Apple Says iPhone Is Safe. We Keep Finding Malware
Key Takeaways
The video discusses the vulnerability of Apple iPhones to malware, despite the company's claims of extreme security, and highlights the sophistication and maliciousness of Pegasus malware developed by the NSO group, as well as the importance of cybersecurity and digital infrastructure security, with tools such as Linux, Python, and Brilliant being mentioned.
Full Transcript
Mr. Robot. There's a scene the very first season where Elliott is talking to Vera's brother and his brother comes and visits him in his little tiny crummy apartment in in New York City and he hacks his phone because easily because they're on the same Wi-Fi network. So the brother asks them, "What's your password on your Wi-Fi?" Oh, okay. Here's my password. You know, 1 2 3 4 5 6 7 8. Okay, go ahead and connect. Once he's on the same network, then it's easy, relatively everything's relative, right? Relatively easy to hack that phone. And I will tell you from firsthand experience that there's a lot of malware on Apple phones. Okay, >> interesting. >> We see a lot. So that that first statement that offtheshelf malware cannot be used against Apple products is false, right? So, >> hey everyone, David Bumble back with the amazing OTW. OTW, great to have you back on the show. David, thanks once again to having me back to talk about the important issues in cyber security and IT in 2025. >> Yeah, >> I'm really looking forward to this because this is like talking about some really interesting topics with malware and the like. I'll let you break the news. But before we get there, for everyone who hasn't seen our previous videos, OTW is the author of this book, fantastic book if you want to learn about Linux. And as OTW says many, many times, he's a hacker and if you want to become like him, you need to learn Linux. So, he's got this great book, Linux Basics for Hackers, if you want to learn Linux. He's also got this book, Network Basics for Hackers. Fantastic from a network point of view. My favorite, obviously. And then, getting started, becoming a master hacker. And OTW, I hate putting you on the spot, but Python for hackers. Coming soon, hopefully. >> It's coming soon. Right around the corner. It's going to be out soon. I, you know, I want to make sure that it's as high a quality as those other books. So, take a little longer, a little longer than I had anticipated. So, >> we'll forgive you for that. Um, so we're looking forward to that. So, no pressure. >> Big shout out to to Brilliant for sponsoring this video. If you really want to understand how technology works, have a look at Brilliant's wide range of courses. Brilliant has clear learning paths for you to learn a whole range of concepts and principles that take you from beginner levels of knowledge to advanced levels of knowledge. Brilliant helps you become a better thinker and problem solver with thousands of visual interactive lessons in math, science, programming, data analysis, and AI. As an example, the digital circuits and circuits courses let you explore gates, timing, and behavior by actually poking at the system. You start with the basics and steadily take on tougher problems until the pieces connect and the whole picture makes sense. This is a very satisfying way to learn where you're learning step by step and getting feedback at every point in your journey. If you want to start learning today for free, go to brilliant.org/davidbombble or scan the QR code on screen or click on the link in the video description. Brilliant also gives you 20% off an annual premium subscription if you use my link which gives you unlimited daily access to everything on Brilliant OW. Now, let's jump into the topic. Right. There's been some interesting updates with regards to one of the topics that we spoke about in the past. So, Pegasus malware. So, perhaps you can tell us about this uh this malware and why people should care and you know what's been happening and then I'll hit you with some questions that I've got as well. >> Okay, sounds good. Well, we did a show a while back about Pegasus. Um, Pegasus is developed by the NSO group out of Israel. It's probably the most sophisticated and malicious uh malware in the world at that time. I questioned whether or not it should be legal and we got a lot of feed got a lot of feedback about that. Um, but a court on Friday, so Friday, what October where that was, uh, 19th, I believe, came out with a ruling that said that Pegasus could not intercept messages on WhatsApp on WhatsApp. The the >> Yeah, I've I've got some cynical takes on this. I'll let you talk and then I'm going to hit you with the cynical stuff. Right. Well, they weren't sued by the government. So, it's not, you know, it's not a um it's not a criminal act. The suit was brought by Facebook, okay, by Meta and they said, "You cannot spy on our application." So, there's no law breaking here. It's a it's a principle that this is their property, WhatsApp is, and that somebody else can't infringe upon their property. and cause damage to it. So the ruling is very specific. It's a permanent injunction. That means they can never they never never in the future access WhatsApp and any other okay and any other Meta product including Facebook and Instagram, what have you. But we don't have any evidence that they ever did that. But it's specifically to Meta because Meta brought the suit. It doesn't extend to anything else on your phone. So any other app you have on your phone, any other communication that's taking place on your phone, it's all can be targeted by NSO groups Pegasus. So this is very specific. It's very narrow, but it also raises issues for anybody who has been accessed, their data has been accessed by NSO, whether or not, you know, I think they have a suit to bring against NSO. And so it was a corporation now owned by an group of American investors. And so this is, you know, this is something that the American courts may be addressing here soon. But it's uh it's really interesting that we finally have some ruling that kind of says yes, this is beyond the pale. This is not acceptable. But unless you sue NSO, and this is what happened, unless you sue and wait six years, this took six years to get a ruling. Six years. and they said, "Okay, you cannot access this particular company's product. It doesn't say anything about anybody else's product, but it also kind of reflects badly upon the NSO, you know, that they really are producing a product that is infringing upon somebody's corporate property, WhatsApp, okay, and people's privacy. And they're doing this specifically to capture information of political enemies, journalists, lawyers, diplomats. They're looking at a lot of people's systems. And I've seen evidence I've seen evidence that it's goes beyond just those people. I mean, so you know, mostly it's been targeted towards human rights activists, journalists, political dissident, some diplomats, foreign uh foreign service people, but I've seen it on regular people's phones, regular like you and I. We're just regular people. And and so it it's something that I've been concerned about for quite a while. And I'm I actually take some heart in this ruling, but it's still very narrow ruling. It just says WhatsApp. So if you're texting or you're calling or you're emailing, they can still have access to what you're talking about, what you're saying, what you're doing. So of course, it doesn't keep them from spying on your location, which is what it's been used for a lot now. So if a government wants to find somebody to kill them, uh or to disappear them, um