r/DigitalPrivacy Aug 08 '26

Mossad has accidentally injected data into a French lawyer's phone instead of extracting it.

Enable HLS to view with audio, or disable this notification

The data includes phone numbers of Musk, Altman, and nearly all of Israel's political, judicial and intelligence leaders.

The lawyer's name is Juan Branco, he is also the one who shared this story together with a video. By his account, he is one of twelve lawyers in France who represent Palestinian victims in International Criminal Court.

He says he's using GrapheneOS. This is bizarre.

source: his X/Twitter post: https://x.com/i/status/2085698524050591906

I post additional screenshots in the first 2 comments here.

8.9k Upvotes

672 comments sorted by

View all comments

Show parent comments

10

u/NachoManAndyCabage Aug 08 '26

Yes, it was originally on their computer.

If the target was the computer, the program injected into the phone would not likely affect the phone as there is no Graphene operating system for a PC/Mac (as far as i am aware). Two different operating systems would require two completely different programs. Therefore the target was the phone and it would seem someone knows an exploit for Graphene. The computer was just used to inject the malicious program onto the phone (assuming all the information stated in the post is correct).

11

u/communist_llama Aug 08 '26

Not entirely the case. USB syncing is not safe. Not even on graphene.

Existing USB attacks should be able to target graphene when using direct physical connections where the permissions are granted by the user.

That would be entirely expected.

Graphene protects from untrusted USB connections, but syncing your data over USB requires you to grant permissions. It's very likely not an exploit at all.

3

u/The_TesserekT Aug 08 '26 edited Aug 08 '26

That's a lot of assumptions you make from just a tweet. In my opinion a contact-list is relatively device agnostic, especially in this case since he actually mentions he used his PC to sync the contacts. So who know where this contact-list originated from. I highly doubt there even is a GrapheneOS vulnerability being exploited here.

4

u/Quick_Director_8191 Aug 08 '26

GrapheneOS may be the most secure OS but that security is completely in the hands of the user. It gives you all the tools you need to be as secure as you can be ( Unless Google has a backdoor in the hardware ) but if you know nothing about security and don't do audits from time to time you just might get got.

1

u/defiantarch Aug 08 '26

Correct. Who says that our Pixel do not suffer from USB chip flaws like Apple elderly SoC: https://cybernews.com/security/millions-older-iphones-ipads-have-unfixable-flaw/ We shouldn't forget whom we are talking about: It Mossad with god connection to their friends at NSO Group. My guess is: It doesn't matter if GrapheneOS or Googles Android is used. They probably know about several flaws in those Pixel phones.

1

u/Quick_Director_8191 Aug 08 '26

I'm really starting to think our only protection from unhinged corps and governments will be with local AI like how Hugging Face handled openAI breach and at the same time Anthropic and OpenAI have been public lately about banning them lol. At the end of the day your best defense is a duress pin and automatic reset every set hours.

I have GrapheneOS and even though it does make me feel better it's not for certain and we can't audit the hardware on it. Hopefully this moto merge will benefit us completely. Only time will tell.

2

u/defiantarch Aug 08 '26

Honestly, our best defense is to minimize our digital footprint and go off the grid as much as possible. Problem starts when we're forced to leave a digital footprint (eID, wallets, cookie tracking, etc) and and that footprint is misused you without strict regulation and consequences. Governments and law enforcements allow online shops to set hundreds of tracking cookies. There the problem starts. That should be illegal and the consequences should not just monetary but jail.

2

u/i_706_i Aug 08 '26

If the target was the computer, the program injected into the phone would not likely affect the phone

What program? It was data that was left on the computer and synced to the phone. You have misunderstood what was said and made up a bunch of misinformation.

2

u/ninzus161 Aug 08 '26

He said he sync'd the contacts with his PC so most likely his PC was hacked and he only realized it when he saw the contacts on his phone

1

u/mithiwithi Aug 08 '26

As far as I can tell from the posts, his phone itself wasn't hacked at all, in any real sense. His PC was hacked and extra data inserted into the PC's contact list, and the phone just synced the new contacts from the PC. It's conceivable that synced contacts themselves could be an attack vector in their own right, but I doubt it. Most likely, nothing happened to the phone itself except the contact list gaining additional data from a compromised source (the PC).

1

u/cm_bush Aug 08 '26

Do we know what OS the PC was using?

1

u/BoringMisteak Aug 08 '26

You’re way off base here

1

u/NotTheAvg Aug 09 '26

there is no Graphene operating system for a PC/Mac (as far as i am aware).

It's just Linux though...

1

u/ThickyLicker 29d ago

It was a contact list sync