13 ms·
Leak uncovers global abuse of cyber-surveillance weapon
- milofeynman 5y agoWas a joint investigation. Here's Washington Post writeup: Private spy software sold by NSO group found on cellphones worldwide - Washington Post https://www.washingtonpost.com/investigations/interactive/2021/nso-spyware-pegasus-cellphones/ https://www.washingtonpost.com/investigations/interactive/20...
- cf100clunk 5y agoFrom the Guardian article: "The research, conducted by Amnesty’s Security Lab, a technical partner on the Pegasus project, found traces of Pegasus activity on 37 out of the 67 phones examined." The results were released by an international consortium of media entities that includes The Guardian and the WaPo.
- milofeynman 5y ago> The Pegasus project is a collaborative reporting project led by the French nonprofit organisation Forbidden Stories, including the Guardian and 16 other media outlets. For months, our journalists have been working with reporters across the world to establish the identities of people in the leaked data and see if and how this links to NSO’s software.
- tuukkah 5y agoSomewhat surprising (disappointing?) for me to find India, Mexico and Hungary on the list: "at least 10 governments believed to be NSO customers who were entering numbers into a system: Azerbaijan, Bahrain, Kazakhstan, Mexico, Morocco, Rwanda, Saudi Arabia, Hungary, India, and the United Arab Emirates (UAE)."
- A4ET8a8uTh0 5y agoI am actually surprised the list is so short. I was expecting to see more names.
- TedDoesntTalk 5y agoPossibly other countries (US, UK, Russia, Australia, China, etc) have enough resources to build their own equivalent tools without needing to buy Pegasus.
- mulmen 5y agoWhy do you find this surprising?
- tuukkah 5y agoI thought these countries still tried to operate legally instead of targeting their opposition leaders etc.
- pm90 5y ago> India, Mexico and Hungary Both India and Hungary are currently governed by anti-democratic right wing administrations (Modi and Orban). Not that surprising to see the State try to abuse power.
- arv_ind1 5y agoWhy do you think India has an undemocratic govt? Just because Modi is RW?
- webdevlion 5y agoIronic that you mention this, since the fact that the Modi government’s name is on the list attests to their anti-privacy way of ruling.
- coldcode 5y agoNSO is clearly in the business of selling surveillance to foreign entities, and saying they vet people is nothing but smoke as there is zero actual evidence other than their blanket statements. If some government or other customer tells them they only attack terrorists, it's clearly easy to target anyone; how would NSO even know. Also rather stupid was Apple's statement about their phones being secure, when its obvious there are zero days being sold to NSO instead of telling Apple. Everything is insecure these days, at some level. If NSO paid people $1M for a zero day (I bet they don't say), and Apple/Google/etc paid $10K, who do you think gets the info.
- netsec_burn 5y agoIt's not that cut and dry, ethics and legality are a concern for a lot of researchers such as myself that sell zerodays. In my experience the actual price difference between unethical and ethical outlets is up to 4x, not two orders of magnitude (10K vs 1M?). I can't speak for everyone of course, but even the other researchers I know refuse to sell to unethical buyers, money isn't a factor.
- fossuser 5y agoThanks for being one of the good guys.
- deleted 5y ago[deleted]
- zrth 5y agoCan you give me a feeling for wat ethical buyers would be. I'd assume bug bounties and ZDI and similar. What else?
- netsec_burn 5y agoFirst and foremost, the original vendor is always the most ethical place to sell it. That's where you stand the best chance of having it fixed for affected users. Second to the vendor are third parties that report vulnerabilities to the vendor by selling early warnings as a service. I don't know if I would recommend ZDI, they provide zero guidance for what their payout ranges are. There are security companies that purchase zerodays to write about them for PR, which also fixes the issue. And finally there's selling it to branches of the US government with license restrictions and a blanket exclusion for the NSA. Beyond those buyers, the lines start to blur (defense contractors, companies in countries allied with the US e.g. FVEY). I would not recommend it either. Unethical buyers have completely different interests. I know Zerodium for one is a terrible place to sell to (you may be a target), and anything that is sold to Crowdfense is likely to be used against American interests. My take away advice is, you can choose between painting a target on your front or one on your back.
