10 ms·
I suspect a strong link between mass surveillance (by corporations for advertising or by states for intelligence purposes) and the very recent targeting of the
by boramalper 1y ago
I suspect a strong link between mass surveillance (by corporations for advertising or by states for intelligence purposes) and the very recent targeting of the senior Iranian nuclear scientist and military officers at their homes in Iran.
Wherever you are from or whatever side of the conflict you are on, I think we can all agree that it’s never been easier to infer so much about a person from “semi-public” sources such as companies selling customer data and built-in apps that spy on their users and call home. It allows intelligence agencies to outsource intelligence gathering to the market, which is probably cheaper and a lot more convenient than traditional methods.
“Privacy is a human right” landed on deaf ears but hopefully politicians will soon realise that it’s a matter of national security too.
- htowi3j4324234 1y agoIf a state actor is after you, cookie and GAIA-id tracking should be the least of your concerns.
- VagabundoP 1y agoWhat always shocks me is how much negligence is shown by politicians and cyber inteligence wrt to standard mobiles. Anyone who runs a country, especially senior politicians, just shouldn't have a standard mobile. It should be a built from the ground up phone by your own countries government services. Running GrapheneOS or something. And you shouldn't have a second phone to have your affairs either.
- yapyap 1y ago> “Privacy is a human right” landed on deaf ears but hopefully politicians will soon realise that it’s a matter of national security too. lol. lmao even. this is the holy mary of security, politicians (US) will not give a damn as long as they’re not the ones being targeted and as long as the ad giants like google and co keep lining their pockets.
- Tokumei-no-hito 1y agomaybe the recent attack in minnesota will change their mind - the shooter used data brokers for his plan https://www.wired.com/story/minnesota-lawmaker-shootings-people-search-data-brokers/ https://www.wired.com/story/minnesota-lawmaker-shootings-peo...
- aussieguy1234 1y agoWeather apps are one of the worst offenders here. Almost all share your location info with data brokers if you give them location access. Check the weather today, get bombed tomorrow.
- FridayoLeary 1y agoTo be fair that's pretty much the forecast in both Iran and israel at the moment.
- aussieguy1234 1y agoYep, tomorrows forecast: raining fire
- bongodongobob 1y agoPoliticians are just the sales and marketing department for multinational corporations and defense contractors. They will never care.
- FilosofumRex 1y agoAlmost all of Iran's cell network system was originally installed by S. Korean firms. They've changed some to Chinese brands, but apparently the compromised S. Korean brands are still around.
- Digital28 1y agoChanging from SK to CN is a trade from intentional vulnerability to unintentional vulnerability. I’ve yet to see a secure piece of software come out of China in my 30+ years of coding.
- dragonelite 1y agoBetter to swallow the poison that doesn't kill you(for now) than to swallow the one that is intended to kill you.
- Dah00n 1y agoYet in telco it is much easier and faster to get a bug fixed in Chinese equipment. IMO it is more likely you don't work with critical infrastructure than the problem being Chinese equipment.
- ReptileMan 1y agoSupermicro IPMI comes to mind. If it was compromised we would have known by now.
- toast0 1y agoThere's a lot of vulnerabilities, of course. Supermicro isn't great at releasing updates for old boards either. https://www.cve.org/CVERecord/SearchResults?query=supermicro https://www.cve.org/CVERecord/SearchResults?query=supermicro
- nullc 1y agoMany vendor IPMI is so fiendishly hard to isolate from untrusted networks (or even networks in general) that it almost has to be an intentional backdoor.
- mike_d 1y ago> I suspect a strong link between mass surveillance [...] and the very recent targeting of the senior Iranian nuclear scientist and military officers at their homes in Iran. We all like to imagine this super cool clandestine hacking operation using peoples mobile phones to secretly track people who visit nuclear facilities back to their homes. The much more logical explanation is someone approached a low level employee at the MEAF who turned over a USB stick with the governments org charts and payroll records in exchange for their kids getting a full ride to a prestigious foreign university.
- boramalper 1y agoIsrael, like any other state, must be using a variety of methods including good old "human intelligence" so it's not either-or. In addition, saying that > someone approached a low level employee at the MEAF who turned over a USB stick with the governments org charts and payroll records in exchange for their kids getting a full ride to a prestigious foreign university is an oversimplification on multiple levels: 1. Low-level employees typically don't have access to sensitive information. 2. With human intelligence, there is always a risk that the person you (e.g. Israel) are in touch with (e.g. an Iranian officer) who pretends to be a "double agent" (e.g. leaking info to Israel), is in fact a "triple agent" (e.g. actually working for Iran to mislead Israel). 3. You can send your kids to foreign universities but not your siblings, your parents, your wife's family, and so on... Some of your beloved ones are almost certain to suffer the consequences of your actions. High treason is no joke.
