5 ms·
OK, I'm going to have to ask: who are the largest and most effective?
by rafaelm 7y ago
OK, I'm going to have to ask: who are the largest and most effective?
- PeterisP 7y agoCellebrite is a popular supplier for mobile forensics, which may require using vulnerabilities are not yet patched, i.e. finding or buying zerodays.
- lawnchair_larry 7y agoDifferent market and different product. Cellebrite customers have the devices in hand, and need to extract data for forensics. NSO customers compromise phones remotely and silently in order to spy on what the owner is doing.
- hunter2_ 7y agoHow does NSO and/or it's customers steer clear of CFAA violations? Are they given some kind of perpetual amnesty? Edit: Oh, they ran up against this just a few weeks ago according to their Wikipedia article. How about that.
- tptacek 7y agoIn addition to the fact that they're not a US company, selling exploits doesn't actually violate CFAA. Google could potentially sue them under civil CFAA if there was some unauthorized access to Google infrastructure needed to develop the exploits, but that's unlikely to be the case. Using NSO tools against unwilling targets would violate US law, but that's not what NSO does.
- zigzaggy 7y agoAccording to recent articles I’ve read this may not be the case. Apparently at least one organization has accused NSO of doing the unlawful accessing. Standby while I look for a source.
- tptacek 7y agoYes, WhatsApp sued NSO under civil CFAA (among other things) for accessing their infrastructure in the process of building and running their tools.
- deleted 7y ago[deleted]