Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×
Security Iphone Apple

Amnesty International Confirms Apple's Warning to Journalists About Spyware-Infected iPhones (techcrunch.com) 75

TechCrunch reports: Apple's warnings in late October that Indian journalists and opposition figures may have been targeted by state-sponsored attacks prompted a forceful counterattack from Prime Minister Narendra Modi's government. Officials publicly doubted Apple's findings and announced a probe into device security.

India has never confirmed nor denied using the Pegasus tool, but nonprofit advocacy group Amnesty International reported Thursday that it found NSO Group's invasive spyware on the iPhones of prominent journalists in India, lending more credibility to Apple's early warnings. "Our latest findings show that increasingly, journalists in India face the threat of unlawful surveillance simply for doing their jobs, alongside other tools of repression including imprisonment under draconian laws, smear campaigns, harassment, and intimidation," said Donncha Ã" Cearbhaill, head of Amnesty International's Security Lab, in the blog post.

Cloud security company Lookout has also published "an in-depth technical look" at Pegasus, calling its use "a targeted espionage attack being actively leveraged against an undetermined number of mobile users around the world." It uses sophisticated function hooking to subvert OS- and application-layer security in voice/audio calls and apps including Gmail, Facebook, WhatsApp, Facetime, Viber, WeChat, Telegram, Apple's built-in messaging and email apps, and others. It steals the victim's contact list and GPS location, as well as personal, Wi-Fi, and router passwords stored on the device...

According to news reports, NSO Group sells weaponized software that targets mobile phones to governments and has been operating since 2010, according to its LinkedIn page. The Pegasus spyware has existed for a significant amount of time, and is advertised and sold for use on high-value targets for multiple purposes, including high-level espionage on iOS, Android, and Blackberry.

Thanks to Slashdodt reader Mirnotoriety for sharing the news.
This discussion has been archived. No new comments can be posted.

Amnesty International Confirms Apple's Warning to Journalists About Spyware-Infected iPhones

Comments Filter:
  • by sinkskinkshrieks ( 6952954 ) on Saturday December 30, 2023 @05:37PM (#64117631)
    Maybe consider using a dumb phone and analog methods instead? Mobile phones are complete listening devices, GPS trackers, comms intercepting, and video surveillance packages all-in-one. Same goes for tablets, smart home devices, and laptops.
    • They can probably just find their voice on any call across the telecommunications networks at this point with voice recognition.
    • After what I've learnt about SIGINT & journalists from following stories about Wikileaks, whistle-blowers, & investigative journalists, it sounds to me like it'd be a good idea to include SIGINT training on journalism courses, e.g. How to get your photos/footage/recording/documents & accompanying analyses & reports out of Saudi Arabia/Israel/Iran/North Korea/UK & reduce your risk of being intercepted at borders or abducted by security services, i.e. publishing the stuff as early as possi
  • by BitterOak ( 537666 ) on Saturday December 30, 2023 @05:46PM (#64117651)
    Rather than warning journalists that their phones may be compromised, why doesn't Apple instead patch the vulnerabilities so the phones won't be infected in the first place!?!?
    • Because laws and money. Ain't that a bitch?

    • by Anonymous Coward

      Then the US government wouldn't have access.

    • Presumably, they donâ(TM)t know how to patch the attacks. It wouldnâ(TM)t surprise me if Pegasus was exploiting side channel and timing attacks similar to spectre. Many of those hardware attacks canâ(TM)t easily be patched without crippling performance.

    • Just a guess... Apple probably has added detection code for known previous flaws, possibly a few bugs were fixed that the Pegasus team didn't even know were fixed (it likely takes at least a few days between an OS update, there new tests to detect what still works/doesn't work and a new version of Pegasus - and then the users of Pegasus need to upgrade to that version which likely takes at least a few more days). So with every OS update, Apple (and Google and Microsoft... they're also targets of this sort o

  • Sad (Score:5, Insightful)

    by Retired Chemist ( 5039029 ) on Saturday December 30, 2023 @06:16PM (#64117697)
    It is sad watching Indian democracy collapse under a fascist bigot. India has the potential to be a great country, but it is rapidly sinking into dictatorship and anarchy.
    • by Anonymous Coward

      It's always been like that under Modi (now almost a decade). However reporting about India has been always in good light irregardless to what India does due to US trade and not military tensions with China. If something bad is reported about India, it quickly leaves the news cycles within days. India assassinated someone in Canada. India kicked out dozens of Canada's diplomats when that happened. Canada didn't kick out India's diplomats, except the person they thought was in charge of the assassination

    • Their gov is quickly turning into an international pariah.
    • by gweihir ( 88907 )

      They did elect him, right?

