• Sumocat@lemmy.world
      link
      fedilink
      English
      arrow-up
      19
      arrow-down
      2
      ·
      9 months ago

      That article is from six years ago and states Cellebrite can unlock high-end Android phones. Since then, Apple has shipped iOS updates to secure against Cellebrite, while the only similarly secure Android phones are Pixels running GrapheneOS and Samsungs with KNOX, all in a perpetual chase.

      • givesomefucks@lemmy.world
        link
        fedilink
        English
        arrow-up
        8
        arrow-down
        4
        ·
        9 months ago

        So when the US government needed in a trump shooters iPhone…

        They gave it to Israel, and Israel gave it back unlocked…

        What did they do? Guess the pass code?

      • Xatolos@reddthat.com
        link
        fedilink
        English
        arrow-up
        3
        arrow-down
        1
        ·
        9 months ago

        Your comment is embarrassing you.

        Read the actual article, not the second hand one linked:

        Military intelligence has also exposed repeated “honeypot” schemes in which operatives posed as women online to lure personnel into installing malware, most notably in Operation HeartBreaker. Analysts noted that such campaigns sought access to contacts, photos, and real-time location data on soldiers’ devices.
        The new step follows earlier efforts to harden mobile use across the force, including training and internal drills designed to raise officers’ awareness of social-engineering tactics. In recent years, the IDF even staged scenarios mimicking Hezbollah-linked “honeypots” to stress-test units’ digital discipline.

        It’s not due to security, it’s due to social engineering. The user will always be the weakest link.

        The real article is linked in this second hand one. https://archive.is/Y7iCJ>>

          • Xatolos@reddthat.com
            link
            fedilink
            English
            arrow-up
            2
            arrow-down
            1
            ·
            9 months ago

            Ah yes, the old “reading is hard so I ignore the facts”. A classic.

            Maybe you could ask Apple Intelligence to explain it to you, and what’s the difference between computer security and social engineering.

              • Xatolos@reddthat.com
                link
                fedilink
                English
                arrow-up
                2
                arrow-down
                1
                ·
                9 months ago

                Good, good. You’re learning basic reading. Now continue read the rest of it.

                Also, since you have no understanding of cyber security, here is Chatgpt to help explain the difference between it and social engineering. I even got it to explain it to a child’s level so it won’t have any scary big words to frighten you:

                • Cybersecurity is like locking the doors and windows of your house so strangers can’t sneak in and take your toys or mess with your stuff. It uses tools like passwords, codes, and special locks on computers to keep everything safe.

                • Social engineering is when a trickster doesn’t try to break the lock but instead pretends to be your friend or someone you trust, so you open the door for them. For example, they might say, “I’m your teacher, give me your homework password,” even though they’re not really your teacher.

                The difference: Cybersecurity is about building strong locks, while social engineering is about tricking people into opening the door themselves.

  • m-p{3}@lemmy.ca
    link
    fedilink
    English
    arrow-up
    13
    ·
    9 months ago

    Nice, so instead of targetting multiple platforms, a bad actor simply has to find a single zero-day to infiltrate the IDF high-ranking officers.

  • prettybunnys@piefed.social
    link
    fedilink
    English
    arrow-up
    13
    arrow-down
    21
    ·
    edit-2
    9 months ago

    I spent quite some time in mobile security and I won’t use an Android device knowing what I know.

    I’d like to caveat that this is not an endorsement of Apple security but rather a “OH MY GOD NO” about Android “security”

    These downvotes brought to you by tech tribalism, read the thread

    People hate that iPhones have locked boot loaders and you can’t boot a custom rom. Defensive security experts love that at least for now a critical threat vector is nearly non-existent.

    • givesomefucks@lemmy.world
      link
      fedilink
      English
      arrow-up
      15
      arrow-down
      3
      ·
      9 months ago

      Literally the opposite…

      https://www.timesofisrael.com/israeli-tech-company-says-it-can-break-into-all-iphones-ever-made-some-androids/

      Israel doesn’t want the IDF able to hide/leak anything about the ongoing genocide, so they’re making everyone use the phone that they can spy on.

      Like, Israel says it’s for safety but they’ve been committing an open genocide for two years now, why they fuck is anyone taking their word?

    • TrickDacy@lemmy.world
      link
      fedilink
      English
      arrow-up
      16
      arrow-down
      6
      ·
      edit-2
      9 months ago

      I spent some time knowing about business practices and user-hostile design and I’ll never use an apple device. And I’ll definitely never give apple another penny, fucking fake assholes.

