• TribblesBestFriend@startrek.website
    link
    fedilink
    English
    arrow-up
    140
    ·
    13 days ago

    The Israeli military has decided to ban Android phones for senior officers

    “Under the expected order, commanders from the rank of lieutenant colonel and above will be permitted to use only iPhones for official communications. The step is aimed at reducing the risk of intrusions on senior officers’ handsets, according to the report.”

    So it seems that Israel (one of the leading country in hackers spies for hire) thinks that there’s a lot « Hezbollah honey pot » that target android device

    • [object Object]@lemmy.world
      link
      fedilink
      English
      arrow-up
      133
      ·
      edit-2
      12 days ago

      Israeli company Cellebrite sells a device to extract data from locked phones, both Android and iPhones afaik. So indeed I’m guessing their government knows some stuff about the security of both platforms.

      Fun fact: comments mentioning Cellebrite get immediately shadow-hidden on Reddit, or at least in some of the main subs.

      • kbobabob@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        38
        ·
        12 days ago

        In 2021, Moxie Marlinspike, creator of the encrypted messaging app Signal, pointed to several vulnerabilities in Cellebrite’s UFED and Physical Analyzer software that allowed for arbitrary code execution on Windows computers running the software. One exploit he detailed involved the UFED scanning a specially formatted file, which could then be used to execute arbitrary code on the computer running the UFED. Marlinspike wrote that the code could then “[modify] not just the Cellebrite report being created in that scan, but also “all previous and future generated Cellebrite reports” from all previously scanned devices and all future scanned devices in any arbitrary way.”[27] Marlinspike also found that Cellebrite software was bundled with out-of-date FFmpeg DLL files from 2012, which lacked over 100 subsequent security updates. Windows Installer packages, extracted from the Windows installer for iTunes and signed by Apple, were also found, which he said raised legal concerns.[28] Cellebrite responded that the company “is committed to protecting the integrity of our customers’ data, and we continually audit and update our software in order to equip our customers with the best digital intelligence solutions available.”[29] The report by Signal followed an announcement by Cellebrite in 2020 that it had developed technology to crack encrypted messages in the Signal app, a claim the company later retracted and downplayed.[30][31] The announcement by Marlinspike raised questions about the integrity of data extracted by the software,[32][33] and prompted Cellebrite to patch some of the vulnerabilities found by Signal and to remove full support for analyzing iPhones.[34][35]

        Source: https://en.wikipedia.org/wiki/Cellebrite

        Sounds like it is just malware to me.

        • [object Object]@lemmy.world
          link
          fedilink
          English
          arrow-up
          20
          ·
          12 days ago

          Vulnerable software is different from malware.

          Iirc there was also the part of the story where the exploit for Cellebrite’s thing was included in Signal, and Marlinspike said that data on any device scanning Signal with Cellebrite software would be poisoned.

            • [object Object]@lemmy.world
              link
              fedilink
              English
              arrow-up
              5
              ·
              12 days ago

              I’m guessing things might’ve changed since then, as this story is pretty old. I doubt it that they gotten newer versions of Cellebrite to screw them again.

      • 418_im_a_teapot@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        5
        ·
        12 days ago

        I wouldn’t assume any news about technology being used by IDF to be true in the first place. It could just as easily be misinformation.

      • HazardousBanjo@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        ·
        11 days ago

        They want to be able to perpetually spy on their military officers to keep them in line. Boot out any dissidents or anyone refusing to carry out illegal and genocidal orders.

        Many fascist states like Stalin’s USSR, Nazi Germany, North Korea, etc all have mass spy programs on the most powerful who aren’t the leader.

        It shows perpetual paranoia, which is expected as popular support for Israel has fucking collapsed in most Western countries. They know their time is limited.

    • muusemuuse@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      77
      ·
      edit-2
      12 days ago

      Google has decided you cannot turn off Gemini in their newer versions of Android. You cannot install other roms that do either, Google is killing those too. But yea, Apple is the bad guy. Ignore the Google rug pull.

      • Khrux@ttrpg.network
        link
        fedilink
        English
        arrow-up
        32
        ·
        12 days ago

        As much as I don’t disagree, I think the “Apple is closest to Nazism” comment touches on something different. Other massive American companies have awful practices but they don’t care particularly how their way of making money looks. Apple wields a specific aesthetic power that generally dictates a hegemonic uniformity, that strays the line of being to their detriment at times. I don’t think any other big tech company would care in the same way if not for their desire to copy Apple.