- bigfatkitten 1y ago> 1. Low-level employees typically don't have access to sensitive information. Snowden was a contract Sharepoint admin. He was on the absolute bottom of the org chart.
- SirHumphrey 1y ago> 1. Low-level employees typically don't have access to sensitive information. You would think, but when I was interning (well, it was a paid internship) for a company, I was fixing an excel spreadsheet with payroll information for an entire department of a few hundred people. Not the best piece of "opsec", but when you are in a hurry (pay was due in a couple of days) and most people are on vacations "hey the junior kid can probably fix it, he seems fine" is a way too common approach. And it is fine - sometimes for a long time. Until it isn't.
- chaosbolt 1y agoI suspect Israel has backdoor access to most CPUs. Here is how Pegasus seems: - China has 1.5 billion people, lots of resources, would profit a lot economically if they found a way to hack iOS, etc. But yet couldn't hack it. - Israel with its 7 million people, not only hacks iOS multiple times, but does it to spy on its allies. Now I've seen the threads analysing Pegasus' complexity, I don't know if it's been reproduced, and if it has then I guess it logically proves me wrong (the tinfoil hatter in me still thinks its right though). Here is why: Israel has a lot of silicon fabs or R&D centers, now it makes ZERO sense for the US to have fabs or R&D centers in Israel, since that country is (allegedly) always at the risk of being bomber for no reason at all (yeah right). Intel has had fabs in Israek since the 80s, why not in Japan or France or the UK (France and the UK are close allies to the US and have no earthquakes or risk of being bombed), why not even Canada? And I compared the dates of when intel started putting the Intel Management Engine in all of their CPU and the date of which they built their biggest fab in Israel, then I went down the rabbit hole of when AMD started using PSP (similar tech to Intel ME), and it coinciding with it buying a large pentesting startup in Israel, then starting to build its R&D centers there, Apple and Qualcomm have similar stories. Obviously this is all tinfoil, and while the dates coincide it's obviously not enough. But to each their own, and I choose to treat my tech as if it was all was backdoored already, because for me the evidence (while not enough to be sure) is enough for how much I value my privacy.
- bsaul 1y ago[flagged]
- cma 1y agoMany are also US citizens who could work at research labs in the US without a visa. Something like 50K or 100K of the illegal settlers in the occupied West Bank alone are US citizens.
- saagarjha 1y ago> China has 1.5 billion people, lots of resources, would profit a lot economically if they found a way to hack iOS, etc. But yet couldn't hack it. What makes you think China can't hack iOS?
- PartiallyTyped 1y agoEuropol now argues that privacy is not a right and that we need to “think of the children”. EU is now pushing some abhorrent policies and legislation to demand backdoors. We, the people, need to demand and force our politicians to work for us.
- kragen 1y agoThe truth is far outside the Overton window. Yes, privacy is a question of civil defense in the drone age. But the existing crop of states will never acknowledge that; their structure and institutions presume precisely the kind of mass databases of PII that create this vulnerability, as well as institutional transparency for public accountability. This makes them structurally vulnerable to insurgencies that expropriate those databases for targeting. The existing states will continue to clutch at their fantasies of adequately secured taxpayer databases until their territorial control (itself an anachronism in the drone age; boots on the ground can no longer provide security against things like Operation Spiderweb) has been reduced to a few fortified clandestine facilities. Things are going to be very unpredictable and, I suspect, extremely violent.
- fpoling 1y agoThis has been going on in Russia on massive scale. For bribes officials sells anything including highly sensitive databases. Those were used to uncover various Kremlin-run assassins targeting oppositions. Then Ukrainian special services used those to target high-ranking Russian military officers. Russia tried to crack down on that but it just increased the database price tag.
- kragen 1y agoDo you have sources for that? No problem if they're not in English.
