Of the 67 phones Amnesty's Security Lab probed, 34 were iPhones, of which 23 showed signs of a successful Pegasus infection and the others showed attempts
Washington Post
Related Coverage
Discussion
-
@lorenzofb
Lorenzo Franceschi-Bicchierai
on x
Why would you pay your PR people to write 2,800 words in an email and then forbid journalists from quoting any of it? Dear Apple, this is a ridiculous PR strategy. https://www.washingtonpost.com/ ... https://twitter.com/...
-
@kimzetter
Kim Zetter
on x
“The text delivered last month to the iPhone 11... made no sound. It produced no image. It...delivered malware directly onto her phone—and past Apple's security systems... The hacked phones included an iPhone 12 with the latest of Apple's software updates.” https://www.washington…
-
@violetblue
Violet Blue®
on x
Guy Rosen, who founded FB's Onavo VPN app that was legit spyware, got pulled when caught. Connects to NSO's Pegasus b/c according to NSO court docs, FB wanted Pegasus b/c Onavo's spying on iPhones was too limited: https://www.vice.com/... https://twitter.com/...
-
@dinodaizovi
Dino A. Dai Zovi
on x
I do think iOS' security capabilities from Apple's vertical integration of hardware + software is a super-power and leads to best-in-class security engineering and features. The challenge is that due to their monoculture, they have to be ridiculously better at it than Android.
-
@reedalbergotti
Reed Albergotti
on x
At the same time, Apple has done some really advanced things with security, like using purpose-built processors to protect devices. But those projects happen internally and are based more on hypotheticals, not specific threats like NSO Group.
-
@carissaveliz
Carissa Véliz
on x
Even #BigTech is calling for #NSO to be stopped. In this case, @WhatsApp's CEO. #WhatsApp was right to sue #NSOGroup But let's not forget that everyone who has normalized #surveillance is complicit in the attempted murder of #democracy. 8 https://twitter.com/...
-
@mfinkel
Matt Finkel
on x
Me: How does Android compare? Article: “three of the 15 Android phones examined showed evidence of a hacking attempt” Me: But...? Article: “but that was probably because Android's logs are not comprehensive enough” https://twitter.com/...
-
@reedalbergotti
Reed Albergotti
on x
But shareholders don't get paid in courage. Meanwhile, this hacking has a tremendous cost, hurting democracy around the world. So what's the answer? I certainly don't have them, but it's an issue I hope we talk about a lot more in the near future.
-
@ortegaalfredo
Alfredo Ortega
on x
iOS may have better security, but I don't think you can use a single exploit chain in >50000 Android targets. Too much variation. Apple lack of software diversity is its downfall. https://twitter.com/...
-
@asymco
Horace Dediu
on x
@spwells @tangojoshua Don't worry, the EU has got your back. Apple will be forced to allow side-loading of apps which are not subject to privacy or security scrutiny.
-
@ashk4n
Ashkan Soltani
on x
Folks looking into @Apple / @NSOgroup: Follow The Money This ecosystem is incredibly well-resourced and fueled by govs / oligarchs who can afford to pay large sums to surveil their targets. A single limited shelf-life vuln can be worth upwards of $1M https://developer.apple.com/ …
-
@reedalbergotti
Reed Albergotti
on x
One former employee told me the security team would send canned responses (to ensure they would not be vetoed by the marketing team) to researchers who submitted bugs. That kind of communication does not lead to good relationships with security researchers.
-
@mfinkel
Matt Finkel
on x
Me: Okay. We don't know if there are fewer compromised Android devices because: 1) Google is just better than Apple at this, 2) market share, or 3) Google's not systemically better, but NSO doesn't have a zero-click vuln right now. Article: Think whatever you want.
-
@reedalbergotti
Reed Albergotti
on x
As @craiu told me, that means we don't know the extent of the problem. He said if Apple allowed more analysis of iPhones for malware, it would generate bad press, but make iPhones more secure. That takes courage, he said.
-
@parismartineau
Paris Martineau
on x
i don't think the average reader understands how much tech companies love restricting the amount of useful information journos can publish about their operations https://twitter.com/...
-
@mfinkel
Matt Finkel
on x
Me: So, Android? Article: “Google has a threat analysis team that tracks NSO Group and other threat actors” Me, great, soooo Android? Article: “A head-to-head comparison of the security of Apple's and Google's operating systems and the devices that run them is not possible”
-
@cesare_c
Cesare Coscia
on x
@ryanaraine I think their model of bundling security fixes with OS releases is destined to change. They need to move to micro services similar to Google to stay ahead of bad actors. It's an archaic model.
-
@jason_kint
Jason Kint
on x
WAIIIIIIITTTTTTTT Facebook's “VP of Integrity” who willingly put his name and reputation on the press release pushing back on White House co-founded Onavo (FB's surveillance tool)????? I entirely forgot about this. He's the VP of Integrity???? You can't make this garbage up. http…
-
@wcathcart
Will Cathcart
on x
Indeed. https://twitter.com/...