        • muusemuuse@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          12
          ·
          11 days ago

          Apple never opened that door. Google did, but they never intended to keep it open. it was there to catch up with apple. they never intended to do any good here. it was there to speed up development and win people over, then after they are already there, google can close the door and screw them all. That’s what’s happening now. It was a bait and switch.

        • BarneyPiccolo@lemmy.today
          link
          fedilink
          English
          arrow-up
          1
          ·
          11 days ago

          Like most things in contemporary society, we are given the choice between two terrible options, and then encouraged to go all in on one of those terrible choices, or you’re a LOSER.

          Modern life is just Pavlov’s lab.

        • muusemuuse@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          11
          ·
          12 days ago

          You actually turned off geminis ability to serve YOU. You never turned off Gemini itself. Google won’t allow that. It’s still running in the background send your data to Google and its advertising partners. Google has publicly stated this is the intended design and they will not allow turning that off.

              • titanicx@lemmy.zip
                link
                fedilink
                English
                arrow-up
                3
                ·
                edit-2
                11 days ago

                No. They provided me a nice little button that allows me to disable Gemini, and they have allowed me to opt out of any usage. So again. Show me that it is still active after I have disabled it.

                • sem@piefed.blahaj.zone
                  link
                  fedilink
                  English
                  arrow-up
                  4
                  ·
                  11 days ago

                  I was curious so I searched. This is the best info I could find.

                  https://proton.me/blog/turn-off-gemini-on-android

                  Proton claims that even if you turn everything off, it will still watch in the background because Google is replacing assistant with Gemini. That still hasn’t happened on my phone. I can still use the regular Google assistant, but I feel like I’m not smart enough to evaluate the claims to know whether it is really running on my phone or not.

                  Proton also has a profit motive in making people upset with Google, so I don’t know.

                • muusemuuse@sh.itjust.works
                  link
                  fedilink
                  English
                  arrow-up
                  3
                  ·
                  11 days ago

                  Let’s say I install a button on your car that flips from “broken” to “fixed” my itself. Anytime you complain something is wrong, I flip that switch to “fixed.” That doesn’t change anything. The switch just tells other things to do something. It doesn’t enforce anything. It’s basically telling Google whether you want it or not, not actually obeying you.

                • asudox@lemmy.asudox.dev
                  link
                  fedilink
                  English
                  arrow-up
                  3
                  ·
                  edit-2
                  8 days ago

                  No. They provided me a nice little button that allows me to disable Gemini, and they have allowed me to opt out of any usage. So again. Show me that it is still active after I have disabled it.

        • bss03@infosec.pub
          link
          fedilink
          English
          arrow-up
          4
          ·
          12 days ago

          I’ve lost features that used to work without Gemini, but I believe it is disabled on both my Pixel 7 Pro and the Pixel 8 I have access to.

          • muusemuuse@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            5
            ·
            12 days ago

            Nope, it’s still running in the background. You just turned off its ability to interact with you but can and does still interact with others.

                • bss03@infosec.pub
                  link
                  fedilink
                  English
                  arrow-up
                  2
                  ·
                  11 days ago

                  The first one does tell you how to “completely remove Gemini from your smartphone” under that heading. I do not have the Gemini app installed.

                  The second one says:

                  Can you fully disable Gemini on Android?

                  No, and that’s by design. While you can turn off activity tracking, revoke permissions, and even uninstall the Gemini app on some devices, Google is actively replacing its Assistant app with Gemini.

                  But, I’ve also disabled Google Assistant across all applications, so I don’t share data with Gemini/Assistant. I had to lose some features to do so.

                  Overall, your reply serves to confirm for me that I have disabled Gemini on both of my Android devices. Still, I appreciate the links!

                • bss03@infosec.pub
                  link
                  fedilink
                  English
                  arrow-up
                  6
                  ·
                  edit-2
                  11 days ago

                  Honestly, it wouldn’t surprise me either way. There IS a lot of telemetry and other BS that is definitely still on my phone, included in OS updates, and not uninstallable (I can “uninstall updates”, but that would also give me back any security issues). But, I don’t think that it is Gemini, or at least predates that naming convention.

                  To get free of Google telemetry, I’d have to install a non-Google ROM, and I haven’t ever tried that.

                  Telemetry certainly can be abused, and Google should be legally (by regulation) required to provide a simple opt-out. BUT, telemetry really is a fairly normal thing to include in “web-scale” deployments and is primarily used to discover issues that have escaped into production without affecting a testing environment–or, at least, that what the telemetry systems I’ve interacted with as an software developer were for. So, I’m not too worried about non-personalized data collection.

