Paragon Graphite is a Pegasus spyware clone used in the US
gamingdeputy.com
gamingdeputy.com
Clearly there was and is still demand form TLAs for this kind of software and services so people who want to get paid will just rebrand or produce an alternative.
Original post from 9to5mac: https://9to5mac.com/2023/05/30/paragon-graphite/
@dang should the link be updated?
> Paragon Solutions doesn’t have a website. There’s very little information at all about them online, even if the Tel Aviv-based smartphone surveillance startup’s employees are all over LinkedIn, more than 50 of them. That’s not a bad headcount for a company that’s still in stealth mode.
[1] https://www.forbes.com/sites/thomasbrewster/2021/07/29/parag...
And how do you know you're running it?
"The firmware is open source" doesn't help. Can it securely attest it's running what you think it is?
If you want enough infrastructure to, say, run a browser on one of thousands of undocumented processor models built by some company you've never heard of? Not gonna happen.
> During our research, we explored several components, including Broadcom’s Wi-Fi firmware, the DART IOMMU, and Apple’s Wi-Fi drivers […] We’ve also seen how the iPhone utilises hardware security mechanisms, such as DART, in order to provide isolation between the host and potentially malicious components.
Companies like NSO Group are certainly capable of developing exploits of this complexity, as Google's team has shown. Their analysis of NSO's FORCEDENTRY exploit showed NSO building a mini-VM from scratch within a little-known image codec used by the iMessage PDF engine: https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...
It is extremely difficult to defend against teams that have this amount of skill and dedication.
Very happy that book on NSO has made the waves it has in my political circles. Everyone needs to be aware of the security/safety climate journalists, and anyone who wants to challenge governments/capital in any meaningful way are facing.
Any more links like those? Fantastic stuff. Should I just be reading Google Project Zero's blog? I've recently found offensiveCon thanks to hackernews.
Time and money. These groups are funded 8 hours a day, 40 hours a week, per person, to dig into your code and find problems to exploit. Unless your place of work has an even bigger security team, you have no chance.
There are question marks over much of available RISC-V chips due to chinese producers, so maybe OpenPower based hardware?
Plus, the entire system (motherboard, etc) would need to be manufactured using a good supply chain.
Hmmm, this has probably all been thought through in depth before by others. :)
There already exists some very secure operating systems, however that only solves the software part of the equation. Systems need hardware to run, and they come with firmware. Often the firmware itself is compromised, such as the firmware coming with most CPU’s, for example Intel Management Engine[^1], and the AMD Platform Security Processor[^2].
[1]: https://en.wikipedia.org/wiki/Intel_Management_Engine
[2]: https://en.wikipedia.org/wiki/AMD_Platform_Security_Processo...
The move to remove one ring level in intel chips was touted as to decrease complexity of the CPU chip and OS start times. That is not the only reason, there is a security reason as well.
Security is about making it hard on all surfaces to attack if feasible. If an OS hardens kernel to attack, then the attack moves to userland. See how virus and other attacks on BSD kernels work.
So the correct question is in the systems realm, can we come together to hardened both the Kernel and Userland equally?
Educating and motivating users to use the features of such an OS in order to maximize its security (e.g., capability bits)?
So much harder. This is, in my opinion, the more insurmountable problem. Most users have no idea what a window manager is, much less how to change their window manager. Security requires someone to set the capabilities allowed based on what's needed, with fine grained security controls. That takes more time and effort. How many of you have deny all on site permissions in your browser, and only enable the ones you need for the sites you need them for? And we are the technical audience.
Being certified against the SKPP required a multi-month NSA penetration test with full source code and design specifications to discover zero deficiencies [4] so qualifies against the standard you are proposing. The certification was done at the behest of the DoD for the F-22 and the F-35, so you can be reasonably certain it was not a false certification by the NSA to make sure the premier fighter jets of the US are vulnerable.
You can also look at some of the other certified systems linked here [5] though I am not sure which of them are still commercially viable or even functional on modern hardware.
[1] https://www.nist.gov/system/files/documents/2016/09/15/aesec...
[3] https://www.commoncriteriaportal.org/files/epfiles/st_vid103...
[4] https://www.commoncriteriaportal.org/files/ppfiles/pp_skpp_h... Page 116
So step one of your new OS engineering process is to build a whole new software engineering paradigm, and all of the engineering tools to go with it, from the ground up, based only on research from like a dozen people that mostly ended around 1990.
> "The DEA did not directly comment, but it has been claimed that the agency bought Graphite for use by law enforcement partners in Mexico to fight drug cartels. A DEA spokesperson said only that it uses 'every lawful investigative tool available to pursue the foreign-based cartels and individuals operating around the world responsible for the drug poisoning deaths of 107,735 Americans last year.'"
