Pegasus spyware found on journalists’ phones, French intelligence confirms
theguardian.com
theguardian.com
Welcome to the future! It's pretty much the same as the past, only more effective.
This is a terribly disturbing comment to me, who cares that they "tend to only target their citizens?"
NSO looms like modern version of mercenaries, selling 'raid and pillage as a service'. It's like spanish conquistadors, kill and steal anything law does not protect.
> moral
Which moral?
The ship already sailed on the whole "ubiquitous gaze" thing.
> We can't have a post-privacy world until we're post-privilege. So when we cave in our autonomy, then we can sort of say, "well, okay, we don't need privacy anymore, in fact we don't have privacy anymore, and I'm okay with that." Realistically though people are not comfortable with that. Because, if you only look at it from a position of privilege, like, say, white man on a stage, then yeah, maybe post-privacy works out okay for those people. But if you have ever not been, or if you are currently not, a white man with a passport from one of the five good nations in the world, it might not really work out well for you, and in fact it might be designed specifically such that it will continue to not work out well for you, because the structures themselves produce these inequalities.
> So when you hear someone talk about post-privacy, I think it's really important to engage them about their own privilege in the system and what it is they are actually arguing for.
-- Jacob Appelbaum, http://www.youtube.com/watch?v=Y3h46EbqhPo&t=7m46s
Right to root, is right to repair.
I'm not convinced any of the folks involved ability to root would prevent the situation described.
The problem in this case is that you get the malware installed through a no-click required iMessage and not a "supply chain" attack on the image your phone is running on. How would that help?
Utilizing different software implementations limits the scope of this type of attack. The current trend to increasing centralization and forced-update monoculture is a huge gift to malware authors: they only have to write one version of their malware to affect everyone.
[1] https://www.schneier.com/blog/archives/2017/01/class_breaks....
In practice we may find a monoculture within a hidden layer of the stack than we're optimizing for, such as an OS kernel method, TLS library or chipset which coincidentally has captured the entire market. When a clever enough exploit on a common resource is found, then the problem transforms to one of coordinating patching for the same, wherein a broad ecosystem of higher level components (like Android or PCs) becomes nearly impossible to thoroughly cover. As such malware authors may potentially still get away with writing a single version of their software so long as they target low-level enough. With sufficient fragmentation they don't even need to invent their own exploits, just use publicly known CVEs that they can brute-force against older devices.
(Not saying you're wrong, your recommendation may still be better in the long-run. We're after all weighing the risk level of black swan events, such as a zero-day on a low level of the stack, or a high level of the stack on a high-volume vendor)
But we were talking about the general case of monoculture, not closed source monoculture. Even for closed source software, where more eyes are prevented from looking "by definition", having a monoculture can in theory allow more code audits to be done, because of economy of scale.
> large number of people using the software doesn't imply there is also a large amount of people reviewing it.
Right, but roughly speaking, the number of reviewers should monotonically increase given an increase in users. Whether that produces better security overall is anyone's guess. My point was just that there was a counteracting force to consider.
The argument is that removing freedoms from owners in the name of security is a false dichotomy because bad actors will still gain the ability to execute arbitrary code whilst owners of devices won't be able to do so.
Also, if I could provide the software I want to run, I'd probably not have iMessage.
Which is all to say, ideally a journalist would have N phones, one per source. But that's impractical.
1. the vulnerability wasn't FOSS. It was kept under wraps because otherwise it would get discovered and apple would patch it
2. what makes you think that amateurs working in their free time can patch 0days faster than the vendors themselves?
I think I'd like to check my iPhone, but I can't reliably do that.
So that, for a start, would help.
but you can, via itunes backup.
Maybe in 1995 it was like that, it's not now.
For example, do public eyes actually catch and did more Linux bugs than three letter agencies? And would this situation be worse if Linux were a very well funded, closed source Windows?
I’m ignorant on whether the open source security mantra is founded upon religion or evidence.
> For example, do public eyes actually catch and did more Linux bugs than three letter agencies?
Is it so important, who found a bug? TLA can find a bug, and then it has a choice: TLA can use it to spy on other countries, or TLA can fix it to protect their own country.
Your TLA may choose to leave your country unprotected, but it is the problem of your country.
I bet you, that image will be provided by the trustworthy people from NSO, free of charge or at a price! Whatever makes you trust their image.
IMHO devices should be root-able but with high barriers of entry, something like soldering should be involved. If you are after doing something that you don't understand but a stranger on the internet told you to do it you shouldn't be able to do it.
I just want to remind you that quite recently a few police agencies come together, built a "secure messaging app", fed it to the criminals and tracked all their communication until gather enough information to take down their entire operation.[0]
Or the time when CIA run a Swiss encryption company[1]
Nobody would be installing a Linux kernel and use the phone like that, they would be installing a distro. There are so many vectors of attack, the person who puts the distro together doesn't need to have malicious intent, the supply chain could be compromised.
Unfortunately, the only way to secure my phone because it no longer receives updates is through rooting, but this phone is not a model that can be rooted so my plan is to buy a new phone and root that, and probably remove all text messaging apps or find a way to sandbox them in a secure environment.
Smartphone landscape of software is a huge failure aside from monetization of apps and user data.
What? how's that possible?