- johnny_reilly 5y agoMore specific details on Pegasus here: https://www.theguardian.com/news/2021/jul/18/what-is-pegasus-spyware-and-how-does-it-hack-phones https://www.theguardian.com/news/2021/jul/18/what-is-pegasus...
- mjreacher 5y agoAt what point are western governments going to crack down on companies such as NSO Group?
- LinuxBender 5y agoI am just guessing, but they would probably crack down on specific companies that sell to governments other than their own.
- bilbo0s 5y agoThey'd also crack down on companies that sell to other governments and their own. The stakes are getting too high at this point. On a completely unrelated note, if I were a security researcher, I'd start being extremely mindful about to whom I'm selling zero-days.
- Leparamour 5y ago>On a completely unrelated note, if I were a security researcher, I'd start being extremely mindful about to whom I'm selling zero-days. Unless you're dependent on the money, responsible disclosure is probably the most ethical way.
- jeffbee 5y agoGovernments objecting to the success of drive-by 0-day malware should be investing in safer operating systems and programming languages, not trying to outlaw malware.
- deleted 5y ago[deleted]
- threatofrain 5y ago> That thesis is supported by forensic analysis on the phones of a small sample of journalists, human rights activists and lawyers whose numbers appeared on the leaked list. > The research, conducted by Amnesty’s Security Lab, a technical partner on the Pegasus project, found traces of Pegasus activity on 37 out of the 67 phones examined. > The analysis also uncovered some sequential correlations between the time and date a number was entered into the list and the onset of Pegasus activity on the device, which in some cases occurred just a few seconds later. > Amnesty shared its forensic work on four iPhones with Citizen Lab, a research group at the University of Toronto that specialises in studying Pegasus, which confirmed they showed signs of Pegasus infection. Citizen Lab also conducted a peer-review of Amnesty’s forensic methods, and found them to be sound. --- > NSO has always maintained it does “does not operate the systems that it sells to vetted government customers, and does not have access to the data of its customers’ targets”.
- rendall 5y agoEdward Snowden predicts this to be "the story of the year" https://twitter.com/Snowden/status/1416797153524174854 https://twitter.com/Snowden/status/1416797153524174854
- 14 5y agoWho is target US journalists?
- nickfromseattle 5y agoPegasus and it's capabilities have been publicly known for several years. Pegasus recently appeared in connection with hack that stole Jeff Bezos' nude selfies. It sounds like the new info putting them back in the new cycle is related to this sentence: "The Guardian and its media partners will be revealing the identities of people whose number appeared on the list in the coming days. They include hundreds of business executives, religious figures, academics, NGO employees, union officials and government officials, including cabinet ministers, presidents and prime ministers." Should be a very interesting release.
- dannyw 5y agoThis sounds absolutely huge. It feels like a Snowden lite.
- camjohnson26 5y agoSnowden says: “Stop what you're doing and read this. This leak is going to be the story of the year” https://twitter.com/Snowden/status/1416797153524174854?s=20 https://twitter.com/Snowden/status/1416797153524174854?s=20
- slg 5y agoI'm not judging the importance of the story, but based off past reception of these stories it is wildly naïve to believe this will be the story of the year. That is especially true in a year in which the globe is still not through a global pandemic that has killed millions. Most people simply don't care that much about digital privacy. Lots of people believe Facebook is spying on them constantly including recording everything said in the presence of their phone and many of those people go right on continuing to use those apps.
- clairity 5y ago> "...wildly naïve to believe this will be the story of the year. That is especially true in a year in which the globe is still not through a global pandemic that has killed millions." if this were true, cardiovascular disease and cancer would be the top stories everyday, as they combine for tens of millions of deaths per year. the media focuses on novel fear because it's attention-getting, not rationally dire.
- dredmorbius 5y agoNSO said that even if Pineda’s phone had been targeted, it did not mean data collected from his phone contributed in any way to his death... NSO are clearly concerned about any such claims sticking. Shared and joint liability for such consequences of software and tools strikes me as one of the more viable ways of limiting their over development. Finding a firm, its officers, its engineers, its salespeople, its investors, and its creditors culpable for assassinations and murders would tend to dampen enthusiasm significantly. That's not enough to utterly quash development, but it makes it far more expensive and unattractive. I don't have high hopes for this. But one may dream.
