Pegasus vs. Predator
citizenlab.ca
citizenlab.ca
Any country harboring this scum deserves at best a few month to clean up their backyard and laws before facing sanctions.
Depending on which European countries those are, I suspect a few of them won't even need prodding.
For the people working there it may be wise to quit now, because after today they can hardly deny having knowledge their employer is selling software to repressive regimes which those use to spy on journalists among others.
This is utterly incompatible with democracy, morally bankrupt, and prison sentences are appropriate.
The complexity and level of some of these attacks makes it unlikely that the companies couldn’t get into android devices too, so is it just the prevalence of iOS amongst the targets?
Or is it because Google is more friendly to government information requests that means attacks like this aren’t required?
Or is it because android is genuinely that much more secure? Or something else? Would be genuinely interested to know!
ECONOMY!
Let me explain, because you are probably not thinking about the same thing as I am right now:
Android exists on different CPU architectures (ARM, x86, MIPS, ...) and from hundreds of different vendors. Even a single companys devices can differ slightly in what SoC (qualcomm, Samsung, mediatek, intel, ...) they use and what security functions have been added to the OS core. For example Samsung has additional hardware and software security functions in high-end phones. Google has some security stuff that started as software in early Pixel models but are more and more done in hardware or at least dedicated security cores in newer models.
Add to that different android and patch versions and a general tendency among users to ignore updates even when available and you end up with thousands of tiny differences that can make an exploit fail on the target machine.
This type of exploits must be reliable, you can't just spray millions of devices and be happy with a 10% success rate. You have one target and maybe only one chance to get it, as a failed attack may be noticed by the owner and the attackers really don't want that.
So the company has the choice of maintaining one set of exploits for latest iOS or hundreds for different android phones. It is simply not economically viable.
I'm guessing the reason why iOS exploits receive more face-time is: 1. Apple has advertised their phones as being at the forefront of security, which holds some merit. 2. iPhones have become commonplace among government employess (possibly as a result of point 1). Political exploits are inevitably more in the public eye if it's the tool of most politicians.
It's the same concept as the early days of Microsoft being the powerhouse of consumer operating systems- everyone was using it making it the most lucrative to exploit.
Higher value targets tend to use iOS more often so their adversaries have more interest in attacking it, and the targets are people who are more likely to come forward if they suspect being attacked. And given we've heard more of iOS attacks, people likely to be targeted are more on the look out for them, as a bit of a self fulfilling prophecy.
Android is considered a bit of a harder target for these types of exploits (playstore malware doesn't count here), though at this level it's not the most meaningful distinction. Fragmentation does make it harder to use these sorts of things in the android world, as it's a bit harder to do QA against all the possible target devices and probably requires knowing exact model numbers to confirm support before being able to launch an attack. The exploits do definitely exist however, at least for flagship phones.
Another thing to consider is that maybe people have better payloads on android, as you can't quite get away with running "Payload2" on the device from a temp directory when process viewers are available. I'm somewhat unsure that'd actually be a meaningful reason for lack of discovery though, especially when the discovery is mostly done by journalists forwarding suspicious links to citizenlab.
Also iOS users tend to be less security savvy, but that's just my impression
Counterpoint 2: There are much more Android devices with outdated versions of Android with known security bugs around than similar iOS devices.
Maybe you just don't need the big guns for most Android phones, so you will find them only on the harder targets.
https://source.android.com/security/bulletin
Counter Counterpoint 2: You are right
Sadly, I don't think that's very relevant. There are countless Android phones in daily use that won't get any security update ever again (mostly because of bad update policies of OEMs). The story is different for iOS. I wouldn't be surprised if that alone makes a difference in statistics in so far as that a random Android phone you encounter is less likely to be so secure to warrant the use of big guns like Pegasus, compared to your random iPhone. And that is regardless of how secure an up to date Android is.
So I think the statistics in the article is less due to Android vs iOS security, but more a reflection of update policies.
Core libraries (where historically the biggest security bugs have been found, see for example stagefreight) plus all core applications (e.g. Web browser, email client) are now updated from the store.
I think Apple should give citizenlab some generous funding to expand their operations. The more samples they capture the more secure the world will be.