Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. GPT-6 Sol and Luna(openai.com)
    587comments
  2. Claude Opus 5.5(anthropic.com)
    790comments
  3. 'We hacked the FBI:' Hackers say they have data on all FBI employees(404media.co)
    254comments
  4. OpenAI GPT–6 Astra breaks Enigma message that has resisted solution since 2005(cryptocellar.org)
    356comments
  5. ReBarUEFI: Resizable BAR for almost any UEFI system(github.com/xcuri0)
    19comments
  6. Microsoft killed FoxPro in 2007. Anyway, here's FoxPro revived(foxscript.org)
    117comments
  7. What California is learning from solar panels built over irrigation canals(kqed.org)
    122comments
  8. SAML: A fractal of bad design(trailofbits.com)
    84comments
  9. Claude Opus 5.5 Intelligence, Performance and Price Analysis (Max)(artificialanalysis.ai)
    65comments
  10. Unreal Agent(unreallabs.ai)
    72comments
  11. WordPress: Unauthenticated path traversal leading to conditional RCE(github.com/wordpress)
    79comments
  12. The new CC, an AI agent built for families(blog.google)
    2comments
  13. Pentagon says overreliance on AI contributed to missile strike on Iran school(bloomberg.com)
    205comments
  14. How did AMD Ryzen get 50% faster in two years?(lemire.me)
    69comments
  15. MUNI Heritage Weekend in San Francisco(lawrence.lu)
    40comments
  16. Native apps written in TypeScript and CSS(github.com/geastack)
    21comments
  17. The current balance of power in open models(interconnects.ai)
    8comments
  18. OpenAI is well positioned to fast-follow Jev(arcturus-labs.com)
    190comments
  19. Show HN: JevBench, a reproducible benchmark for typed decision models(benchmarkheaven.com)
    11comments
  20. Markdown in /src(htmx.org)
    42comments
  21. Obscura: VPN that can't log your activity(obscura.com)
    72comments
  22. The UV index is not the warm sensation of sunlight on bare skin(asciitweezers.com)
    49comments
  23. George Lucas Returns to Earth, Bearing Gifts(commonedge.org)
    39comments
  24. Make Math Automatic with Mathy(gmays.com)
    1comments
  25. People hooked on vapes try a new way to quit: cigarettes(bloomberg.com)
    89comments
  26. Show HN: Training a model to identify AI web content from structure alone(arxiv.org)
    9comments
  27. 16-bit Intel 8088 chip (c. 1985)(allpoetry.com)
    13comments
  28. The JavaScript Midlife Crisis(maroun-baydoun.com)
    15comments
  29. Apple has added persistent 'ads' to iOS, and it's driving users crazy(techradar.com)
    451comments
  30. Launch HN: Coverage Cat (YC S22) – Umbrella insurance via your personal agent(coveragecat.com)
    24comments

Dozens of Al Jazeera journalists allegedly hacked using NSO Group spyware

111 pointsby 5y agotheguardian.com
22 comments
5y agoHN ↗

Journalists can't seem to keep up with the latest threat model material. I'm wondering if a resource for journalist training is a good idea considering the resources stacked against them.

5y agoHN ↗

More of a failing of AJ's IT dept than anything else. Not sure if they were using AJ issued devices but they should be on managed devices that get updated on schedule, which may have mitigated this attack. Journos aren't necessarily deeply technical folks, that's really not their core competency.

5y agoHN ↗

When you work in a sensitive environment such as the middle east as a journalist, one really needs to go overboard and keep an insulated protection layer - separate devices, clean contacts, Tor and VPN, the whole gamut. It is the journalist's responsibility in such environments to ensure their survival and make sure that they don't engage in something stupid.

I presume AJ, just like the others, tends to use a lot of freelancers - in fact, they pay out some of the highest commissions to freelancers. Most freelancers are responsible for their own lives.

5y agoHN ↗

Read the details on this attack. They were running the latest software. I wouldn’t be surprised if the devices were managed in some way too. It doesn’t matter. This highly-targeted attack couldn’t be mitigated and that’s exactly the point.

5y agoHN ↗

??? From TFA?

Researchers at Citizen Lab said the apparent malicious code they discovered, which they claim is used by clients of Israel’s NSO Group, made “almost all” iPhone devices vulnerable if users were using an operating system that pre-dated Apple’s iOS 14 system, which appears to have fixed the vulnerability.

Edit: and that's almost not relevant to my point - what I'm saying is that journalists aren't inherently technical people, and that the work of reading reports on the latest exploits and vulnerabilities and developing countermeasures should probably go to someone else in their org

5y agoHN ↗

And my point is that with this attack, that wouldn’t matter. The exploit was state-sponsored and specifically targeted and was going after even up to date (at the time) devices. Citizen Lab was only able to glean as much information as it was in one case because the journalist reached out 7 months before he was hacked and they gave him a VPN they could use to monitor his traffic logs. The journalist was a key part of figuring this out, which goes against your entire point that the IT department would have caught this.

They wouldn’t have and they didn’t. This isn’t a scenario where you can blame lack of information or talk about who is or is not inherently technical. It was state-sponsored targeted hacking.

