[HN Gopher] Scan iPhone backups for traces of compromise by "Ope...
       ___________________________________________________________________
        
       Scan iPhone backups for traces of compromise by "Operation
       Triangulation"
        
       Author : j4nek
       Score  : 262 points
       Date   : 2023-06-02 12:45 UTC (10 hours ago)
        
 (HTM) web link (github.com)
 (TXT) w3m dump (github.com)
        
       | slobiwan wrote:
       | Slightly off-topic, but how do I download an iCloud backup so I
       | can scan it with this tool? The googles imply that I can only
       | recover my device from the cloud, not retrieve old backups for
       | other purposes.
        
         | LouisEleven wrote:
         | Maybe this will help you? https://securelist.com/find-the-
         | triangulation-utility/109867...
        
         | hummer_embark wrote:
         | [dead]
        
         | Tepix wrote:
         | Why don't you make a local backup?
        
           | slobiwan wrote:
           | Oh, got it. I thought the tool wanted to go back and walk
           | through a progression of previous backups. I can certainly do
           | a new backup
        
       | infotogivenm wrote:
       | Given how these 0days were clearly "burned" for this occasion
       | tells me the NSA has no shortage of them.
        
         | jerf wrote:
         | I think if we could somehow see all the "zero days" that are
         | out there that all of us, and I mean, things that exist _at
         | all_ , not just things discovered by some human and an exploit
         | written, even those in the industry and those well-endowed with
         | cynicism, would be surprised. I include myself even as I
         | expound this opinion.
         | 
         | Just "SELECT * FROM nsa_exploits" would probably turn all our
         | stomachs and I'd guess they still only have a small fraction of
         | what exists.
         | 
         | Software is to a large extent built on default-unsafe
         | primitives, and we wrest security from them at great effort and
         | with dubious efficacy. We _still_ have fights on HN about
         | whether or not  "memory safety" is necessary, and that is
         | frankly so far below the level we need to operate that it would
         | be humorous if it weren't sad. Granted, that fight is dying
         | down as we gradually converge on "yes, it's necessary", but
         | it's like level 2 and we need to be operating on level 18.
        
           | hsudvsish wrote:
           | > Just "SELECT * FROM nsa_exploits" would probably turn all
           | our stomachs and I'd guess they still only have a small
           | fraction of what exists.
           | 
           | good thing we live in a free democratic society!
        
             | renewiltord wrote:
             | We do. And a resilient free society creates agents that it
             | cannot police so that it can achieve its aims. No-ships are
             | necessary for the Secher Nbiw.
        
         | jeroenhd wrote:
         | I don't know about the current status quo, but three years ago
         | Zerodium stopped buying several types of iOS exploits because
         | of how many submissions they received:
         | https://www.macrumors.com/2020/05/14/zerodium-pauses-acquiri...
         | 
         | It's gotten to the point where full-chain Android exploits,
         | traditionally easier to find and use because of lacking update
         | policies and incompetent manufacturer chains, are worth more
         | than their iOS counterparts: https://zerodium.com/program.html
         | 
         | Because of iOS' excellent update rate and generally very secure
         | operating system model, I'd expect this to mean that there are
         | so many exploits for either platform that the trade of exploits
         | for the ostensibly more secure platform isn't restricted by the
         | amount of exploits anymore, but rather by the rate the existing
         | 0day stock gets burned by use.
         | 
         | I expect intelligence agencies to be fully stocked with more
         | 0days than they currently need. Not just intelligence agencies
         | either; for your average large international criminal
         | organization, whether it's the maffia or the NSO group, there
         | should be plenty of exploits to be found and bought.
        
           | joshspankit wrote:
           | And the iOS jailbreak community is _starved_ waiting for
           | single root-priv exploit because no one [wants to|can] give
           | them away for free any more.
        
           | swang wrote:
           | i think you're extrapolating a bit too much from that tweet
           | from more than 3 years ago considering they resumed buying
           | them ~6 months later.
           | 
           | https://twitter.com/Zerodium/status/1326498688621948928
           | 
           | now did they have too many? maybe. but maybe also because
           | they were expecting apple to announce a new ios at the wwdc
           | that was happening in june.. or maybe lots of 0-day
           | exploiters suddenly wanted to dump their exploits knowing
           | that apple was probably going to be patching them soon. oddly
           | enough that tweet about resuming payment coincided with the
           | release timeline of ios 14.
           | 
           | most of this is irrelevant though because we lack any
           | information. what is, "too many"? 10? 100? 1000? it could be
           | that just like any other middleman they sometimes need to sit
           | on "inventory" and they can't just buy up that many at one
           | time in case apple fixes them all in an update.
        
