14 ms·
Apple will notify users about state-sponsored cybersecurity threats
- FridayoLeary 5y agoEven if the state in question is the USA? I think Apple should be clear if there are any states whose attacks they might ignore, for the sake of privacy, of course.
- boomboomsubban 5y agoSo something like PRISM that targets everybody won't trigger a warning?
- deleted 5y ago[deleted]
- funnyflamigo 5y agoI doubt it. Keep in mind this will only work for non-court-gag-ordered instances. If the US subpoenas Apple about an individual they won't be allowed to notify them. I have no idea how this applies to other countries. I think this is more like: "We noticed unusual API usage and we don't have a gag order so whatever it is, it's not likely to be good"
- simondotau 5y agoTo be fair, a subpoena isn't a cyberattack. But yes, this will be mostly of value of people being targeted by governments that are not the USA or best buddies with the USA.
- quitit 5y agoThe methods of detecting such attacks are not at all similar to a government requesting data which contains the non disclosure clause. Apple doesn’t need to know the source of the attack to issue the warning, and if the attacker is competent Apple likely wouldn’t know the source, such that a gag would not apply.
- WarOnPrivacy 5y agotl;dr: Apple will notify us as long as the attacking state isn't the US - which it very often is.
- schleck8 5y agoIt's rare that programmes like PRISM surface publicly. I don't see how Apple would gather top secret intel on national surveillance programmes on their own, so there is a good chance they aren't even aware.
- GeekyBear 5y agoIn the case of Google, the NSA was reading their unencrypted replication traffic as it moved between data centers. I don't see how Google could have been aware that this was happening, although they certainly could have known it was theoretically possible.
- protomyth 5y agoWhy do I get the feeling that if the state is China, then it won't get reported as such. I assume their supply chain is more important.
- temac 5y agoAlso if the state if USA...
- zepto 5y agohttps://www.apple.com/legal/transparency/us.html https://www.apple.com/legal/transparency/us.html Contains the canary: “To date, Apple has not received any orders for bulk data.”
- grlass 5y agothat appears to only be connected to requests under those specific acts. Otherwise, given their involvement in the PRISM program [1] I don't see how we can take that canary seriously. [1] https://en.wikipedia.org/wiki/PRISM_(surveillance_program) https://en.wikipedia.org/wiki/PRISM_(surveillance_program)
- zepto 5y agoThe specific acts include FISA requests.
- deleted 5y ago[deleted]
- capableweb 5y agoCould also be weasly wording here. They can still truthfully make that statement even if Apple themselves have decided to be pro-active and decided to give out bulk data without receiving any orders before. As the Snowden leaks showed, we should be really careful about how we read the words from large companies about data.
- cblconfederate 5y agoWhat if it is illegal to do so?
- bell-cot 5y agoFrom a pragmatic user's point of view, that would look just like "Apple didn't happen to notice that I was a target of state-sponsored activity". Recent headlines do not suggest that Apple's cyberdefenses are all that great against state-sponsored stuff. From a more philosophical point of view - expecting a large corporation to go mano a mano on your behalf, against a major state security organization...that's right up there with expecting Santa Claus to punish all the evil spies for being naughty.
- atmosx 5y agoAnd yet, in the contact tracing case both Apple and Google refused to give data and control to EU governments. I believe the contact tracing app was used against protesters in rallies about BLM though, by the FBI IIRC.
- hunterb123 5y agoSource? Pretty bold claim to just toss out with an IIRC. First, I haven't seen any indictments of any BLM rioters. Note when I say rioters I'm not including protesters but those who set fires and harmed people. Second, while I'm against contact tracing apps in general for the reason they can be abused, I don't think they would be needed by LE given their ability to setup string rays, drones, and monitor social media. Most of the BLM rioters and Antifa terrorists are known. Raz Simone is still free although he setup CHAZ, passed out rifles, and extorted public officials with political demands while claiming public land allowing 6 people to be killed under his "security".