5y agoHN ↗

Many journalists who are frequently engaging in conversations that would be deemed highly sensitive are keeping up with the latest thread model material and following best security practice, moreover, the circumstances we know in this case make me question if any individual outside of the most security paranoid, could have prevented being hacked in this way.

This was an iOS 0-day that appears to have targeted iMessage [1] and worked via zero-click, meaning user interaction wasn’t necessary. CitizenLabs says that in one case, the initial vector appears to be Apple’s own servers.

So you’ve got people with modern (if not the latest) phones running the latest software on what is considered to be the most secure mobile operating system and you have highly-targeted attacks that appear to be state-sponsored, with high precision, going after these individuals.

What could education do to help in this case? Literally every single person I know, and this includes some extremely sophisticated security experts, would have been victims here too.

In the abstract, I agree with more training — though I’ll offer that these resources are widely available already in many newsrooms — but in this case, it would have done nothing.

[1]: https://citizenlab.ca/2020/12/the-great-ipwn-journalists-hac...

5y agoHN ↗

Why are companies that stockpile zero-days for resale legal? Aren't they also a threat to the countries that host them, even if some or all of the intelligence is shared?

And why aren't countries that host these companies sanctioned?

5y agoHN ↗

NSO is owned by a European company Novalpina Capital with headquarters in London.

5y agoHN ↗

My original comment asked if we should assume that the NSO Group arsenal is shared with the Israeli Intelligence Community, given that we've talking about an Israeli company.

That's a valid question, because hosting such a company is a major diplomatic liability. Why would you consider this question, as you said, a slander?

5y agoHN ↗

But they are not an "Israeli Company". They are owned by a European Private Equity group, with HQ in London, despite what the Guardian's "reporter" "Jassar Al-Tahat" says.

Should we assume that comments and logs for Hacker News are all shared with the UK Intelligence Community because Paul Graham was born in Weymouth, UK?

5y agoHN ↗

Technically the joint venture between Novalpina Capital and two of the original founders have a majority stake on the company.

Is ARM a Japanese company because it's (currently) owned by SoftBank? Will it be American when Nvidia takes over? Or are they a British company because they are based in the UK?

5y agoHN ↗

But they are not an "Israeli Company". They are owned by a European Private Equity group, with HQ in London, despite what the Guardian's "reporter" "Jassar Al-Tahat" says.

Yes, Novalpina Capital purchased a majority stake in NSO Group in February 2019. NSO Group was and still is an Israeli company, with headquesters in Herzliya, Israel. The company will cease to be an Israeli company, when it stops being under the jurisdiction of Israel.

Again, I don't understand how any of this made my question a slander. And why are you mocking the author of the article?

Should we assume that comments and logs for Hacker News are all shared with the UK Intelligence Community because Paul Graham was born in Weymouth, UK?

HN and Paul Graham are not in the weapons trade business, but yes, you should assume that all of this is monitored, though not because of Paul Graham's place of birth.

5y agoHN ↗

To add a personal note, I came here to ask questions, to learn something new, and to try understanding how any of this is allowed to happen. You've ruined my experience and this thread for no reason. Please don't ever do that again.

5y agoHN ↗

Especially because this hasn’t been the first time the commenter has done this. ‘fortran77, you’ve been around here a while. You should know better than to engage in pedantic nationalistic battles.

5y agoHN ↗

Israel sure does siphon off intel with all their companies, but it's not strictly limited to just them though.

Also it's definitely not slander, they always just seem to get pissy anytime one calls them out.

5y agoHN ↗

I'm willing to go one step further and say that NSO Group is operated by and is a core part of Israeli intelligence. It just has layers of deniability baked into the business structure like any good limited liability entity.

What it comes down to is that with NSO group:

1. Israel has access to the best 0-days it needs

2. The knowledge to develop further exploits is maintained within the Israeli intelligence apparatus

3. Israel is able to dominate the digital intelligence apparatus of autocratic regimes and, as a consequence, be able to defend itself against those tools

4. Israel is able to use it as a back channel for establishing and maintaining relationships, as well as exerting power and leverage on those nations

Given that it is an Israeli-government entity, much like the rest of the Israeli government, it is politically untouchable and buried under layers of denial. It's a direct, toxic exploitation of the relationship that Western countries maintain with Israel.

5y agoHN ↗

The same reasons that the companies that make guns, bombs, and tanks are legal.

5y agoHN ↗

Journalists as messengers have always been targeted, and even killed, and it seems that Apple’s messaging system was the attack vector here.

While the article decries NSO for being nefarious and selling to suspect “authoritarian” countries, high schools here in our democratic US have been buying hacking solutions to spy on students:

https://gizmodo.com/u-s-schools-are-buying-phone-hacking-tec...

5y agoHN ↗

Less than a decade ago NSO Group assisted the then president of Panama, Ricardo Martinelli, in spying his political adversaries. Around the same time Martinelli requested similar assistance from the US, but they refused his request (according to Wikileaks).

5y agoHN ↗

Join NSO! Protect your favorite colonial interests without the stigma of working for big tech!