero-click-imessage-exploit/
Apple will notify users about state-sponsored cybersecurity threats
91–100 of 166 posts
Re: Apple will notify users about state-sponsored cybersecurity threats
#92I know of one case of a Polish prosecutor who does not obey (do not want to bend the law) Zbigniew Ziobro, who is both the minister of justice and the prosecutor general. She received a notification from Apple just today. Source: https://mobile.twitter.com/e_wrzosek/status/1463551631648251...
Is it concerning to any security people with more knowledge than me that this is sent via iMessage?!
Re: Apple will notify users about state-sponsored cybersecurity threats
#93I know of one case of a Polish prosecutor who does not obey (do not want to bend the law) Zbigniew Ziobro, who is both the minister of justice and the prosecutor general. She received a notification from Apple just today. Source: https://mobile.twitter.com/e_wrzosek/status/1463551631648251...
I think you need to add a translation of the tweet. Because it sounds as if he didn't obey Apple's warning. Yet I think he approves of Apple's s notification. It is the government who he wasn't obeying? So the government installed the spyware?
Re: Apple will notify users about state-sponsored cybersecurity threats
#94Edit : silly me, US doesn’t need that, they can simply ask for the data..
Re: Apple will notify users about state-sponsored cybersecurity threats
#95So something like PRISM that targets everybody won't trigger a warning?
I don't see how Google could have been aware that this was happening, although they certainly could have known it was theoretically possible.
Re: Apple will notify users about state-sponsored cybersecurity threats
#96I see a lot of pessimism in the comments. But I think this is a great step in the right direction. Other companies should take note. More of this, please!
Google does this for some time at least. I received an imminent advanced security threat notification back in January 2019. Urging me to get one of those 2fa dongles (which I did). And just as well, because the next month my account was locked due to an attempted unathorized access. (whoever works on this at Google, thank you)
Re: Apple will notify users about state-sponsored cybersecurity threats
#97Earlier quoted context omitted.
You shouldn't argue with @smoldesu, he has a history of trying to troll and spread FUD about Apple at every possible opportunity, even on completely unrelated topics. It's so ridiculous, a complaint about it is the #1 result on Google if you type "smoldesu" in. They also are not typically the most factual of complaints but they aren't interested in corrections. Beats me why the mods haven't sent warnings.
Thank you for your crack forensic work, this guy seems like a really reprehensible character, it's a wonder that his throwaway troll account has accrued so much karma and even regularly commented on a variety of topics to avoid arousing suspicion. After some more OSINT (open source intelligence for my fellow Redditors out there) we even discovered that he had accounts on other sites, where he also espoused original o…
”Please stop posting these long-winded [hate] essays every couple days. It would be one thing if this was [Reddit], but the slimyness and dishonesty here is yet another brick in the wall of non-fungible sketchiness.”
A reminder to you that it is against Hacker News rules to do any ideological warfare, “trolling”, or bad-faith commentary.
Re: Apple will notify users about state-sponsored cybersecurity threats
#98Earlier quoted context omitted.
Thank you for your crack forensic work, this guy seems like a really reprehensible character, it's a wonder that his throwaway troll account has accrued so much karma and even regularly commented on a variety of topics to avoid arousing suspicion. After some more OSINT (open source intelligence for my fellow Redditors out there) we even discovered that he had accounts on other sites, where he also espoused original o…
Let me paraphrase your own quote: ”Please stop posting these long-winded [hate] essays every couple days. It would be one thing if this was [Reddit], but the slimyness and dishonesty here is yet another brick in the wall of non-fungible sketchiness.” A reminder to you that it is against Hacker News rules to do any ideological warfare, “trolling”, or bad-faith commentary.
Re: Apple will notify users about state-sponsored cybersecurity threats
#99Earlier quoted context omitted.
Is it concerning to any security people with more knowledge than me that this is sent via iMessage?!
iMessage is extremely secure and utilizes end-to-end encryption, why is this concerning to you?
Also imagine another bug that allows someone to spoof the 'from' or hell even send a message that looks similar, basic phishing.
Like: This is apple. Click this link to secure your account you are being hacked (literally). Seems like a bad precedent. But I guess there isn't a great way to securely communicate. Maybe just say google the official apple 1800 number and enter this secret number pad code.
Re: Apple will notify users about state-sponsored cybersecurity threats
#100So something like PRISM that targets everybody won't trigger a warning?
I doubt it. Keep in mind this will only work for non-court-gag-ordered instances. If the US subpoenas Apple about an individual they won't be allowed to notify them. I have no idea how this applies to other countries. I think this is more like: "We noticed unusual API usage and we don't have a gag order so whatever it is, it's not likely to be good"
Apple doesn’t need to know the source of the attack to issue the warning, and if the attacker is competent Apple likely wouldn’t know the source, such that a gag would not apply.