14 ms·
Amazon Shuts Down NSO Group Infrastructure
- justinclift 5y agoOuch. > The Amnesty report said NSO is also using services from other companies such as Digital Ocean, OVH, and Linode ... We've been using Digital Ocean for a few years now (sqlitebrowser.org), and they've been really good. Hopefully they look into this and take some useful action. :)
- deleted 5y ago[deleted]
- neom 5y agoIt's "DigitalOcean" - sorry to be pedantic, it drives me absolutely nuts when people put a space between, especially publications.
- syspec 5y agoCareful of the Streisand effect.
- lokedhs 5y agoThere is another point if view, and that is that corporate marketing should not take precedence over correct use of language. Some languages tend to be more strict about this. I think it's particularly common to see English play fast and loose with the language compared to other languages. In Sweden, for example you will see media write Iphone, because it's a name, and names are capitalised. The same goes for Digital Ocean, or Digitalocean if you prefer. It can definitely be argued fairly that the writer does not have to break language conventions just because a company says they have to.
- wpietri 5y agoExactly. Language is for all its users. I can insist that my name be rendered only in 14.5 pt Comic Sans colored with Pantone 19-3336 ("Sparkling Grape"). But people get to decide for themselves how they're going to speak and write. Corporate branding guidelines constrain only their employees and people who want to curry favor with them. Everybody else can do as they please.
- toss1 5y agoGood point that everyone else can do as they please. Moreover, this can be a big problem for the corps, and it is up to the Corp to protect their trademark and prevent everyone from doing quite as much as they please. If people start using a trademark as a generic term too much, the trademark can be lost. There are legions of examples, starting with aspirin, escalator, dumpster, etc. [1]. So, they try to insist that it be used only the (TM) or as "Acme Brand widgets". It would not surprise me to see Google end with the same fate. [1] Lexology: Death of a Trademark: Genericide. https://www.lexology.com/library/detail.aspx?g=5027217f-1db2-4ebb-9838-8696e97c6191 https://www.lexology.com/library/detail.aspx?g=5027217f-1db2...
- midev 5y ago> Corporate branding guidelines constrain only their employees and people who want to curry favor with them. Everybody else can do as they please What a weird take on why you should spell a company name correctly. Correct, nobody is going to put you in jail for misspelling Digital Ocean. You can do as you please. But everyone else is going to think you don't know what you're talking about if you can't even get their name correct.
- cinntaile 5y agoThe media in Sweden use both by the looks of it. They do that for IKEA as well but it doesn't really make sense imo since it's an abbreviation of names. Both are made up language constraints anyway so I don't really see why the typographic rules of a language are more important than the equally artificial typographic rules of a company name.
- deleted 5y ago[deleted]
- lokedhs 5y agoYou will definitely see both. You'll see things like Iphone being written by media sources that pride themselves on good writing, such as Dagens Nyheter. If you go to https://sv.wikipedia.org/wiki/Ikea https://sv.wikipedia.org/wiki/Ikea the first sentence can be translated to English as: "Ikea Group, written by the company as IKEA Group, is a multi-national furniture company founded in 1943 by Ingvar Kamprad" Words such as TV started out in upper case because it's an acronym, but once it becomes a normal word, it's written in lower case.
- cinntaile 5y agoThey still write Iphone X, why not Iphone x? or Iphone 10? or Iphone tio? Roman numerals aren't really a part of the Swedish language after all. They write IOS or iOS, why not Ios? Is this not a normal enough word? It's just artificial rules replaced by a different set of artificial rules. Why not just use what everyone else uses, haha. A bit of a meta discussion in a thread totally unrelated to this, sorry about that.
