US immigration agents will have access to one of the world’s most sophisticated hacking tools after a decision by the Trump administration to move ahead with a contract with Paragon Solutions, a company founded in Israel which makes spyware that can be used to hack into any mobile phone – including encrypted applications.

The Department of Homeland Security first entered into a contract with Paragon, now owned by a US firm, in late 2024, under the Biden administration. But the $2m contract was put on hold pending a compliance review to make sure it adhered to an executive order that restricts the US government’s use of spyware, Wired reported at the time.

That pause has now been lifted, according to public procurement documents, which list US Immigration and Customs Enforcement (Ice) as the contracting agency.

  • rc__buggy@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    17
    arrow-down
    7
    ·
    3 days ago

    Every early morning. Mine is right before my alarm goes off, so the notification sounds just meld.

    Also, no one should be using biometric data to log into thier phones. 6 digit pin isn’t very obtrusive once you get used to it

      • rc__buggy@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        9
        arrow-down
        4
        ·
        edit-2
        3 days ago

        Sure bro, put a 30 character password into your phone every time you want to find the nearest fucking coffee shop.

        edit: I guess I should explain. I’m into privacy not necessarily absolute security. If a cop wants in my phone I forgot my PIN. There’s no biometric to get into it so he’s going to have to get a warrant if he wants anything to actually stick. With face ID he just holds it up to my face. With fingerprint he can force my finger onto the sensor. In the USA, don’t know about Europe.

        • lIlIlIlIlIlIl@lemmy.world
          link
          fedilink
          English
          arrow-up
          10
          ·
          3 days ago

          I just needed this info out there, I don’t really care what you do - I just need to make sure Lemmy stays safe and you’re spouting leaky insecurity disguised as best practices.

          Best of luck

          • rc__buggy@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            10
            arrow-down
            3
            ·
            edit-2
            3 days ago

            I think I just leaked a little right now. I don’t believe you have a 30 character unlock on your phone. That doesn’t make sense on a device someone uses multiple times a day in one hand at like a bus stop or something.

            And I’m no security professional, just some dumbass out in the street.

            • Tangent5280@lemmy.world
              link
              fedilink
              English
              arrow-up
              1
              ·
              2 days ago

              30 characters is like five words. Entirely doable. You can take your favorite TV show, sort character names by some logic and mispell a few of them to make a very strong very long password.

            • choochooMF@lemmy.world
              link
              fedilink
              English
              arrow-up
              3
              arrow-down
              1
              ·
              3 days ago

              I use a 15 character pw with a mix of upper and lower case, numbers, and symbols, which according to that link is pretty damn good.

                • choochooMF@lemmy.world
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  edit-2
                  2 days ago

                  You don’t need to buy it, but I ain’t lying. I am 100% a psychotic outlier tho. 😂 The way I see it, this is a computer that is almost always on me with tons of personal information inside. The chances of it being compromised is WAY higher than any other computer I own. I take that very seriously. Like I said tho, I’m a psychotic outlier.

                • xthexder@l.sw0.com
                  link
                  fedilink
                  English
                  arrow-up
                  3
                  ·
                  edit-2
                  2 days ago

                  + biometrics

                  This means you only enter the password when your phone restarts, you access specific settings, or I think one or two other rare cases. Personally I only need to enter my pin maybe once a week

                  • rc__buggy@sh.itjust.works
                    link
                    fedilink
                    English
                    arrow-up
                    1
                    arrow-down
                    1
                    ·
                    2 days ago

                    What the actual fuck>!><!>>!>!

                    Are you assholes actually inputting 24+characters plus biometrics into your phone to unlock it?

                    Fuck you, no you are not.

            • lIlIlIlIlIlIl@lemmy.world
              link
              fedilink
              English
              arrow-up
              2
              arrow-down
              2
              ·
              3 days ago

              Of course I do. FaceID allows me to input it exactly once a week, sometimes less.

              What don’t you understand?

        • lIlIlIlIlIlIl@lemmy.world
          link
          fedilink
          English
          arrow-up
          4
          ·
          3 days ago

          If you’re in the USA and a cop gets your phone they’re going to pop it onto a graybox and will be digging through your shit up to their elbows. I wish I were wrong

        • lIlIlIlIlIlIl@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          3 days ago

          With biometrics I only enter it once a week, at the very most. It’s insane to me that people want their phones to be less secure, but best of luck to you and your super secure TSA lock on your phone lol

                • lIlIlIlIlIlIl@lemmy.world
                  link
                  fedilink
                  English
                  arrow-up
                  4
                  arrow-down
                  1
                  ·
                  3 days ago

                  No? I quint-click my power button through my pocket any time there’s even a whiff of sketch. Now biometrics are 100% off. And even if a cop was holding my phone I’d have to open my eyes, keep one shut at all times and after 2 bad scans biometrics turn off completely.

                  I don’t understand your argument in the least, maybe you could read about how current biometrics work and give me your feedback once you’re caught up?

                  • AdamBomb@lemmy.sdf.org
                    link
                    fedilink
                    English
                    arrow-up
                    2
                    arrow-down
                    1
                    ·
                    2 days ago

                    I heard elsewhere that anything less than powering down can leave data in memory that can be used to hack your device. So while the quintuple click is better than nothing, powering down is better.

                  • rc__buggy@sh.itjust.works
                    link
                    fedilink
                    English
                    arrow-up
                    1
                    arrow-down
                    3
                    ·
                    3 days ago

                    Has that been shown? Has some MMA fighter not been able to unlock their iPhone after a fight?

                    Otherwise, nope. Still gonna recognize you.

      • xthexder@l.sw0.com
        link
        fedilink
        English
        arrow-up
        3
        arrow-down
        1
        ·
        2 days ago

        That’s for breaking a bcrypt hash, and I don’t believe there’s any way to extract the pin hash from a phone since it happens inside a secure hardware layer (like a TPM). If it is possible, the attacker would most likely have to physically destroy your phone to get at it. To bruteforce a 4 digit pin with retry lockout timers, it takes 16 hours to try all combinations, according to a tool I found that auto-enters pins via usb keyboard emulation.

    • WhyJiffie@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 days ago

      worthless when there’s cameras in every corner that record as you unlock your phone all 40 times through the day

      • rc__buggy@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        2
        ·
        2 days ago

        Fuck you too, buddy. You’re being recorded as you input your absurdly long password into your phone. They probably got it on camera. haha