- ponector 1y agoHere is an example of such investigation into russian general: https://youtu.be/alUPgLLIxeM?si=0x1QtJrJf2yfPCZi https://youtu.be/alUPgLLIxeM?si=0x1QtJrJf2yfPCZi Or investigation into some russian topics: https://theins.ru/en/inv https://theins.ru/en/inv
- dredmorbius 1y agoThis is sufficiently-well established presently that it's almost hard to find specific documentation as it's largely accepted fact. I'm finding few hits post-2019, so it's possible that data practices have improved. WNYC's On the Media carried several interviews with a documentarian filming Alexy Navalny as Navalny and the documentarian team identified Navalny's (initial) would-be assassins, including various FSB agents. They specifically targeted a person they'd think might have weak opsec, a scientist directly engaged in producing nerve agents (novichok IIRC). His core competence was chemistry rather than spycraft. The documentary team included a former Bellingcat investigator: Brooke Gladstone: In the months following Navalny's poisoning, Christo Grozev, former lead Russia investigator at Bellingcat, was stuck in Vienna with filmmaker Daniel Roher. The two had just been booted from Ukraine where they had been trying to film an investigation. Now Grozev had lots of time on his hands and a laptop and a fresh stack of data from the Russian black market.... Christo Grozev: When we were looking at the Navalny poisoning, we thought, "Well, they must have used the same scientists. They can't have hundreds of scientists who do this. This has to be kept top secret. These people have to take the risk to manufacture this toxin." I started looking at the phone records of these scientists, and we bought them on the Russian markets where you can buy absolutely any kind of data.... [Navalny's people] provided the data of how Navalny had traveled to what locations. I matched it to the known travel data of the poisoners and spies. We saw this pattern, essentially a group of six to eight FSB poisoners had been tailing him for more than four years to a total of 66 different towns and cities. <https://www.wnycstudios.org/podcasts/otm/episodes/revisiting-documentary-navalny?tab=transcript https://www.wnycstudios.org/podcasts/otm/episodes/revisiting...> Other general coverage (searching "russia black market data"): "Russian data theft: Shady world where all is for sale" (26 May 2019) According to cyber-security experts, vast quantities of supposedly private data - including from Russian state institutions - are bought and sold every day.... <https://www.bbc.com/news/world-europe-48348307 https://www.bbc.com/news/world-europe-48348307> And for a long time. From 2009: Goldmine of black market in Russian data Gorbushka Market, just outside central Moscow, does a thriving trade in any electronics good you could want: mobile phones, plasma television sets, the latest DVDs, and, if you ask to see them, software peddlers will show potential clients a list of “databases”. These consist of CDs with names such as “Ministry of Interior – Federal Road Safety Service”, “Tax Service” and “Federal Anti-Narcotics Service” and cost about $100 apiece. Each contains confidential information gathered by Russian law enforcement or government agencies: anything from arrest records, personal addresses, passport numbers, phone records or address books to bank account details, known associates, tax data and flight records are on offer... <https://www.ft.com/content/07dedd34-d921-11de-b2d5-00144feabdc0 https://www.ft.com/content/07dedd34-d921-11de-b2d5-00144feab...> Archive: <https://archive.is/UPPHK https://archive.is/UPPHK> And 2005: "In the stolen-data trade, Moscow is the Wild East" <https://web.archive.org/web/20050708015611/http://www.globetechnology.com/servlet/story/RTGAM.20050705.gtrussia05/BNStory/Technology/ https://web.archive.org/web/20050708015611/http://www.globet...> Adjacent article on Bellingcat OSINT generally (2024), though nothing on black markets: "The forensic empire that is Bellingcat" <https://www.theprojectcounselgroup.com/2024/06/19/the-forensic-empire-that-is-bellingcat/ https://www.theprojectcounselgroup.com/2024/06/19/the-forens...>
- lm28469 1y agoIf you're a valuable enough target, like these Iranians generals/scientists they just need to find you once and then they can continuously track your movements via satellite. They don't need much precision, just which building to level
- beeflet 1y agothis is a totally illogical way of understanding warfare in terms of absolutes. Not every target is worth leveling a building over. It isn't that black and white
- mousethatroared 1y ago"Just which building to level" What's "just" a war crime amongst friends?
- Henchman21 1y agoWhen there is no one willing to prosecute it, is it still a crime?
- consp 1y agoYes, though one without consequences. Until the next guy comes along and actually enforced it.
- bawolff 1y agoNothing stopping Iran from joining the ICC. Except that the investigations would go both ways.
- mousethatroared 1y agoPalestine is a member and we all saw what happened there. The US has personally threatened the judges.
- bawolff 1y ago
- footlose_3815 1y agoSomeone needs to go into congress and demonstrate to them, live, how easy it is to lift their phone numbers and call them all at once.
- larrled 1y ago“hopefully politicians will soon” The gop is controlled by donors who are mostly free market liberals. Elon won’t let anyone “censor” (regulate) x. The democrats don’t care about national security historically, and it’s not currently an issue their cosmopolitan TikTok loving base cares anything, at all, about. “Security” is something that most democrats I talk to now associate with deportation or military spending, both of which they ferociously hate. Across parties, policy and discourse are reactive. Security requires a proactive orientation that it seems the public sector may structurally lack.