they can find them. And uh and similar software has been being used recently by ICE, not the same software, but similar software by ICE in the US to uh locate people that they want to deport from the United States. So yeah, it's it's a it's a big and important issue. It's not, you know, I think this is we're shaping we're shaping the future of cyber security and it right now in real time. So these kinds of rulings will have effect, you know, for years to come. And hopefully we'll see like other companies also sue NSO and then and then prohibit get prohibitions on intercepting their information as well. >> So I'm going to take on the role in this video as being a bit cynical. Let me see if I got this right. Mark Zuckerberg is upset that someone is spying on his software. Doesn't he spy on us all the time? So that's just a cynical joke, right? So my take on that is yeah that WhatsApp and spies on all of us right and Facebook Facebook spies we we know this Facebook's been spying on us for for you know since the beginning of Facebook and WhatsApp spies but they don't want anybody else spying on us. They only want they only want to spy on us. They this is our territory. Only we can spy here. >> Our territory, >> right? You guys can't spy. there's Facebook is spying on us and they're selling our data. You know, they're selling everything they know about us. And that's kind of the model of the, you know, the IT, you know, industry right now is that companies are making huge amounts of money just selling our information, which a very wise man said a long time ago that if uh service is free, you're not the customer, you're the product. So, >> unless it's Linux. Sorry, go on. >> As someone in the comments said, cuz I I must give credit to the people commenting. So, for everyone who comments on the videos, I really appreciate it cuz someone said, "What about Linux?" And there were quite a few comments like that. But you can't say that. What about Linux? What about open source? So, I mean, there are exceptions, right? But it's I know what I know what you're saying. >> And I guess it comes down to the definition of service. I would say Linux is a product, right? >> It's a product. Um but technically in the United States any all software is considered a service. So that's why for instance you know like if your car if your car breaks down or has a defect and you die in a crash because your car has a defect you can sue the car manufacturer. Toyota, Mazda, General Motor. You can sue them. And there's a lot of lawsuits that take place in the United States what's called product liability laws, right? But that doesn't apply to software because in the United States software is a service. It's not a product. So it's one of those it's one of those things that the lobbyists in the United States got software tagged as a service rather than a product. So if it was considered a product every time you lost your data because you know of a hack, you could sue the developer like you can with a car. a car puts out a they put out a bad car or if you you have a baby seat and it fails and your baby gets hurt, you can sue the manufacturer for compensation. You can't do that with software. And it's actually, you know, it's been around. Bruce Schneider said this a long time ago and he said if if we make software into a product and hold them responsible like we do with products then there will be a lot fewer bad software out there that hackers can easily easily get inside of. >> So that's great. I mean it's ironic is perhaps the word that someone like Facebook is complaining that another company is spying on them when they spy on us all the time. So that >> it's kind of like it's it's kind of like trespassing, right? That's basically what they're saying. It's like this this this is our territory. Only we can spy here. You can't. >> So next thing next thing I'm going to hit you with, right? Okay. So a judge um has decided in a court of law in the US that um NSO can't spy on WhatsApp. But you, as you mentioned, and we've discussed as well in the past, the the governments around the world use Pegasus and use the software to spy on their citizens. I think you mentioned before that Pegasus is banned in the US. Is that right? But what's to stop the NSA? Let's just I mean I is kind of controversial. So just for everyone watching, I'm based in the UK, so you know I I I hear stuff happening in the US, but leaving the politics out of it. Let's pick on the NSA cuz you know OTW you and I like to pick on them. What's to stop the NSA just using the software because it feels sometimes that governments are above the law. So a judge could say whatever they want, but I mean it doesn't affect some of these three-letter agencies. >> No, it it certainly does not because the three-letter agencies are always above the law law. They make the law. Whatever they decide is legal is legal, right? And there have been cases in the past where the NSA, CIA have actually run into legal problems, but we don't see that in recent years. Basically, they're doing whatever they want to do. So, even though NSO groups products are banned in the US by the US government, that doesn't mean that other other companies aren't producing something almost exactly the same or the NSO actually NSO the NSA has contractors who are very talented people, right? So, not everything that the NSA does comes out of the NSA. They buy products, they buy services, and so they contract out, okay, to this kind of development, and they they'll pay millions, tens of millions of dollars for products and services that they can spy on us. I mean, you and I had talked about Eternal Blue, which was that piece of software that came out, meaning software, malware, software, whatever you want to call it. um came out 2017, developed by a contractor to the NSA that allowed the NSA to spy on everybody's machine that we only know about that because it got stolen, right? And then it got released to the public. There's all kinds of things that are out there that three-letter agencies like ICE, like CIA, like NSA, and I think in the United States there's 17 intelligence agencies. There's seven there's 17 intelligence agency. So we can we're talking about you know these three but there's another 14 out there who who are also doing intelligence and uh so they can develop on their own. They can purchase you know there's a lot of companies out there for for all you young hackers out there's actually a legitimate career that's legal to produce malware for governments. Okay? As long as you're serving the government, it's legal. If you're serving somebody else, it's illegal. >> Yeah. I want to I want to hit on that in a second because Apple's there's been some recent developments with Apple as well that we should talk about. But I mean, while you're talking about this, I remember the case of Edward Snowden where the US government wasn't allowed to spy on their citizens, but they were working handinhand with the UK and GCHQ, if I remember correctly, and you guys can correct me in the comments, but I think it was the way it worked at that time is the US uh organizations couldn't spy on US citizens. So, they just got GCHQ in the UK to do it, and then they could spy all their telecommunications from of US citizens. I don't know if you remember that story. I >> I do remember that. Yes. Uh and and that's the way that the the intelligence agencies work hand in hand. The NSA though their mission is like counterintelligence. Unlike the cyber command which their and the CIA their job is to attack enemies, NSA's job is to find the enemies in America and that