HN user

Ansil849

3,653 karma

Sorry, you can't comment here.

Posts27
Comments874
View on HN
theintercept.com 2y ago

The Other Players Who Helped Almost Make the Biggest Backdoor Hack

Ansil849
2pts1
www.context.news 2y ago

'Wild West' of neuroscience drives new laws on brain privacy

Ansil849
1pts0
www.context.news 3y ago

Privacy or safety? U.S. brings 'surveillance city to the suburbs'

Ansil849
8pts1
docs.google.com 3y ago

Google Lets Anyone See Original Uncropped Images – Proof of Concept

Ansil849
3pts1
www.yahoo.com 4y ago

Amazon to end Cloud Cam service

Ansil849
1pts0
news.ycombinator.com 4y ago

Ask HN: How to Compete in a Global Remote Work Environment?

Ansil849
6pts20
theintercept.com 4y ago

Getting my personal data from Amazon was weeks of confusion and tedium

Ansil849
362pts182
www.vice.com 4y ago

Watch the First Stars in the Universe Being Born in This Incredible Simulation

Ansil849
3pts1
www.vice.com 4y ago

Scientists Capture Best Images yet of Unexplained Ring Structures in Space

Ansil849
2pts0
www.bbc.co.uk 4y ago

Computer Says No [AI hiring documentary]

Ansil849
3pts2
longreads.trust.org 4y ago

Coal to crypto: The gold rush bringing Bitcoin miners to Kentucky

Ansil849
4pts0
news.ycombinator.com 4y ago

Ask HN: How can I have companies reveal where they obtained my personal data?

Ansil849
3pts2
www.theguardian.com 4y ago

Life and Death in the Warehouse – the terrible true cost of online shopping

Ansil849
1pts0
www.ncia.nato.int 4y ago

NATO experiments with secure network withstanding attack by quantum computers

Ansil849
6pts0
www.reuters.com 4y ago

Hundreds of Salesforce employees object to NFT plans

Ansil849
23pts7
www.forbes.com 4y ago

How One Journalist Is Using Music Royalties to Fund His Ocean Reporting

Ansil849
3pts0
www.inputmag.com 4y ago

Did a former ‘New York Times’ reporter exploit musicians for his personal gain?

Ansil849
16pts2
www.foxbusiness.com 4y ago

Facebook investor exposes metaverse rollout as distraction

Ansil849
4pts1
www.economist.com 5y ago

Gulp The secret economics of food delivery

Ansil849
3pts0
code.firstlook.media 5y ago

Attackers using Twitter's response to recent breach to phish account credentials

Ansil849
1pts0
www.vox.com 6y ago

Zuckerberg – Trump’s post “has no history of being read as a dog whistle”

Ansil849
5pts0
code.firstlook.media 6y ago

When Your Office Scanner Is Framed for Phishing

Ansil849
1pts0
code.firstlook.media 6y ago

How to Pick a Video Conferencing Platform

Ansil849
1pts0
twitter.com 6y ago

Large-Scale BGP Hijack

Ansil849
161pts50
mediafilter.org 6y ago

Crypto AG: The NSA's Trojan Whore? (1998)

Ansil849
27pts3
tech.firstlook.media 6y ago

Anatomy of a Facebook-Hosted Phishing Attack

Ansil849
8pts1
code.firstlook.media 6y ago

Anatomy of a Facebook-Hosted Phishing Attack

Ansil849
6pts0

It might stun you to learn that the US is part of the west and isn't blocking RT.

Golly gee, you sure got me there on that! Let's rephrase to "parts of the West", what impact does that have on the argument that Western powers engage in media censorship as well?

I don't want to stun you too much, but the west is not some uniform block of countries.

LOL. You understand it is _literally_ called the "Western Bloc", right? https://en.wikipedia.org/wiki/Western_Bloc

Lockdown is literally presented by Apple as being for people targeted by APTs like those developed by NSO Group, therefore I expect it to prevent attack vectors used by these APTs, like exploitation of the Developer program to facilitate sideloading malicious apps. I don't feel like this is an unrealistic expectation, and not having the mode actually do that amounts to security theater, which is a far cry from decrying everything as such.

"What constitutes an enterprise that should be allowed to have 'enterprise apps'"

Apple has a list of requirements - https://developer.apple.com/programs/enterprise/ - for example, a company needs to have at least 100 employees. The issue, however, seems to be how stringently these requirements are enforced, or whether they are at all. In the case of Hermit, the Italian spyware company seems to have created a fake company and tricked Apple into granting the fake company access to the developer program. Now, the interesting question for me is whether the fake company actually managed to pass all of the requirements, like giving Apple a list of 100 fake employees, and whether Apple actually performed their due dilligence and checked whether the employee list was real, or whether they accepted it at face value, or didn't even require it.

