12 ms·
iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones
- sneak 5y agoThis coupled along with the fact that iMessage's E2EE has been backdoored by the non-E2EE iCloud Backup key escrow is a good argument for leaving iMessage, FaceTime, and iCloud all turned off on a device. I go one step further and leave the SIM card out, which means the SMS vulnerability path is closed too.
- msh 5y agoThen you could just as well get a iPod touch or iPad mini.
- sneak 5y agoNeither of those has a vibrate motor to let me know about notifications. They also can't be used to pair to an Apple Watch. I know this because I used to carry an iPad Mini in my pants pocket.
- gjsman-1000 5y agoThen buy an iPhone, and turn off iCloud Backup in Settings, it's not hard to do. Then your iMessages are fully E2E Encrypted.
- sneak 5y agoNope, because they get escrowed by the other end of the iMessage conversation. Also, the whole point of disabling iMessage (in this thread) is to close the iMessage-related zero click exploits described in TFA.
- gjsman-1000 5y agoThe other end of the conversation escrows the key on any messenger. Otherwise how would you read the message? Unless you consider Snapchat, but that's not End to End Encrypted. And are you really sure that Signal or your preferred messengers don't also have Zero-Click exploits? After all, they aren't sandboxed to the degree iMessage is with BlastDoor.
- sneak 5y agoSnapchat claims to be end to end encrypted, last I looked. Signal does not escrow endpoint keys in an iCloud Backup, so your first statement is incorrect.
- gjsman-1000 5y agoThis is false. Snapchat has "snaps" protected, but text messages and group messages are not end to end encrypted. Also, Signal putting your escrow keys in iCloud? I don't think you know what you are talking about. You can set iMessage to not put your keys in iCloud like I said above by turning off iCloud Backup which makes it fully End-to-End with your own key on your device, just like Signal. If you are worried about the other party having their conversations being backed up, tell them to disable iCloud Backup. If you are this worried about the privacy of your communications, hopefully the other party would be as well. And Signal and any other E2E messenger is absolutely storing copies of your key on the recipient's phone, just like iMessage would. If it didn't, there'd be no way to verify that a message was sent from the same sender.
- Dah00n 5y ago>You can set iMessage to not put your keys in iCloud like I said above by turning off iCloud Backup which makes it fully End-to-End "Fully" smells like a weasel word here. Either it is E2EE or it isn't. iMesssage isn't by default from what you are saying and if it requires the other end to also turn off icloud backup before it is E2EE then I'd go as far as stating that it is a completely useless attempt to be E2EE. In fact I'd argue Apple is full of sh*t if they actually ever stared that it is E2EE (but I have no idea if they did). Comparing Signal to such a mess is... well at a minimum it is disingenuous.
- smoldesu 5y ago...or I could just use a truly-secure option that doesn't destroy my personal security model. Owning an iDevice presents a considerable security risk to my current setup.
- gjsman-1000 5y agoThere is no such thing as a "truly-secure option." As anyone truly concerned about security will tell you. You will be forced to make compromises somewhere unless you want to live under a rock in the desert. You can't drive without a State ID, can't get a home loan without credit, can't work without a Social Security Number except under limited circumstances, can't make money without reporting to the IRS, and so on. It's entirely about what compromises you want to make, and the tradeoffs therein.
- sneak 5y ago> can't work without a Social Security Number except under limited circumstances Something like 96% of human beings don't have a social security number. Many of them work.
- gjsman-1000 5y agoLike the nation you live in doesn't have its own Tax Authority with information on you, and doesn't have its own ID Number you need to use for working. The technicals are different, the point is the same.
- smoldesu 5y agoI don't count on a "truly secure" option existing, I just manage my risk by reducing the amount of Big Tech thumbs in my personal pie. Apple, much like Amazon, Microsoft and Facebook, have no right to any of my personal information, end of story.
- nobodylikeme 5y agoI just wanna know how big are your pants pockets
- gjsman-1000 5y agoBut then you are using SMS, which your cell carrier can absolutely see and intercept because it's decrypted. So in either case... turn off native messaging and use Signal or something if you are paranoid. You aren't really using the "phone" part anymore, so buy an iPod touch or something. Also, iMessage is fully E2E if you disable iCloud Backup. Which can easily do in Settings.
- sneak 5y agoPlease stop using the term "paranoid" to describe those who desire personal privacy.
- gjsman-1000 5y agoThere is a degree to where you are actually paranoid though, otherwise we wouldn't have that word. If you are this paranoid, you shouldn't be carrying an electronic device.