often includes Americans. uh and they can spy on Americans if they are in communication with somebody that they believe is a enemy. So if you're communicating with somebody who they believe is an enemy, they can spy on your that's legal for them. There's no reason to believe that your communication is with a spy or somebody who has is against the US interest. They're supposed to not listen in on your conversation. That's the that's the difference that they make in their minds, right? That that they they can only spy on you if they think you're talking to somebody who's bad, right? And so that does that basically doesn't that that doesn't exclude anybody really. >> Exactly. >> Yeah. OTW, they're listening to you right now. >> Oh, I know. I know they listen to me because they they tell me they are. I actually get messages and they say, "Oh, just just just know that we're listening." >> That's funny. >> That we're we know everything that you're doing. And okay, thank you. Thank you for for reminding me of that. >> So, so let's let's let's bring this back, right? This ruling, I mean, what's your take on it? Is it is it valuable? I mean, I suppose from the point of view that citizens can sue, like you said, because I don't it doesn't seem to me that it's going to stop much. Um, but perhaps I'm wrong about it. >> Well, it's probably not going to stop anything probably, right? But it does give the people who are spied upon the right to sue. And but that's a long drawn out process. Hopefully, you know, in the United States, the way it would work is that some enterprising lawyer, let's call him enter, let's call him enterprising. >> I love it when I drive around the US and I see all those billboards, >> right? >> I'm this lawyer. I can sue on your behalf. It's like really strange to see it from a UK point of view, but sorry, go on. >> Those are the enterprising lawyers I'm talking about. >> Yeah. >> That that will be soliciting business. And of course they'll take 30 to 40% of whatever is awarded. So they these enterprising lawyers will will create a class action suit okay against NSO and and that's probably the only thing that'll happen unless there's somebody very wealthy who's being spied on then it's not going to happen. But even that you can see here that you know it took them six years to get a ruling through the American legal system which is really really slow unless you're an illegal alien and then legal system works in like 30 seconds. >> At least now it does. >> Yeah. I mean I mean let's avoid the the situation the politics right there because I think that's um >> the edit editors can cut that out. >> No no we'll leave it in. It doesn't matter. Just for everyone who's watching, I don't restrict what people say on these interviews, so they can say what they want. OTW, it seems really strange, right? Just in the news recently, NSO, who makes Pegasus, has been purchased or acquired by a US investor group. That doesn't sound like a good investment, unless there must be lots of money to be made or something, right? >> Oh, yeah. I mean, if I were an investor who was only interested in making money and not interested in any kind of the legal or ethic issues, um, NSO makes a lot of money. They make they charge they charge $20,000 a phone. $20,000 a phone. All right. So that it's it's a significant amount of money and they've got a lot invested in it. I don't know how many people know this, but NSO has a long history with unit 8200 in Israel. And so those guys kind of go unit 8200 in Israel. This is not being political or nationalistic at all, but they're probably the best hacking group in the world. All right? And so these guys are good. And so guys go to the unit 8200. They work there. It's kind of like the US's NSA. Similar except that it's more it's both defense and offense both. Um and then they go to NSO after leaving the uh 8200. And there's also a big facility, apple facility right there. And so we we see a lot of cross-pollination cross-pollination taking place between NSO, the unit 8200 and Apple. Okay. So that's interesting. >> That's why that's why that's why they're so good at hacking Apple products because really I mean this is why they have in insight inner insight into the operating system that few others have. So, I'm glad you raised Apple because iPhone 17, I mean, forgetting the flashiness and like all the consumer related related stuff, there was something in the announcement that was really interesting where they are talking about memory integrity enforcement and they would in this like release that I was I've been reading about it. They say that Apple phones, iPhones specifically are very very difficult to hack. There's no consumer kind of malware that attacks an iPhone. But the problem is this mercenary spyware which Pegasus is an example of. And so what they are doing is they have now got this memory integrity protection on iPhones which they say is going to make it much much harder and much more expensive to attack iPhones. So what's your take on that? Do you think it's a good thing? Would you recommend an iPhone for someone who's like a journalist or someone who's scared of being or having the software put on their phones? My take on it first is that one of the services that we offer at Hackers Arise is that we we help people who've been hacked. And I will tell you from firsthand experience that there's a lot of malware on Apple phones. Okay. >> Interesting. >> We see a lot. So that that first statement that offtheshelf malware cannot be used against Apple products is false. Right? So, and people who are listening to this, okay, all of you who are listening, many of you know this already. Many of you already know this because you know that your phone's been hacked, right? Apple is in the dark in that regard that they don't realize that their phones are getting hacked and they're getting hacked at a really high level. The software is not that sophisticated. But, so that's the first point. Okay, the second point. The second point is that this reminds me a lot of address space randomization or ASLR which is a good thing you know or data execution protection which basically limits what can actually take place in certain data areas in the operating system or it randomizes where a a service is going to execute. just keeps it makes it harder for the malware to predict okay where the data is actually going to be at. This reminds me the new measures by Apple, you know, the what they call the memory integrity enforcement is is a lot sounds a lot and I haven't really looked at it closely, but it sounds a lot like ASLR where, you know, we've had this in our in our operating systems for well over a dec. And it was meant to do the same thing as the memory integrity enforcement uh or similar things. and it it became relatively easy to overcome. Um, lots of malware overcomes it. And so my thoughts are that it it'll slow some people down. Yeah, it'll slow some people down. It'll probably make it a little little harder to hack than an Apple phone, but quite frankly, it's not that hard right now. And I know people always come to me, they're all, isn't an iPhone unhackable? Like, well, not from not from my experience. Look at I got all these photos. >> That's what Apple's selling. Go. I got all these phones right here that are full of malware. So that's my proof. So people come to me like, I I bought it I bought an iPhone because I thought it was unhackable. Well, you're proof that it's not. So, you know, this latest measure by Apple, and I give Apple, you know, a lot more credit than I give to Google in terms of cyber