22 ms·
Pegasus spyware found on journalists’ phones, French intelligence confirms
- DSingularity 5y agoWell, I thought it was only terrorists that were targeted?
- deleted 5y ago[deleted]
- stavros 5y agoTerrorists, journalists, only a few letters are different.
- dathinab 5y agoYes, just a word edit distance of 13 (6del, 7adds). It's the same distance as changing <Freedom> to <Dictator> ;=) EDIT: Yes I miscalculated, I overlooked the r.
- benque 5y agoOne man's journalist is another man's .... ;-)
- stavros 5y agoAnd the same invariable lie is always used, "oh, don't worry, we're only going to use this against the bad guys". Bad guys only exist in a world without nuance.
- mtnGoat 5y agobad guy is a just not a term that should be trusted when coming from politicians at this point. "bad" is an opinion in the sports of politics and power, because they are worried about their own hind end, not that of the state at large.
- kota2 5y agoExactly. 'Bad' and 'terrorist' is just the word play decision of some politician who surely does not have your best interest at heart. People are really getting fed up with being lied to on a constant, grand scale.
- Hamuko 5y agoA lot of the current world news strike fear into its readers. Surely that is some kind of terrorism.
- ekianjo 5y agoeveryone is a potential terrorist under imaginary laws
- rodgerd 5y agoNSO customers' definitions of terrorist may not align well with yours.
- belter 5y agoI have seen some manuals were released and some tools reverse engineered. What is currently the best link for a deep technical overview of how these tools work/worked?
- belter 5y agoAs I did not get any replies I share what I found. If anybody has better or more detailed resources, please be kind and feed our curious minds: "Technical Analysis of Pegasus Spyware" https://info.lookout.com/rs/051-ESQ-475/images/lookout-pegasus-technical-analysis.pdf https://info.lookout.com/rs/051-ESQ-475/images/lookout-pegas... "Pegasus Spyware" https://en.wikipedia.org/wiki/Pegasus_(spyware) https://en.wikipedia.org/wiki/Pegasus_(spyware) "The Million Dollar Dissident" https://citizenlab.ca/2016/08/million-dollar-dissident-iphone-zero-day-nso-group-uae/ https://citizenlab.ca/2016/08/million-dollar-dissident-iphon...
- metabagel 5y agoTaki taki, beratna!
- belter 5y agoIm ta nating!
- journey_16162 5y agoSo basically it can install itself after clicking a link in a web browser. I know it's very hard but could the browsers be improved so that something like this is virtually impossible?
- bj-rn 5y ago"Forensic Methodology Report: How to catch NSO Group’s Pegasus" https://www.amnesty.org/en/latest/research/2021/07/forensic-methodology-report-how-to-catch-nso-groups-pegasus/ https://www.amnesty.org/en/latest/research/2021/07/forensic-...
- canistel 5y agoIronically, users themselves are disallowed from rooting their phones. Right to root, is right to repair.
- duxup 5y agoI'm all for having the right to repair. I'm not convinced any of the folks involved ability to root would prevent the situation described.
- js8 5y agoIf you could safely (on the hardware level) replace image of the phone with another, it would be easy to guarantee that you can get a rootkit-free phone - all you need is a trusted image.
- dewey 5y ago> it would be easy to guarantee that you can get a rootkit-free phone The problem in this case is that you get the malware installed through a no-click required iMessage and not a "supply chain" attack on the image your phone is running on. How would that help?
- tremon 5y agoYou could replace the image with software that doesn't support iMessage, for example.
- pdkl95 5y agoIt could help by simply being sufficiently different. The only reason this type of malware is such a widespread problem is the large monoculture of potential targets. Just like in agriculture (e.g. potatoes, bananas), a monoculture allows a single pathogen to affect an entire crop. In security this is a class break[1]. Utilizing different software implementations limits the scope of this type of attack. The current trend to increasing centralization and forced-update monoculture is a huge gift to malware authors: they only have to write one version of their malware to affect everyone. [1] https://www.schneier.com/blog/archives/2017/01/class_breaks.html https://www.schneier.com/blog/archives/2017/01/class_breaks....
- ku-man 5y agoWhat annoys most the French intelligence is that the Moroccan intelligence services had access to high level French politicians phones.
- mcguire 5y ago"Bredoux added: “It takes a bit of time to realise it, but it’s extremely unpleasant to think that one is being spied on, that photos of your husband and children, your friends – who are all collateral victims – are being looked at; that there is no space in which you can escape. It’s very disturbing.”" Welcome to the future! It's pretty much the same as the past, only more effective.
- cronix 5y agoA depressing thought experiment a professor once posited many years ago....Hitler comes to power in the internet era and now has state of the art tools to find people of certain traits, vs manpower and spies to discover them. Ability to go through your entire lives digital footprint. Every picture. Every video you've created, or viewed on a website. Every location you've visited, how long you were there, and who was around you. Everything you've ever searched. Everything you've ever purchased. Every contact you have. Content of email, text, phone calls, etc. All keyword searchable with beautiful charts and graphs showing how you relate to everyone you've ever come into contact with.
- fsflover 5y agoIt's pretty much what we have in China now.
- kota2 5y agoThere are programmes doing this in the West as well.
- miohtama 5y agoTo the positive spin for China, they tend to target only their fellow citizens and have some internal coherency and moral. NSO is an Israeli national problem that sells the spying capabilities to the highest bidding crook dictator around the world.