- caymanjim 5y agoIt's not paranoia when it's true. While most people value the convenience of conventional phones calls and default messaging applications over true privacy, those who prefer privacy aren't being paranoid. Companies are monitoring communication to increase ad revenue; government are monitoring communication to catch criminals, enable industrial espionage, and suppress dissent. It's only paranoia if it's delusional. We know that we're being spied on, even if we're not being individually targeted. Even democracies that supposedly value freedom engage in widespread surveillance in direct violation of their own laws. I'm in the camp of pragmatic resistance to surveillance. I use browser plugins to block ads and cookies where it doesn't get in the way of reaching the content I want; I use Signal for messaging even though almost none of my recipients do; I disable location services except for things like Maps that actually need to know where I am; I turn off all the spyware I know about that's built into operating systems; etc. I'm not a tin-foil-hat-wearer; I'm not doing anything illegal that I need to hide; I'm just trying to push back in a small way against the erosion of privacy and rights that permeates everything electronic. But the parent isn't paranoid. They really are watching. And we shouldn't be so complacent.
- askonomm 5y agoShould probably also dig an underground bunker and collect cans of sardines to last for decades.
- abaracadab 5y agoDon’t forget your pentium and DOS collection! Air-gapped of course.
- beervirus 5y agoCanned food has a surprisingly short shelf life. Sealed containers of dry beans and rice are the way to go.
- 3pt14159 5y agoI dated a journalist once. She used some random free app for phone calls because recording calls isn't built into iOS and she needed to record calls. I suggested a small device for her to plug her headphones through, but she declined. I'm sure there's a few journalists out there that take cybersecurity seriously, but I'd wager the vast majority are pretty trivially monitored.
- xenocratus 5y agoBut it also depends on what kind of journalism they're doing, right? Not all report on criminal activity, or on investigating the government. It's kinda like threat-models, no need to be super secure if your work brings no risks to you, your organisation, or those you come in contact with.
- jdavis703 5y agoJournalists from celebrity gossip reporters to foreign affairs correspondents needs to take security seriously. Even gossip journalists receive information from sources that ranges from information that would get the source fired or blacklisted to put in jail (e.g. LA sheriffs leaking celebrity photos).
- certnlyuncertn 5y agoHow likely is it that people are exploiting zero days against reporters in any of those examples though. That's why threat models are different for different types of journalism.
- reader_mode 5y agoDoes it take a zero day when you install random freeware crapware from the store ?
- c7DJTLrn 5y agoAgreed. The parent comment makes a ridiculous extrapolation.
- max_ 5y agoTime for a cyber security focused smartphone?
- esens 5y agoWould it actually have more resources that say Apple? I think if Apple can not do it, I am unsure if anyone else could. All supposedly secure smart phones are not, but they are at least obscure. I think that one should probably buy an Apple (at least they control everything rather than the cobbled together android clones) and disable basically everything except exactly what is needed. At least that reduces the surface area. And keep personal stuff on a separate phone.
- Dah00n 5y agoApple can do it (create a security focused phone), it just isn't anywhere near what they want to do. The instant security (or privacy for that matter) gets in the way of profit for Apple they will back away.
- gjsman-1000 5y agoOr maybe it's because they're doing their best to make every iPhone the security-focused phone, while not doing anything that would anger the FBI enough to try to pass legislation. When you are that big of a company, the things you can get away with are much more restricted than a small company.
- redprince 5y agoThey have already angered the FBI quite a lot during the 2016 San Bernadino case and made their position on the matter clear: https://www.apple.com/customer-letter/ https://www.apple.com/customer-letter/
- Dah00n 5y agoYes, a good PR move by Apple. Especially when you can get access by going to someone like NSO instead.
- nonameiguess 5y agoApple needs to make it possible for users to choose other ways of sending and receiving messages and listening to music, or of choosing not to do either of those things if they don't want to. Obviously, you can currently install and use other applications that provide the same functionality, but you cannot uninstall or disable defaults. The most shocking experience to me in trying to evaluate the Mac ecosystem when they released the M1 and I bought a Macbook Air is being in meetings where I'm using bluetooth headphones, take the headphones off and put them back on, and music.app automatically opens and comes to the foreground of my desktop. There is no supported way of disabling this user-hostile anti-feature. I look on Google and StackOverflow and all of the suggestions for how to disable it dating back to 2014 or whenever no longer work. Apparently, the likely answer is turn off System Integrity Projection, reboot, rename or remove the file containing the application launcher, turn SIP back on, and hope that doesn't break anything else and hope Apple doesn't revert your changes on the next system update. That did not seem worth it. The fact that Apple Music can and has been used as an attack vector makes it even worse that it is so tightly integrated with the audio subsystem of the hardware as to take over your device thanks to movements you are making in the physical real world even when you may not be touching the device at all. I just can't understand what the thought process was in making this a default behavior, let alone one that cannot be disabled.
- 6gvONxR4sf7o 5y agoI also have bluetooth headphones I use with a mac, and that’s never happened to me. Is it a new thing with the M1 machines or something?
- danieldk 5y agoHaven't seen this either. Both my wife and I are on M1 MacBooks.
