4 ms·
If "crooks" as a category would be so stupid, we wouldn't have crime at all. While good, this is fishing the ocean with a fishing rod to me. The comfiest, surf
by joebiden2 3y ago
If "crooks" as a category would be so stupid, we wouldn't have crime at all.
While good, this is fishing the ocean with a fishing rod to me. The comfiest, surface-nearest and most trusting fish get arrested, which ironically could well be strengthening the real underground.
- c7DJTLrn 3y agoThe smart crooks use Signal on iOS with backups off. Maybe a VPN for good measure.
- joebiden2 3y agoI think the real crooks do the old-fashioned stuff. Like, not use a smartphone at all for criminal things. Just use expendable workers over two or three layers of hierarchy :)
- account-5 3y agoIs signal on iOS safer than signal on Android?
- wmf 3y agoYes, just because iOS itself is harder to hack. For example there are trivial evil maid style attacks against Android: https://www.tiktok.com/@android_infosecurity/video/7185907898814352645 https://www.tiktok.com/@android_infosecurity/video/718590789...
- CommitSyn 3y agoSecurity 101: Physical compromise is full compromise. If someone with the means has access to your unlocked iPhone, it's game over as quickly as Android. Remember JailbreakMe? That was the NiceGuy™ version of iPhone hacking. Now companies bill governments millions of dollars for iPhone jailbreaks and you can't even sideload apps after.
- deleted 3y ago[deleted]
- hsbauauvhabzb 3y agoAs time goes on the cost of physical attacks increases. This was more true in the 90s when secure boot and FDE weren’t a thing, sure it’s still possible but it’s much harder now.
- CommitSyn 3y agoSecureboot and FDE will still protect against this. The attack in the linked video just uses a flipper zero to mimic someone holding your phone and disabling protections then installing malware. Even if the phone was on, unencrypted, and locked it would fail. Edit: I initially misunderstood where you were coming from. Yes, today things are more secure, but if someone has unfettered physical access to your device they can just as easily install hardware that waits for you to login and then do these things or replace your charger plug (on a mobile device) or use a modified Bluetooth or USB proxy to keylog (on a full device). We're of course getting into high-level corporate attacks at that point if to be unnoticed (i.e. no popups, prompts, unexpected changes), so the average user is much more safe.
- hsbauauvhabzb 3y agoPretty much, iOS jailbreaks were common and free, now they’re worth millions (assuming they can be exploited remotely). At some point, if you have physical access and the device pin, you should assume it’s game over, but there may also be a point in time where we no longer care about physical security as much, if at all.
- Kostchei 3y agoNo. Actual criminals are going much deeper than that. Custom hardware, custom apps, custom servers. Sometimes it works, sometimes they get this.
- c7DJTLrn 3y agoAre you speculating or is there precedent for this? I highly doubt even the largest criminal organisations are producing custom hardware or software.
- 55555 3y agoThe largest cartels operate their own cell networks and have dedicated proprietary technology and netsec divisions.
- boeingUH60 3y agoEl Chapo’s cartel had their proprietary cell network, but the FBI simply grabbed up the cartel’s technology/IT head and threatened him into giving them access. https://amp.cnn.com/cnn/2019/01/09/americas/el-chapo-it-technician-rodriguez/index.html https://amp.cnn.com/cnn/2019/01/09/americas/el-chapo-it-tech...
- themoonisachees 3y agoGood old $5 wrench attack.