news.volyx.in

U.S. State Department phones hacked with Israeli company spyware (reuters.com)

1093 points by amadeuspagel · 1751 days ago · 592 comments on HN

Article summary

The U.S. State Department's phones were hacked using spyware from an Israeli company. The company, NSO, claims its technology cannot be used to spy on phones with U.S. numbers. However, this claim has been met with skepticism. The hack has raised concerns about the security of mobile devices and the effectiveness of measures to prevent spying.

Main themes

  • NSO spyware
  • mobile device security
  • memory-safe languages
  • software development practices
  • government surveillance
  • privacy concerns
  • cybersecurity risks

What commenters say

  • NSO's claim that its technology cannot be used to spy on U.S. numbers is not credible and may be a marketing ploy.
  • The use of memory-unsafe languages in mobile operating systems is a major security risk that can be exploited by hackers.
  • Implementing memory-safe languages and better software development practices could significantly reduce the risk of zero-day attacks.
  • NSO's statements about its controls to prevent spying on innocent targets are not trustworthy and may be intended to deflect criticism.
  • The hack highlights the need for more robust security measures, such as dedicated processors for parsing potentially malicious content.
  • The effectiveness of NSO's controls in preventing spying on certain targets is questionable and may be based on flawed assumptions.
  • The use of spyware by governments and other organizations poses a significant threat to individual privacy and security.
  • Apple's software development practices, including the lack of CI and fuzzing, contribute to the security risks faced by its users.