security. you know they Google you know doesn't put as much effort into keeping their platform uh free but at the same time they don't free of malware and making it unhackable but what bothers me about Apple is they try to sell the public that the system is unhackable and then you know these people like I'm you know they have all the evidence that they've been hacked and but they're convinced that it's not their phone because that the phone is unhackable these They have I have an iPhone. OTW, I have an iPhone. It can't be the phone, right? And then we go inside their phone and go, "Oh my god, look at all this stuff." So, it'll make it a little harder to hack the phones. And once again, it's encouraging to see a company who takes cyber security as seriously as Apple does. They do. They take it far more seriously than the Android platform does and the other platforms do. But at the same time, to sell the idea that it's unhackable is not true. That's that's marketing fluff. That's not real. >> I'm glad you said that cuz my I mean, you were ahead of me. My next question, as I wrote down here, is what would you recommend? Is Android better than iOS or Apple? So, from a cyber security point of view, would you recommend someone get or is it like graphine OS or something like that? Um, it sounds like Android you see is worse than iOS. Sorry, but go on. >> Yeah, it's certainly it's easier to hack an Android phone. One of the things that's kind of surprised me, Dave, if I can just take a side view here, is that >> Yeah. >> Yeah. And this kind of addresses the same issue, but since we started doing um forensic investigations on phones and computers and what have you, I'm shocked to see how much malware these people have on their phones. I I don't >> it it's coming from all different places. It's not just one place. And it's not it's not the government. It's coming in from all different places. and they have they have malware from multiple sources and it's kind of disturbing you know it's disturbing that there is this much malware floating around in the world I think that in part that people are using hacker for higher services and hacking their friends neighbors uh business competitor I saw one recently I saw I have I have a client who's a YouTuber and his you his YouTube competitor paid somebody to hack his phone and it was inside his phones and just driving him crazy. So, my staff knows, maybe I mentioned this to you, that, you know, I get these emails all the time like, "Oh, my house has been hacked, my home has been hacked, my car has been hacked, my computer's been hacked, and my phone's been hacked, and my garage door has been hacked, and my speaker has been hacked, my my smart home has been hacked." And I would go right away. I'd look at that and I'd go, "These people have mental health problems. It's not it's not this isn't a hacking problem. This is a mental health." But I now take that back. Okay. >> Interesting. Yeah. >> I take I take that back. I'm correct. They really are hacked. We have been going through these homes and we've been going through these phones and we've been going through these computers and they're full of malware. They're full of their routers are full of malware. Their smart home devices are full of malware. And you know, people are having their garage doors open randomly, their lights go on and off, the doors open and close because in a smart home you can do all of those things once you're inside that network. And so this is something that's been eyeopening to me because for years I thought that those people were imagining that they were hacked. I'm like, okay. But in reality, they are hacked. They have been hacked. And this is really concerning that. So many people it looks like it's kind of low-level hacking. It's not like real sophisticated hacking. So it's not coming from a you know advanced persistent threat. It's not coming from a government. It's coming like low-level hackers are hacking people right for whatever reason. I don't know. I still we're still trying to decipher this or what is what's going on here? Why are these people's lives entirely hacked? So yeah, and some of you out there know what I'm talking about because you've experienced this, but I would have said they were all crazy until recently. It's like maybe nine months ago. >> It's pretty It's pretty new for me. >> Yeah. So I mean the question is like I'll get back to I want to still push you on the Android versus iOS thing. But before we get there, how did they get hacked though? Is it It sounds like social engineering is the way because to hack an Apple phone, it's going to be like NSO type level hacks. or is it just like people are downloading stuff or getting convinced to install malware? I mean, how does it actually get on the device? >> I think I'm going to refrain from answering that because it's too easy and what we've seen is is is a very simple way. It's a it's a very simple way to get into an iPhone. And I'm not going to mention it here because, >> you know, we'll see more of it then, right? But it's it's a simple way to get inside of a Apple phone and uh and so and we're seeing a lot of it. Um and I don't see anybody talking about it. I don't see anybody online talking about it. So, and anybody else I talked to in the industry, you know, they're all everybody's focused on, you know, the the social engineering, the NSO group, but there's some simple ways and and I guess you would probably throw it into the category of social engineering. you probably put it in that way. So yeah, it's it's social engineering has an element of social engineering which goes back to what I've said so many times is that like 80% of the hacks have a social engineering element. So that's how you social engineering is how you get into the system. But then what you do inside the system is very technical. So you've got to have a good product. Once you're inside the system, you got to have a good product to get in stay get in there and stay in there, right? So you can control the system. So it has two key elements. Got to get inside the system. Social engineering. What you do inside the system is very technical. >> Yeah. Because it's very interesting what you're saying and kind of shocking, right? Because Apple have now just doubled their bounties. So, their bug bounty program where they will pay $2 million from up from 1 million and increased to $5 million if someone can hack into an iPhone that has lockdown mode enabled, which obviously really restricts the device and um get past this memory integrity stuff. So, I mean like we can put the bounties on screen, but there's like huge bounties to be made. Well, huge. And I'm pretty sure you as a as like a hacker will say you can get money elsewhere, but like $5 million. Um I mentioned this on a video and a lot of the comments well like that's too little money. So what's your take on that? Like would that make it harder firstly and what about the money and the payouts? >> Okay, so if I I'm sitting home in my home lab and I develop a Pegasus like piece of malware that can do what what Pegasus does, which basically allows them to get inside your phone and totally control and read everything you're doing. It's going to be worth a lot more than $5 million to sell to governments, right? So, I can sell it to whatever government, whoever wants to spy on their citizens. It's worth lot more than $5 million. So, it's going to be the person who has, you know, some uh ethical or moral boundaries and says that's not I don't want to do that. But people who are simply in it for money, which a lot of people are, $5 million