- angulardragon03 5y agoNope, I’ve never had this happen to me on my M1 machine, Bluetooth or 3,5mm headphones. If you don’t have another media app focussed or active, pressing a media control button/key will open Music iirc.
- hugh-avherald 5y agoAn intelligence agency cannot have the following properties simultaneously: (1) The ability to detect espionage from China and Russia (2) The inability to access journalists' phones If you want an intel agency to be able to thwart Chinese intelligence activities, you can't also publicly state you won't be looking closely into members of a profession who act a lot like spies.
- wolverine876 5y agoIn fact, in (most/many) advanced democratic countries intelligence agencies can and do exactly that.
- criley2 5y agoWe understand that the intelligence agencies can and do monitor a number of people associated with hostile foreign governments. For example, this is believed to be how "Tucker Carlson got surveilled by the CIA" -- he is believed to have contacted a surveilled Russian agent to discuss interviews with the Russian president. This is called "incidental collection" and it's a touchy subject for sure. But this subject is different than the DoJ directly surveilling journalists who leak, which is a problem, and governments surveilling their own citizens directly, not incidentally. We can and should hold our government(s) to a standard of effective fire-walling of acceptable intelligence gathering and holding them accountable when they go beyond to surveil citizens directly, or indirectly through spying agreements. We can make sure that the people who surveil Chinese or Russian "diplomats" are totally different than the people who execute search warrants against our citizens, and expect there to be zero crossover there.
- cronix 5y ago> For example, this is believed to be how "Tucker Carlson got surveilled by the CIA" -- he is believed to have contacted a surveilled Russian agent to discuss interviews with the Russian president. Yes, that happens all of the time but one difference here with Tucker is he was deliberately "unmasked." Normally when an American is caught up in foreign surveillance, their identity is blocked out or masked, "incidental collection" as you said. Someone purposefully unmasked it. And someone purposefully leaked it. The same thing was done to General Flynn. https://en.wikipedia.org/wiki/Unmasking_by_U.S._intelligence_agencies https://en.wikipedia.org/wiki/Unmasking_by_U.S._intelligence...
- coldcode 5y agoJust because it was only used to target journalists, supposedly, does not mean someone could not also target random individuals. I doubt NSO has such control over their customers that the uses can't be expanded to almost anything, like blackmail, theft and harassment.
- wolverine876 5y ago> However, it is unlikely that Pegasus will be a problem for the vast majority of iPhone users. While the tool is used as intended against criminals by governments, the attacks against innocent people are seemingly against those who could be critics to a regime, including journalists and human rights activists. Attacks against the freedom of others and critics of government are a much larger threat to ordinary people than if they were surveilled themselves.
- Ar-Curunir 5y agoOne isn’t necessarily a larger threat than the other; both are horrible
- twobitshifter 5y agoThey are governments that will happily track and monitor everyone- maybe they won’t use Pegasus but they could use the same vulnerabilities.
- comodore_ 5y agothere are apparently 50k names in that list, last I've checked they confirmed ~180 journalists are among them. spying on journalists is atrocious, but who are the other 49.800?
- Ar-Curunir 5y agoOpposition Politicians, activists, critics, etc
- Miner49er 5y agoThey're releasing more names including, "lawyers, human rights defenders, religious figures, academics, businesspeople, diplomats, senior government officials and heads of state" From: https://www.theguardian.com/news/2021/jul/18/huge-data-leak-shatters-lie-innocent-need-not-fear-surveillance https://www.theguardian.com/news/2021/jul/18/huge-data-leak-...
- j45 5y agoI wonder if there is a way to disable iMessage and iTunes usage. With windows server I used to have a target of balance in any attack footprint.. if Microsoft provided the OS, the component services that the server exists to provide should always try to be third party software (db, web server, etc) to try and minimize one type of escalation vulnerabilities… while possibly opening up to another, hopefully less worse set of holes.
- rsync 5y agoYou can block or restrict these with the (free) tool apple publishes called “apple configurator”.
- j45 5y agoI’ll have a look at this, thanks
- sneak 5y agoYou can use a NextDNS configuration profile at https://apple.nextdns.io https://apple.nextdns.io and a NextDNS account to block the device communicating with many Apple services. A good way to disable iMessage and iTunes, though, is to simply not have an Apple ID. (This prevents the install of applications via the App Store, however.) You can of course set up the device with no Apple ID and then only add the Apple ID to the App Store (and not iTunes or iMessage/FaceTime/iCloud). This is what I do.
- j45 5y agoThis looks great, thanks
- skarz 5y agoI like the end of the article, he says "its concerning, but unless you happen to be a major critic of a government, you probably won't be a target of the spyware tool" Yeah, okay.
- TravisHusky 5y agoI have never heard of MVT (Mobile Verification Toolkit) before this article, but now I may just have to test it out; seems like an interesting project.