TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Apple will notify users about state-sponsored cybersecurity threats

538 点作者 evercast超过 3 年前

37 条评论

imarid超过 3 年前
I know of one case of a Polish prosecutor who does not obey (do not want to bend the law) Zbigniew Ziobro, who is both the minister of justice and the prosecutor general. She received a notification from Apple just today.<p>Source: <a href="https:&#x2F;&#x2F;mobile.twitter.com&#x2F;e_wrzosek&#x2F;status&#x2F;1463551631648251915" rel="nofollow">https:&#x2F;&#x2F;mobile.twitter.com&#x2F;e_wrzosek&#x2F;status&#x2F;1463551631648251...</a>
评论 #29335167 未加载
评论 #29335940 未加载
评论 #29341568 未加载
BluSyn超过 3 年前
I see a lot of pessimism in the comments. But I think this is a great step in the right direction.<p>Other companies should take note. More of this, please!
评论 #29334148 未加载
评论 #29334225 未加载
评论 #29336059 未加载
评论 #29334489 未加载
评论 #29335849 未加载
thih9超过 3 年前
I&#x27;m surprised to see protection against state sponsored attacks implemented by a company as big as Apple. Is any other &#x27;mainstream&#x27; company offering a similar feature?<p>Warrant canary [0] comes to mind, but that is usually a message to all users, as opposed to notifying an individual user.<p>[0]: <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Warrant_canary" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Warrant_canary</a>
评论 #29337351 未加载
评论 #29333946 未加载
评论 #29334703 未加载
boomboomsubban超过 3 年前
So something like PRISM that targets everybody won&#x27;t trigger a warning?
评论 #29334515 未加载
评论 #29335016 未加载
评论 #29336745 未加载
评论 #29333999 未加载
type0超过 3 年前
Will it notify users about cybersecurity threats from the US authorities or will it obey the gag order?
评论 #29337921 未加载
jaegerpicker超过 3 年前
I wonder if this could be used to expose those that are in sensitive position. IE offer attacks at people you think are in important positions and watch how they react to the news. For example if you work somewhere sensitive and you have an accounts not tied the Apple account. The State Sponsored group is probably good enough to see your traffic patterns and to see if they change after you have been notified. Not that I think Apple shouldn&#x27;t do this but I can see someone being crafty and trying to take advantage of this. There are always trade offs in security!
kube-system超过 3 年前
I see a lot of people in the comments conflating legal requests and attacks. Regardless of your opinion on either of those issues, they <i>are</i> different things.
评论 #29335298 未加载
raxxorrax超过 3 年前
This is a good service since states felt it was necessary to use surveillance powers against the domestic population.<p>To me that warrant retaliation in my opinion, it would be a case for self-defense. For example isolating the trojan in a honey-pot OS and delivering it to foreign actors cybersecurity research labs. Just make it unfeasible to support such software and it will stop. My country (Germany) sadly is prone to ignore civil liberties. There were home searches because someone called a some minister a penis on Twitter and there were other severe transgressions. Since the law doesn&#x27;t protect against them anymore, the state has proved that it is not capable for responsible conduct with software the relies on zero-day-exploits which endanger every computer system.<p>Glad that companies with real security expertise put up the slack here, although they shouldn&#x27;t have to do that.
max47超过 3 年前
they&#x27;ll only do it if the US government allows them to.<p>Like it or not, if they go against three-letter-agencies in the US, high ranked apple employees will spend years in jail based on the rulings of secret courts where all of your rights are irrelevant. The moment the cia says the word &quot;terrorism&quot;, all your rights are gone regardless of how wrong the investigators might be. They can literally declare you guilty without you even knowing you were were accused of anything because according to them, national security is more important than the constitution.<p>they are on the same level as the ccp
评论 #29341598 未加载
评论 #29338662 未加载
评论 #29338177 未加载
notkurt超过 3 年前
Has anyone put forward some theories as to how they are pulling this off? Are they tapping into iMessage Metadata, scanning crash logs, or something along those lines? While I totally understand the need for them to keep how they are doing this private, I do find it slightly concerning. Unless they are just flagging suspicious iCloud login attempts. If it’s relating to crash logs, it would be nice to know as I’m sure a bunch of privacy focused users have that disabled.
评论 #29334871 未加载
评论 #29335033 未加载
评论 #29337178 未加载
nabakin超过 3 年前
Now if only Apple wouldn&#x27;t search for CSAM on device, allowed repair shops to get the parts they need from the manufacturer, and provided schematics for repair shops. If they did those things, I might actually buy an iPhone.
评论 #29338521 未加载
bsd44超过 3 年前