is not enough, right? $5 million is not enough money to to get somebody to to choose Apple versus some authoritarian government um who wants to spy on their citizens who will pay, you know, millions and millions probably in in the area of hundreds of millions of dollars for a piece of software like that. >> It's interesting. I mean, I've seen I I've interviewed Steven Sims, amazing malware guy, and he's like he spoke about like these these places where you can go sell 20 million or whatever it is. I mean, I I I can see why why you why you have that point of view. Um certain governments, you know, that what's 100 million or 20 million to them. So, I mean, that is a problem. It's good to see that Apple are doing this though to try and encourage people that are moral and ethical to um to to make them aware of it. So I I understand both sides. So I want to pull you back into this about like Android versus iOS versus say graphine which is is a very popular choice for a lot of privacy and security focused folks. What's your take like I mean I I mean I don't want to put you on the spot but like if you had to choose a phone because you have to have a phone let's say in today's world is it stock Android? Is it iOS? Is it graphine or maybe something else? Well, of the the the major manufacturers, I would have to say that Apple does takes security more serious than the others. The only problem I have is is the marketing and says that they they portray themselves as unhackable. That's not true, but it's harder to hack. I >> Okay, >> that's and it's always the case in in the real world that nothing's unhackable. Nothing's unhackable. Everything's hackable. It's just a matter of how hard is it to hack. This is an important point because hackers will tend to target the easiest targets, right? So, if I can't get into your phone because you're using a graphine, well, I might check to see if you have another phone and I'll I'll look over your shoulder and see on your desk, oh, wait, there's an Android phone over there and or there's an Apple phone or you know, many multiple ways of determining that or get into somebody else in your household. I've seen this. Okay, so they're targeting you, but they'll get into somebody else in your household. And then once they're inside your local area network because your phone's going to connect to the Wi-Fi, right? Your phone's going to connect to Bluetooth, your phone's going to connect to the Wi-Fi, and from there, it will move to all the devices on the network. That's why we're that's what we're seeing happen in in so many of these cases where everything is hacked. One person carries in a phone that's been infected, right? Thinking about that portrayal in mass media again and my favorite TV TV show, Mr. Robot. There's a scene the very first season where Elliot is talking to Vera's brother and his brother comes in, visits him in his little tiny crummy apartment in in New York City, and he hacks his phone because easily because they're on the same Wi-Fi network. So the brother asks them, "What's your password on your Wi-Fi?" Oh, okay. Here's my password. You know, 1 2 3 4 5 6 7 8. Okay, go ahead and connect to it. Once he's on the same network, then it's easy, relatively. Everything is relative, right? Relatively easy to hack that phone. So once you're on the same network, once the attacker is inside your perimeter, okay, inside your network, everything is much easier. Then the grafting is real hard to hack. The Apple's hard to hack. Apple mean the um Android is easier to hack is the easiest of the major market and the older the phone is the easier it is to hack. There's lots and lots of relatively simple hacks that can be done against an Android phone. And we know that there are millions and millions of people out there with old phones and Android is like Android in global market I think it's 82% right and many of those people are using old um unupdated phones um and those are pretty easy to attack but >> I should get a Nokia. Sorry. Go on. I was just going to make a joke. Get a Nokia. Right. Go on. >> Yeah. Is is Nokia still around? I'm just kidding. >> Oh yeah yeah yeah. Good point. Yeah. So yeah, I mean it's that old joke. Should I just get a flip phone? Right. >> I actually have a Nokia here on my desk that I I use I use for various purposes. It's not my main phone, but it's like, oh yeah, Nokia is still around. At one time they were the dominant company in in cell phone handsets, right? The uh the Finnish, I believe that's they got purchased by Microsoft, didn't they? Well, maybe not. Yeah, >> there was a Yeah, Microsoft was involved some of the phones, but it's like um so I'm going to pull you back to graphine maybe is a graphine is a good choice. iOS iOS and then Android last >> stock Android. But like a flip phone is not going to protect you because a lot of people say that flip phones are the way to go if you want it to be private and secure. >> Well, it's going to take a whole different attack, but it's, you know, for the most part those old flip phones, you have almost no defenses in place. And and then remember of course that all of the devices when we talk about IoT, right? And a phone is probably I can put it in the category of IoT as internet of things, right? There's a Linux operating system there, right? All these devices have Linux kernels. They have Linux operating systems and they Linux people sometimes will think that Linux isn't hackable, but it is hackable, right? And so yes, there's probably less malware. No, there is less malware developed for Linux just because there's fewer systems that use Linux, but almost all of those devices in your home, in your hand, in your car are running Linux kernels, right? And so that means that attacker can get inside of that operating system just like they can get inside of your desktop or your server and do all kinds of bad things. And then once they're inside one device, right, it's relatively easy to hop to other devices in the home, in the office, in the network. So just keep that in mind. Everything is hackable. It's only a matter of how much time, energy, and money the hacker wants to put into attacking. There's always a way in. And >> I think people for forget about the fact that um if you have a flip phone, you still got to communicate somehow, right? So, if you've got a flip phone, you're going to communicate with voice calls and you're going to communicate with SMSS. And it's funny, I just saw something recently where university uh students were looking at satellites and the communication was in clear text. So, they were getting a lots of phone calls and SMSs through satellite communication. So, I mean, what's your take on that? I mean, you still got to communicate and the problem is SMS is clear text. Is that right? And phone calls could be clear text. >> Yes. So, let's let's talk a little bit about that. So if the attacker is inside the phone system, which we know that the Chinese did last year and they still might be there, okay, and probably, you know, the US and Britain are in other countries phone system because it's not when you're at that level of attack, a message threat, when you're at that level, it's relatively easy to attack a phone system. So that's why the the governments are attacking each other's phone systems. So that is and it can be done by cyber crime too. If somebody is inside the phone system that all of your calls and all of your texts, okay, can be intercepted and eased dropped on, right? We have a satellite hacking class that we So I was been a little snarky on on X lately. It's like, okay, this new study came