- atmosx 5y agoHere are some links: - https://www.zdnet.com/article/singapore-police-had-used-covid-19-contact-tracing-data-in-murder-probe/ https://www.zdnet.com/article/singapore-police-had-used-covi... - https://slate.com/technology/2020/06/contact-tracing-law-enforcement-protests.html https://slate.com/technology/2020/06/contact-tracing-law-enf... Given the past decade (Snowden & Assange) I don't find strange contact tracing being used for "other purposes". The data is readily available so, why bother with drones?
- jaegerpicker 5y agoI wonder if this could be used to expose those that are in sensitive position. IE offer attacks at people you think are in important positions and watch how they react to the news. For example if you work somewhere sensitive and you have an accounts not tied the Apple account. The State Sponsored group is probably good enough to see your traffic patterns and to see if they change after you have been notified. Not that I think Apple shouldn't do this but I can see someone being crafty and trying to take advantage of this. There are always trade offs in security!
- thih9 5y agoI'm surprised to see protection against state sponsored attacks implemented by a company as big as Apple. Is any other 'mainstream' company offering a similar feature? Warrant canary [0] comes to mind, but that is usually a message to all users, as opposed to notifying an individual user. [0]: https://en.wikipedia.org/wiki/Warrant_canary https://en.wikipedia.org/wiki/Warrant_canary
- suprfsat 5y agoGmail does it https://blog.google/threat-analysis-group/updates-about-government-backed-hacking-and-disinformation/ https://blog.google/threat-analysis-group/updates-about-gove...
- RL_Quine 5y agoYeah, I loved having my work gmail account peppered with a giant red banner warmomg "THIS ACCOUNT IS THE TARGET OF STATE SPONSORED HACKERS". That was fun. We didn't really know how to respond or attempt to mitigate such a warning so, left it ignored.
- ridaj 5y agoRespond by using 2fa if you weren't already, not signing into the account from untrusted devices, checking OAuth grants for apps you don't recognize, not using same pw elsewhere
- RL_Quine 5y agoYeah, we were doing that, so the response was to just shrug. Without a lot more context it's hard to know what your reaction should be to something like that.
- WarOnPrivacy 5y agoA lack of context is kind of the problem here. What we need are specific method details, including origination addresses. There may be times when only most of that info is helpful, but withholding is always the opposite of helpful.
- funman7 5y agoWhat if you opted in to the terms of the Chinese App Store then switch to USA.
- diegorbaquero 5y agoYou are asked to accept new ones when changing store location
- zenlf 5y agoUnless, it's Chinese government. In that case, Apple handle over their control over database to Guizhou-Cloud Big Data
- jetsetgo 5y agoOr US. It's already running. So default.
- bsd44 5y ago"If Apple discovers activity consistent with a state-sponsored attack" I am really interested in understanding more about a "state-sponsored attack" as someone who works in Ops and has experience in CyberSec. All these years working in the industry and I had no idea you could identify an "attack" that easily.
- _jal 5y agoWhere do you see the word 'easily' in Apple's statement? If the complaint is that attribution is sometimes sketchy, so? Sometimes it isn't.
- atmosx 5y agoI believe it has to do with phishing attempts by known tools (NSO’s Pegasus). If anyone has the resources to fend them off, fingerprint them, etc it is Apple, Microsoft and Google.
- floatingatoll 5y agoSee also: Apple sues NSO Group to curb the abuse of state-sponsored spyware (apple.com) https://news.ycombinator.com/item?id=29320986 https://news.ycombinator.com/item?id=29320986
- jaegerpicker 5y agoFor a company with the resources of Apple? I'd imagine their Threat Hunting/Identification and classification systems are top notch. There are a number of know taxonomies for different attacks around and I'm quite sure Apple has some automation around identifying those attacks. It even addresses that many will be false positives. Example taxonomy: https://us-cert.cisa.gov/CISA-National-Cyber-Incident-Scoring-System https://us-cert.cisa.gov/CISA-National-Cyber-Incident-Scorin...