- lokedhs 5y agoI think we're drifting away from the original point, which is about not letting corporate marketing departments decide how the written language should work. I used Swedish as an example of a language where this is a more firm rule than English, but Swedish is certainly not alone. It just happens to be the language I know best. But, I do find the topic of Swedish writing standard to be interesting, so I'll be happy to do my best in responding to your questions, even though I'm not formally a linguist (although I was raised among them) With regards to your question, I'd write Ios, because it's not an acronym and I do believe that I'm not alone in this. About the version number, I find at least one case of the use of Ios 10 at Svenska Dagbladet: https://www.svd.se/apple-har-atgardat-problem-med-ios-10/om/itunes https://www.svd.se/apple-har-atgardat-problem-med-ios-10/om/... However, it seems to be highly inconsistent, and this is probably caused by these organisations saving money on proof readers.
- deleted 5y ago[deleted]
- lupire 5y agoIn English, Also, Marty McFly is not Marty Mc Fly or McFly. Internal capital letters are OK.
- unfunco 5y agoAnother point of view: DigitalOcean.com works but Digital Ocean.com does not.
- midev 5y ago> There is another point if view, and that is that corporate marketing should not take precedence over correct use of language. There is no such thing as correct use of language. That being said, you should spell proper names as they are registered. It's iPhone, not Iphone. > It can definitely be argued fairly that the writer does not have to break language conventions just because a company says they have to. Language convention is to spell the name as the company as it is registered. You wouldn't change someone's last name because it didn't follow some other, slightly related convention... https://english.stackexchange.com/questions/38827/how-to-write-company-name https://english.stackexchange.com/questions/38827/how-to-wri...
- dylan604 5y agoMy pet peeve is publications spelling NASA as Nasa. They've come up with some story to explain their decision that sounds just as bad as some of the lies Walter White told. I don't care how ubiquitous NASA maybe, it is and always will be an acronym. I accept removing the dots so it's not N.A.S.A., but I will only accept Nasa as a formal name if that's the name of a person.
- FactolSarin 5y agoHow do you feel about "scuba" or "laser?" Acronyms that are pronounced like they're spelled (eg, Nasa, gif, taser) tend to end up being spelled like words sooner or later instead of being in all caps.
- dylan604 5y agoPersonally, I don't write SCUBA or scuba, as it's just not part of my day to day conversation, but I would go with SCUBA. Also, it's never just laser or LASER, it's friggin LASER!!! Pew Pew!
- jumelles 5y agoIt's a British/American English difference.
- Bayart 5y agoAllow me some pedantry as well : if people consistently make the same mistake with the name of a product, is the problem with people or the name ? As lokedhs alluded, it clearly breaks established typographic rules.
- LoveLeadAcid 5y agoI call it an iPad and an iPhone, not iPad and iPhone like Apple wants me to.
- apercu 5y agoThanks for this. I needed a chuckle.
- detritus 5y agoI see you 'helped build' Digital Ocean, so I can understand your personal reasoning, but really - it's not at all important to anyone else. Also, wasn't that a bit of a fad back in the late 90s early 00s? I know my wee business followed the path of concatenating words for brand ...something... , but I honestly couldn't care less how other people deploy it in their own space, as long as they remember the name.
- neom 5y agoOf course, some people might choose to reply "Oh I see you worked on DigitalOcean! Funny people care about something like that, but given another human does, I'll respect that!" Some might chose to reply "I can do whatever I want, I don't really care what you think" - people can choose how they react. It's always very interesting to me who choses what, it's very telling regarding personality. I am well aware people are welcome to do as they please, nevertheless, the name of the company is "DigitalOcean" not "Digital Ocean".
- detritus 5y agoReading my response back now, I didn't mean to sound cynical or abrasive when I quoted 'helped build' from your profile. I could have as easily said "I see you were involved in.." or whatever and that would not have sounded snarky. Honestly though, I didn't think it through that much, I just literally quoted what I saw. Just in case you thought that was where I was coming from! </reddit>
- neom 5y agoThe replies to my comment generally simply serve to remind me of the quality of humans in this community, I'm certainly not sure why I waste my time contributing to it.