out and said that you can intercept phone calls on satellites, satellite phones. Like, oh yeah, we did this already. This is this is something that we've done in class, right? Yeah. >> So, it's it's not new. It's not new information. I'm glad that somebody confirmed what we've already done. And I'll plug our satellite hacking class in 2026. We're going to have a new updated satellite hacking class in 2026. and you'll see all the ways that you can hack a satellite. And many of the services are still sending messages in clear text. All right? So, even if they they encrypt it, you know, there's still a possibility of decryting it. It's not easy obviously, but when you send it in clear text, you're really looking for trouble. And it's important to know this also because almost at least in the US, okay, and I they're like Starlink, okay, Starlink is a low Earth orbit satellite system, 40,000 satellites around the globe, right? Low Earth. The reason that's important is it's low Earth is that the latency between the handset and the satellite is small. It's shorter and so you get good throughput, okay? And it's done very quickly. Starlink did this. Now many other companies are offering for instance Amazon is going to start competing with Starlink with low earth satellites. >> Interesting. >> But but there's other companies who have low earth satellites up there now who are renting space. Okay. contracting with your telecom carrier like Verizon, AT&T in the US and they're offering satellite services so that if you're on a mountaintop some place and you don't have cells service there's actually a lot of places in the US even though the US is pretty saturated you know in the rural areas oftentimes there's no service so they're selling this as a way that you can text you can SMS through the satellite right so You're never offline. So if you're on a mountaintop and a big snowstorm comes through, you can you can say goodbye to your friends. >> That's very dark. But yeah, go on. It's a dog take. Ootw. I would expect that from a black hat hacker. >> Sorry. >> No, that's funny. Go on. >> Um, yeah, you can say goodbye to your friends by by satellite text message. So this means that the whole system of satellite text messages is a potential vector to intercepting and easedropping on these communications. So >> so we started talking about this thing that WhatsApp which is hilarious in a way is complaining that someone's spying on them. So I just want to I had it written down here. Another question WhatsApp or Signal or have you got a preference or would you prefer not to say? No, I I always am reluctant to endorse a product because what happens then if I endorse a product and then people get hacked then they blame me, right? >> Yeah. >> So my my advice always is be vigilant. That's that's the only solution is be vigilant, right? You cannot in in 2025 we have built this incredible digital infrastructure that spans the globe. All right. But that digital infrastructure is flawed. It's weak, right? And it needs to be strengthened. Otherwise, everything that you do, you say, your location is available to anybody who wants it. So, be vigilant. All right? And don't necessarily trust anything. Now, you know, it's a good rule that when you're online on the internet, don't trust anything. Don't trust the don't trust the information you're being given. Don't trust that link that somebody sent you that's going to make you millions of dollars. Don't trust >> And don't trust Liz don't don't trust what we say. No, sorry. Go on. I was just joking. >> And and don't trust what I say. You can trust what David says. Just don't trust what I say. >> That's right. >> Um because they've built they us digital infrastructure that is so flawed, right? because people built it, you know, starting in the 1970s and that most of much of the infrastructure has been built without security in mind and that's put all of us at risk. So some point in the future maybe this system gets replaced and this time it gets built with security in mind instead of constantly trying to bolt on security. Rather than build it with security, they bolt on security and bolt on means an after. It's an after effect. They try to put something into secure afterwards versus designing it for security which is you know this is a cardinal rule that almost every software engineer gets taught right now. Okay, you start from security. You start thinking about security when you're designing the whole architecture of your application. Unfortunately, not everybody does that because everybody's under this kind of commercial time frame that has to come out, you know, as quickly as possible and we get lots of software that comes out that is just really, really flawed. And sometimes we don't know how flawed it is until somebody starts hacking it like our VPN router article that showed that we did a while ago. And that continues. I mean, there's still the the VPNs and routers are getting hacked like all the time that because nobody paid attention to them how easy it is to hack them, right? And these guys didn't design it with security in mind. They like, "Oh yeah, we can do all the things that a VPN should do. We'll encrypt the data, blah blah blah." But you didn't make your operating system safe. So, you can hack the operating system inside the router. And then once you're inside the router, then everything is mine. you know, everything. I I see everything you're doing. I see all your traffic. You know, I can intercept all your traffic. And so, this continues today that we still continue to see these these devices or like the F5 that came out, you know, the the load balance the F5, >> you know, it's it's being hacked right and left. Why? Because they built it without security in mind. Oh, we're just going to build a load balancer, right? So, who's thinking about security at a load balancer? But it's important that we think about security on all pieces of software. And so I'm going to kind of roast a little bit the software industry and say, "Hey, you guys get your act together." Right? You're turning out products that are too easy to hack, right? You need to make it more difficult and you need to build it into your system from day one versus trying to fix the problems after we find them. So >> yeah, it's really interesting. I mean, we had a lot of flack on that video. I get a lot of hate because of that video where we spoke about hacking VPNs. To use the word again, it's ironic because every other day or week, it's Cisco, it's Palo Alto, it's Forinet, your favorite, it's uh just name them. They're all getting hacked. It's always in the news. Yeah. And it's >> every every day we see it seems like every day we see a new VPN router hack, right? Because all of a sudden it's come on people's radar now. It's like, oh yeah, well that's that's just a little Linux operating system there. Y >> and if they didn't design it properly, which they probably didn't, then I can hack it and I can get inside the router. Now, the NSA has been doing this for at least 15 years, at least. So, they're kind of the ones who turned me on to the idea that that router that routers and VPNs are hackable, right? I mean, I probably like most people, I didn't think that I never thought about it really is what it was is that I never thought about attacking the router, attacking the VPN, and then the NSA was attacking him. Oh, wow. This is this this is this is a vector that I hadn't considered and it's so easy to hack. >> So, OTW, I mean, I think we need to wrap up, but I wanted to hit you with this and we've spoken about this offline and in other