       | dmix wrote:
       | Context, imessage attachment based iOS exploit:
       | https://news.ycombinator.com/item?id=36151220
       | 
       | Seems pretty noisy IMO. It prevents software updates with visible
       | errors. I wonder if its just the limitations of iOS or its a non-
       | nation state actor. I noticed it modifies some Facetime files, I
       | wonder if it exploits the camera through that.
        
         | troad wrote:
         | > It prevents software updates with visible errors
         | 
         | Unfortunately, given the state of the Apple first-party
         | software, I doubt this would ring too many alarm bells.
         | 
         | If anything, were I to start getting visible errors, I'd
         | welcome the change from Apple's previous MO of simply silently
         | failing.
        
       | m3kw9 wrote:
       | If you are someone "important", You need to turn off iMessages as
       | that is a huge risk factor as it's a system app. There will
       | always be zero click exploits and that should be all you need to
       | know
        
         | kornhole wrote:
         | I am important, and so are you. I am not a person of interest
         | to state security. If you want to go next level, carefully use
         | an anonymous phone and a data only SIM card. This makes it more
         | difficult to identify your device to which any one click
         | exploit can be sent to the baseband or OS.
        
           | sampa wrote:
           | > I am not a person of interest to state security.
           | 
           | you might be surprised. you don't have to be somebody
           | important, you just might be working somewhere interesting or
           | know somebody important.
           | 
           | ps Snowden leaks showed NSA hacked ordinary broadband
           | providers administrators to get access to networks, because
           | POIs were using those providers.
        
         | darknavi wrote:
         | If you are "important" you should 100% run Lockdown Mode[0].
         | 
         | [0] https://support.apple.com/en-us/HT212650
        
       | londons_explore wrote:
       | If I was an intelligence agency, I would have one department
       | whose job is to 'get caught'. Ie. they use dumb methods to spy on
       | obvious targets, like using exploits to install malware that
       | leaves a wake of plenty of discoverable info and loudly sends
       | data back to the mothership.
       | 
       | I would then have another department whose job is to be as subtle
       | as possible - for example, all their exploits are 'in ram' and
       | all data sent back is plausibly deniable. (for example, rather
       | than using a random 256 bit nonce while establishing an HTTPS
       | connection to apple to check for updates, use 256 bits of
       | encrypted data you wish to exfiltrate)
        
         | DriverDaily wrote:
         | You want me to double your budget so you can get the same
         | amount of work done?
        
           | londons_explore wrote:
           | Do add a zero the the budget while you're at it please!
        
           | asmor wrote:
           | And probably triple the number of exploits burned on
           | senseless misdirection.
        
           | jerf wrote:
           | Intelligence does not get funded the same way that everything
           | else does. It has a history of being self-funding if
           | necessary. This could easily all be funded off the books via
           | a third department that simply straight-up acts as a
           | conventional ransomware attacker. I would be deeply
           | unsurprised most ransomware payouts ultimately land in some
           | intelligence budget for some country somewhere.
        
             | ciupicri wrote:
             | Rumors say that North Korea is behind some ransomware.
        
             | supriyo-biswas wrote:
             | Yup. For example, the US government recently sold $215M in
             | BTC originally seized from Silk Road operators[1].
             | 
             | [1] https://decrypt.co/125081/us-government-dumps-seized-
             | silk-ro...
        
             | RetpolineDrama wrote:
             | >It has a history of being self-funding if necessary.
             | 
             | Cocaine Import Agency
        
         | localplume wrote:
         | [dead]
        
         | alphaursaemin wrote:
         | If I was an intelligent person, I would use a basic phone for
         | making phone calls and not carry surveillance devices on my
         | person or have them in my house. This way I would not have to
         | worry about keeping up with agencies that operate above the
         | law, are accountable to none, and operate with huge budgets to
         | subvert the ethics and mores of capable people.
        
