[ad_1]
iPhone 12 Mini and iPhone 12 Pro Max.
Todd Haselton | CNBC
Apple’s iPhones can be hacked and their sensitive data stolen through hacking programs that don’t require the phone’s owner to click a link, according to a report from Amnesty International on Sunday.
Amnesty International said it had discovered that the iPhones of journalists and human rights lawyers were infected with the NSO Group’s Pegasus malware, which could give an attacker access to messages, emails, phone microphone and camera.
The disclosure indicates that governments using NSO Group’s software have been able to successfully hack iPhones to spy on user data using methods unknown to Apple, and even keeping the iPhone updated cannot stop a dedicated attacker using secretive and expensive spyware.
The nature of the attacks also suggests that changing user behavior, such as avoiding clicking unknown links or phishing messages, may not protect iPhone users from NSO programs. AI said that previous versions of Pegasus required a user to click on a malicious link in a message.
NSO Group is an Israeli company that says it sells to vetted government agencies and law enforcement to prevent terrorism, car bombings, break up sex gangs and drug smuggling.
AI has found evidence that the iPhone 12, the latest iPhone model, running iOS 14.6, which was the latest software before Monday, was hacked. Apple updated its software to iOS 14.7 on Monday but has yet to release security details that could indicate whether it has fixed vulnerabilities identified by AI.
Amnesty International has obtained a leaked list of 50,000 phone numbers that may have been targeted by spyware made by the NSO Group. It found evidence that Android devices were also targeted by NSO Group’s software, but was not able to scan these devices in the same way as the iPhone.
“Apple unequivocally condemns cyber-attacks against journalists, human rights activists, and others who seek to make the world a better place. For more than a decade, Apple has led the industry in security innovation, and as a result, security researchers agree that the iPhone is the most The safest, most secure consumer mobile device on the market,” Apple’s Head of Security Engineering and Architecture Ivan Kristić said in a statement.
Apple’s iPhone software update can fix the vulnerability
Security experts say the most effective way to stop malware is to keep devices patched with the latest software, but this requires the device maker to be aware of the errors attackers use. If it is “0 days”, as NSO Group has been accused of using it, it means that Apple has not yet been able to fix the vulnerabilities.
Once Apple fixes this exploit, it is no longer 0day and users can protect themselves by updating to the latest OS version.
This suggests that NSO Group’s software may stop working or lose the ability to target modern phones once Apple fixes the vulnerabilities — which it starts doing as soon as it learns of the attacks, Apple said.
“Attacks like the ones described are extremely complex, cost millions of dollars to develop, often have a short lifespan, and are used to target specific individuals. While this means they do not pose a threat to the vast majority of our users, we continue to work tirelessly to defend all of our customers, We are constantly adding new protections for their devices and data.”
iPhone privacy has been a major marketing strategy
Apple has made security and privacy one of its main marketing strategies, arguing that its control over the operating system, and the devices that power it, allows Apple to offer a higher level of security and privacy than devices made by competitors.
Apple said its security team is four times larger than it was five years ago, and employees are working to improve device security as soon as new threats are discovered. Apple posts security fixes for every software update on its website, indexing them with industry-standard “CVE” numbers and crediting security researchers who find them.
The AI report said that NSO Group software does not stay on the iPhone when it restarts, making it difficult to confirm that the device is infected. It also suggests that users worried about targeting may want to restart their devices regularly.
Amnesty International said it worked with international media groups to publish details about a few of the phone numbers it found in the leaked list and the specific circumstances that led to their being targeted by NSO software. The Washington Post reported that some US phone numbers were on the list, but it is unclear whether they were hacked.
A spokesperson for NSO Group said the company will investigate all allegations of misuse.
“We would like to emphasize that NSO only sells its technologies to vetted government law enforcement and intelligence agencies for the sole purpose of saving lives by preventing acts of crime and terrorism. NSO does not operate the system and has no data visibility,” said a NSO spokesperson.
Other technology companies consider the NSO Group’s business unacceptable and a threat to the security of its users. Last year, Facebook subsidiary WhatsApp sued NSO Group over an alleged WhatsApp hack. In a lawsuit beginning in December as part of the case, third parties, including Microsoft, Google, Cisco and others, said the NSO Group had violated US laws and did not deserve immunity because it sells to foreign governments.
.
|
Sources 2/ https://news.google.com/__i/rss/rd/articles/CBMigAFodHRwczovL3d3dy5jbmJjLmNvbS8yMDIxLzA3LzE5L2FwcGxlLWlwaG9uZXMtY2FuLWJlLWhhY2tlZC1ldmVuLWlmLXRoZS11c2VyLW5ldmVyLWNsaWNrcy1hLWxpbmstYW1uZXN0eS1pbnRlcm5hdGlvbmFsLXNheXMuaHRtbNIBhAFodHRwczovL3d3dy5jbmJjLmNvbS9hbXAvMjAyMS8wNy8xOS9hcHBsZS1pcGhvbmVzLWNhbi1iZS1oYWNrZWQtZXZlbi1pZi10aGUtdXNlci1uZXZlci1jbGlja3MtYS1saW5rLWFtbmVzdHktaW50ZXJuYXRpb25hbC1zYXlzLmh0bWw?oc=5 The mention sources can contact us to remove/changing this article |
[ad_2]