US immigration agents will have access to one of the world’s most sophisticated hacking tools after a decision by the Trump administration to move ahead with a contract with Paragon Solutions, a company founded in Israel which makes spyware that can be used to hack into any mobile phone – including encrypted applications.

The Department of Homeland Security first entered into a contract with Paragon, now owned by a US firm, in late 2024, under the Biden administration. But the $2m contract was put on hold pending a compliance review to make sure it adhered to an executive order that restricts the US government’s use of spyware, Wired reported at the time.

That pause has now been lifted, according to public procurement documents, which list US Immigration and Customs Enforcement (Ice) as the contracting agency.

    • rc__buggy@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      9
      arrow-down
      4
      ·
      edit-2
      3 days ago

      Sure bro, put a 30 character password into your phone every time you want to find the nearest fucking coffee shop.

      edit: I guess I should explain. I’m into privacy not necessarily absolute security. If a cop wants in my phone I forgot my PIN. There’s no biometric to get into it so he’s going to have to get a warrant if he wants anything to actually stick. With face ID he just holds it up to my face. With fingerprint he can force my finger onto the sensor. In the USA, don’t know about Europe.

      • lIlIlIlIlIlIl@lemmy.world
        link
        fedilink
        English
        arrow-up
        10
        ·
        3 days ago

        I just needed this info out there, I don’t really care what you do - I just need to make sure Lemmy stays safe and you’re spouting leaky insecurity disguised as best practices.

        Best of luck

        • rc__buggy@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          10
          arrow-down
          3
          ·
          edit-2
          3 days ago

          I think I just leaked a little right now. I don’t believe you have a 30 character unlock on your phone. That doesn’t make sense on a device someone uses multiple times a day in one hand at like a bus stop or something.

          And I’m no security professional, just some dumbass out in the street.

          • Tangent5280@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            2 days ago

            30 characters is like five words. Entirely doable. You can take your favorite TV show, sort character names by some logic and mispell a few of them to make a very strong very long password.

          • choochooMF@lemmy.world
            link
            fedilink
            English
            arrow-up
            3
            arrow-down
            1
            ·
            3 days ago

            I use a 15 character pw with a mix of upper and lower case, numbers, and symbols, which according to that link is pretty damn good.

              • choochooMF@lemmy.world
                link
                fedilink
                English
                arrow-up
                1
                ·
                edit-2
                2 days ago

                You don’t need to buy it, but I ain’t lying. I am 100% a psychotic outlier tho. 😂 The way I see it, this is a computer that is almost always on me with tons of personal information inside. The chances of it being compromised is WAY higher than any other computer I own. I take that very seriously. Like I said tho, I’m a psychotic outlier.

              • xthexder@l.sw0.com
                link
                fedilink
                English
                arrow-up
                3
                ·
                edit-2
                2 days ago

                + biometrics

                This means you only enter the password when your phone restarts, you access specific settings, or I think one or two other rare cases. Personally I only need to enter my pin maybe once a week

                • rc__buggy@sh.itjust.works
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  arrow-down
                  1
                  ·
                  2 days ago

                  What the actual fuck>!><!>>!>!

                  Are you assholes actually inputting 24+characters plus biometrics into your phone to unlock it?

                  Fuck you, no you are not.

          • lIlIlIlIlIlIl@lemmy.world
            link
            fedilink
            English
            arrow-up
            2
            arrow-down
            2
            ·
            3 days ago

            Of course I do. FaceID allows me to input it exactly once a week, sometimes less.

            What don’t you understand?

      • lIlIlIlIlIlIl@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        ·
        3 days ago

        If you’re in the USA and a cop gets your phone they’re going to pop it onto a graybox and will be digging through your shit up to their elbows. I wish I were wrong

      • lIlIlIlIlIlIl@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        3 days ago

        With biometrics I only enter it once a week, at the very most. It’s insane to me that people want their phones to be less secure, but best of luck to you and your super secure TSA lock on your phone lol

              • lIlIlIlIlIlIl@lemmy.world
                link
                fedilink
                English
                arrow-up
                4
                arrow-down
                1
                ·
                3 days ago

                No? I quint-click my power button through my pocket any time there’s even a whiff of sketch. Now biometrics are 100% off. And even if a cop was holding my phone I’d have to open my eyes, keep one shut at all times and after 2 bad scans biometrics turn off completely.

                I don’t understand your argument in the least, maybe you could read about how current biometrics work and give me your feedback once you’re caught up?

                • rc__buggy@sh.itjust.works
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  arrow-down
                  3
                  ·
                  3 days ago

                  Has that been shown? Has some MMA fighter not been able to unlock their iPhone after a fight?

                  Otherwise, nope. Still gonna recognize you.

    • xthexder@l.sw0.com
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      1
      ·
      2 days ago

      That’s for breaking a bcrypt hash, and I don’t believe there’s any way to extract the pin hash from a phone since it happens inside a secure hardware layer (like a TPM). If it is possible, the attacker would most likely have to physically destroy your phone to get at it. To bruteforce a 4 digit pin with retry lockout timers, it takes 16 hours to try all combinations, according to a tool I found that auto-enters pins via usb keyboard emulation.