Or at least often not by law, there are some stupid laws around WiFi/broadband etc. which can be interpreted to state that it's not allowed for a phone to be sold which can be rooted (without a hack) as the user could use it to setup a WiFi hot-spot which uses non-legal frequencies. This law was made because supposedly that (with routers) is a problem, except it isn't as far as I know and it as pure lobby work from a certain industry which also loves the user to be forced to use their routers.
(PS: Also country dependent.)
But on the larger point: I agree there should be an option for suers to replace firmware and become root. But limiting root access makes work for Pegasus and others harder, which is good.
It's not enough to "make it harder", to actually know whether it's a useful mitigation you would have to compare how much harder it makes it compared to what inconvenience it caused for that. Pegasus has no problem getting root right now. I strongly suspect they have a built up hoard of 0-days to apply in case the current faorite technique is patched (how else could you make a business out of it? If you're running a business you can't allow some other party to control your main product).
So, how much does limiting root access hurt Pegasus? Very little, IMO. A case could be made that it helps them, in the same way that excessive regulation helps large companies, which already have resources and experience dealing with it that smaller companies must overcome to enter the market. Pegasus, and the ability to hack into phones on-demand, may have been largely hidden from the public because it was relegated to a few large players.
And what does everyone get for this? Vendor lock-in, higher prices, less control over your own devices.
"Technical Analysis of Pegasus Spyware"
https://info.lookout.com/rs/051-ESQ-475/images/lookout-pegas...
"Pegasus Spyware"
https://en.wikipedia.org/wiki/Pegasus_(spyware)
"The Million Dollar Dissident"
https://citizenlab.ca/2016/08/million-dollar-dissident-iphon...
I know it's very hard but could the browsers be improved so that something like this is virtually impossible?
https://www.amnesty.org/en/latest/research/2021/07/forensic-...
It's the same distance as changing <Freedom> to <Dictator> ;=)
EDIT: Yes I miscalculated, I overlooked the r.
People are really getting fed up with being lied to on a constant, grand scale.
https://github.com/AmnestyTech/investigations/issues/11
If anyone can help on that front it'd be much appreciated.
https://www.nolo.com/legal-encyclopedia/types-databases-that...
In the same sense, recipes are not copyrightable. The thought that goes into composing them may be creative, but the list of ingredients itself is not subject to copyright.
I'm very noob wrt firmware and rootkits and even CPU microcode. My understanding is some kind of factory reset is no longer feasible. And certainly no longer verifiable.
--
Ages ago, I proposed that electronic voting machines (tabulators) boot from CD-ROM. Device's ROM would only have bare minimum boot loader. Imagine some super minimal embedded controller, zero unnecessary features. Mount a CD, run the optical scanner, a few buttons, 2 line LCD panel, dot matrix printer.
Assume 2000s best practices election administration. Scantron style ballots, precinct-based poll sites, tabulation occurs the moment polls close, tabulated results posted publicly.
These CD-ROMs would then by secured, as much as possible, thru physical chain of custody. Just like all other election artifacts. They'd also contain snapshot of entire source and toolchain and election data, so any one could inspect them, reproduce the builds, verify the dataset, etc.
My jurisdiction had 100s of poll sites. Instead of programming each ballot scanner, they'd burn CD-ROMs.
Any way.
I mention this because I think such simplistic view of secured computing is no longer feasible. And to consider all the things we'd have to give up to return such a world.
Could I put a phone's entire dev stack onto some WORM media and then reimage the device? What would that even look like?
Instead of blaming the victims of pegasus, we should focus our attention on the lack of actions from key policymakers and regulatory bodies. It is not possible for every individual to be a technical expert when it comes to malware removal, but we can reduce the likelihood of misusing surveillance software by creating an ethical framework around it, backed by nations that value freedom and democracy.
Nope! It's not even clear if Pegasus and its employees broke any laws. (Though I would love to see CFAA and copyright law tested against this.) Optimistically, this might be the wake-up call to change that.
Even if they are found guilty, policy makers have noticed that this too hasn't any effect at all. They just need to craft an exception et voilà it is allegedly legal.
Is it that nobody is filing these or just that the revelations are too new and that the lawyers are just beginning to spin up?
1. If NSO enjoy the tacit support of the Israeli government, then they are effectively judgement proof, no different to crimeware businesses that enjoy the tacit support of the Russian government.
2. Major Western governments such as the US will support the Israeli government for "bigger picture" reasons, and potentially implicitly the NSO. Particularly if the NSO are "only" facilitating the torture and murder of journalists who upset the Saudi government. So again, whatever national laws or international agreements may be in place don't really matter. Much as you'll never see a Blackwater mercenary in front of the war crimes tribunal in the Hague, you'll never see the NSO charged anywhere.
3. More broadly, there have been solid international frameworks for cracking down on, for example, money laundering. The AMLAT treaties are quite effective for money laundering, not so much for finance of terrorism. No nation outside of Canada has designated ISIS-like organisations as terrorists, subject to finance controls, for example. Trying to get an effective, multilateral agreement on how to handle tools that many governments want cheap access to in order to attack their enemies will be quite the challenge.
Forget regulatory compliance, we didn't get safe http traffic or disk encryption by listening to policy makers. That isn't a general indictment, they just are too slow and their motivation is compromised on the topic of surveillance.
They're knowingly selling to untrustworthy organizations knowing they'll be used for criminal purposes. They're criminals, and should be treated as such.
I also wonder if there was something like that when windows mobile was on the market.