top | item 47034754

(no title)

ExoticPearTree | 13 days ago

Keep your devices always up to date and limit the number of apps you use (lower attack surface).

If paranoid, use a different device to access suspicios apps/sites with nothing on it.

discuss

order

hmmmmmmmmmmmmmm|13 days ago

How do we know it is not rigged with an explosive like the Pagers?

Edit: https://news.ycombinator.com/item?id=45763674

"Cohen (former head of Mossad) insisted that the publicly recognized success against Hezbollah was merely one element of a far wider, systematic deployment of sophisticated devices worldwide, although notably abscent in the Gaza Strip."

ivl|13 days ago

His claim there did not necessarily imply rigged explosives, but supply chain attacks either for surveillance or assassination purposes.

And his limiting it to "virtually every potential theater" would suggest that it's mostly present in Lebanon, Syria, Iran, Yemen, most likely Iraq as well.

But let's be honest here, this isn't civilian equipment that's been compromised. It's supply chain attacks where the buyer is manipulated into buying goods that they've tampered with, or re-engineered. They weren't pagers anyone could pick up at Radio Shack. (Everyone who got hit was a target, or a direct relative of a target.)

magicalhippo|13 days ago

Take it with you on an international trip or three. Surely those airport scanners will pick it up.

foolserrandboy|13 days ago

We know because we're not shooting rockets at them.

ignoramous|13 days ago

> limit the number of apps ... lower attack surface ... If paranoid

While true in general, super apps that do too many things and used by billions (WhatsApp, Chrome, TikTok, Instagram, CleanMaster etc) are big enough of an attack surface already.

Defenses (compile-time / runtime memory safety & control flow integrity, media coders/decoders, sandboxes, for example) are getting better & so exploits are getting expensive.

> use a different device to access suspicios apps/sites with nothing on it

While using different devices is good enough, it requires the end user to maintain strict isolation (and sometimes may require appropriate features from the OS). Using burners is an extreme version of this practice.

gruez|13 days ago

>super apps that do too many things and used by billions (WhatsApp, Chrome, TikTok, Instagram, CleanMaster etc)

One of these are not like the others...

dietr1ch|13 days ago

Burners seem extreme, but old used hardware still seems the best and only way you can sort of prove isolation on your own.

You can't trust software not to be buggy and both, hardware, and software not to be purposely compromised because "think of the children" (that the EFs proved to be BS).

jsheard|13 days ago

And if you use iPhones and have reason to be really paranoid, consider using lockdown mode.

https://support.apple.com/en-us/105120

PlatoIsADisease|13 days ago

Has android been hacked?

I only know pegasus broke iOS.

I find it interesting that Apple has spun Lockdown mode from a 'we are terrible at security' into a feature for marketing.

Now when someone gets hacked Apple can say: "Well they weren't in lockdown mode, its their own fault."

Gosh I wish I was as good at marketing as Apple. They really need to sell their marketing team as a service. If they did that, I'd buy their stock outright.

iririririr|13 days ago

two last attacks from paragon for pixel devices uses the modem firmware. these things doesn't help much.