Hacker News new | ask | show | jobs
by dwater 1799 days ago
The media has presented it's evidence and reasoning for why they believe the list of 50k numbers is from NSO. In the original Washington Post article, they link to the methodology used by Amnesty to determine why they concluded it's likely from NSO.

https://www.washingtonpost.com/investigations/interactive/20...

https://www.amnesty.org/en/latest/research/2021/07/forensic-...

From the Washington Post article:

"The media consortium, titled the Pegasus Project, analyzed the list through interviews and forensic analysis of the phones, and by comparing details with previously reported information about NSO. Amnesty’s Security Lab examined 67 smartphones where attacks were suspected. Of those, 23 were successfully infected and 14 showed signs of attempted penetration.

For the remaining 30, the tests were inconclusive, in several cases because the phones had been replaced. Fifteen of the phones were Android devices, none of which showed evidence of successful infection. However, unlike iPhones, Androids do not log the kinds of information required for Amnesty’s detective work. Three Android phones showed signs of targeting, such as Pegasus-linked SMS messages."

1 comments

I don't dispute that there is evidence that 67 phones had been targeted with Pegasus software. I am however skeptical of that justifying an international breaking news story that so-and-so is on the "list" without having checked if their phone has been infected.