- eightysixfour 5y ago
- PradeetPatel 5y agoIs there no regulatory or compliance requirements for surveillance software? Instead of blaming the victims of pegasus, we should focus our attention on the lack of actions from key policymakers and regulatory bodies. It is not possible for every individual to be a technical expert when it comes to malware removal, but we can reduce the likelihood of misusing surveillance software by creating an ethical framework around it, backed by nations that value freedom and democracy.
- JumpCrisscross 5y ago> Is there no regulatory or compliance requirements for surveillance software? Nope! It's not even clear if Pegasus and its employees broke any laws. (Though I would love to see CFAA and copyright law tested against this.) Optimistically, this might be the wake-up call to change that.
- sofixa 5y agoIANAL but lots of countries have laws against gaining access to computing devices or data without prior authorisation.
- SMAAART 5y agohttps://en.wikipedia.org/wiki/Aaron_Swartz#Arrest_and_prosecution https://en.wikipedia.org/wiki/Aaron_Swartz#Arrest_and_prosec...
- raxxorrax 5y agoWe have a lot of laws against dragnet surveillance. They didn't help at all as there is no consequence of breaking them. Even if they are found guilty, policy makers have noticed that this too hasn't any effect at all. They just need to craft an exception et voilà it is allegedly legal.
- bsder 5y agoTo me, it would seem that this kind of software trips over all kinds of European laws and directives. Hell, it probably trips over all kinds of wiretap laws in the US. Is it that nobody is filing these or just that the revelations are too new and that the lawyers are just beginning to spin up?
- johnchristopher 5y agoI wonder what would have happened to windows phone/lumias if things had turned out differently. I also wonder if there was something like that when windows mobile was on the market.
- SubzeroCarnage 5y agoSlight OT: the malware indicators of compromise that Amnesty International released have no license, thereby prohibiting use in other projects as far as I understand. https://github.com/AmnestyTech/investigations/issues/11 https://github.com/AmnestyTech/investigations/issues/11 If anyone can help on that front it'd be much appreciated.
- robgibbons 5y agoIANAL but arguably, those indicator files are merely lists of information, and therefore are not subject to copyright. They are not, on their own, a creative work. https://www.nolo.com/legal-encyclopedia/types-databases-that-cant-be-protected.html https://www.nolo.com/legal-encyclopedia/types-databases-that...
- jhgb 5y agoBut that page says things like "[when] no judgment is needed to decide which names and addresses should be included". Surely somebody decided what are the things for a classifier to look for, and that would be a creative decision?
- robgibbons 5y agoAgain, IANAL, but a decision whether to add a domain or email address to one of these lists is not a creative decision, it's a mechanical boolean decision. It's a matter of fact, not of creativity or subjective inclusion. The regex pattern they used might be an example of a creative work, but the list of matches is probably not. In the same sense, recipes are not copyrightable. The thought that goes into composing them may be creative, but the list of ingredients itself is not subject to copyright.
- olliej 5y agobut remember, NSO is just doing the dirty work that needs to be done /s They're knowingly selling to untrustworthy organizations knowing they'll be used for criminal purposes. They're criminals, and should be treated as such.
- N1H1L 5y agoYeah. They are like unlicensed gun sellers who have a surprised pikachu face when that gun turns up in a murder investigation.
- firebaze 5y agoIf I were a journalist I'd almost feel insulted if I or at least my organization hadn't been targeted.
- kota2 5y agoRFI and France24 did some reporting a few days ago how everyone from activists to journalists were targeted, see: https://www.france24.com/en/technology/20210718-private-israeli-malware-used-to-spy-on-journalists-activists-and-politicians https://www.france24.com/en/technology/20210718-private-isra...
- kota2 5y agoIs there a way to check Android devices for infections yet?
- sss111 5y agoCould a pegasus infection be detected with something like Litte Snitch or Lulu for iphones, in my mind, it'd be suspicious if some application was sending gigabytes of data over the wire
- Goety 5y agoSo it was the French. /s
- specialist 5y agoHow would I factory reset and then cold boot my phone? I'm very noob wrt firmware and rootkits and even CPU microcode. My understanding is some kind of factory reset is no longer feasible. And certainly no longer verifiable. -- Ages ago, I proposed that electronic voting machines (tabulators) boot from CD-ROM. Device's ROM would only have bare minimum boot loader. Imagine some super minimal embedded controller, zero unnecessary features. Mount a CD, run the optical scanner, a few buttons, 2 line LCD panel, dot matrix printer. Assume 2000s best practices election administration. Scantron style ballots, precinct-based poll sites, tabulation occurs the moment polls close, tabulated results posted publicly. These CD-ROMs would then by secured, as much as possible, thru physical chain of custody. Just like all other election artifacts. They'd also contain snapshot of entire source and toolchain and election data, so any one could inspect them, reproduce the builds, verify the dataset, etc. My jurisdiction had 100s of poll sites. Instead of programming each ballot scanner, they'd burn CD-ROMs. Any way. I mention this because I think such simplistic view of secured computing is no longer feasible. And to consider all the things we'd have to give up to return such a world. Could I put a phone's entire dev stack onto some WORM media and then reimage the device? What would that even look like?
- npteljes 5y agoYou can't really be sure about your device, even after a supposed reset. Lenovo, for one, had a way to reinstall its bloat/spyware on its laptops, even after you reinstalled Windows yourself. https://en.wikipedia.org/wiki/Lenovo#Lenovo_Service_Engine https://en.wikipedia.org/wiki/Lenovo#Lenovo_Service_Engine