TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

iMessage, Apple Music used by NSO Pegasus to attack journalist iPhones

325 pointsby esensalmost 4 years ago

11 comments

3pt14159almost 4 years ago
I dated a journalist once. She used some random free app for phone calls because recording calls isn&#x27;t built into iOS and she needed to record calls. I suggested a small device for her to plug her headphones through, but she declined.<p>I&#x27;m sure there&#x27;s a few journalists out there that take cybersecurity seriously, but I&#x27;d wager the vast majority are pretty trivially monitored.
评论 #27883999 未加载
评论 #27883707 未加载
评论 #27884288 未加载
评论 #27886858 未加载
评论 #27883949 未加载
wolverine876almost 4 years ago
&gt; However, it is unlikely that Pegasus will be a problem for the vast majority of iPhone users. While the tool is used as intended against criminals by governments, the attacks against innocent people are seemingly against those who could be critics to a regime, including journalists and human rights activists.<p>Attacks against the freedom of others and critics of government are a much larger threat to ordinary people than if they were surveilled themselves.
评论 #27884938 未加载
评论 #27888050 未加载
coldcodealmost 4 years ago
Just because it was only used to target journalists, supposedly, does not mean someone could not also target random individuals. I doubt NSO has such control over their customers that the uses can&#x27;t be expanded to almost anything, like blackmail, theft and harassment.
sneakalmost 4 years ago
This coupled along with the fact that iMessage&#x27;s E2EE has been backdoored by the non-E2EE iCloud Backup key escrow is a good argument for leaving iMessage, FaceTime, and iCloud all turned off on a device.<p>I go one step further and leave the SIM card out, which means the SMS vulnerability path is closed too.
评论 #27883537 未加载
评论 #27883457 未加载
评论 #27883558 未加载
nonameiguessalmost 4 years ago
Apple needs to make it possible for users to choose other ways of sending and receiving messages and listening to music, or of choosing not to do either of those things if they don&#x27;t want to. Obviously, you can currently install and use other applications that provide the same functionality, but you cannot uninstall or disable defaults.<p>The most shocking experience to me in trying to evaluate the Mac ecosystem when they released the M1 and I bought a Macbook Air is being in meetings where I&#x27;m using bluetooth headphones, take the headphones off and put them back on, and music.app automatically opens and comes to the foreground of my desktop. There is no supported way of disabling this user-hostile anti-feature. I look on Google and StackOverflow and all of the suggestions for how to disable it dating back to 2014 or whenever no longer work. Apparently, the likely answer is turn off System Integrity Projection, reboot, rename or remove the file containing the application launcher, turn SIP back on, and hope that doesn&#x27;t break anything else and hope Apple doesn&#x27;t revert your changes on the next system update.<p>That did not seem worth it. The fact that Apple Music can and has been used as an attack vector makes it even worse that it is so tightly integrated with the audio subsystem of the hardware as to take over your device thanks to movements you are making in the physical real world even when you may not be touching the device at all.<p>I just can&#x27;t understand what the thought process was in making this a default behavior, let alone one that cannot be disabled.
评论 #27884738 未加载
评论 #27884470 未加载
评论 #27885562 未加载
评论 #27884102 未加载
评论 #27884338 未加载
评论 #27884319 未加载
评论 #27886595 未加载
评论 #27889240 未加载
comodore_almost 4 years ago
there are apparently 50k names in that list, last I&#x27;ve checked they confirmed ~180 journalists are among them. spying on journalists is atrocious, but who are the other 49.800?
评论 #27885021 未加载
评论 #27884954 未加载
skarzalmost 4 years ago
I like the end of the article, he says &quot;its concerning, but unless you happen to be a major critic of a government, you probably won&#x27;t be a target of the spyware tool&quot;<p>Yeah, okay.
j45almost 4 years ago
I wonder if there is a way to disable iMessage and iTunes usage.<p>With windows server I used to have a target of balance in any attack footprint.. if Microsoft provided the OS, the component services that the server exists to provide should always try to be third party software (db, web server, etc) to try and minimize one type of escalation vulnerabilities… while possibly opening up to another, hopefully less worse set of holes.
评论 #27886848 未加载
评论 #27886123 未加载
max_almost 4 years ago
Time for a cyber security focused smartphone?
评论 #27883712 未加载
评论 #27884150 未加载
评论 #27884054 未加载
评论 #27888076 未加载
评论 #27884502 未加载
评论 #27884119 未加载
评论 #27883718 未加载
评论 #27886256 未加载
评论 #27883940 未加载
评论 #27883759 未加载
hugh-avheraldalmost 4 years ago
An intelligence agency cannot have the following properties simultaneously:<p>(1) The ability to detect espionage from China and Russia (2) The inability to access journalists&#x27; phones<p>If you want an intel agency to be able to thwart Chinese intelligence activities, you can&#x27;t also publicly state you won&#x27;t be looking closely into members of a profession who act a lot like spies.
评论 #27885344 未加载
评论 #27884453 未加载
TravisHuskyalmost 4 years ago
I have never heard of MVT (Mobile Verification Toolkit) before this article, but now I may just have to test it out; seems like an interesting project.