5 ms·
It should be explained to public how such exploit take place, with open sourcing necessary parts. Otherwise there is no way for us to know it wasn't intentional
by alienalp 5y ago
It should be explained to public how such exploit take place, with open sourcing necessary parts. Otherwise there is no way for us to know it wasn't intentional at first place.
I am not meaning there is a possibility like Apple as a company decides to put exploits. However governments can easily do it with single engineer at right place.
- javajosh 5y agoAccording to wikipedia[1] Pegasus is usually installed via a zero-click iMessage exploit. Open-sourcing Pegasus doesn't seem likely as NSO Group sells it for big bucks. It seems unlikely that Apple has colluded with NSO, as Pegasus is actually a bit of a black eye for the company. I'm not sure what governments can do with an engineer in the right place - in general I'd say "not much, and certainly not as much as with the courts and guys with guns, the other things a government can do. 1 - https://en.wikipedia.org/wiki/Pegasus_(spyware) https://en.wikipedia.org/wiki/Pegasus_(spyware)
- saagarjha 5y agoI understood the parent comment as requesting that iOS be made open source to allow a further understanding of how the exploit works. My response to that would be that making things open source makes this process easier, but is not, by and means, a requirement for this ability.
- christophilus 5y agoInteresting. Didn’t realize it was zero-click. I got a bunch of weird iMessages a few months ago which I didn’t open. How do I check if I’ve been compromised?
- username190 5y agoiMazing[0] can analyze an iTunes (or Finder in macOS Catalina and later) backup to determine whether Pegasus is present. [0] https://imazing.com/ https://imazing.com/