Hacker News new | ask | show | jobs
by pmontra 25 days ago
"he did not recall receiving the Apple notifications" so he didn't notice them.
6 comments

That is kind of surprising given he is on the comittee investigating pegasus. I'd assume someone on the comittee would be paying much more attention to this than a normal person.

I wonder what triggered him to suspect he was hacked then. Since presumably something triggered him to have his phone forensically investigated.

> That is kind of surprising

Have you seen notifications on iOS? There are even notifications for the notifications.

But this type of notification I believe is delivered via iMessage and email. So unless you’re actively using iMessage or your icloud email then chances are all this is practically invisible.

People seem to have this fiction that parliamentarians working on a committee actually have some expertise. This can happen but is actually rare. They are not elected for skill but for political reasons, and then the parties pawn them to different committees.

So in other words he probably speaks about security, whatever his staffers feed him, but most likely has no clue whatsoever what it's about.

Or that Apple could either run searches on the names of affected users against publicly known members of government or have close relationship with governments to flag exactly this.
If he knew he was compromised, and was okay with it for one reason or another (like money or other coercion), this is what his cleanup would look like.

Not saying this is likely. Just another possibility.

Could those have been intercepted or suppressed somehow?
It's possible, if the attacker controls the device enough. I don't think a big "you're being targeted" warning is something you don't notice, or forget.
Do they send them via notification infrastructure or email? Personally I almost never check the email associated with my Apple ID so I would miss those. But if all my Apple devices were notifying me and I had a badge in Settings.app, I’d notice.

Then again, you’d think that’s the kinda thing malware developers would spend some time learning to hide from the user.

Do we know how Apple sends these? Is it just a notification, or also email?
https://support.apple.com/en-us/102174

>A Threat Notification is displayed at the top of the page after the user signs into account.apple.com.

>Apple sends an email and iMessage notification to the email addresses and phone numbers associated with the user’s Apple Account.

You can see what it looks like in https://reddit.com/r/iphone/comments/1c10jai/i_have_received...

I wonder how they detect it, is it for known IOCs that they've already found elsewhere, or do they have heuristic detection that flags things that might need further investigation.

I could be wrong here, but I can’t see any way of viewing old notifications.

It isn’t hard to accidentally dismiss one then wonder what it was. Why there isn’t there an interface for looking back?

Edit: below it says there are emails and notices on web login.

If a notification is dismissed on iphone, there's indeed no central UI to see it again on the phone. That's a sad state of iphone. Many people have asked, but Apple just doesn't care enough to do it. Now I hope this kind of high-profile security incidents could nudge Apple towards taking action.
Any source for that “Apple just doesn’t care”, as opposed to thinking there are security/privacy tradeoffs or other considerations that cut against such a feature?
Ok, apple does not care, but gives “security/privacy” consideration as a public reason for not doing anything.
If Apple can store the sms/iMessage, and email history, and health/journal history, and my Wallet payment history, in a safe manner I would think Apple can store notification history in a safe manner. How would notifications be meaningfully different from these?

I think the proof of Apple’s level of care is in their lack of attention to this issue.

> How would notifications be meaningfully different from these?

Ephemeral transit layer owned by third-parties constantly,

vs

cold storage of secrets your architecture owns from start to finish.

> Ephemeral transit layer owned by third-parties constantly

This is a good description of SMS and RCS.

With modern cryptography techniques, Apple could certainly do it if they cared enough. I guess the potential benefit doesn't justify the potential effort and cost related to the change, from Apple management point of view.
If they cared, they would give user triple confirm option to choose for example.

Oh wait this is apple, they always know whats best for the user and do the choices for them, even when wrong. So all is as expected

Or he lied about noticing them to avoid embarrassment.