      I’d like to caveat that this is not a denial that google is horrible, their os is just the only reliable alternative to a Linux phone atm

      Edit: this dude seems really invested in apple. He went back through the thread and edited in weird stuff in several of his comments. I think their appeal to authority fallacy is pretty glaringly on display. Fair to bring up that you know what you’re saying and why, but beating someone over the head with it just makes you sound wrong and like you’re giving a flimsy excuse as to why you don’t have to prove anything.

      • prettybunnys@piefed.social
        link
        fedilink
        English
        arrow-up
        9
        arrow-down
        20
        ·
        edit-2
        9 months ago

        I think you’re doing the tech tribalism thing here whereas I’m talking about actual device security.

        I get it’s popular to hate Apple. Cool. You’re cool for hating Apple.

        Anyone who is genuinely interested in mobile security ought to read some of the white papers or device analysis’ which are available to the public. Security conferences are your best avenue for finding information available to the public.

        Anyways, cool, hate Apple but for some reason give Google a pass.

        • TrickDacy@lemmy.world
          link
          fedilink
          English
          arrow-up
          10
          arrow-down
          4
          ·
          edit-2
          9 months ago

          On the contrary. Someone posted evidence showing apple bullshit is not secure and yet here you are saying it’s a fact and that any denial of that would undoubtedly be rooted in some baseless fanboy shit. K.

          Ps I used to like apple until I realized that everything they claim to be is a lie. That and their entire business model is to prevent you from using your device any way besides ways that make them more money.

          • prettybunnys@piefed.social
            link
            fedilink
            English
            arrow-up
            5
            arrow-down
            8
            ·
            edit-2
            9 months ago

            What evidence are you referring to?

            As far as I can tell my anecdote about my professional experience is the only context here besides the post.

            Your ps is irrelevant, I’m a security researcher and spent the last decade in this field, specifically mobile security. I’ll take my professional experience over the it’s cool to be a tech tribalist opinion.

            Disagree if you’d like, the device you use doesn’t matter to me at all.

            Edit popped the thread in a browser and saw the other comment. They were refuted there too. Fucking hell dude why are you beating this drum?

            • TrickDacy@lemmy.world
              link
              fedilink
              English
              arrow-up
              8
              arrow-down
              3
              ·
              edit-2
              9 months ago

              You can pretend they didn’t post a link showing that an Israeli software company can unlock any iPhone. Pretend is all you can do though. Kind of telling that I explicitly said fuck Google but you still insist I’m tRiBaLiSt.

              And you claiming to be an expert couldn’t possibly mean less. I have no way of confirming that and honestly even if I did it wouldn’t mean you know everything.

              Enjoy your unsecure, unusable phone in a literal fascist ecosystem.

              • prettybunnys@piefed.social
                link
                fedilink
                English
                arrow-up
                5
                arrow-down
                7
                ·
                edit-2
                9 months ago

                I legitimately don’t see the link you’re referring to, I’m not pretending about anything.

                Maybe it’s not federating on my end, could you link it?

                Cellebrite struggles with iPhones, and some newer Android devices. Is it another company?

                You’re getting awfully vitriolic about this discussion, I’m not sure if you’re unfamiliar with the concept of tech tribalism but this is it basically to a T.

                Again, use whatever device you want. My experience informs my anecdote which has you so upset.

    • Eheran@lemmy.world
      link
      fedilink
      English
      arrow-up
      6
      arrow-down
      1
      ·
      9 months ago

      I don’t downvote you because I like one side or the other, I do it because of what you write: Hefty claims with zero substance behind.

    • Possibly linux@lemmy.zip
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      1
      ·
      9 months ago

      I’m not sure why you think Android has security problems. In general it is very secure since it enforces least privilege everywhere.

      It does have security vulnerabilities but so does iOS and ever other piece of software

      • prettybunnys@piefed.social
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        1
        ·
        9 months ago

        It does not actually enforce least privilege everywhere, its application of SELinux is … well it’s better than what targeted policy does, but it’s designed to be unobtrusive not protective. The issue isn’t Android itself, as a concept it’s not awful. The issue is the reality of being a security professional and attempting to secure the edge which in this case is the users and their devices.

        From a practical standpoint administering and protecting one device type on a fairly closed OS is significantly easier than one where the hardware landscape is so varied.

        If you look critically at what it appears this action (the article, and what I am responding to) is for it is because the USERS being exploited is the threat vector. Android devices have significantly more documented malware out in the wild AS WELL AS many documented and active boot exploits.

        My comments have nothing to do with what I like. This isn’t fanaticism. It’s practical reality.

        A nation state actor likely doesn’t care what device you use because they can get the data they want elsewhere, your device is just a beacon at that point for where.