In other words, I think a key takeaway from the latest incident is Apple needs to take accountability and harden their Enterprise program entry requirements, and I haven't seen anything about that being the case.

Running an enterprise app still is not a trivial single tap on iOS.

Yes, but still successful, as Hermit demonstrated. So my question is whether Lockdown mode would have prevented APTs like Hermit which it claims to prevent against. If not, then the move is security theater which doesn't address the actual flaws (like poor vetting into the Enterprise Program) being successfully leveraged in the wild.

High-level targets (for whom this mode is specifically advertised) are likely aware of the dangers of installing apps.

I firstly don't believe this is true at all, plenty of high-level targets are not tech savvy; but more to the point of Lockdown mode, you could then say the same thing about most of its other features ("High-level targets are likely to already be aware of the dangers of doing $thing_Lockdown_prevents").

So this would have prevented Hermit as you'd need to install a new configuration profile to allow sideloading of applications from that source.

Are you sure that's true? I haven't seen a Hermit sample firsthand, but from everything I've read about it targets did not need to install an MDM profile, they simply needed to click a link. Looking at Apple's distribution guidelines - https://support.apple.com/en-bw/guide/deployment/depce7cefc4... - MDM is listed as one option, and simply going to a link is listed as another:

There are two ways you can distribute proprietary in-house apps: Using MDM Using a website

It seems like the latter was used, so I don't think installation of a custom profile was required, which brings me back to my original question of whether Lockdown would have prevented it.

It's not clear to me if Lockdown Mode would have prevented Hermit, the latest mobile APT which targeted iOS via sideloading by enrolling in the Apple Developer Enterprise Program.

The list of lockdown features don't seem to explicitly list that in-house app sideloading is disabled - is it? If not, then this mode seems like security theater from Apple, in that it doesn't actually lock down the parts of the attack surface that are actively being leveraged. How about instead, or better yet alongside this, Apple explains how they granted entry in the Enterprise program to the spyware company, and what measures they're taking to prevent it from happening again.

How failure to generate income on their degrees is a lender's problem? Clearly,there is an issue with inflated costs of getting a degree and finding a job with a low-demand degree, but why try solving it at the lender's expense?

Yeah, I've never really understood this logic either. If someone lends money from me to, let's say go buy a tow truck, and then is not able to repay the loan because there are too many other folks with tow trucks (or for whatever other reason), why should that be my problem? I gave money with the expectation that it would be paid back. That is by definition what lending is, yet student loans are somehow touted as an exception where repayment shouldn't be seen as compulsory.

If 1000 big youtubers put $100/month toward an association or union of some kind, they could afford a $100,000/month legal team to combat this.

Millionaire youtubers can already afford high-priced lawyers if they want to, I'm not worried about that.

Who I am worried about are regular people who create content but don't have large followers and don't make to it to the frontpage of HN, but still get hit by copyright trolls.

For what it's worth, the work of an few engineers implementing the business decisions of their employer does not make those people inherently evil

I think when people do unethical actions, it makes the person doing the unethical action unethical. People are defined by their actions. I'm also tired of this 'need to pay the bills somehow' excuse. Someone who has an engineering job at Facebook has vast career options.

Comparing American football and hockey and other brutal sports to a high five is what dilutes the meaning of the word. These are sports where men aggressively assault each other. They are institutionalized violence.

The answer to this is sports. War is competition through violence.

Absolutely not. Sports is competition through violence, as well. Watch a game of American football, or ice hockey, or basketball for that matter and be able to say otherwise with a straight face.

The answer is cooperative, not competitive, activities.

Sorry, I have zero interest in discussing some nonexistent hypothetical. Obviously, a technology that 1) was not opt-in, but universal, and 2) broadcast your information to not just you but everyone, would be problematic. You might as well add that this hypothetical system also broadcasts your credit card number while you're at it, and say that you would find this quite troubling indeed.

That being said, I think it would be totally fair for a person to feel embarrassed about any personal information being displayed publicly on a monitor without their consent.

OK, but this is a pure fantasy, if not outright delusion. The way this display works is 1) it requires your consent, and 2) the information is only visible to a person standing in specific coordinates, i.e. you.