Meanwhile, courts just shielded the Sackler opiate cartel members from civil liability for their massive US-wide opiate marketing scheme (they were already shielded from criminal prosecution):
"Sackler family wins immunity from opioid lawsuits, May 31 2023"
https://www.bbc.com/news/world-us-canada-65764307
Considering the widespread propensity of humans to indulge in the use of various consciousness-altering substances, what you end up with is highly selective prosecution and many instances of the Lavrentiy Beria (Stalin's deputy) quote: "Show me the man and I'll show you the crime."
Wash my hands, but don't make them wet! As long it is used to target criminals, ok. But it won't.
On the one hand, yes, I'm afraid for my freedom and that of my friends, but on the other hand, drug cartels are really, really bad.
Not enough is being done about drug cartels. So far the war on drugs has been staggeringly effective, with such classics as https://www.worldatlas.com/articles/countries-that-have-decr...
Better just add backdoors to the ambient atmosphere in case drug cartels use air.
The thing is, as long as you give the government the door to justify doing shit like this, they will find a justification that will upset few enough people for them to push it through, aka muh children etc.
The only way to win is to literally pursue open source hardware and software exclusively.
>...maybe that's just not good enough?
Perhaps addressing the problem instead of the symptoms could be a way to go? Decriminalizing responsible recreational drug use would destroy the cartels, as the general public would never trust buying something that could be laced with poison.
Instead of thinly veiled veneer of bullshit smeared over the giant turd that is spying on everyone why not explore these options?
Let me ask the question differently. How many children are being illegally spied on by the government to help "catch" drug cartels?
If I were an ASI though, I would certainly push as hard as possible to get eyes on every organic, by whatever means possible. Whether it be position tracking via triangulating ambient radiation http://rfpose.csail.mit.edu/ or something else.
As at least one other has pointed out the issue here is not really the tool(s) used to break | search | intercept | etc but the strength of oversight of the use of those tools.
It follows the general problem of police acting in a manner as though outside the law via friendly judges, rubberstamped warrents, and general immunity to prosecution for BadThings.
So does this mean it is wise to turn off iMessage so that all messages come through as text message?
Fix FISA and warrant ruberstamping instead of pearl clutching about the tool used to achieve it.
Is this an assumption? We don't have much information into this process so it surprises me that we jump to the conclusion that they're a rubber stamp. Is there any supporting evidence for this assertion?
Where was this detailed?
We would need to know how many requests the FISA courts receive and how many they reject and we would also need to know these numbers for the in-the-open legal system. Even still- if investigators are good at their job they aren't going to give the judge flimsy requests that will get rejected.
I know for example that police often err on the side of caution and request warrants where a warrant might not be required because it's better than being wrong and tainting the entire case.
We aren't entirely without numbers
"1,856. That's the number of applications presented to the court by the government last year. And it's also the number that the court approved: 100 percent success." (https://www.npr.org/2013/06/13/191226106/fisa-court-appears-...)
I would personally like to see law enforcement and intelligence agencies double down on their use of these kinds of tools, but, you know, to catch drug traffickers, terrorists, illegal arms dealers, money launderers, actual criminals who want to harm people, or is that too much to ask?
If Trucker John is going to be arrested for posting something vaguely racist under a Twitter video where 5 guys are brutally murdering someone, why not also catch the actual criminals in the video?
I’m dead serious here. Let’s just accelerate. Make the internet and internet-connected devices defacto public property and allow full access to law enforcement. I’d rather have all this be regulated with oversight, than the alternative.
Yeah well, that raises the old question: who guards the guards?
As far as I am aware, police and politicians themself, react quite allergic to more transparency (surveillance) for them.
So the only way I would be remotely ok with more surveillance and regulation, is if would apply to everyone and especially to the regulators. Otherwise a clear no from me, I simply do not trust the authorities. And there are still lots of ways to communicate besides regulated spaces. But sure if, you want to be heard by the mainstream, you are going into regulated territory.
This conversation needs to start at a point where we take the status quo of government, intelligence agency and private company operations into account, and not from an idealistic utopian perspective.
Companies or governments with unlimited budgets, zero morals and access to the worlds smartest hackers will always exist. I’m not being some kind of doomer, I’m being realistic.
If you steal money from a digital bank account, you go to prison. If you steal data from OneDrive, usually nothing happens.
Actually, you are not realistic, as no government has unlimited budget.
And yes, we have to work with, what we have. But that doesn't mean we have to make it easy to let the NSA in.
So if they have (something like) a warrant, I am fine with them breaking into someones computers. But it has to be an effort and not just if they feel like it. That would be unchecked power and I am not aware, how that ever turned out fine.
1. It would be abused to hell and back - have you ever seen how people act with power?
2. Wrongdoers will still use covert tools. Cryptography has many forms, one of them is steganography - hiding information in plain sight.
So, what you end up with by enabling this is a totalitarian state, where the most vulnerable are hurt the most. Which is basically what we originally wanted to get away from.