389: Kali Linux New Release, HADOOKEN Malware gets a Tiger Uppercut, & more Cybersecurity

My notes regarding the episode:

  • Apple dropping it’s lawsuit against NSO is unlikely to be because of the claim that the discovery process will let NSO get more technical information - the DL crew is correct to be suspicious of that. It is much more likely that they either figured out they can’t prevail on the merits and are trying to save face, or - I think less likely, but as the DL crew mentioned - because exposing NSO techniques might be a PR disaster for Apple, especially if these techniques are still viable.

  • Lindroid: saying that you need a rooted device to install it isn’t technically accurate - yes, it currently needs a device with su, but the device also need to run a patched AOSP ROM - you can’t just run it on any OEM ROM that had been rooted. They claim that in the future they might offer this capability to rooted OEM ROMs as a Magisk module - but there’s not even a hint of a timeline for that. The Lindroid documentation talks about supposedly offering prebuilt fastboot images of a working AOSP ROM - for specific devices, which would let you just replace your existing system with a Lindroid capable one, and that would not require jailbreaking your Android, just unlocking the bootloader - something that most vendors let you do today without too many hoops, except that you have to format your device and lose all your data. I also couldn’t find where such images can be downloaded from and the lindroid.org site does not appear to be functioning.

1 Like