videos. It sounds like there's no hope because if you live in the digital age, you're going to get hacked. So, what's your take on that? Perhaps you can give us some hope at the end of the the video. >> I'm always hopeful, right? I'm always hopeful. And so, one of the things that I think all of us have to do, like I mentioned earlier, is you need to be vigilant, right? You know, if you were if you were walking through the jungle with lots of wild animals who could eat you, you would be vigilant. you you might be you might be frightened, but you'd be vigilant. You'd be looking over your shoulder. If you hear a noise, you see something, you're you're going to react. That's what the digital world is in 2025. We have things that will eat you at every at every corner. And so, you just need to always be on your toes. And you have to kind of practice this idea of not trusting anything on the internet, not trusting anything until our digital infrastructure gets rebuilt. I hope that happens soon. You know, you have to be vigilant. You have to take responsibility. You have to take responsibility for your safety because your software company's not going to do it. Okay? Your telecom company's not going to do it. Your bank's not going to do it. You have to do it. And that you don't have to be a genius. You just have to be skeptical of everything. So, >> so OTW, we'll end on that. That was great. Um, don't you want to tell us about the discount that people can have if they sign up for your courses because I don't think everyone knows about the courses that you have. So, tell us about that and, you know, tell us about some of the cool courses that you're creating. >> Well, we have a lot of cool courses coming up. Uh, we have a smart home hacking coming in January. So, we're going to be getting inside all of those little Linux kernels and all of those little devices that connect in your smart home. And this is something we've been seeing a lot in our forensic investigations. We have satellite hacking coming up in uh in 2026. It's a new version of our satellite. So we we did one a couple years ago. We're updating that to new techniques and new satellite protocols. And we also have our SCADA, our advanced SCADA class coming up in December. So those of you who aren't familiar, SCADA is industrial control systems. People often refer to them SCADAICS industrial control systems and these are the systems that run every business in the industrialized world. They are all computers and those are hackable. It's one of the industries that probably really needs to up their game to keep from getting shut down. I mean, we see ransomware being used against these systems now. And so if you get hit with a ransomware and you're like an oil refinery. Yeah. >> You know that's that's serious stuff. We saw the one with the oil pipeline got hit with ransomware in the US a few years. Colonial pipeline that that can have effects upon the entire economy and certainly it's very damaging to the company. But if it's if it's an oil refinery or it's an oil pipeline, it can actually have international geopolitical repercussions. So we specialize is one of our specialty areas is SCADA ICS and we'll be doing an advanced course in December and and if you use the coupon code B O M B A L BLE, you take an automatic 20% off anything in our catalog. I really appreciate that and thanks for you know sharing the knowledge so freely online and also making those courses for people to attend. So for everyone who's watching I'll put links below. OTW as always fantastic to talk to you again. Thanks so much. >> Thanks David. Good seeing you again.
Original Description
Big thanks to Brilliant for sponsoring this video. To try everything Brilliant has to offer, visit https://brilliant.org/davidbombal or scan the QR code onscreen - You’ll also get 20% off and annual premium subscription
Apple says iPhone is extremely hard to hack. OTW says he keeps finding real malware on normal people's iPhones. We talk Pegasus spyware, the Meta vs NSO lawsuit over WhatsApp, Apple's new memory integrity protections, and why a $5M bug bounty still won't stop well-funded spyware. We also get into how one infected phone can take over your entire WiFi and smart home, why your router and VPN box are the weakest link, and what “everything is hackable” really means for you.
// Occupy The Web SOCIAL //
X: https://twitter.com/three_cube
Website: https://hackers-arise.net/
// Occupy The Web Books //
Linux Basics for Hackers 2nd Ed
US: https://amzn.to/3TscpxY
UK: https://amzn.to/45XaF7j
Linux Basics for Hackers:
US: https://amzn.to/3wqukgC
UK: https://amzn.to/43PHFev
Getting Started Becoming a Master Hacker
US: https://amzn.to/4bmGqX2
UK: https://amzn.to/43JG2iA
Network Basics for hackers:
US: https://amzn.to/3yeYVyb
UK: https://amzn.to/4aInbGK
// OTW Discount //
Use the code BOMBAL to get a 20% discount off anything from OTW's website: https://hackers-arise.net/
// Playlists REFERENCE //
Linux Basics for Hackers: https://www.youtube.com/watch?v=YJUVNlmIO6E&list=PLhfrWIlLOoKOs-fjCPHdzD2icF2vORfwK&pp=iAQB
Mr Robot: https://www.youtube.com/watch?v=3yiT_WMlosg&list=PLhfrWIlLOoKNYR8uvEXSAzDfKGAPIDB8q&pp=iAQB
Hackers Arise / Occupy the Web Hacks: https://www.youtube.com/watch?v=GxkKszPVD1M&list=PLhfrWIlLOoKOf1Ru_TFAnubVuWc87i-7z&pp=iAQB
// David's SOCIAL //
Discord: https://discord.com/invite/usKSyzb
X: https://www.twitter.com/davidbombal
Instagram: https://www.instagram.com/davidbombal
LinkedIn: https://www.linkedin.com/in/davidbombal
Facebook: https://www.facebook.com/davidbombal.co
TikTok: http://tiktok.com/@davidbombal
Y
Watch on YouTube ↗
(saves to browser)
Sign in to unlock AI tutor explanation · ⚡30
Playlist
Uploads from David Bombal · David Bombal · 0 of 60
← Previous
Next →
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
RYU SDN Controller Part 4: Graphical User Interface (GUI): Practical GNS3 SDN and OpenFlow
David Bombal
HPE Network Protector SDN Application Part 1 - Introduction
David Bombal
HPE Network Protector SDN Application Part 2 : DNS Interception using OpenFlow
David Bombal
HPE Network Protector SDN Application Part 3 - Lab Setup using Physical Switches
David Bombal
HPE Network Protector SDN Application Part 4 - Demo of malicious websites blocked
David Bombal
HPE Network Protector SDN Application Part 5 - Demo OpenFlow table interception flows
David Bombal
HPE Network Protector SDN Application Part 6 - Demo of Physical Switch configuration
David Bombal
HPE Network Protector SDN Application Part 7 - Demo Service Insertion Tunnel / GRE Tunnel
David Bombal
HPE Network Protector SDN Application Part 8 - Demo SDN OpenFlow Reporting
David Bombal
HPE Network Protector SDN Application Part 9 - Demo switches interception of DNS traffic
David Bombal
GNS3 Talks: GNS3 version 1.5.X Appliance Tips
David Bombal
CCNA 200-125 Exam: AAA demo: TACACS+ with GNS3
David Bombal
GNS3 2.0.0 beta 2 install
David Bombal
CCNA #012: Learn SNMP with GNS3, Wireshark and Solarwinds NPM - CCNA 200-125 exam
David Bombal
CCNA #013: Spanning Tree CCNA Exam Questions: Know the answer? CCNA 200-125 exam
David Bombal
GNS3 2.0.0 beta : GNS3 VM integration with GNS3 GUI
David Bombal
CCNA #018: Routing exam questions: Who wins? OSPF, EIGRP or RIP? Sure? CCNA 200-125 exam
David Bombal
CCNA #019: Spanning Tree CCNA Exam Questions: Root Bridge, Root Port and more: CCNA 200-125 exam
David Bombal
GNS3 Download, installation and configuration - GNS3 1.5.3 and Windows 10
David Bombal
CCNA #023 EIGRP Neighbor Troubleshooting (DUAL Issues) for the CCNA 200-125 Exam
David Bombal
GNS3 2.0 Architecture and schema Part 1: What is the GNS3 Controller?