           | Cthulhu_ wrote:
           | I'm not sure what you understand to be a "basic phone", but
           | they are easily intercepted and traced (triangulation from
           | mobile phone towers, it's how the emergency services can
           | locate you if you dial 112 all across Europe).
        
             | londons_explore wrote:
             | One where you have to wind the handle to make a bell ring
             | at the other end?
        
               | hbn wrote:
               | Any self-respecting security industry veteran only
               | communicates using 2 cans on a string
        
             | alphaursaemin wrote:
             | Communication has always been known to be a risky endevour
             | with potential for various compromises, even for
             | sovereigns. That telephony and now network communication
             | infrastructure the world over is minimally at risk of, if
             | not subject to, surveillance is understood.
             | 
             | Carrying a general purpose computer of substantial
             | complexity that is equipped with state of the art sensors,
             | optics, and components (including ai), which is then topped
             | with yet another thick complex layer of software, which is
             | subject to known and unknown access (by various parties),
             | is not the same thing as a telephone (analog, digital,
             | wired, or not).
             | 
             | Today, unless in a secured EM cage, there really aren't
             | that many places where you can be certain you can have a
             | private conversation, face to face. Visiting friends? Alexa
             | and friends may be listening. Even the lousy TV sets :)
             | Walk in the park? Your companion likely has a smartphone.
             | 
             | A healthy society requires the availability of private
             | spaces and private interactions. When a citizenry becomes
             | aware of pervasive surveillance it self censors. Self
             | censorship prevents airing of views in an unemcumberred
             | manner. When views are constrained, problems remain
             | unaddressed.
             | 
             | Tyranny typically thrives in such insecure and non-optimal
             | circumstances.
        
               | runjake wrote:
               | Basic phones are computers running pretty shoddy
               | operating system distributions, like BREW, with serious
               | security issues.
               | 
               | If anything, you're making yourself more vulnerable with
               | a basic phone over an iPhone or Android device with
               | proper security practices.
        
               | nvy wrote:
               | >Today, unless in a secured EM cage, there really aren't
               | that many places where you can be certain you can have a
               | private conversation, face to face.
               | 
               | Even then the assurance is only so high. Governments
               | operate what are called SCIFs, Secure Compartmentalized
               | Information Facilities, where they not only conduct
               | physical exclusion and EM hardening but also acoustic
               | damping so that an adversary can't, in theory, listen
               | through the walls with a fancy stethoscope or a laser
               | microphone.
               | 
               | There's a scene from Neuromancer where Molly and Case pay
               | another character for a private discussion room, which is
               | basically a cyberpunk SCIF. I've always found that scene
               | oddly prescient; privacy today is quickly becoming a
               | luxury.
        
           | narrator wrote:
           | Have a really small 4g hotspot hotglued to a tiny Linux
           | computer running the Tails distribution read-only with a
           | removable SD card with all your data and no executable code
           | on it if you're a real cypherpunk.
        
             | capableweb wrote:
             | I'm guessing you're connecting to 4G with a sim card?
             | Essentially a small computer, so you're exposed that way
             | regardless.
        
               | narrator wrote:
               | The 4g is in the hotspot that you're connecting to via
               | wifi from the mini-computer. That way you don't have
               | baseband firmware exploits to deal with on the linux
               | machine like you would now with a traditional android
               | phone. 4G firmware are all binary blobs that probably
               | have backdoors.
        
               | kortilla wrote:
               | Hotspot. You assume the hotspot is compromised and only
               | connect via WiFi
        
             | predictabl3 wrote:
             | We really ought to push for something better than Tails.
             | I'd love to run something like it on an aarch64-linux or
             | riscv64-linux board. I'd love to run something that doesn't
             | have a hacked, nearly broken debian boot process, which
             | broke the ability to kexec it many versions ago, etc.
             | 
             | /me keeps (semi-)patiently waiting for SpectrumOS...
             | https://spectrum-os.org/
        
             | KMag wrote:
             | Why a hotspot instead of a USB 4g modem? Concerned about 4g
             | hardware/driver vulns but not WiFi hardware/driver vulns?
             | 
             | Edit: yes, I guess you're concerned about sim-resident
             | malware exploiting the modem, exploiting the rest of the
             | machine via USB.
             | 
             | Also, if you're that paranoid, you should probably be
             | running something seL4-based to better compartmentalize
             | compromises.
        