- kube-system 5y agoIt’s not easy. > Unlike traditional cybercriminals, state-sponsored attackers apply exceptional resources to target a very small number of specific individuals and their devices, which makes these attacks much harder to detect and prevent. > State-sponsored attackers are very well-funded and sophisticated, and their attacks evolve over time. Detecting such attacks relies on threat intelligence signals that are often imperfect and incomplete. It’s possible that some Apple threat notifications may be false alarms, or that some attacks are not detected. Identifying the source of these attacks is often done by analyzing the tools and techniques, in comparison to other known tools and methods, and/or by information gathered in meat space.
- BluSyn 5y agoI see a lot of pessimism in the comments. But I think this is a great step in the right direction. Other companies should take note. More of this, please!
- varjag 5y agoGoogle does this for some time at least. I received an imminent advanced security threat notification back in January 2019. Urging me to get one of those 2fa dongles (which I did). And just as well, because the next month my account was locked due to an attempted unathorized access. (whoever works on this at Google, thank you)
- Shank 5y agoThe Google warning page can be viewed by anyone, but they do specifically tell targeted individuals through other channels (a big red warning message at the top of Gmail, for example): https://myaccount.google.com/stateattackwarning https://myaccount.google.com/stateattackwarning
- jsnell 5y agoApple is like the last company in that space to do this. Google has had these warnings since 2012. Facebook, Microsoft and Twitter since 2015. (I agree that it's great that Apple is finally doing this. But it seems entirely par for the course for them to be a decade late and still get the credit.)
- punnerud 5y agoI have never seen any warnings from Google or Facebook if I automate against my own accounts, and dumping the data. Only on sign-in attempts. That kind of warning is very limited, and Apple also have them. It seems like Apple now have introduced ‘honey pots’ and other techniques to discover if there already is someone with access to your account/device, and that is a big deal and good news. And something I have never seen from any of the other big companies.
- 5y ago
- imarid 5y agoI know of one case of a Polish prosecutor who does not obey (do not want to bend the law) Zbigniew Ziobro, who is both the minister of justice and the prosecutor general. She received a notification from Apple just today. Source: https://mobile.twitter.com/e_wrzosek/status/1463551631648251915 https://mobile.twitter.com/e_wrzosek/status/1463551631648251...
- pomian 5y agoI think you need to add a translation of the tweet. Because it sounds as if he didn't obey Apple's warning. Yet I think he approves of Apple's s notification. It is the government who he wasn't obeying? So the government installed the spyware?
- awestley 5y agoTranslates to: "I just received an alert @AppleSupport about a possible cyberattack on my phone from state services. With the indication that I may be targeted for what I am doing or who I am. I will take the warning seriously because it was preceded by other incidents @ZiobroPL is this a coincidence?"
- aakkaarr 5y agoIt is like polish Watergate: the prosecutor has been criticizing minister Ziobro and already lost her job (not only her, this problem is now on EU table and European trials say polish gov is breaking the law doing this) and now she learned minister Ziobro was spying her (and probably is still doing this)
- ngcc_hk 5y agoWow. Just need to have something against state level power … just can’t fight them on an individual basis on one’s own alone.
- ajuc 5y agoThe problem is that Ziobro was already doing this (illegally wiretapping opposition) together with Kamiński and Kaczyński when they were in power in 00s. They lost power, almost got to jail but avoided it thanks to political calculation of the next party (that used them as "look at least we aren't like them" threat), then they got elected again anyway in 2015. They have majority support right now because of social spending and their supporters don't care about rule of law, corruption, any of that. There were already dozens of similar-scale scandals since 2015. Nobody cares. It's frustrating, really.
- deleted 5y ago[deleted]
- nabakin 5y agoNow if only Apple wouldn't search for CSAM on device, allowed repair shops to get the parts they need from the manufacturer, and provided schematics for repair shops. If they did those things, I might actually buy an iPhone.
- deleted 5y ago[deleted]
- questiondev 5y agoexcept in china, i pray that the people of the free world unite from within all countries and say enough is enough to their oppressors. it is wild to think that we still have ill actors in high ranks that are from bloodlines upon bloodlines of “ownership” of nations. there really still is a ruling class that has existed forever, sounds like a conspiracy until you look at who is buddies with who
- gambiting 5y agoWill it let them know that their own phone has decided that they are a potential pedophile and their photos will be sent unencrypted to some tech centre god knows where where someone will decide whether to report them to authorities or not? Or is that ok to keep secret?
