Hacker Newsnew | past | comments | ask | show | jobs | submit | cyckl's commentslogin

The issue is that iMessage is already a big spammy dumpster fire—in my experience. I get plenty of spam messages sent by email addresses essentially made up of random strings of characters


This is one of the reasons I daily drive a 1990 BMW 325i—the visibility is just unparalleled.


Even with the increase visibility, I'm sure you'd be much safer in a 2020 BMW 3-series. Heck even a 2010.


The occupants of the vehicle would be safer, but what if your main worry is hitting pedestrians during in-city driving? If that was my worry, I would greatly prefer the 1990 model.


Same with most 90s cars. My old honda is practically a greenhouse, and was ctitisized for its c pillar at the time.


if you dont mind me asking—where can i find this manual?


How was her performance in CC? I was considering doing the same thing and potentially seeing how my chances at UCSD would work out...


3.9, majoring philosophy.


Windows 10 LTSC doesn't come with a built in photo viewer


i am in high school and the 48GX is undeniably the best calculator that i've ever had to use. unfortunately i don't have the serial cable for it so i can't load anything cool like metakernel i wish there was a modern alternative with the same simplicity :(


That’s neat! Those calculators are literally antiques now. I think my parents threw mine out after I moved out.


I didn't mean this to be offensive. I wish I still had an HP48...


Suicide cables!


SK Hynix is South Korean—no?


I use a GX and feel the same way—something about the HP 48 is just really charming and I wish for a modern alternative. Software emulation isn't enough! Leaves me longing.


I’m also getting these—no idea what the exploits actually are or how they work. Am I theoretically already exploited?


Not really.

1. There's no reason why a threat actor would have to send you 3-4 messages per day. Of the exploits I've seen, they only need to send one. Sending 3-4 messages per day just unnecessarily increases the risk of getting caught (ie. the target getting suspicious and asking on hacker news whether they're getting hacked)

2. There's no reason why the message has to contain sketchy links. They could very well disguise messages as ads/notifications for well known businesses, political organizations, or from random people who got the wrong phone number.

3. There's no reason why the attacker can't erase any trace of the initial message after your device is infected, so unless you're staring at your phone 24/7 it's very easy to miss the message.


Disagree with all 3 points.

If I am sneaking a payload in, and I have different exploits for different OS versions, I would exactly disguise it as spam.

Pretending to be a busines, or a random person with wrong number, and then DELETING IT is a noteable indicator of compromise.

I know this isn't how Pegasus works, but I'm sure there are more exploit kits being sold in the world. Some may not be as sophisticated, and may rely on spraying and praying with different exploits.


>If I am sneaking a payload in, and I have different exploits for different OS versions, I would exactly disguise it as spam.

Right, but the point is that GP seems to have been tipped off by the "sketchy links", rather than the spam itself, and that there are far better ways to compose your spam texts than ones with sketchy links.

>Pretending to be a busines, or a random person with wrong number, and then DELETING IT is a noteable indicator of compromise.

It depends on the nature of the exploit. I was operating under the assumption that "0 click" means the exploit gets run as soon as the phone receives it, which would allow for the exploit to clean up after itself without alerting the owner, unless the owner was staring at the phone the exact moment the message came in.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: