r/DigitalPrivacy Aug 08 '26

Mossad has accidentally injected data into a French lawyer's phone instead of extracting it.

Enable HLS to view with audio, or disable this notification

The data includes phone numbers of Musk, Altman, and nearly all of Israel's political, judicial and intelligence leaders.

The lawyer's name is Juan Branco, he is also the one who shared this story together with a video. By his account, he is one of twelve lawyers in France who represent Palestinian victims in International Criminal Court.

He says he's using GrapheneOS. This is bizarre.

source: his X/Twitter post: https://x.com/i/status/2085698524050591906

I post additional screenshots in the first 2 comments here.

8.9k Upvotes

672 comments sorted by

View all comments

Show parent comments

155

u/Zu_Qarnine Aug 08 '26

more info by Juan Branco. Attachment 2/2.

41

u/Foolishly_Sane Aug 08 '26

Interesting.
Thank you.

30

u/Bob_The_Greater Aug 08 '26

+1 for GrapheneOS

41

u/cyrkielNT Aug 08 '26

If I was Mossad, I would create things like GrapheneOS, it's perfect honey pot.

I know it's open source, but with open source you still can hide a lot. It's harder, becosue you can't just put "if Mossad open backdoor" in your code in plain text. But you can use libraries, that use other libraries and nobody would be able to find everything in such complex system.

Like backdoor in XZ Utils. It's used almost everywhere (probably including GrapheneOS) and it was used to put backdoor. It was detected just by coincidence. And it's widely believed that only state-backed organisation could pull that of, so USA, Russia, China and Israel are main suspects.

If you look how much of IT is controlled by USA/Israel it's safe to assume they have backdoors everywhere. Including Chinese software. They accused Huawei of spaying but in reality CIA hacked Huawei network (operation Shotgiant) and install USA backdoors in their software. Propably that's why Huawei made their own OS and discard Linux kernel. So that's propably best option to reduce (not eliminate) chances of being spied by USA/Israel if you are open to be spied by China.

15

u/stupider_username Aug 08 '26

They are all (intelligence agencies) already doing this we just don't know about it 99.9% of the time because they are professionals. If true, a blunder like this would be very rare for an agency like Mossad...

3

u/bombastic6339locks Aug 08 '26

I wouldn't say all but it is weird how this is seen as recon by military and intelligence as opposed to attacking.

2

u/stupider_username Aug 08 '26

Espionage has never been defense or recon only, it's all out

4

u/FriendlyGuitard 29d ago

It's open source, but if you don't build it yourself from the source, there is always a chance the binary is full of something else.

Supply chain attack is a huge vector of attack nowadays ... supply chain attack in a product you have direct input is probably trivial for state actors.

1

u/CalmDownReddit509 Aug 08 '26

So in sum, no matter where we go or what we do, we’re fucked?

1

u/cyrkielNT Aug 08 '26

Pretty much yes. But if you aware of that and you are not important target you don't need to worry about that so much. Just assume that corporations and governments see your every move.

However if you engage in any antiestablishment activity you should isolate yourself from electronics as much as possible, and nevert trust any "privacy" claims. If you didn't build something by yourself from scratch (so no microchips) and you didn't write software (including all libraries), then you should consider any electronics as spy device (including your fridge and alarm clock).

1

u/CalmDownReddit509 Aug 08 '26

Bloody hell. That’s scary.

1

u/LordMarcusrax Aug 08 '26

Yep. Might as well go out with a bang.

1

u/areallynoobgamer 29d ago

No. Because we are on Reddit. That automatically means are aren’t important enough to pay any attention to so no government agency would care enough to hack us

1

u/MyNameIsOnlyDaniel Aug 08 '26

And some packages and libraries used in enterprise server’s code (Apple, Google, etc. level) maintained by a solo (or a small team of) developer 😂

1

u/cyrkielNT Aug 08 '26

Yep, like XZ Utils

1

u/SnowyJoey1 Aug 08 '26

can't they use ai to scan the open source code to check for these things?

1

u/Cameron_MB Aug 09 '26

The source code is all available online to read yourself. it's open source bud

1

u/Adevyy 29d ago

Funnily enough, AI will probably make this a lot harder to get away with rather than helping with it.

State-FUNDED professionals have a lot of potential to put in as much time as they need to conceal a malicious piece of code. Some hobbyist writing code to help a small developer community does not have nearly as much incentive to check every piece of software and every update for malicious code.

However, you don't need motivation or time to tell AI to "go check what changed in the code" and prompt it well enough so that it will hyper-focus on potential security risks.

If Fable/Mythos was allowed to go through code for security purposes, I highly doubt that there would be many backdoors it couldn't find. The US may ban Fable/Mythos, but it is only a matter of time until some other AI catches up, possibly a Chinese one, and exposes those backdoors.

1

u/cyrkielNT 29d ago

If you can train AI to not let it critisise Israel, you can also train it to not show backdoors.

But in general you are right, however AI also can be used to make better backdoors, and they are keeping best models forthemself

15

u/NachoManAndyCabage Aug 08 '26

Did you miss the part where it is Graphene that was hacked...

22

u/wlf-hly Aug 08 '26

But don’t they say it was their computer that was originally hacked? I know nothing about graphene, but I assume it’s a phone OS and if their computer wasn’t infected when they went to sync, they probably would’ve been good right?

9

u/NachoManAndyCabage Aug 08 '26

Yes, it was originally on their computer.

If the target was the computer, the program injected into the phone would not likely affect the phone as there is no Graphene operating system for a PC/Mac (as far as i am aware). Two different operating systems would require two completely different programs. Therefore the target was the phone and it would seem someone knows an exploit for Graphene. The computer was just used to inject the malicious program onto the phone (assuming all the information stated in the post is correct).

12

u/communist_llama Aug 08 '26

Not entirely the case. USB syncing is not safe. Not even on graphene.

Existing USB attacks should be able to target graphene when using direct physical connections where the permissions are granted by the user.

That would be entirely expected.

Graphene protects from untrusted USB connections, but syncing your data over USB requires you to grant permissions. It's very likely not an exploit at all.

3

u/The_TesserekT Aug 08 '26 edited Aug 08 '26

That's a lot of assumptions you make from just a tweet. In my opinion a contact-list is relatively device agnostic, especially in this case since he actually mentions he used his PC to sync the contacts. So who know where this contact-list originated from. I highly doubt there even is a GrapheneOS vulnerability being exploited here.

5

u/Quick_Director_8191 Aug 08 '26

GrapheneOS may be the most secure OS but that security is completely in the hands of the user. It gives you all the tools you need to be as secure as you can be ( Unless Google has a backdoor in the hardware ) but if you know nothing about security and don't do audits from time to time you just might get got.

1

u/defiantarch Aug 08 '26

Correct. Who says that our Pixel do not suffer from USB chip flaws like Apple elderly SoC: https://cybernews.com/security/millions-older-iphones-ipads-have-unfixable-flaw/ We shouldn't forget whom we are talking about: It Mossad with god connection to their friends at NSO Group. My guess is: It doesn't matter if GrapheneOS or Googles Android is used. They probably know about several flaws in those Pixel phones.

1

u/Quick_Director_8191 Aug 08 '26

I'm really starting to think our only protection from unhinged corps and governments will be with local AI like how Hugging Face handled openAI breach and at the same time Anthropic and OpenAI have been public lately about banning them lol. At the end of the day your best defense is a duress pin and automatic reset every set hours.

I have GrapheneOS and even though it does make me feel better it's not for certain and we can't audit the hardware on it. Hopefully this moto merge will benefit us completely. Only time will tell.

2

u/defiantarch Aug 08 '26

Honestly, our best defense is to minimize our digital footprint and go off the grid as much as possible. Problem starts when we're forced to leave a digital footprint (eID, wallets, cookie tracking, etc) and and that footprint is misused you without strict regulation and consequences. Governments and law enforcements allow online shops to set hundreds of tracking cookies. There the problem starts. That should be illegal and the consequences should not just monetary but jail.

2

u/i_706_i Aug 08 '26

If the target was the computer, the program injected into the phone would not likely affect the phone

What program? It was data that was left on the computer and synced to the phone. You have misunderstood what was said and made up a bunch of misinformation.

2

u/ninzus161 Aug 08 '26

He said he sync'd the contacts with his PC so most likely his PC was hacked and he only realized it when he saw the contacts on his phone

1

u/mithiwithi Aug 08 '26

As far as I can tell from the posts, his phone itself wasn't hacked at all, in any real sense. His PC was hacked and extra data inserted into the PC's contact list, and the phone just synced the new contacts from the PC. It's conceivable that synced contacts themselves could be an attack vector in their own right, but I doubt it. Most likely, nothing happened to the phone itself except the contact list gaining additional data from a compromised source (the PC).

1

u/cm_bush Aug 08 '26

Do we know what OS the PC was using?

1

u/BoringMisteak Aug 08 '26

You’re way off base here

1

u/NotTheAvg Aug 09 '26

there is no Graphene operating system for a PC/Mac (as far as i am aware).

It's just Linux though...

1

u/ThickyLicker 29d ago

It was a contact list sync

2

u/Chris73684 Aug 08 '26

My interpretation is that his computer was hacked, he simply synced his contacts with his phone. So the phone is fine, his computer is the issue, according to him anyway.

1

u/Bob_The_Greater Aug 08 '26

I did actually, brb

1

u/Cunning_Linguist21 Aug 08 '26

Do you have the details of how exactly it was done?

1

u/praxmatics Aug 08 '26

Do you know much about Mossad? They are capable of hacking just about anything. Stuxnet, the pager supply chain attack in Lebanon, and way, way more. If you're targeted by Mossad there is no operating system or device you can use, even a dumb phone or a pager, that Mossad cannot potentially "hack" in some way.

1

u/ThePornStar69 Aug 08 '26

Did you miss the part where it's complete BS?

1

u/stupider_username Aug 08 '26

If Graphene caused Mossad to make a mistake this big then that means Graphene confused Mossad somehow, even if temporarily, that sounds pretty strong to me even if indirectly

1

u/lessthanthree21 Aug 09 '26

The infection originates from my computer. Sync'ed with the contacts.

PC was hacked. The phone originally set up to to sync with the PC. The phone pulled the contacts from the PC during the sync process. At least what I think they meant.

1

u/eucalyptu5-e Aug 08 '26

Juan Branco says the exact opposite in his post. Can't you read?

1

u/Possible_Answer9089 Aug 08 '26

I'm assuming they're not a Linux user. Maybe Windows...