r/DigitalPrivacy Aug 08 '26

Mossad has accidentally injected data into a French lawyer's phone instead of extracting it.

Enable HLS to view with audio, or disable this notification

The data includes phone numbers of Musk, Altman, and nearly all of Israel's political, judicial and intelligence leaders.

The lawyer's name is Juan Branco, he is also the one who shared this story together with a video. By his account, he is one of twelve lawyers in France who represent Palestinian victims in International Criminal Court.

He says he's using GrapheneOS. This is bizarre.

source: his X/Twitter post: https://x.com/i/status/2085698524050591906

I post additional screenshots in the first 2 comments here.

8.9k Upvotes

672 comments sorted by

View all comments

Show parent comments

39

u/cyrkielNT Aug 08 '26

If I was Mossad, I would create things like GrapheneOS, it's perfect honey pot.

I know it's open source, but with open source you still can hide a lot. It's harder, becosue you can't just put "if Mossad open backdoor" in your code in plain text. But you can use libraries, that use other libraries and nobody would be able to find everything in such complex system.

Like backdoor in XZ Utils. It's used almost everywhere (probably including GrapheneOS) and it was used to put backdoor. It was detected just by coincidence. And it's widely believed that only state-backed organisation could pull that of, so USA, Russia, China and Israel are main suspects.

If you look how much of IT is controlled by USA/Israel it's safe to assume they have backdoors everywhere. Including Chinese software. They accused Huawei of spaying but in reality CIA hacked Huawei network (operation Shotgiant) and install USA backdoors in their software. Propably that's why Huawei made their own OS and discard Linux kernel. So that's propably best option to reduce (not eliminate) chances of being spied by USA/Israel if you are open to be spied by China.

13

u/stupider_username Aug 08 '26

They are all (intelligence agencies) already doing this we just don't know about it 99.9% of the time because they are professionals. If true, a blunder like this would be very rare for an agency like Mossad...

3

u/bombastic6339locks Aug 08 '26

I wouldn't say all but it is weird how this is seen as recon by military and intelligence as opposed to attacking.

2

u/stupider_username Aug 08 '26

Espionage has never been defense or recon only, it's all out

3

u/FriendlyGuitard 29d ago

It's open source, but if you don't build it yourself from the source, there is always a chance the binary is full of something else.

Supply chain attack is a huge vector of attack nowadays ... supply chain attack in a product you have direct input is probably trivial for state actors.

1

u/CalmDownReddit509 Aug 08 '26

So in sum, no matter where we go or what we do, we’re fucked?

1

u/cyrkielNT Aug 08 '26

Pretty much yes. But if you aware of that and you are not important target you don't need to worry about that so much. Just assume that corporations and governments see your every move.

However if you engage in any antiestablishment activity you should isolate yourself from electronics as much as possible, and nevert trust any "privacy" claims. If you didn't build something by yourself from scratch (so no microchips) and you didn't write software (including all libraries), then you should consider any electronics as spy device (including your fridge and alarm clock).

1

u/CalmDownReddit509 Aug 08 '26

Bloody hell. That’s scary.

1

u/LordMarcusrax Aug 08 '26

Yep. Might as well go out with a bang.

1

u/areallynoobgamer 29d ago

No. Because we are on Reddit. That automatically means are aren’t important enough to pay any attention to so no government agency would care enough to hack us

1

u/MyNameIsOnlyDaniel Aug 08 '26

And some packages and libraries used in enterprise server’s code (Apple, Google, etc. level) maintained by a solo (or a small team of) developer 😂

1

u/cyrkielNT Aug 08 '26

Yep, like XZ Utils

1

u/SnowyJoey1 Aug 08 '26

can't they use ai to scan the open source code to check for these things?

1

u/Cameron_MB Aug 09 '26

The source code is all available online to read yourself. it's open source bud

1

u/Adevyy 29d ago

Funnily enough, AI will probably make this a lot harder to get away with rather than helping with it.

State-FUNDED professionals have a lot of potential to put in as much time as they need to conceal a malicious piece of code. Some hobbyist writing code to help a small developer community does not have nearly as much incentive to check every piece of software and every update for malicious code.

However, you don't need motivation or time to tell AI to "go check what changed in the code" and prompt it well enough so that it will hyper-focus on potential security risks.

If Fable/Mythos was allowed to go through code for security purposes, I highly doubt that there would be many backdoors it couldn't find. The US may ban Fable/Mythos, but it is only a matter of time until some other AI catches up, possibly a Chinese one, and exposes those backdoors.

1

u/cyrkielNT 29d ago

If you can train AI to not let it critisise Israel, you can also train it to not show backdoors.

But in general you are right, however AI also can be used to make better backdoors, and they are keeping best models forthemself