- justinclift 5y agoOh, didn't realise. Sorry about that. Ironically, I'm the same way with "PostgreSQL". There used to be _so_ many weird mis-spellings of it. eg "postGreSQL" seemed to be popular for some unknown reason
- wila 5y agoThanks for working on sqlitebrowser!
- justinclift 5y agoYou're welcome. :)
- walrus01 5y agoI have to say I'm not surprised that NSO and similar entities are using any CDN/large-scale hosting company they can find. The bigger the better, and spreading their stuff around as widely as possible with as much obfuscation in server purpose as possible. Such things are impossible or problematic to block/null-route without breaking many other things hosted at same AS.
- Scoundreller 5y agoWhich is a sad state of affairs. Want to run a service with few problems? Here are the 6 companies you better run it through otherwise you can’t guarantee anything.
- bob1029 5y ago> sqlitebrowser.org Everyone at my company loves your tool. Please keep up the great work!
- justinclift 5y agoAwesome, thanks. :)
- TravelPiglet 5y agoPurged my account at DO now. Sad that companies like DO care more about money than a free society
- justinclift 5y agoHmmm, maybe give them a change to look into it first?
- Spooky23 5y agoShouldn’t there be an outcry against the suppression of free speech? When Facebook or Google blocks extremist propaganda, it’s a big thing. What jurisdiction’s laws were broken by this company?
- asah 5y agoYou gotta draw the line somewhere - this is way over that line.
- geofft 5y agoIsn't the line due process of law, though? If NSO is allegedly committing a crime, then we can punish them in courts of law that are empowered and qualified to investigate the allegations fully and decide whether to deprive them of their rights. Why would we put these decisions in the hands of Big Tech? At least, that's what I heard during the debates about deplatforming Parler. It was apparently very bad for private companies to decide that a customer was engaging in distasteful but legal actions. What is the principled argument that it was not okay for AWS to take down Parler but it's okay for AWS to take down NSO?
- JumpCrisscross 5y ago> Isn't the line due process of law, though? For state actions, yes. For private actors, if I suspect someone is using my services to break the law or engage in terrorism, "but your honor, I didn't have a court order confirming they were terrorists" won't cut my liability. Parler was a free speech question because it was almost purely speech. NSO Group isn't just speaking. It's doing, and it's doing things that will bring liability for people around it.
- Dah00n 5y agoSo then the question becomes Did Amazon let police gather evidence before touching anything?
- bluetwo 5y agoWonder if NSO was involved in that leak of Bezo's phone data awhile back.
- sva_ 5y agoI thought about the same. Perhaps an "order from the top."
- tnolet 5y agoI was thinking exactly the same thing. Given what we know about this hack — a Whatsapp or iMessage essentially taking over his whole phone — this seems plausible.
- kaonwarb 5y agoFrom Amazon Unbound, p.344: > De Becker then commissioned an examination of Bezos’s iPhone X. The eventual report by Anthony Ferrante, a longtime colleague of de Becker’s and the former director for cyber incident response for the U.S. National Security Council, concluded that the promotional video about broadband prices that MBS had sent Bezos the previous year likely contained a copy of Pegasus, a piece of nearly invisible malware created by an Israeli company called NSO Group. Once the program was activated, Ferrante found, the volume of data leaving Bezos’s smartphone increased by about 3,000 percent.
- whymauri 5y agoJesus Christ, this software really is a weapon.
- cronix 5y ago> The eventual report by Anthony Ferrante, a longtime colleague of de Becker’s and the former director for cyber incident response for the U.S. National Security Council, concluded that the promotional video about broadband prices that MBS had sent Bezos the previous year likely contained a copy of Pegasus, a piece of nearly invisible malware created by an Israeli company called NSO Group. Key word in that sentence: "likely." AFAIK, nothing has been proven beyond rumor and conjecture, which isn't proof of anything at all. Did they find the Pegasus or related code on the phone, or not? That is a yes or no answer. Likely?
