MVT any good?

Saw this thread: https://xcancel.com/kaepora/status/1823761203593929114#m

Deeply impressed by mvt, the tool used by @AmnestyTech and @citizenlab to detect “devices compromised with Pegasus” and other malware, and which marked my iPhone as having “indicators of compromise” because… I have iMessage sticker apps installed. Unconscionable scam artists.

Ah yes, the “Pegasus indicators of compromise database”, which includes things like scanning your SMS messages for the string “weather4free dot com” and other expired domain names that could be texted to you by anyone, including Amnesty Tech staffers themselves.

There are helpful warnings on Device Integrity - Privacy Guides. But this threads shows an actual example of allegedly a false positive on his device.

One of the replies there said it best, don’t conflate surface-level scans for indicators as definitive proof of an exploit. It’s as we already say:

These tools can trigger false-positives. If any of these tools finds indicators of compromise, you need to dig deeper to determine your actual risk. Some reports may be false positives based on websites you’ve visited in the past, and findings which are many years old are likely either false-positives or indicate previous (and no longer active) compromise.

“Scam artists” seems a bit over the top to describe a free/open-source tool.

3 Likes

Forensics and generally intel can always contain false positives. If you are a victem of such spyware or find any indicators I would urge you to get professional help when possible.

MVT also gives indicators on most devices for example by allowing other installation sources. That is just something you see and asses. Correct assesement on indicators should not be underestimated.

A proper solution:

GrapheneOS + Auditor.

Would recommend to read this first:

GrapheneOS users should definitely use that but MVT does other things and provides also a solution for iOS and other android phones.

Auditor isn’t GrapheneOS exclusive.

But yes, it’s not something that can be used on iOS.

1 Like

Actually did not know it could verify other android phones, just checked but the list of supported devices seems rather low.

One can make it work themselves on other devices too, but it’s not user friendly.

There is work being done to have a lot more officially supported devices: Initial generic device support by quh4gko8 · Pull Request #236 · GrapheneOS/Auditor · GitHub