But, a hypothetical braver me would then know (from my alternate universe life as a techie) that I can't trust any of my devices much, in any case, no matter how many experts review them or how many burners I cycle, and that I should use the devices accordingly.
EDIT: Is it just a matter of there being easier/cheaper vectors?
Also, phrasing.
Most modern smartphones use usb for baseband comms. I’m no expert but I don’t think the DMA thing hasn’t been true widely for a very long time.
I certainly was still under the impression that phones were a crapshoot of vulnerabilities especially outside the iphone.
This is a real problem, that smart people don't know how to keep their stuff secure.
I'd like to know why it isn't. A rootkit doesn't necessarily need access to every ring of a system, just enough to compromise it .
Is there some reason that you seem to be purposely vague when speaking about basebands in these kind of threads? ( https://news.ycombinator.com/item?id=10906188 )
The baseband may not have as much authority as some purport, but it's still a subsystem with it's own code and purpose -- and (like any other subsystem), a villain could theoretically use this to their advantage in all sorts of imaginable ways.
(tl;dr : DMA isn't needed to be evil. It's just nice.)
If I were Apple, I'd give journalists all the "disposable" iPhones they need to swap them frequently for free.
My only condition would be to periodically inspect them for hacking activity, or have them specially instrumented to detect it. It would be a good way to ferret out state-actor zero days (or increase the security of the platform by making state-actors horde exploits even more jealously).
Apple could do it practically for free too, if it was something like "Any accredited journalist can trade their iPhone for a refurb at any Apple store at any time. We'd appreciate, but not require, some information about the general areas of stories you cover and any threats you're suspicious might be focused on you."
Also, this comment isn't intended to touch the question of Apple's trustworthiness so please don't wave downvote over that, I am merely stating that such a system would _really_ motivate three-letters to put an immense amount of pressure into compromising such a system (whether they did so with or without Apple's co-operation can remain untouched).
EDIT: What's to stop Mr. Greenwald from sending a buddy from an old job to swap a new device on his behalf?
I misread the original proposal a bit and had assumed it'd be a mail-in-service, but with even determination the three-letter folks could probably leave spiked devices in the stores glenn would be likely to walk into. This is more reasonable but I still have reservations.
It's not like _any_ journalist would trust this service at an Apple Store in Saudi Arabia, and probably not the UAE, Oman, or Qatar either. (Or may other countries.)
Being "not a perfect and universal solution" doesn't make it worthless. Snowden isn't about to stroll into Apple Store Moscow to take advantage of a refurbed iPhone. I suspect things would be different if Omar Abdulaziz could have dropped into Apple Store Toronto and swapped his Pegasus-infected phone over...
On the other hand - you've now identified the phones for remote exploit. Also identifying which journalists are significant enough to be beneficiaries of this program is probably hard.
As far as I can tell, "journalist accreditation" has no objective meaning and is determined on an organization-by-organization basis using subjective standards. Here is the list of criteria the UN uses: https://www.un.org/en/media/accreditation/request.shtml
At first glance, Greenwald would seem to qualify by that standard, provided whoever was judging him were reasonable (by my personal standards) in judging criteria such as whether The Intercept is a "recognized media organization." However I also notice that some of the criteria listed on the page seem very restrictive and could quite possibly disqualify a lot of investigative journalists (requiring six publications per year, when that investigative journalist may be working on serious stories that take more time than that...)
I wonder if Jamal Khashoggi and Omar Abdulaziz would evaluate (or "have evaluated", in the case of Jamal) the risk of "TLA's who have the power to coerce Apple" vs "Saudi Security and Royal Family"?
You are right, in that this is adding an extra organisation you need to trust (although if you're carrying an iPhone you've already surrendered a significant amount of trust to Apple and their ability to resist TLAs).
A possible workaround might be to make the bar of "accredited journalists" super low (perhaps "anyone who's ever had a published byline in anything accepted as an original source by Wikipedia", and push it super publicly, so pretty much every journalist from cutting edge human rights activist/journalists down to the cub reporter on University newspapers is swapping their phone for refurbs every 3 months...
Not saying it’s super practical but definitely a failure point.
Not necessarily, the journalist could go to a random store and the process could be setup as an exception to a normal purchase flow, so the journalist only needs to identify themselves after the phone has been removed from stock (and any effort to swap it would be super suspicious).
You missed a key point.
Having a turned employee is only helpful if the person you're targeting goes to that person, but the whole point of the process I outlined was to make it too difficult to predict or control which employee the targeted person would interact with, which makes turning employees impractical (since you'd have to turn so many to have a reasonable chance of success that you'd probably just reveal your attack instead).
Cheap semi-disposable laptop + trustworthy encryption (edit: Probably with OpenBSD as the OS) is the best you can do, and if I don't have encryption I trust for the task at hand a wired network.
It's unfortunate that wireless networks apparently uniformly have terrible encryption and poor security. There is no fundamental reason this needs to be the case.
I'm not sure anyone will burn a no interaction zero day on a human rights journalist. I suspect that kind of thing is hoarded by the big boys for when life and limb are on the line.
> The attacks utilized a cyber weapon called Karma. As Reuters reported in January, Karma allowed Raven operatives to remotely hack into iPhones by inputting a target’s phone number or associated email address into the attack software. Unlike many exploits, Karma did not require a target to click on a link sent to an iPhone, they said. Apple declined to comment.
I'm surprised it's still circulating then, it sounds like a very serious bug. It's still not known? (No CVE?)
There have been multiple reports of no interaction zero days used on journalists, including in the article above. Turns out, authoritarian governments really hate journalists who aren't sympathetic toward their regimes.
For example, switching to a dumbphone makes them likely to be more insecure, since they usually operate on 2 or 3g and offer zero encryption.