- zzleeper 5y agoPerhaps NSO Group should be considered a terrorism-aiding organization. Freeze its assets, track all their employees, backers, etc. Wonder if they are even helping to hack US government employees through China, etc. (besides just helping to torture dissidents).
- flyinglizard 5y agoThe biggest customers for these companies are Western governments. You’re not going to take away their toys.
- igorzx31 5y agoTheir biggest customers are middle eastern governments according to the WaPo article. US certainly has bought the software but it's mostly Saudi, UAE, Qatar, etc. US has NSA so they don't really need some software. Middle eastern powers dont have the same type of technical expertise to develop their own in-house.
- h1fra 5y agoSo should we consider the NSA a terrorism-aiding organization? edit: the tone is lost via internet; my own opinion on this: yes, it is.
- bobthechef 5y agoDoes terrorizing citizens through illegal spying and mass surveillance constitute terrorism? Or does only setting off bombs in public spaces count?
- throwaway210222 5y agoOnce you too have had the misfortune of a bomb going off near your family, you will know the answer.
- PeterisP 5y ago
- CTDOCodebases 5y agoWTF? Wasn’t it the NSO that hacked Bezos’s and Khashoggi’s phone? I guess the customer is always right up until the point the widow of your murdered employee goes to the press.
- polar 5y ago> Bezos Bezos' phone probably wasn't hacked. https://www.bloomberg.com/news/features/2021-05-05/how-jeff-bezos-beat-the-tabloids-the-untold-story-of-money-sex-and-power https://www.bloomberg.com/news/features/2021-05-05/how-jeff-...
- s_dev 5y agohttps://www.wired.com/story/bezos-phone-hack-mbs-saudi-arabia/ https://www.wired.com/story/bezos-phone-hack-mbs-saudi-arabi...
- tedunangst 5y agoWhy would you post an article from Jan 2020 as a rebuttal to an article from May 2021?
- s_dev 5y agoCan anyone read your URL since it's behind a paywall?
- ehsankia 5y agoWhat concrete proof does your article have? Bezos literally has access to his phone and the text that MBS sent him, containing the exploit. You're going to take some conspiracy theory based on rumors over the analysis of the actual phone that was hacked? The affair and all those things are probably true, but that doesn't really negate the fact that he was most likely also hacked by MBS.
- sofixa 5y agoDidn't Bloomberg ruin their tech reputation with the still-unproven (years later) and probably baseless claims of nano chips planted in the supply chain of Supermicro ?
- sloshnmosh 5y agoI contacted Amazon to report an advertiser out of Tel Aviv that was using JavaScript hosted on CloudFront to fingerprint user's devices and if an Android device was detected a fake media player or fake CAPTCHA would trick user's into accepting push notifications for fake virus warnings to install questionable apps from the Play Store. This script also pushed ads for a fake AdBlock app that was a dropper for banking trojan apps. Amazon refused to do anything about it. More info: https://forum.xda-developers.com/t/massive-mobile-advertising-fraud-campaign-fake-virus-warnings-free-iphone-scams-surveys.4242181/ https://forum.xda-developers.com/t/massive-mobile-advertisin...
- ericbarrett 5y agoDid they reply in the negative or just not respond?
- achow 5y agoHow does it matter? No response is a response and in this kind of situation it is explicit "I will not do anything and I'm dishonest enough to not acknowledge that.".
- ericbarrett 5y agoI was curious, not being cynical toward sloshnmosh. Much can be inferred from Amazon's choice of reply.
- jabberwik 5y agoTo me, a negative response says "We have evaluated our policy and decided that we will not stop this." A non-response says "A frontline agent didn't know how to make a call on a non-downtime ticket from a non-customer so now it's in a bureaucratic black hole and nobody has actually read your email and probably never will." Which is still crappy, but not really malicious in the same way.