           | codetrotter wrote:
           | I tried going back to a basic phone again for a few months
           | some years ago.
           | 
           | Tbh the only two positives were:
           | 
           | - Battery would last several days on a single charge. I had
           | totally forgotten that that used to be the case.
           | 
           | - Less time wasted on social media etc.
           | 
           | But the drawback was immense!
           | 
           | For one, it was not until I put my smart phone away that I
           | realised just how valuable Google Maps is to me.
           | 
           | And of course, a lot of my communications with other people
           | are in various apps these days. SMS is just not very useful
           | at all now.
           | 
           | So the lesson learned was that it is better to have a smart
           | phone.
        
             | hsudvsish wrote:
             | isn't an regular offline gps device an option?
        
               | sethherr wrote:
               | No traffic updates, no transit directions, no bike
               | directions.
               | 
               | It's very much worse
        
               | daneel_w wrote:
               | Not to mention that map application availability was
               | equal to zero unless using the very latest breed of pre-
               | smart phones from the late 2000s, and even then it was
               | so-so.
        
               | codetrotter wrote:
               | Many of my searches in Google maps are also for things
               | like grocery stores etc. With a regular offline gps
               | device I would not have that
        
             | the_pwner224 wrote:
             | Any modern smartphone will have several days of battery
             | life, if not more, if you use it as a dumb phone (WiFi &
             | mobile data turned off, only using it for calls & SMS). My
             | Galaxy S5 (~8 years old now?) passively discharged at 1%
             | per day with WiFi & data disabled.
        
             | daneel_w wrote:
             | _> "- Battery would last several days on a single charge. I
             | had totally forgotten that that used to be the case."_
             | 
             | Several days? Surely you meant _weeks_? Unless you spent an
             | hour or two calling on the phone every day, of course.
             | 
             | I get 5-10 days out of my iPhone depending on desire for
             | leisure. In the "dumb" era the number was about 2-3 weeks,
             | even when I was young and always texting throughout the
             | day.
        
               | codetrotter wrote:
               | > I get 5-10 days out of my iPhone depending on desire
               | for leisure
               | 
               | I probably use the phone a lot more than you. My iPhone
               | has to be charged at least twice a day, and it's not even
               | that old. My current iPhone is an iPhone 14 Pro.
        
               | daneel_w wrote:
               | Yeah that definitely sounds like you're constantly on the
               | phone - or at the very least keep everything and then
               | some running in the background with app refresh and
               | location services etc. enabled.
        
               | codetrotter wrote:
               | Guilty as charged :p
        
               | seized wrote:
               | Don't you mean discharged?
        
               | smoldesu wrote:
               | > Unless you spent an hour or two calling on the phone
               | every day, of course.
               | 
               |  _That 's_ what people are using iPhones for these days?
        
               | daneel_w wrote:
               | _Talking_ on the phone, like some sort of psychopath...
        
               | [deleted]
        
           | fsflover wrote:
           | "Basic phone" can easily spy on you, too. Perhaps you need a
           | phone with open schematics and hardware kill switches.
        
           | FieryTransition wrote:
           | I think sim cards have been able to run java for quite a
           | while[0], and who knows what else they can do. So I guess
           | encrypted post cards it is.
           | 
           | [0] https://www.extremetech.com/defense/161870-the-humble-
           | sim-ca...
        
           | badpun wrote:
           | > surveillance devices on my person or have them in my house.
           | 
           | Unfortunately, even if you trust your "basic" phone to not be
           | compromised, it still means you can't have a personal
           | computer. From what I've read, that's the strategy used on
           | the Kremlin - for security reasons, they banned computers and
           | went back to typewriters.
        
           | tiahura wrote:
           | Don't forget the foil!
        
           | tivert wrote:
           | > If I was an intelligent person, I would use a basic phone
           | for making phone calls and not carry surveillance devices on
           | my person or have them in my house. This way I would not have
           | to worry about keeping up with agencies that operate above
           | the law...
           | 
           | Why do you assume a "basic phone" would protect you in any
           | way? It's far more likely to _only_ be capable of insecure,
           | easily interceptable forms of communication (e.g. SMS). Also,
           | it 's software is likely much worse than more popular phones
           | (e.g. an egregious example is cheap Android phones shipping
           | with malware preinstalled).
        
