Live data from Hacker News

Apple will notify users about state-sponsored cybersecurity threats

support.apple.com

91–100 of 166 posts

Re: Apple will notify users about state-sponsored cybersecurity threats

#91

Earlier quoted context omitted.

That article is seven years old and in no way reflects current reality. In fact it has never reflected my own experience or that of anyone I know, where iMessage spam has been near enough to non-existent. And even if there were a spam problem, the risk is mostly on the upside anyway. It would only be an issue if iMessage got a reputation for flooding people with admonishments to take security seriously, purportedly f…

Meanwhile apple has added iMessage apps[1], that you can add to your iMessage and there recently were a few iMessage exploits including a zero-click one[2]. [1] https://support.apple.com/en-us/HT206906 [2] https://9to5mac.com/2021/07/19/zero-click-imessage-exploit/

I think you have replied to the wrong person, otherwise I fail to see how either of these citations are in any way relevant.

Re: Apple will notify users about state-sponsored cybersecurity threats

#92
post #22

I know of one case of a Polish prosecutor who does not obey (do not want to bend the law) Zbigniew Ziobro, who is both the minister of justice and the prosecutor general. She received a notification from Apple just today. Source: https://mobile.twitter.com/e_wrzosek/status/1463551631648251...

Is it concerning to any security people with more knowledge than me that this is sent via iMessage?!

The transport is secure, but if an attacker has already found their way into the device, they can intercept notifications/iMessages and remove it automatically anyway, so yes it's a bit or concern. But at that point, anything will be concerning, not only iMessage.

Re: Apple will notify users about state-sponsored cybersecurity threats

#93
post #43
post #22

I know of one case of a Polish prosecutor who does not obey (do not want to bend the law) Zbigniew Ziobro, who is both the minister of justice and the prosecutor general. She received a notification from Apple just today. Source: https://mobile.twitter.com/e_wrzosek/status/1463551631648251...

I think you need to add a translation of the tweet. Because it sounds as if he didn't obey Apple's warning. Yet I think he approves of Apple's s notification. It is the government who he wasn't obeying? So the government installed the spyware?

It is like polish Watergate: the prosecutor has been criticizing minister Ziobro and already lost her job (not only her, this problem is now on EU table and European trials say polish gov is breaking the law doing this) and now she learned minister Ziobro was spying her (and probably is still doing this)

Re: Apple will notify users about state-sponsored cybersecurity threats

#95

So something like PRISM that targets everybody won't trigger a warning?

In the case of Google, the NSA was reading their unencrypted replication traffic as it moved between data centers.

I don't see how Google could have been aware that this was happening, although they certainly could have known it was theoretically possible.

Re: Apple will notify users about state-sponsored cybersecurity threats

#96
post #23
post #15

I see a lot of pessimism in the comments. But I think this is a great step in the right direction. Other companies should take note. More of this, please!

Google does this for some time at least. I received an imminent advanced security threat notification back in January 2019. Urging me to get one of those 2fa dongles (which I did). And just as well, because the next month my account was locked due to an attempted unathorized access. (whoever works on this at Google, thank you)

The Google warning page can be viewed by anyone, but they do specifically tell targeted individuals through other channels (a big red warning message at the top of Gmail, for example): https://myaccount.google.com/stateattackwarning

Re: Apple will notify users about state-sponsored cybersecurity threats

#97

Earlier quoted context omitted.

You shouldn't argue with @smoldesu, he has a history of trying to troll and spread FUD about Apple at every possible opportunity, even on completely unrelated topics. It's so ridiculous, a complaint about it is the #1 result on Google if you type "smoldesu" in. They also are not typically the most factual of complaints but they aren't interested in corrections. Beats me why the mods haven't sent warnings.

Thank you for your crack forensic work, this guy seems like a really reprehensible character, it's a wonder that his throwaway troll account has accrued so much karma and even regularly commented on a variety of topics to avoid arousing suspicion. After some more OSINT (open source intelligence for my fellow Redditors out there) we even discovered that he had accounts on other sites, where he also espoused original o…

Let me paraphrase your own quote:

”Please stop posting these long-winded [hate] essays every couple days. It would be one thing if this was [Reddit], but the slimyness and dishonesty here is yet another brick in the wall of non-fungible sketchiness.”

A reminder to you that it is against Hacker News rules to do any ideological warfare, “trolling”, or bad-faith commentary.

Re: Apple will notify users about state-sponsored cybersecurity threats

#98

Earlier quoted context omitted.

Thank you for your crack forensic work, this guy seems like a really reprehensible character, it's a wonder that his throwaway troll account has accrued so much karma and even regularly commented on a variety of topics to avoid arousing suspicion. After some more OSINT (open source intelligence for my fellow Redditors out there) we even discovered that he had accounts on other sites, where he also espoused original o…

Let me paraphrase your own quote: ”Please stop posting these long-winded [hate] essays every couple days. It would be one thing if this was [Reddit], but the slimyness and dishonesty here is yet another brick in the wall of non-fungible sketchiness.” A reminder to you that it is against Hacker News rules to do any ideological warfare, “trolling”, or bad-faith commentary.

[deleted]

Re: Apple will notify users about state-sponsored cybersecurity threats

#99
post #73

Earlier quoted context omitted.

Is it concerning to any security people with more knowledge than me that this is sent via iMessage?!

iMessage is extremely secure and utilizes end-to-end encryption, why is this concerning to you?

because the KSA hack was supposedly an iMessage zero door? And others allegedly don't even need to be clicked/opened.

Also imagine another bug that allows someone to spoof the 'from' or hell even send a message that looks similar, basic phishing.

Like: This is apple. Click this link to secure your account you are being hacked (literally). Seems like a bad precedent. But I guess there isn't a great way to securely communicate. Maybe just say google the official apple 1800 number and enter this secret number pad code.

Re: Apple will notify users about state-sponsored cybersecurity threats

#100

So something like PRISM that targets everybody won't trigger a warning?

I doubt it. Keep in mind this will only work for non-court-gag-ordered instances. If the US subpoenas Apple about an individual they won't be allowed to notify them. I have no idea how this applies to other countries. I think this is more like: "We noticed unusual API usage and we don't have a gag order so whatever it is, it's not likely to be good"

The methods of detecting such attacks are not at all similar to a government requesting data which contains the non disclosure clause.

Apple doesn’t need to know the source of the attack to issue the warning, and if the attacker is competent Apple likely wouldn’t know the source, such that a gag would not apply.

Post reply on HN