&quot;If Apple discovers activity consistent with a state-sponsored attack&quot;<p>I am really interested in understanding more about a &quot;state-sponsored attack&quot; as someone who works in Ops and has experience in CyberSec. All these years working in the industry and I had no idea you could identify an &quot;attack&quot; that easily.
评论 #29334352 未加载
评论 #29334060 未加载
评论 #29334084 未加载
评论 #29335767 未加载
评论 #29334073 未加载
vincentpants超过 3 年前
Does it tell you about US sponsored cybersecurity threats?
iJohnDoe超过 3 年前
How can Apple differentiate between state sponsored FISA hacks vs. other hacks or USA hacks?<p>Before Apple sends a notification, do they cross reference any existing warrants they received and make sure they don’t notify the customer that the US tried to hack their account, or iPhone, or requested their info?<p>Or are we to assume that Apple only means non-USA based attacks?<p>Or is the US gov going ape shit right now that all their targets they been infiltrating are going to get notified of that fact?<p>Or are we to assume anything FISA related means Apple happily and willingly had over the data and really isn’t a hack attempt?
protomyth超过 3 年前
Why do I get the feeling that if the state is China, then it won&#x27;t get reported as such. I assume their supply chain is more important.
评论 #29334078 未加载
评论 #29333870 未加载
eptcyka超过 3 年前
Yet you still can&#x27;t download VPN apps in China and Saudi Arabia.
WarOnPrivacy超过 3 年前
The state-sponsored cybersecurity threats I most want to know about are the ones from my country - because that is the state most likely to harm me and my family.
FridayoLeary超过 3 年前
Even if the state in question is the USA? I think Apple should be clear if there are any states whose attacks they might ignore, for the sake of privacy, of course.
varispeed超过 3 年前
It&#x27;s only possible because Apple is too big too fail. Probably they won&#x27;t notify about the US snooping, but smaller countries often have smaller budgets that this company, so they can&#x27;t really do anything about Apple pulling strings. It&#x27;s a shame that smaller companies cannot do that without risking being closed down.
atmosx超过 3 年前
Probably related: <a href="https:&#x2F;&#x2F;www.apple.com&#x2F;gr&#x2F;newsroom&#x2F;2021&#x2F;11&#x2F;apple-sues-nso-group-to-curb-the-abuse-of-state-sponsored-spyware&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.apple.com&#x2F;gr&#x2F;newsroom&#x2F;2021&#x2F;11&#x2F;apple-sues-nso-gro...</a>
cblconfederate超过 3 年前
What if it is illegal to do so?
评论 #29335177 未加载
评论 #29338672 未加载
chaosisequal超过 3 年前
Does this include USA sponsored attacks?<p>This again another attempt at owning the device or your customer, like that CSAM backdoor wasn’t enough, now they have AI monitoring accounts, connections, etc out of each device.
lurchpop超过 3 年前
What if the state is the US demanding data using NSLs or dragnet warrants?
calebm超过 3 年前
<a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Advanced_persistent_threat" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Advanced_persistent_threat</a>
upofadown超过 3 年前
An interesting spin. So Apple might somehow treat just regular threats differently in the past or the future? How does Apple know who paid NSO group to hack their phone?
questiondev超过 3 年前
except in china, i pray that the people of the free world unite from within all countries and say enough is enough to their oppressors. it is wild to think that we still have ill actors in high ranks that are from bloodlines upon bloodlines of “ownership” of nations. there really still is a ruling class that has existed forever, sounds like a conspiracy until you look at who is buddies with who
schleck8超过 3 年前
It&#x27;s one of the largest enterprises against state-funded specialists and intelligence agencies, this will be an interesting arms race.
funman7超过 3 年前
What if you opted in to the terms of the Chinese App Store then switch to USA.
评论 #29334798 未加载
chaosisequal超过 3 年前
Will it send notifications also when it is a USA sponsored attack?<p>What a joke
fortran77超过 3 年前
So Apple is saying they can’t solve their security problems?
评论 #29337958 未加载
bsaul超过 3 年前
Wonder if that works for USA targeting terrorists and how well that’ll play in court if a terrorist attacks was helped in that way.<p>Edit : silly me, US doesn’t need that, they can simply ask for the data..
authed超过 3 年前
cybersecurity treats include secret orders by governments to comply to any requests?
ben_palaskas超过 3 年前
completely and absolutely based. I have ambivalent feelings about apple
zenlf超过 3 年前
Unless, it&#x27;s Chinese government. In that case, Apple handle over their control over database to Guizhou-Cloud Big Data
评论 #29333956 未加载
trasz超过 3 年前
Does this include US-sponsored threats?
Epitom3超过 3 年前
&quot;trust me bro&quot;
gambiting超过 3 年前
Will it let them know that their own phone has decided that they are a potential pedophile and their photos will be sent unencrypted to some tech centre god knows where where someone will decide whether to report them to authorities or not? Or is that ok to keep secret?