                  EDIT: I confirmed that Google says I have no Gemini activity to delete, so while I’m sure my phone is reporting stuff, it’s not to Gemini.

    • Isthisreddit@lemmy.world
      link
      fedilink
      English
      arrow-up
      5
      ·
      12 days ago

      This is it right here. I can’t believe the nonsense I’m reading in this thread. Just goes to show how absolutely uninformed most people are when it comes to security and privacy

      • bluemoon@piefed.social
        link
        fedilink
        English
        arrow-up
        2
        ·
        12 days ago

        also illiterare on sarcasm too lmao i see my comment got 60 upvotes and your unsarcastic comment got downvoted

  • D_C@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    58
    ·
    edit-2
    12 days ago
              Apple   
    

    The Official Phone Of Genocide


    Lets face it, the more you know about ol’ tyranty boy StevieJobs the more it makes sense.

  • The Quuuuuill@slrpnk.net
    link
    fedilink
    English
    arrow-up
    53
    ·
    12 days ago

    frankly this is because israel knows exactly how much spyware they’ve gotten their partner, Google, to put into android. the iphone is also chock full of spyware, and they do want to spy on their military force to make sure it’s as ideologically and racially pure as they need it to be to continue their genocide. further consider that budget iphones don’t exist and you realize that their systemic impoverishing of the indigenous Palestinian people means that all of the targets of their genocide are much more likely to be android users than iphone users. given this, israel is in real time creating a new signifier of jewish-israeli identity. soon having an android phone as civilian will be evidence of HAMAS.

    and again.

    i want to remind everyone that google is a major partner to israel. this is not a case of iphones bad guys, android phones good guys. this is a case of both being components in a system of torture. i can’t tell you yet to divest yourself of both to switch to linux phones like postmarketos because even i can’t do that without buying a new device, but please watch that space. and until you can, if you’re using a google pixel please consider installing grapheneos, and if you’re not please consider using a de-googled lineage based rom. israel greatly values the intel they get from their partner google.

  • itisileclerk@lemmy.world
    link
    fedilink
    English
    arrow-up
    49
    ·
    11 days ago

    IDF rules:

    OK things to do:

    • Kill children,
    • Rape women,
    • Kill prisoners,
    • Destroy peoples property,
    • Use iPhone.

    Not OK things to do:

    • Use Android OS
    • CatAssTrophy@safest.space
      link
      fedilink
      English
      arrow-up
      19
      ·
      12 days ago

      It’s also just not true, the villain/killer/etc has iPhones in many shows and movies already, including multiple AppleTV shows.

    • PeachMan@lemmy.world
      link
      fedilink
      English
      arrow-up
      41
      ·
      13 days ago

      Really depends on the phone and how the controlling organization (whether it’s a private company or the IDF) uses MDM/MAM. It’s totally possible to poorly manage iPhones, and if you do they’ll be insecure as hell. If you were to restrict everyone to a specific Android phone model with hardened software, then you could theoretically do better than deploying all iPhones. Hell, you could even put GrapheneOS on them, but that would be quite an undertaking, and I’m not aware of any company doing it at scale.

      Because of the homogeneity of iPhones and how strictly Apple controls them, it’s generally simpler for organizations to manage them and ensure all of their employees are using updated software on a relatively secure phone. So that (in my opinion) is why we’re seeing a lot of organizations just say “screw it, only iPhones allowed”.

    • Reddfugee42@lemmy.world
      link
      fedilink
      English
      arrow-up
      7
      ·
      12 days ago

      It’s secure if you’re not stupid and you don’t turn off the safety protocols it literally warns you not to turn off. Stupid people need apple’s domineering control to protect them from themselves

  • HazardousBanjo@lemmy.world
    link
    fedilink
    English
    arrow-up
    20
    ·
    11 days ago

    If ever anyone still doesn’t get how Western countries still support Israel despite the populations of those countries widely hating Israel, this shit is why.

    They have blackmail on all our politicians, but moreover they can sell their domestic surveillance spy tools (such as malware) to bad actors (such as the US gov) to spy on their own citizens too.

    Israel is the #1 perpetrator and exporter of fascism and police states.

  • NGC2346@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    18
    ·
    11 days ago

    The reason for this is because Pegasus is better used on iPhones than Androids and you can flash GrapheneOS on them while iPhones are locked down.