- jjoonathan 5y agoIt feels like this is more a result of Amazon not being able to connect you with the right escalation path to verify & act on these claims than a considered decision to ignore them. Does anyone here know what an individual reporter should do? Is there an escalation ramp that exists but was so poorly marked that neither sloshnmosh nor Amazon support was able to find it? Does the ramp go through other organizations (e.g. report to CERT or some other org first and come back with a case ID)? Does the ramp not exist and need to be built?
- javajosh 5y agoIsn't NSO just a poor-man's NSA, since the NSA can force Google/Apple/Microsoft/Amazon/[Any Carrier] to do anything to any number of devices or data, and in secret?
- esens 5y agoNSO seems to be used by tyrants to go after legitimate opposition. The NSA isn't used by the President to target the party out of power no? But in NSO case in India apparently it was: https://www.theguardian.com/news/2021/jul/19/key-modi-rival-rahul-gandhi-among-indian-targets-of-nso-client https://www.theguardian.com/news/2021/jul/19/key-modi-rival-... NSO is used to keep those with money and access to NSO in power undermine their legitimate rivals. It can be used to plant evidence on their devices as well as monitor everything they do.
- deleted 5y ago[deleted]
- hammock 5y ago>The NSA isn't used by the President to target the party out of power no? No, definitely not.
- kdkdmdm 5y ago> The NSA isn't used by the President to target the party out of power no Close, but you've got the wrong organization. It was the FBI that used evidence it knew was false from the start to justify a spying campaign into the opposition candidate and then used the candidate's campaign's resistance of that illegal election interference to justify political interference and, ultimately, an indictment. That's right, the Obama DOJ illegally harassed the Trump campaign and then the out of control FBI and House Democrats (led by the former FBI director, Mueller) followed through with the farce of an impeachment, aided and abetted by misleading coverage of the proceedings, which resulted in only an indictment for resisting the illegal investigation and election interference And now the same people assure us that the 2020 election was the fairest and most secure ever. Real confidence inspiring! Personally I never had any doubt in the security of the US elections until the same machine that insisted the Russian collusion was real (it definitely wasn't), and that the lab leak theory was never plausible (it's not definitely true but it's definitely plausible and always has been), insisted that there was no way they could've been fraudulent. Thou dost protest too much, methinks.
- esens 5y agoAnyone notice that this statement from NSO in the article doesn't make sense: "NSO does not operate its technology, does not collect, nor possesses, nor has any access to any kind of data of its customers." If this is true, how do we have a singular list of all phone numbers penetrated? If there was this type of "segmentation" or firewall between NSO and its clients, why was there this huge central data leak? NSO is tracking what its clients are doing. It may not be telling its clients it is also tracking them. I wouldn't be surprised if NSO could also access every one of those penetrated devices as well independently of its clients.
- hn8788 5y agoIt could mean that NSO controls the infrastructure that manages the tool, but that they don't actually collect the data themselves. So what they said could technically be true if all they do is manage the infrastructure that enables their clients to do the collection of data.
- esens 5y agoBut do they have access to the phone numbers that their customers are targeting? That seems by itself to contradict their statement ("nor has any access to any kind of data of its customers") right there. Something isn't adding up.
- hn8788 5y agoThey could be lying, or they could just be trying to use weasel words. "Data" could be referring to collected data, and they consider phone numbers "metadata". I haven't been following the story though, so I don't know which is more likely.
- JumpCrisscross 5y ago> Something isn't adding up It's bullshit at best. If we assume they aren't lying, which is generous given their track record, it could be that they provide the tools and infrastructure to collect the data, but don't instruct the software to collect the data. Sort of like if I had a loaded gun and told you I would point and shoot it where you told me to, and then argued that I didn't technically make the decision. It's technically true and complete bullshit.
- sneak 5y agoI am willing to bet money that NSO Group has multiple AWS accounts, many under several layers of cover. You can't really spin them up with any significant quota on short notice (ask me how I know, AWS service team) so having established ones with workable limits in advance across multiple cloud providers would be table stakes for any competent spying organization.
