[HN Gopher] Paragon accidentally uploaded a photo of its spyware...
___________________________________________________________________
Paragon accidentally uploaded a photo of its spyware control panel
Author : CGMthrowaway
Score : 101 points
Date : 2026-02-11 19:42 UTC (3 hours ago)
(HTM) web link (twitter.com)
(TXT) w3m dump (twitter.com)
| recursivecaveat wrote:
| This company btw for anyone else who had not heard of them before
| (there are a lot of companies by that name):
| https://en.wikipedia.org/wiki/Paragon_Solutions
| phendrenad2 wrote:
| It's too bad that "The right of the people to be secure in
| their persons, houses, papers, and effects, against
| unreasonable searches and seizures, shall not be violated, and
| no Warrants shall issue, but upon probable cause, supported by
| Oath or affirmation, and particularly describing the place to
| be searched, and the persons or things to be seized" has become
| "we can download a full copy of all of your files at any time,
| or continually, if we feel like it, even if we don't suspect
| you of a crime".
| moralestapia wrote:
| Awesome.
|
| Moxie's "unbreakable" end-to-end communication protocol.
| thmsths wrote:
| The message can't be intercepted in transit, since we are
| talking about spyware, I assume they get it from the device,
| hard to defend against that if they have access to your
| process' memory space.
| Hamuko wrote:
| Surprising that end-to-end encryption doesn't really matter
| when you get into one of the ends.
| akimbostrawman wrote:
| not at all. there is no encryption that can save you when
| one of the legitimate participants is somehow compromised.
| doesn't even need to be a sophisticated device compromise,
| literal shoulder surfing does that too.
| ASalazarMX wrote:
| Even if you had to input your private key every time you
| wanted to read or send a message, having malware in your
| phone voids practically any form of encryption, because it
| has to be decrypted eventually to be used.
| moralestapia wrote:
| >The message can't be intercepted in transit
|
| Lol, so like ... all encryption schemes since the 70s?
| sowbug wrote:
| They do have stronger schemes, which are called hash
| functions.
| moralestapia wrote:
| What?
|
| Hashing is not encrypting.
|
| You can learn more about the topic here,
| https://www.okta.com/identity-101/hashing-vs-encryption/
| p-o wrote:
| Hashing is a part of encryption, maybe you are the one
| who needs to shore up on the topic?
| aipatselarom wrote:
| Nice try. However, hashing and encryption are two
| different operations.
|
| Load this page, https://en.wikipedia.org/wiki/Advanced_En
| cryption_Standard
|
| Ctrl-F "hash". No mention of it.
|
| Before being pedantic at least check out the url in that
| comment to get the basics going.
| sowbug wrote:
| This entire thread should be annihilated, but since you
| mentioned being pedantic...
|
| You're correct that a pure encryption algorithm doesn't
| use hashing. But real-world encryption _systems_ will
| include an HMAC to detect whether messages were altered
| in transit. HMACs do use hash functions.
| AlotOfReading wrote:
| A good hash function is surjective. Encryption is
| bijective. They're very different things.
| sowbug wrote:
| _> What?_
|
| _> Hashing is not encrypting._
|
| _> You can learn more about the topic here,
| https://www.okta.com/identity-101/hashing-vs-encryption/_
|
| Thank you for that link. Your original comment implied
| that Signal's threat model should have included an
| attacker-controlled end. The only way to do that is to
| make decryption impossible by anyone, including the
| intended recipient. A labyrinthine way to do that would
| be to substitute the symmetric-encryption algorithm with
| a hash algorithm, which of course destroys the plaintext,
| but does accomplish the goal of obfuscating it in
| transit, at rest, and forever.
| coldtea wrote:
| It's a joke, because hashing loses information, and thus
| the original is not retrievable, woosh
| lmm wrote:
| Certainly very hard to defend against that when the messenger
| you're using won't let you use a device you control.
| Insanity wrote:
| How is this related?
| moralestapia wrote:
| I see there's some room for ambiguity.
|
| See, https://en.wikipedia.org/wiki/Moxie_Marlinspike
| dualbus wrote:
| Apologies for being dense. Could you spell out how you went
| from Paragon Solutions to the Signal Protocol?
| ale42 wrote:
| I guess they've seen a Signal icon in the photo. Of
| course the interception is done locally on the phone (so
| it's basically "man-in-the-client" rather than a "man-in-
| the-middle"), therefore the Signal protocol is not really
| worth being mentioned as it has nothing to do with local
| interception.
| Insanity wrote:
| Yea I knew which Moxie it was but that didn't help at all
| haha
| jabwd wrote:
| Cool, can you now show how the protocol has been broken?
| Lot of smart people would love to see your novel research.
| rtaylorgarlock wrote:
| Looks like image was removed and maybe only a demo?
| phendrenad2 wrote:
| Non-X link: https://archive.is/kqvnH
| ronsor wrote:
| From one Twitter user:
|
| > It's just a demo instance, but, these front ends are barely
| revealed to the public
|
| This genuinely doesn't look any different from the control panels
| of commercial infostealers and RATs sold on Russian hacking
| forums. Those usually sell for between $200 and $20,000 depending
| on features and pricing model (one-time vs. ongoing
| subscription).
|
| These spyware companies hype themselves up, but they're really
| not any different from Ivan's RAT-as-a-Service, besides having
| extra exploits to burn and wealthier customers.
| walletdrainer wrote:
| As it turns out, you just can't make malware for targets like
| these much better.
| amai wrote:
| I read Pentagon instead of Paragon.
| efilife wrote:
| Can somebody please explain to an idiot (me) how is this possible
| for this to keep going? I thought that the world has decided that
| spyware is illegal and can't be produced. Is this company related
| to israeli government? If not, why is it allowed to function?
| muvlon wrote:
| The world has not decided that spyware can't be produced.
| Mostly, the powers that be treat it like weapons of war.
|
| That is, companies can make and sell it as long as they only
| sell it to governments and only the ones that we like.
| general1465 wrote:
| What is allowed to companies is not allowed to private
| citizens. If you want to systematically break copyright laws or
| steal data from people, do it as Joe's LLC. Joe would go to
| prison for copyright infringement or hacking other people,
| Joe's LLC can do as it please.
| ra wrote:
| [delayed]
___________________________________________________________________
(page generated 2026-02-11 23:00 UTC)