- toptal 5y agoSo, PBS seems to have done a documentary on this, which was just released an hour ago: https://m.youtube.com/watch?v=a2BIYWHdfTE https://m.youtube.com/watch?v=a2BIYWHdfTE Did all of the media outlets organize together for months in advance to be able to release everything today? The content and production quality makes it seem like this release was planned months in advance. Also, assuming they did, what’s the process all of these news organizations go through in order to plan such a release on the same exact day? The planning of the release in such a coordinated way is almost questionable itself, though it would be good to get insight into this.
- eXpl0it3r 5y agoThe case around Jamal Khashoggi is also documented quite well in the documentary: "The Dissident" It was that movie/documentary where I first heard of Pegasus and how it had been used by the Saudi government.
- alex_duf 5y agoHey, former software engineer at the Guardian here. Yes the news outlets are collaborating on stories too big for a single one. The last I can remember was the Panama papers, which followed a very similar process. I seem to remember they all synchronized through the ICIJ [1], and more or less each journalist would cover their own territory / domain. Then they agreed on a reasonable date to release the news. They shared more than just information, but also technical infrastructure to do the investigation. [1]: https://www.icij.org/ https://www.icij.org/
- toptal 5y agoSo, if the ICIJ coordinated the last one, then who coordinated this one? It seems like Forbidden Stories is the main organizer though they also make it seem like “The Pegasus Project” is the organizer as well, which seems rather confusing.
- tedunangst 5y agoYou can't read the article? > Forbidden Stories, a Paris-based nonprofit media organisation, and Amnesty International initially had access to the leaked list and shared access with media partners as part of the Pegasus project, a reporting consortium.
- h2odragon 5y agoWe'll be putting the leakers in the cell beside Assange any day now, right?
- WarOnPrivacy 5y agoEthics says we shouldn't be okay with surveillance predators.
- phtrivier 5y agoSadly, an haveibeenpawned-like service to know if a number is in the list would be unfeasible ; so, the only way to know if you've been monitored is to be some kind of celebrity that the giardian and co will decide to out.(I suppose it will be better in terms of PR to be outed in this case than in the Panama papers...)
- deleted 5y ago[deleted]
- deleted 5y ago[deleted]
- c7DJTLrn 5y agoDisgusting. When the topic of commercial "cyberweapons" comes up, I immediately wonder about the people who created them. How they can sleep at night knowing how tools of their design are used. I'd argue that it's a completely different class of cybercrime and worse than anything else out there. Unprecedented action needs to be taken against NSO Group.
- helge9210 5y agoSale of these technologies is heavily regulated. If this kind of technology is deployed in your home country, State of Israel gave permission to sell it and your own state have permission to buy and deploy it.
- c7DJTLrn 5y agoThis is beyond regulation - these tools are infringing on human rights. But frankly, I don't mind what sales the State of Israel permits, they're free to do what they want. However, I would be upset if the government of my own home country permits these sales (which they probably do) or does not reprimand those associated with NSO Group.
- 34679 5y agoI imagine it helps to think of your victims as cattle put here by god for you to exploit.
- Leparamour 5y agoI wouldn't go so far and drag Judaism into this. At least it's an interesting question why so many shady companies seem to operate out of Israel.
- Leparamour 5y agoWithout programmers disregarding ethics these companies would have nothing to sell. My proposition is to put known employees of these companies on a blacklist for conferences like CanSecWest or similar.
- tigerBL00D 5y agoHow is this legal and why companies like NSO and their principals are not being prosecuted?
- A4ET8a8uTh0 5y agoIs it forbidden? Then it is likely legal. I am not defending NSO here, but I just want to provide a sample of a simple defense of this. In practical sense, there is very little regulation in this space. And if you add to it some of the territories involved in that race, you will quickly notice that it may be hard to force them to do anything. They are sovereign after all.