           | flerchin wrote:
           | So you'd make your phone calls in the clear?
        
             | SV_BubbleTime wrote:
             | Are you implying that calls made from smart phones are
             | anything but on the clear? Are you making all your voice
             | calls using some merging other than the phone app?
        
               | cj wrote:
               | A lot of people (especially outside the US) use whatsapp,
               | etc, for calling which happens over data/wifi rather than
               | traditional cellular.
        
               | Tepix wrote:
               | Many calls are made using apps these days. WhatsApp alone
               | had more than 15 billion voice minutes on average per day
               | back in 2020.
               | 
               | If your phone and the phone of the other party are not
               | compromised, it is indeed possible to conduct end-to-end
               | encrypted calls with perfect forward secrecy.
        
               | Scoundreller wrote:
               | Trick is to do the on-the-fly encryption and decryption
               | in your own brain.
               | 
               | Getting the key length up is a real challenge tho.
               | 
               | But WhatsApp (or... anything) would be great if it could
               | easily share PGP coded messages scanned in via QR codes.
        
               | BobbyJo wrote:
               | > If your phone and the phone of the other party are not
               | compromised, it is indeed possible to conduct end-to-end
               | encrypted calls with perfect forward secrecy.
               | 
               | That's something you can never rely on though.
        
               | SV_BubbleTime wrote:
               | And let's be honest, you would be foolish to think
               | WhatsApp isn't compromised by intelligence agencies.
        
               | Scoundreller wrote:
               | And has been used as a vector of device compromise
               | itself.
        
               | predictabl3 wrote:
               | I uh, y'all do know there are open source voip apps,
               | right? You can fire up most any popular Matrix client and
               | call me E2EE right now.
        
           | Ozzie_osman wrote:
           | You would need to, also, only communicate with other
           | "intelligent person"s because otherwise you might be in the
           | clear but the folks you call may not.
        
           | KingOfCoders wrote:
           | If I was an intelligent person, I would not spend so much
           | time on HN writing comments. But hey! ;-)
        
             | alphaursaemin wrote:
             | I am crushed by the awareness of my shortcomings, brother.
        
               | this_steve_j wrote:
               | This is probably my favoritest hot retake I have seen in
               | awhile.
        
         | 2OEH8eoCRo0 wrote:
         | Doesn't sound wise- especially when targeting security
         | researchers. The "dumb" method gets discovered and opened the
         | device to extreme scrutiny. Exploits should be considered
         | disposable because once they are used they can be discovered
         | and patched.
        
         | samstave wrote:
         | Chinese spies did a version of this against Lockheed...
         | 
         | They would phish lockheed/military folks with emails stating
         | "Hey we met at 'military conference' here is my contact file -
         | lets stay in touch"
         | 
         | The file had malware which would trickle very slowly data out.
         | 
         | it was discovered due to one user complaining about his machine
         | being slow... then it was discovered that it was _discovered_
         | and the chinese opened the fire-hose and the worms were
         | flooding the 3-egress points to the internet Lockheed had at
         | that time, until they could kill the connects and clean up the
         | system.
         | 
         | The other thing the chinese did was to infect 3rd party
         | suppliers who were supposed to be air-gapped, so they infected
         | machines at suppliers to go after any USB sticks that were used
         | to transfer info and get the malware back to Lockheed systems
         | via the USB transfer of info between contractors and
         | lockheed...
         | 
         | Which is basically how stuxnet managed to get its foothold.
        
         | nikcub wrote:
         | This is effectively what happens but not for that reason. Take
         | the CIA and NSA, and then the FSB and GRU - within each you
         | have different operational groups with different practices and
         | techniques each uniquely developed. Some are more advanced than
         | others based on both the spread and importance of the target.
         | Further, within these groups they would again separate out
         | their techniques based on the importance of targets.
         | 
         | Where this is an issue, which goes against your point - the
         | groups can step on each other toes. The discovery of the
         | broader and more detectable attacks invites attention, further
         | scrutiny and additional forensics which may uncover the more
         | sophisticated attacks.
         | 
         | Where the real deceptive action takes place is in learning how
         | other opposing groups operate and mimicking their tactics to
         | make the process of attribution more difficult.
        