- varispeed 5y agoIt's only possible because Apple is too big too fail. Probably they won't notify about the US snooping, but smaller countries often have smaller budgets that this company, so they can't really do anything about Apple pulling strings. It's a shame that smaller companies cannot do that without risking being closed down.
- kube-system 5y agoI see a lot of people in the comments conflating legal requests and attacks. Regardless of your opinion on either of those issues, they are different things.
- fsflover 5y agoNSA surveillance is illegal. Will we be notified?
- kube-system 5y agoBy "legal request" I mean requests made through channels of the law. These things aren't "attacks" because they're functionally not attacks. 'Cooperation' is the antithetical to 'attack'. For example, when China demanded that iCloud for Chinese users was handed over to GCBD[0], and Apple complied, it was not, in any way, something that would be accurately described as an "attack". Apple cooperated with the demands that the legal environment presented. [0] https://www.apple.com/legal/internet-services/icloud/en/gcbd-terms.html https://www.apple.com/legal/internet-services/icloud/en/gcbd...
- deleted 5y ago[deleted]
- lern_too_spel 5y agoWhich surveillance? By what ruling? The phone metadata collection was ruled illegal, but that does not affect Apple.
- WarOnPrivacy 5y agoUnder rulings that never happen due to the FISA court declaring a lack of standing due to the court keeping the evidence secret that proves standing. It utterly sucks having the sole oversight court having IC's back at our expense.
- fsflover 5y ago> By what ruling? https://news.ycombinator.com/item?id=24356741 https://news.ycombinator.com/item?id=24356741 https://news.ycombinator.com/item?id=24362047 https://news.ycombinator.com/item?id=24362047
- notkurt 5y agoHas anyone put forward some theories as to how they are pulling this off? Are they tapping into iMessage Metadata, scanning crash logs, or something along those lines? While I totally understand the need for them to keep how they are doing this private, I do find it slightly concerning. Unless they are just flagging suspicious iCloud login attempts. If it’s relating to crash logs, it would be nice to know as I’m sure a bunch of privacy focused users have that disabled.
- marcan_42 5y agoI assume they have iMessage metadata on what accounts the NSO accounts talked to. The contents are E2E encrypted, but unless they have explicitly promised not to keep logs, they probably have the metadata logged.
- gjsman-1000 5y agoApple claims in their lawsuit that they have over 100 false iCloud accounts that were created, and is confident in their identities to the degree they are going to use them for standing to prove that NSO signed a legal agreement in the lawsuit. In which case, NSO f!@#ed up and left iCloud Messages Backup enabled, which stores unencrypted copies of the End-to-End messages and makes it trivial for Apple to alert any person that these accounts messaged to. That's one possibility.
- smoldesu 5y agoBecause the NSO group definitely used iMessage to communicate with one another...
- HatchedLake721 5y agoNot with one another. With targets
- deleted 5y ago[deleted]
- 5y ago
- schleck8 5y agoIt's one of the largest enterprises against state-funded specialists and intelligence agencies, this will be an interesting arms race.
- calebm 5y agohttps://en.wikipedia.org/wiki/Advanced_persistent_threat https://en.wikipedia.org/wiki/Advanced_persistent_threat
- trasz 5y agoDoes this include US-sponsored threats?
- Epitom3 5y ago"trust me bro"
- lurchpop 5y agoWhat if the state is the US demanding data using NSLs or dragnet warrants?
- atmosx 5y agoProbably related: https://www.apple.com/gr/newsroom/2021/11/apple-sues-nso-group-to-curb-the-abuse-of-state-sponsored-spyware/ https://www.apple.com/gr/newsroom/2021/11/apple-sues-nso-gro...
- ben_palaskas 5y agocompletely and absolutely based. I have ambivalent feelings about apple
- throwawaymanbot 5y agoWhat about their own "on device/phone" hash creating/matching surveillance set up?