- rootkea 5y agoHere is the full forensic methodology report of this leak by Amnesty International's Security Lab: https://www.amnesty.org/en/latest/research/2021/07/forensic-methodology-report-how-to-catch-nso-groups-pegasus/ https://www.amnesty.org/en/latest/research/2021/07/forensic-... With this report, the Amnesty International has also released Mobile Verification Toolkit (MVT) - a forensic tool to look for signs of infection in smartphone devices: https://github.com/mvt-project/mvt https://github.com/mvt-project/mvt
- deleted 5y ago[deleted]
- maratumba 5y agoResponse from NSO: https://amp.theguardian.com/news/2021/jul/18/response-from-nso-and-governments https://amp.theguardian.com/news/2021/jul/18/response-from-n...
- zrth 5y agoGaslighting at its finest.
- dredmorbius 5y agoDe-amped link: https://www.theguardian.com/news/2021/jul/18/response-from-nso-and-governments https://www.theguardian.com/news/2021/jul/18/response-from-n...
- Zigurd 5y agoHow much consideration does NSO and other "forensic tools" makers get from platform makers and malware detection providers? Does intelligence and law enforcement get to keep their vulns longer after they are detected?
- owlbynight 5y agoWhy is this seemingly okay but if my Mom leaves a card in my mailbox, it's illegal? I really hate that our countries are largely run by incompetent corrupt geezers. Compromising the personal devices of private citizens for nefarious means should be globally illegal and, if perpetrated by a government, should be considered an act of war. Why does it seem like we're all just kind of okay with citizens being attacked like this?
- burgreblast 5y agoWhy is collecting all this information suddenly OK as long as it's "only" used for Advertising purposes? Is there a reason we also also forbid Google and FB from gathering this information? Or are their business models too important, and we can't decrease shareholder value? Or since "the users" click-agreed the business model is absolved and it's okay! What could go wrong, ever? Or, a modest proposal: we could agree that even corporations who sell HW/SW for personal devices shouldn't be allowed to collect this data, period. No one needs to mine our GPS history, messages, search, etc. Even if it means those who do it today makes less money. Ads are fine, but maybe we agree it's fine if ads aren't quite as targeted, either. I'm wondering if we might be better off with "punch the monkey" than hyper tracking and targeting.
- deregulateMed 5y agoI just pretend my devices are compromised. I'm genuinely surprised this isn't how all business handle IT. Maybe it isn't practical when you have trade secrets and engineering actively working on development. But maybe if IT was given this constraint, they'd figure out a solution.
- ttctciyf 5y agoGlad to see reporting on this, but struggling to understand how it's so much more outrageous than the UK's own behaviour in this regard vis-a-vis Gamma Group and the Finspy / Finfisher products. For example: > Despite rules saying the UK should not export security goods to countries that might use them for internal repression, ministers have signed off more than £75m in such exports over the past five years to states rated “not free” by the NGO Freedom House. > The 17 countries include China, Saudi Arabia and Bahrain, as well as the United Arab Emirates, which was the biggest recipient of licences totalling £11.5m alone since 2015. > Human rights groups said the UK was developing a reputation for not conducting proper checks on who it sold arms to, while Labour called on the government to show it is working to prove that it is complying with its own rules against arming dictators. - UK selling spyware and wiretaps to 17 repressive regimes including Saudi Arabia and China[1] Or just search[2] for "gamma" and "privacy international" 1: https://www.independent.co.uk/news/uk/politics/uk-spyware-wiretaps-saudi-arabia-china-bahrain-uae-human-rights-a9613206.html https://www.independent.co.uk/news/uk/politics/uk-spyware-wi... 2: https://www.google.com/search?q=%22gamma%22+%22privacy+international%22&tbs=cdr%3A1%2Ccd_min%3A1%2F1%2F2015%2Ccd_max%3A https://www.google.com/search?q=%22gamma%22+%22privacy+inter...
- teongpengheo555 5y agoMega88
- teongpengheo555 5y agoMeva888
- known 5y ago“Politicians and diapers must be changed often, and for the same reason” --Mark Twain (b. 1835)
- greengrom 5y agoIn fact, such leaks are absolutely not new. I am sure that everyone has seen a lot of funny videos on the Internet with cuts of people falling or ridiculous cases at work. Most of these videos have recently been posted by completely different people who had access to these cameras. So I bought myself https://ajax.systems/ https://ajax.systems/, and not some vaunted Amazon. Everyone has heard about how Amazon sells user data along with camera recordings, right? Think a few times before using the services of monopolists.