Live data from Hacker News

iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

appleinsider.com

1–10 of 177 posts

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#2
This coupled along with the fact that iMessage's E2EE has been backdoored by the non-E2EE iCloud Backup key escrow is a good argument for leaving iMessage, FaceTime, and iCloud all turned off on a device.

I go one step further and leave the SIM card out, which means the SMS vulnerability path is closed too.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#3
post #2

This coupled along with the fact that iMessage's E2EE has been backdoored by the non-E2EE iCloud Backup key escrow is a good argument for leaving iMessage, FaceTime, and iCloud all turned off on a device. I go one step further and leave the SIM card out, which means the SMS vulnerability path is closed too.

Then you could just as well get a iPod touch or iPad mini.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#4
post #2

This coupled along with the fact that iMessage's E2EE has been backdoored by the non-E2EE iCloud Backup key escrow is a good argument for leaving iMessage, FaceTime, and iCloud all turned off on a device. I go one step further and leave the SIM card out, which means the SMS vulnerability path is closed too.

But then you are using SMS, which your cell carrier can absolutely see and intercept because it's decrypted.

So in either case... turn off native messaging and use Signal or something if you are paranoid. You aren't really using the "phone" part anymore, so buy an iPod touch or something.

Also, iMessage is fully E2E if you disable iCloud Backup. Which can easily do in Settings.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#5
post #3
post #2

This coupled along with the fact that iMessage's E2EE has been backdoored by the non-E2EE iCloud Backup key escrow is a good argument for leaving iMessage, FaceTime, and iCloud all turned off on a device. I go one step further and leave the SIM card out, which means the SMS vulnerability path is closed too.

Then you could just as well get a iPod touch or iPad mini.

Neither of those has a vibrate motor to let me know about notifications. They also can't be used to pair to an Apple Watch.

I know this because I used to carry an iPad Mini in my pants pocket.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#6
post #2

This coupled along with the fact that iMessage's E2EE has been backdoored by the non-E2EE iCloud Backup key escrow is a good argument for leaving iMessage, FaceTime, and iCloud all turned off on a device. I go one step further and leave the SIM card out, which means the SMS vulnerability path is closed too.

Should probably also dig an underground bunker and collect cans of sardines to last for decades.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#7
post #5
post #3

Earlier quoted context omitted.

Then you could just as well get a iPod touch or iPad mini.

Neither of those has a vibrate motor to let me know about notifications. They also can't be used to pair to an Apple Watch. I know this because I used to carry an iPad Mini in my pants pocket.

Then buy an iPhone, and turn off iCloud Backup in Settings, it's not hard to do. Then your iMessages are fully E2E Encrypted.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#8
post #2

This coupled along with the fact that iMessage's E2EE has been backdoored by the non-E2EE iCloud Backup key escrow is a good argument for leaving iMessage, FaceTime, and iCloud all turned off on a device. I go one step further and leave the SIM card out, which means the SMS vulnerability path is closed too.

But then you are using SMS, which your cell carrier can absolutely see and intercept because it's decrypted. So in either case... turn off native messaging and use Signal or something if you are paranoid. You aren't really using the "phone" part anymore, so buy an iPod touch or something. Also, iMessage is fully E2E if you disable iCloud Backup. Which can easily do in Settings.

Please stop using the term "paranoid" to describe those who desire personal privacy.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#9
post #5

Earlier quoted context omitted.

Neither of those has a vibrate motor to let me know about notifications. They also can't be used to pair to an Apple Watch. I know this because I used to carry an iPad Mini in my pants pocket.

Then buy an iPhone, and turn off iCloud Backup in Settings, it's not hard to do. Then your iMessages are fully E2E Encrypted.

Nope, because they get escrowed by the other end of the iMessage conversation.

Also, the whole point of disabling iMessage (in this thread) is to close the iMessage-related zero click exploits described in TFA.

Re: iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

#10
post #8

Earlier quoted context omitted.

But then you are using SMS, which your cell carrier can absolutely see and intercept because it's decrypted. So in either case... turn off native messaging and use Signal or something if you are paranoid. You aren't really using the "phone" part anymore, so buy an iPod touch or something. Also, iMessage is fully E2E if you disable iCloud Backup. Which can easily do in Settings.

Please stop using the term "paranoid" to describe those who desire personal privacy.

There is a degree to where you are actually paranoid though, otherwise we wouldn't have that word.

If you are this paranoid, you shouldn't be carrying an electronic device.

Post reply on HN