- type0 5y agoWill it notify users about cybersecurity threats from the US authorities or will it obey the gag order?
- WarOnPrivacy 5y agoUS state attackers get to ruin lives with impunity.
- deleted 5y ago[deleted]
- bsaul 5y agoWonder if that works for USA targeting terrorists and how well that’ll play in court if a terrorist attacks was helped in that way. Edit : silly me, US doesn’t need that, they can simply ask for the data..
- authed 5y agocybersecurity treats include secret orders by governments to comply to any requests?
- iJohnDoe 5y agoHow can Apple differentiate between state sponsored FISA hacks vs. other hacks or USA hacks? Before Apple sends a notification, do they cross reference any existing warrants they received and make sure they don’t notify the customer that the US tried to hack their account, or iPhone, or requested their info? Or are we to assume that Apple only means non-USA based attacks? Or is the US gov going ape shit right now that all their targets they been infiltrating are going to get notified of that fact? Or are we to assume anything FISA related means Apple happily and willingly had over the data and really isn’t a hack attempt?
- fortran77 5y agoSo Apple is saying they can’t solve their security problems?
- dvhh 5y agoThat sound like it, but then again the security problem could be a user issue.
- WarOnPrivacy 5y agoThe state-sponsored cybersecurity threats I most want to know about are the ones from my country - because that is the state most likely to harm me and my family.
- max47 5y agothey'll only do it if the US government allows them to. Like it or not, if they go against three-letter-agencies in the US, high ranked apple employees will spend years in jail based on the rulings of secret courts where all of your rights are irrelevant. The moment the cia says the word "terrorism", all your rights are gone regardless of how wrong the investigators might be. They can literally declare you guilty without you even knowing you were were accused of anything because according to them, national security is more important than the constitution. they are on the same level as the ccp
- 8fingerlouie 5y ago> they'll only do it if the US government allows them to. This is a warning that someone is trying to gain unauthorized access to your account. If the US government wants access it probably has better methods than brute force, such as ordering Apple to hand over your stuff.
- jmondi 5y ago> they are on the same level as the ccp Nonsense.
- docmars 5y agoProof?
- Thorrez 5y agoThere's a difference between a warrant with a gag order and noticing that someone is trying to hack into a user's account. I see no reason to think Apple will want to stay silent about an attacker trying to hack a user's account just because they might stay silent about warrants with gag orders.
- max47 5y agoYou think I'm taking about BS gag orders or NDA agreements.... When we're talking CIA, you can't get your way out of it with a better lawyer of by paying a fine. It's a decade of jail waiting for you if you don't bend over and give them exactly what they want. You have no constitutional rights when it comes to national security. they are legally allowed to kill US citizens without having to get court approval if they think they are a threat to the nation.
- vincentpants 5y agoDoes it tell you about US sponsored cybersecurity threats?
- eptcyka 5y agoYet you still can't download VPN apps in China and Saudi Arabia.
- chaosisequal 5y agoWill it send notifications also when it is a USA sponsored attack? What a joke
- chaosisequal 5y agoDoes this include USA sponsored attacks? This again another attempt at owning the device or your customer, like that CSAM backdoor wasn’t enough, now they have AI monitoring accounts, connections, etc out of each device.
- upofadown 5y agoAn interesting spin. So Apple might somehow treat just regular threats differently in the past or the future? How does Apple know who paid NSO group to hack their phone?
- raxxorrax 5y agoThis is a good service since states felt it was necessary to use surveillance powers against the domestic population. To me that warrant retaliation in my opinion, it would be a case for self-defense. For example isolating the trojan in a honey-pot OS and delivering it to foreign actors cybersecurity research labs. Just make it unfeasible to support such software and it will stop. My country (Germany) sadly is prone to ignore civil liberties. There were home searches because someone called a some minister a penis on Twitter and there were other severe transgressions. Since the law doesn't protect against them anymore, the state has proved that it is not capable for responsible conduct with software the relies on zero-day-exploits which endanger every computer system. Glad that companies with real security expertise put up the slack here, although they shouldn't have to do that.