       | transpute wrote:
       | The open-source Mobile Verification Toolkit scans local
       | iPhone/iPad backup images for filesystem IoCs (Indicators of
       | Compromise) cataloged in STIX format, https://docs.mvt.re &
       | https://github.com/mvt-project/mvt
       | 
       |  _> A collection of utilities to simplify and automate the
       | process of gathering forensic traces helpful to identify a
       | potential compromise of Android and iOS devices ... released by
       | the Amnesty International Security Lab in July 2021 in the
       | context of the Pegasus project along with a technical forensic
       | methodology.._
       | 
       | STIX IoC format, https://www.oasis-
       | open.org/2021/06/23/stix-v2-1-and-taxii-v2...
       | 
       |  _> The [threat intelligence] work was based initially on three
       | specifications contributed by the US Department of Homeland
       | Security (DHS) for development and standardization under the
       | OASIS open standards process: STIX (Structured Threat Information
       | Expression), TAXII (Trusted Automated Exchange of Indicator
       | Information), and CybOX (Cyber Observable Expression)._
       | 
       | iOS IoC sources, please add to this list:
       | https://github.com/AmnestyTech/investigations
       | https://github.com/citizenlab/malware-indicators
       | https://securelist.com/operation-triangulation/109842/
        
       | chrisfinazzo wrote:
       | Local, encrypted backups are a thing - use them.
       | 
       | It's debatable how useful this advice is for field agents, who
       | might not be carrying a computer with them all the time, but for
       | regular people it's entirely feasible.
        
         | delfinom wrote:
         | Your device is infected, the backups now contain a backup of
         | the infected device you didn't know because it was a covert
         | tool for years.
         | 
         | What now?
        
         | dagmx wrote:
         | how would a local, encrypted backup help here unless people
         | were constantly doing it and also did it before they were
         | compromised?
         | 
         | The issue here isn't backups. Cloud and local would be equally
         | affected if the system is compromised.
        
       | avodonosov wrote:
       | FSB statement, from the same day Kaspersky reported this exploit:
       | 
       | https://www-fsb-ru.translate.goog/fsb/press/message/single.h...
        
         | NotYourLawyer wrote:
         | Oh it's from the Russian government, so you KNOW it's
         | trustworthy.
        
           | Cthulhu_ wrote:
           | Name me one government that is trustworthy.
        
             | NotYourLawyer wrote:
             | There are degrees of trustworthiness.
        
               | saiya-jin wrote:
               | Nope. Either there is trust, period, or there isn't. In
               | this case there simply isn't, and if you are non-US
               | person then US government definitely 100% falls into that
               | category. We don't have same human rights you have as per
               | US laws god dammit, how can we talk about any trust here.
               | Our interest are momentarily aligned is the best we can
               | go for.
               | 
               | Which is not the end of the world in any means, but lets
               | be factual and act accordingly.
        
               | mmastrac wrote:
               | That's a classic false dilemma. While the US government
               | is not perfect by far and has MANY flaws, the Russian
               | government is an entirely different level of corrupt.
        
               | impeplague wrote:
               | US corruption is a worldwide operation effort. Russia's
               | is at best significant on Eurasia and US. It will take
               | Putin some time to reach US level.
        
             | throwaway290 wrote:
             | A government that maintains a procedure for regular
             | peaceful replacement of itself?
        
               | seanw444 wrote:
               | You totally couldn't exploit that, right?
        
               | throwaway29812 wrote:
               | You can exploit anything, what's your point? There is
               | still a fundamental difference at play.
        
               | sampa wrote:
               | replacing talking heads from 2 parties (that you are
               | allowed to choose from) does not equal replacing
               | government
        
               | throwaway29812 wrote:
               | Are you implying there was no fundamental difference
               | between the Obama and Trump governments? Clinton and
               | Bush?
        
               | sampa wrote:
               | fundamental, of course, no. you're allowed to choose from
               | 2 parties, thinking you're making a difference.
        
           | [deleted]
        
           | chrisfinazzo wrote:
           | If you talk to certain old people - like my parents, one is
           | 70 and other will hit the mark this November - they might
           | say, "Russia? Like, the KGB?" and then I can quote Robbie
           | Coltrane's Valentin in The World is Not Enough...
           | 
           | "Now it's FSB. Federal Security Bureau. Same friendly service
           | with a new name."
        