- duxup 5y agoI'm sure that applies to most every service as far as bad guys operating covertly. I've no problem with AWS or anyone playing whack-a-mole and giving them the run around in the meantime ...
- coldcode 5y agoIf someone were to use NSO paid hacking to attack Apple executives's devices and then release everything they found, I bet Apple might take this more seriously instead of having some PR flack write marketing copy. Same is true of any tech company: until it hurts them specifically they can just ignore it or make it sound innocuous. Maybe Amazon has been targeted and they found out. If someone were to use it against US government entities, maybe the NSA/CIA/etc might decide enough is enough, no matter what country they are in. So far at least publicly it seems like a non-event. But once the phone numbers are identified from that leaked list, things might become more serious for NSO. People used to fight real wars against adversaries who targeted their country in some way, why should commercial entities supporting such attacks not be treated the same, except via non military action? Spying has always been done, but it can lead to serious consequences.
- JumpCrisscross 5y ago> Apple might take this more seriously instead of having some PR flack write marketing copy What are they supposed to do?
- kilroy123 5y agoTake security a lot more serious than they currently do. They've had some seriously embarrassing security holes in their software the last few years. Also, they could increase the payout for their bug bounty. Why report to apple for a 0-day when you can make $1 million from these guys? It's not like Apple doesn't have the cash.
- adventured 5y ago> Take security a lot more serious than they currently do. That statement doesn't mean much. How do you know they're not taking it seriously enough and still struggling with the enormity of the problem regardless? You could always claim any entity isn't taking security serious enough. The alternative explanation makes a lot more sense: security is extremely difficult at Apple's scale, serving a billion consumers with complex and essentially always-connected electronic devices (not to mention their huge services business now). Devices that also happen to be one of the single most important attack points that there is.
- m3kw9 5y agoI wonder if Amazon kept a copy of all their images?
- fjtktkgnfnr 5y agoGiven how much care they took not to write the payloads to the phone storage, presumably they took the same care not writing it to server storage on cloud hardware.
- ed25519FUUU 5y agoEverybody is coming down on NSO but why aren’t we asking more about the clients? Who is spying on “CEOs, politicians, religious leaders, union bosses”? And once these people are compromised, what are they being asked to do?
- dredmorbius 5y agoNSO (and its infrastructure) are the vulnerable single point of control. That's in fact part of the service they're offering, whether they realise it or not: outsourcing blame, exposure, culpability, and liability. Something like how a re-entering spacecraft is fitted with a sacraficial ablative heat shield. The shield's job is to absorb punishment, often destroying itself in the process, protecting the more valuable payload. The problem with this model is that NSO are, as with heat shields, replaceable. A new target will appear to take its place. But that too will draw attention, it will have to assemble talent (leadership, engineering, sales, operations), and will itself have vulnerabilities. As I suggested in a thread yesterday, playing in the field of dirty ops raises prospects for piercing the corporate shield of liability for all those involved: the firm, its personnel, investors, creditors, suppliers, and where identifiable, clients.
- confiq 5y agohttps://www.digitalviolence.org/ https://www.digitalviolence.org/ It kinda describes how NGO operated and it's great infographic!
- salimmadjd 5y agoFrontline (PBS)in partnership with Forbidden Stories are doing a report [1] on NSO hacking the phone of Khashoggi’s fiancé and other journalist and activists around the world. Looks like her phone was compromised by NSO based on the reporting on this video. [1] https://www.pbs.org/wgbh/frontline/article/how-nso-group-pegasus-spyware-found-jamal-khashoggi-fiancee-phone/ https://www.pbs.org/wgbh/frontline/article/how-nso-group-peg...
- deleted 5y ago[deleted]
- giantg2 5y agoAnd cue a slew of CEOs in non-ESG friendly companies rethinking their AWS contracts...
- ashtonkem 5y agoGood. Every single person employed by them should also find themselves shut out of the industry for life.
- theknocker 5y agoI'm sure we're imminently start applying the same standards to organizations in the U.S. doing the same shit.