-
@dinodaizovi
Dino A. Dai Zovi
on x
There is a nuanced trade-off between security in a monoculture of targets versus in a diverse ecosystem. Artificial diversity such as ASLR isn't quite it. I spoke about this a bit just as my voice was completing giving out at Black Hat Asia in 2016: https://www.youtube.com/... ht…
-
@reedalbergotti
Reed Albergotti
on x
Apple has so many bugs that it can't fix them all, and can take years to implement fixes. It created a bug bounty program in 2016, which it says pays the most in the industry. But inside and outside the company, the view is that it has room for improvement. A lot of room.
-
@uzmabarlaskar
Uzma
on x
@matthew_d_green I wish they didn't have a dismissive tone because it impacts only a small group of ppl. Protection against mass surveillance may not be enough if all it takes to silence free speech are tapping journalists and the opposition. The trickle down impact of this can b…
-
@rohini_sgh
Rohini Singh
on x
Hello @Apple. When are you taking NSO to court? Why should people pay a premium on your products if they are so easy to hack into? https://twitter.com/...
-
@washingtonpost
@washingtonpost
on x
Pegasus, NSO's signature surveillance tool, can collect emails, call records, social media posts, user passwords, contact lists, pictures, videos, sound recordings and browsing histories, according to security researchers and NSO marketing materials. https://www.washingtonpost.co…
-
@matthew_d_green
Matthew Green
on x
I think it's amusing that we're still having a debate about breaking end-to-end encryption in a world where governments indiscriminately toss NSO at their political opponents.
-
@matthew_d_green
Matthew Green
on x
I sympathize with Ivan here. Imagine building up Apple's security for years and doing a great job, then finding out you also have to deal with the worst people, willing to spend infinite money on bespoke exploits — so they can murder journalists. https://twitter.com/...
-
@josephmenn
Joseph Menn
on x
Apple's iMessage is a hot mess. https://twitter.com/... https://twitter.com/...
-
@jasonhaw_
Jason Haw
on x
Of all the Pegasus news articles in the past 24 hours, this is probably the most disappointing because Apple likes to tout they have the most secure smartphones - the iPhone's security features are basically a dud against Pegasus https://www.washingtonpost.com/ ...
-
@alexhern
Alex Hern
on x
The security of iPhones is, Apple assures us, world class. But it hides an unspoken trade-off: the same restrictions that make it so hard to hack also mean users have to have total faith in iOS security. And when that fails, it fails hard: https://www.theguardian.com/ ...
-
@reginadulanjali
Regina Dulanjali
on x
Apple sent a 2800-word explanation to Washington Post defending iPhone but says Apple can't be quoted directly. Why can't Apple be quoted directly? BTW - heading of the Washington Post article is “Despite the hype, iPhone security no match for NSO spyware” https://twitter.com/...
-
@snowden
Edward Snowden
on x
“Apple restricts the access researchers have to iOS in a way that limits the ability of consumers to discover when they've been hacked.” https://www.washingtonpost.com/ ...
-
@jimwaterson
Jim Waterson
on x
This explanation of the Pegasus spyware and how it no longer even requires a target to click a dodgy link before gaining full access to the user's phone is pretty chilling. https://www.theguardian.com/ ...
-
@geoffreyfowler
Geoffrey A. Fowler
on x
Zero-click attacks “can work on even the newest generations of iPhones, after years of effort in which Apple attempted to close the door against unauthorized surveillance—and built marketing campaigns on assertions that it offers better privacy & security” https://www.washingtonp…
-
@snowden
Edward Snowden
on x
The text delivered last month to the iPhone 11 made no sound. It produced no image. It offered no warning of any kind as an iMessage from somebody she didn't know delivered malware directly onto her phone — and past Apple's security systems. https://www.washingtonpost.com/ ...
-
@khalidbshah
Khalid Shah
on x
Despite the hype, iPhone security no match for NSO spyware International investigation finds 23 Apple devices that were successfully hacked https://www.washingtonpost.com/ ...
-
@kimzetter
Kim Zetter
on x
Activists and journalists around the world who face imprisonment and potentially death are concerned about the security of their devices and the no-click malware that can silently infect their fully-patched phones, and Apple pr is concerned about being quoted https://twitter.com/…
-
@pwnallthethings
@pwnallthethings
on x
Or put it another way, we're past the point where we can seriously believe we'll ever bug-fix our way out of these parsers having exploitable bugs, and so now the question is where the investment is to replace them and why that investment is so low.
-
@pwnallthethings
@pwnallthethings
on x
For journos, a follow up question would be “how many engineers will Apple now assign to rewriting the exploited iOS image parsers in a memory-safe language” https://twitter.com/...
-
@pwnallthethings
@pwnallthethings
on x
A lot of problems in cybersecurity can't be fixed by just throwing engineers and money at it. But those specific parsers? This is an example where really can spend your way to closing the attack surface.
-
@datadrivenmd
Jorge A. Caballero
on x
🔥 This part of the story isn't getting enough attention: this espionage-for-hire company can turn any iPhone into a surveillance device without the user ever knowing about it— that means taking photos, turning on your microphone, and more https://twitter.com/...
-
@neilmacfarquhar
Neil MacFarquhar
on x
Claim by @Apple that iPhones thwart spyware are a lie as numerous rights activists, journalists and others have found that even their latest models were infected by Israeli-made,"zero-click" spyware called Pegasus. https://www.washingtonpost.com/ ...