           | [deleted]
        
         | judge2020 wrote:
         | is that a wildcard subdomain that takes the subdomain and does
         | `s/-/./g` to proxy and translate it? Or is this only for
         | russian media-related websites you probably don't want to be
         | visiting directly?
        
           | pieter_mj wrote:
           | Yes, it's a wildcard subdomain, works for every site.
        
           | glth wrote:
           | Do you mean `s/./-/g`?
        
           | avodonosov wrote:
           | That's google translate. The original is in Russian.
        
       | AlbinoDaffy wrote:
       | iMazing supports same kind of scanning based on open source
       | Mobile Verification Toolkit. Plus overall better backup
       | management for iOS and iPadOS compared to iTunes even on free
       | tier
       | 
       | https://imazing.com/guides/detect-pegasus-and-other-spyware-...
        
       | cynicalsecurity wrote:
       | Warming: Kaspersky is a fierce supporter of the Putin's fascist
       | regime. His company is known for working for FSB. Think twice
       | before running any software created by them on your computer.
       | 
       | I would recommend to fork it, thoroughly analyse every line of
       | code and run it on a dedicated computer without internet. Always
       | keep in mind you can't trust them at all.
        
       | buildbuildbuild wrote:
       | Cautionary note: many entities do not allow running Kaspersky
       | software including this tool.
       | 
       | https://en.wikipedia.org/wiki/Kaspersky_bans_and_allegations...
        
         | psychphysic wrote:
         | Or just read the 300 lines of python it entails
        
         | chewmieser wrote:
         | Good point but it's also a pretty small open source python
         | script. Looks like everything is handled on-device in this case
         | (at least at the time of writing this comment).
        
           | kfrzcode wrote:
           | That doesn't necessarily matter to your enterprise device
           | usage agreement.
        
         | AHOHA wrote:
         | FUD by other AV makers.
        
           | nikcub wrote:
           | it's impossible to build any type of business in Russia
           | without being tied to the state.
        
           | dwater wrote:
           | FUD stands for Fear, Uncertainty, and Doubt. But the comment
           | you're replying to is a factual article that lists what
           | entities have restricted use of Kaspersky software and under
           | what circumstances. You may think that the arguments against
           | Kaspersky are FUD, but this post is not.
        
             | AHOHA wrote:
             | I know very well what FUD stands for.. and there's nothing
             | factual in whatever links up there, it's all allegations
             | with no proof that resulted in a government ban
             | 
             | >There's no evidence that they have any back-doors in their
             | software or any ties to the Russian mafia or state...
             | 
             | It's just to happen that an NSA spy contractor was detected
             | by an anti virus software that's basically doing its job.
             | 
             | All AV software are technically malware to prevent other
             | malwares, and old AV -including kaspresky, used to operate
             | in an offline manner unless you update the local db, then
             | things evolved to the need to have a cloud service to
             | upload and analyze new suspicious files, in fact, the new
             | ones -EDR- do more intensive tasks than AV by real time
             | monitoring what the user does, analyzing the traffic,
             | programs opened, forensics, and data collection for further
             | analysis and immediately uploaded to the cloud (or the
             | MDR), that's part of its design, banning something because
             | it did its job detecting a spy software IS a complete FUD
             | only to happen that the business is in X country or an
             | allegation that its CEO or founder worked in X.
             | 
             | If you are serious about security, using windows to start
             | with shouldn't be your first choice, but if you have no
             | options in here and you have to use an AV, would you choose
             | an AV made in the same country you are in (or in the same
             | intelligence alliance like the 5 eyes/14 eyes), or would
             | you choose an external one how you usually do with a VPN
             | for example? At the end of the day, AV or even EDR it's
             | just another software that can be bypassed, exploited, and
             | even targeted with zero day attacks, so base your personal
             | policy about these facts and not outsourcing yours to NSA
             | or some spy agency.
        
               | suction wrote:
               | [dead]
        
             | anaganisk wrote:
             | So we pretty much love the closed nature of "Open" AI, and
             | don't hesitate to send a lot of data to it, but we're
             | suspicious about a small open source python file? In this
             | context IT IS FUD.
        
               | optimalsolver wrote:
               | Who's "we"? There are posts and comments here every day
               | whining about "Closed AI".
        