  • with iOS17.2.1 is this ios version vulnerable? i checked the app store for Pegasus detection apps and nothing for it
    • "Pegasus detection apps" - an ios app written by a third party should not be able to detect what other apps are installed on my phone. Including Pegasus. IOS itself could, obviously. And probably has, because otherwise how did Apple manage to earn these people?
    • There probably isn't much value in a detection app, at least not that uses the current instance of the OS (Pegasus probably has good code to hide its tracks in memory well). Pegasus, by its nature, is exploiting a set of unknown vulnerabilities. The moment they are known, they get fixed fairly quickly. Pegasus is (probably... I am just speculating) finding new vulnerabilities all the time and retiring the ones that have been fixed. As I mentioned in a previous post, there is a window between when a new OS v

    • https://www.forbes.com/sites/d... [forbes.com]

      The human rights organization Amnesty International has developed a utility that allows you to identify this malware. It is called MVT (Mobile Verification Toolkit), and its source code is available on GitHub.

      The MVT utility is compatible with Android and iOS, but there are no ready-made solutions for the quick installation of the application. They need to be compiled for a specific device, which can be done only on a computer with Linux or macOS.

      The utility saves a backup copy of the data from the smartphone on the computer, scans all data and checks if the device is infected with the Pegasus spyware, and informs the user if information from his device could be compromised and transferred to third parties.

      This utility, in particular, scans data transfer logs - it is there that infection indicators can most likely be found (information about sending calls history, SMS, IM messages, and other things to a remote server). On iOS, these logs are stored longer than on Android, so it is much easier to detect the Pegasus spyware on the iPhone. Given the complexity of using the Mobile Verification Toolkit, this utility should only be recommended for tech-savvy users or those who suspect Pegasus is tracking them.

  • I mean, they assassinated a Sikh on Canadian soil and then threw a shit fit of denial and defiance when our PM pointed it out.

  • Dog that got hit, barks. They did elect that asshole though, right?

    • by dryeo ( 100693 )

      The question with these types is whether the re-election was a fair election. When you jail or assassinate political opponents, do things like removing a large States status as a State, suspend parts of the Constitution and are in charge of vote counting, it becomes questionable whether the re-election was honest.
      Lots of dictators started out by honestly getting elected.

      • by gweihir ( 88907 )

        Indeed, including the worst of the worst. Makes one almost wish that such cretins get judged in the afterlife. (Which I do not think happens, you just get reincarnated someplace again.) Trump tried it too, but was too incompetent. But the American people may be stupid enough to give him a 2nd chance.

        • by dryeo ( 100693 )

          What is scary is how many people are attracted to authoritarianism. Something like a third of the population are authoritarian themselves and find authoritarians very attractive, throw in a lot of repeated bullshit, as it seems if you repeat a lie enough, it is believed, and the need for a change and they get elected, often with a big enough majority that they can change things to stay in power.

          • by gweihir ( 88907 )

            Yep. About that many people do not want freedom, for themselves or anybody else. It scares them deeply.
            Good reference I found that explores this more: https://theauthoritarians.org/ [theauthoritarians.org]

            • by dryeo ( 100693 )

              Oh, they want freedom, look at the names, "Freedom Caucus" "Moms for Liberty" etc. Just their view of freedom is freedom for themselves to remove others freedoms. They heard the meme that "Your freedom to swing your fist ends where my face is" and think it means that you are in the wrong to have a face and remove their freedom to swing their fist, making you the enemy.

              • by gweihir ( 88907 )

                Well, they are so scared of the concept of freedom that they even try to redefine the word...

  • We are helping Apple all of the time on TRADE and so many other issues, and yet they refuse to unlock phones used by killers, drug dealers and other violent criminal elements. They will have to step up to the plate and help our great Country, NOW! MAKE AMERICA GREAT AGAIN. #maga #magaAGAIN #trump2024

Dynamically binding, you realize the magic. Statically binding, you see only the hierarchy.

Working...