David Bombal
GNS3 2.0 Architecture and schema Part 2: Emulators and virtualization
David Bombal
CCNA #028 VTP Troubleshooting for the CCNA 200-125 Exam
David Bombal
CCNA #029 VTP & DTP Troubleshooting for the CCNA 200-125 Exam
David Bombal
CCNA #030 VTP Troubleshooting for the CCNA 200-125 Exam
David Bombal
GNS3 : How to download Cisco IOS images and VIRL images. Which is the best? How do you get them?
David Bombal
GNS3 ASA setup: Import and configure Cisco ASAv with GNS3
David Bombal
GNS3 switching setup and options: Cisco and other switching options in GNS3
David Bombal
GNS3 switching setup and options Part 2: GNS3 unmanaged built-in switch
David Bombal
GNS3 switching setup and options Part 3: Router on a sick with GNS3 unmanaged built-in switch
David Bombal
GNS3 switching setup and options Part 4: Etherswitch Router for Cisco Dynamips Part 1
David Bombal
GNS3 switching setup and options Part 5: Etherswitch Router for Cisco Dynamips Part 2
David Bombal
GNS3 switching setup and options Part 6: Etherswitch, Wireshark, 802.1Q, InterVLAN routing
David Bombal
GNS3 Talks: Docker, Open vSwitch, SDN and OpenFlow Part 1: GNS3 Switching Part 7
David Bombal
GNS3 Talks: Docker, Open vSwitch, SDN and OpenFlow Part 2: GNS3 Switching Part 8
David Bombal
GNS3 Talks: Docker, Open vSwitch, SDN and OpenFlow Part 3: GNS3 Switching Part 9
David Bombal
GNS3 Talks: Docker, Open vSwitch, SDN and OpenFlow Part 4: GNS3 Switching Part 10
David Bombal
GNS3 Talks: Docker, Open vSwitch, SDN and OpenFlow Part 5: GNS3 Switching Part 11
David Bombal
GNS3 Nexus (NX-OSv) switch setup and configuration Part 1: GNS3 switching options Part 12
David Bombal
GNS3 Nexus (NX-OSv) switch setup and configuration Part 2: GNS3 switching options Part 13
David Bombal
GNS3 Talks: Docker, Open vSwitch, SDN and OpenFlow Part 6: GNS3 Switching Part 14
David Bombal
GNS3 Talks: Docker, Open vSwitch, SDN and OpenFlow Part 7: GNS3 Switching Part 15
David Bombal
GNS3 Cisco CSR 1000v setup and configuration Part 1: GNS3 NFV
David Bombal
GNS3 Cisco CSR 1000v setup and configuration Part 2: GNS3 NFV
David Bombal
GNS3 Talks: Use the NAT node to connect GNS3 to the Internet easily!
David Bombal
GNS3 Talks: GNS3 2.0 RC1 is now available
David Bombal
GNS3 Talks: GNS3 2.0 Portable Projects - easily export and import GNS3 projects
David Bombal
GNS3 Talks: Multiple clients sharing projects in real time, plus console session shadowing!
David Bombal
CCNA #035 NAT Troubleshooting Scenario 1 - Can you find the issue? CCNA Exam 200-125 troubleshooting
David Bombal
CCNA #036 NAT Troubleshooting Scenario 2 - Can you find the issue? CCNA Exam 200-125 troubleshooting
David Bombal
GNS3 Talks: ESXi, GNS3 VM and KVM support Part 1: leverage servers and the cloud
David Bombal
CCNA #037 OSPF Troubleshooting - can you find the issue? CCNA Exam 200-125 troubleshooting
David Bombal
GNS3 Talks: ESXi, GNS3 VM and KVM support Part 2: leverage servers and the cloud
David Bombal
CCNA #038 NAT Troubleshooting Scenario 3 - Can you find the issue? CCNA Exam 200-125 troubleshooting
David Bombal
CCNA #039 - OSPF DR, BR and DROTHER Election - do you know the answers?
David Bombal
CCNA #040 NAT Troubleshooting Scenario 4 - Can you find the issue? CCNA Exam 200-125 troubleshooting
David Bombal
GNS3 Talks: Arista vEOS GNS3 import and configuration Part 1
David Bombal
CCNA #041 - OSPF DR, BR and DROTHER Election - do you know the answers?
David Bombal
GNS3 Talks: Arista vEOS GNS3 import and configuration Part 2
David Bombal
GNS3 Talks: ipterm: Linux, Docker, Python, SDN and more! Part 1
David Bombal
More on: AI Security
View skill →Related Reads
📰
📰
📰
📰
How HTTPS Actually Works: TLS, Certificates, and Encryption
Dev.to · Juma Evans
I built a typical AI-generated app and scanned it. It had 5 critical security holes before I touched a line of code.
Dev.to · Michael Iheanacho
Vulnerability Watch — 1 high-severity CVE (2026-07-24)
Dev.to · pkgdrift
# The wp2shell Exploit Chain: Understanding the Critical WordPress Core Pre-Auth RCE…
Medium · Cybersecurity
🎓
Tutor Explanation
DeepCamp AI