             | medo-bear wrote:
             | the post was edited
        
             | neximo64 wrote:
             | Its an open source python script that doesn't really fit
             | that description
        
               | George83728 wrote:
               | Do you think you would enjoy the process of trying to
               | convince a court that their laws don't apply to python
               | scripts? (they do, btw)
        
               | neximo64 wrote:
               | The fact you need to ask whether an open source python
               | script needs a court to prove its a product and the lack
               | of certainty is how FUD works.
               | 
               | - What if you fork it, edit it, re-publish it as yours? -
               | And what if other anti virus vendors do this?
        
         | quenix wrote:
         | Literal FUD. It's a 300 line python script.
        
           | annoyingnoob wrote:
           | I've committed to the US Government, in my own name, that I
           | will not use or provide certain products. If you service a
           | government contract that includes FAR 52.204 then you are
           | agreeing not use Kaspersky products[0]. If you claim to be
           | compliant and then have an incident where you've used
           | prohibited products, the government can come after you with
           | the False Claims Act[1].
           | 
           | There is no way I'm going to just download and run that
           | script because I'm honest and I like not being in prison.
           | 
           | [0] https://www.acquisition.gov/far/52.204-23
           | 
           | [1] https://www.justice.gov/opa/pr/deputy-attorney-general-
           | lisa-...
        
           | tom_ wrote:
           | Written by some people whose code you are getting paid to not
           | run!
           | 
           | On the plus side, since it's a 300 line Python script, you
           | can read it (which does not involve running it), figure out
           | what it's doing, explain it to somebody else in broad terms,
           | and get them to write some equivalent code.
        
             | [deleted]
        
             | cdchn wrote:
             | Someone is furiously converting this to Rust as we type.
        
               | permo-w wrote:
               | 300 lines is probably short enough to do it with a single
               | 8k gpt-4 API call
        
               | cdchn wrote:
               | A new variant of the "reimplement everything in the
               | language du jour" game.
        
               | amoss wrote:
               | [flagged]
        
         | dfadsadsf wrote:
         | According to the link you shared, it seems Kaspersky has been
         | prohibited solely on governmental computer systems in certain
         | nations which Kaspersky previously revealed as deploying
         | malware against their adversaries, correct? I doubt many on HN
         | work for those entities and besides I am not sure Python script
         | fit the definition of Kaspersky software.
        
           | pc86 wrote:
           | It's a Kaspersky repository, it's 100% Kaspersky software.
           | Not sure how the fact that it's a Python script changes that
           | at all.
        
           | 8organicbits wrote:
           | The US Federal government is the largest employer in the
           | world, with well over two million civilian employees. Lots of
           | people on HN are unable to use Kaspersky at work based on
           | that prohibition.
           | 
           | A carve out for python scripts is a dubious claim.
        
       | nailer wrote:
       | > While monitoring the network traffic of our own corporate Wi-Fi
       | network using the Kaspersky Unified Monitoring and Analysis
       | Platform (KUMA), we discovered a previously unknown mobile APT
       | campaign targeting iOS devices.
       | 
       | What is APT in this context?
        
         | blakesterz wrote:
         | Advanced Persistent Threat. Usually very talented and patient
         | hackers, usually state level, so government agents are commonly
         | called APTs..
        
         | [deleted]
        
         | Georgelemental wrote:
         | "Advanced Persistent Threat"
        
         | Veen wrote:
         | Advanced persistent threat.
        
         | iJohnDoe wrote:
         | Advanced persistent threat
        
         | titannet wrote:
         | Advanced persistent threat.
        
           | [deleted]
        
       | psychphysic wrote:
       | Now we just need a tool to detect Pegasus and Graphite
        
         | eimrine wrote:
         | Probably NetBSD is unbreakable for them.
        
       | kornhole wrote:
       | The NSA has no problem with end to end encryption as long as they
       | can listen in on one end.
        
         | nikcub wrote:
         | You're describing the current status quo of the the e2e debate
         | - allow e2e, but accept that the best exploits aren't going to
         | be reported and patched, but reserved for intel agencies to use
         | against high-value targets.
        
           | kornhole wrote:
           | I am referring to the device or OS on either end rather than
           | the client SW used for communication. When those are
           | compromised, nothing is safe.
        
         | kitkat_new wrote:
         | what e2ee? backups are by default not e2ee
        
       ___________________________________________________________________
       (page generated 2023-06-02 23:01 UTC)