11 ms·
NSO Group Hacked
- rollulus 5y agoThe "hacked" part is only an assumption, isn't it? The leaked information could also come from, say, a whistleblower. An employee that suddenly developed a sense of ethics.
- IndySun 5y ago>only an assumption... leaked information could also come from... The first paragraph of the article broadly mentions an alt scenario. "Or, at least, an enormous trove of documents was leaked to journalists."
- jachee 5y agoYeah… the press loves the term “hacked”. Remember when Voicemail PIN guessing was “phone hacking”?
- samstave 5y ago"hacked" is a distraction - you think that NSO is going to be "hacked" without a honeypot - or some other "thing" as to make them look weak? Nope. They are trying to plausibly deny their bullshit by saying "Ey... look -- weez alsa beenz haxd... we no do dis..." Yep - nope - fuck this company... *laughs all the way to the bank with palantir folks.....
- deleted 5y ago[deleted]
- beermonster 5y agoI had assumed a whistleblower until now. The worry with them being hacked is their tools leaking to public domain. If they do I hope Apple et al can plug the vectors
- swarnie_ 5y agoOne unnamed company is still struggling to secure a print spooler after most of a month. I don't have the optimism you do.
- beermonster 5y agoI think Apple have been trying to secure iMessage for nearly as long ! They’ll be following the story closely as it unfolds.
- j16sdiz 5y agoI think apple have added a much more restricted sandbox for iMessage in the past few releases
- beermonster 5y agoYes [1] but it’s been proven to be ineffective for its intended purpose in these recent revelations. [1] https://googleprojectzero.blogspot.com/2021/01/a-look-at-imessage-in-ios-14.html https://googleprojectzero.blogspot.com/2021/01/a-look-at-ime...
- pajko 5y agoSeems like there was a $100,000 bounty on hacking them: > On Friday, Fisher claimed to have hacked the bank in 2016 and proposed a "Hacktivist Bug Hunting Program" that would offer bounties of up to $100,000 to those who hacked and dumped documents "in the public interest" from companies such as "South America, Israeli spyware vendor NSO Group, and oil company Halliburton." https://boingboing.net/2019/11/19/2tb-and-counting.html https://boingboing.net/2019/11/19/2tb-and-counting.html
- darig 5y agoWhy would anyone seek to harm Israelis?
- Shank 5y agoI suppose that broadly, the takeaway here (and in all of this) that I’ve missed is that fundamentally, this list of phones that were targeted shouldn’t exist, or shouldn’t be leakable in this way, if we want to believe that NSO Group is targeting the most genuine targets. To frame it differently: NSO Group sells tools to governments that are apparently trustworthy. Its security and system architecture should be decentralized enough that a list of all targets should be extremely difficult to obtain. If the list is obtainable, then what else is? Are their exploit toolkits just as leakable? Are the internal controls not sufficient to stop these leaks? How can we continue to allow orgs like NSO Group to exist if they surely can’t keep something like their entire target list safe? Even if we assume of the targets are legitimate threats (which, again, requires enough suspension of disbelief to hold a small army at this point), why would we want that list leakable? If they’re all the most legitimate targets, then that list is essentially 50k people who can now discover this fact and change their patterns to hide. It’s pretty bad to tip off “all the people who we find important enough to 0-day” if that assumption holds. Now the real question? I’m not sure I know what we can do, actionably. Call Congress and ask them to care?
- baybal2 5y ago> Now the real question? I’m not sure I know what we can do, actionably. Call Congress and ask them to care? I maintain that NSO is just a deniability front for Israel's espionage agencies, otherwise I don't know how they weren't shut down for so long, knowing what kind of a state Israel is. NSO is well known to the Israeli state, after all it is their cabinet that clears every deal NSO make. Per Israeli laws, pegasus is a "weapon" So yes, the problem is primarilly in political dimension.
- aritmo 5y agoThat looks reasonable. The NSO Group malware perform active attacks. By creating this front (the NSO Group) that is supposed to have private customers, they can put in their own targets and have some form of deniability.
- maltalex 5y agoWould you have said the same about HackingTeam [0] and the Italian Government? They were featured on citizen lab a LOT a few of years ago [1]. These guys still operate under the name "Memento Labs". There's obviously money to be made from selling offensive cybersecurity tools to governments. And you can hardly blame governments for buying these services in the age of end-to-end encryption in the hands of every criminal and terrorist. While I definitely don't condone spying on human rights activists, journalists, or even regular citizens for that matter, pegasus really is a weapon and as such should definitely be heavily regulated. But as with other types of weapons, the responsibility for its use (or rather misuse) should lie with the weapon's user first and foremost, not the manufacturer. If NSO/HackingTeam were in the business of selling physical weapons to foreign governments, would they have been responsible for a government killing journalists with said weapons? If they were selling to North Korea, sure. But what about the legitimate governments of stable countries not under sanctions? [0]: https://en.wikipedia.org/wiki/Hacking_Team https://en.wikipedia.org/wiki/Hacking_Team [1]: https://citizenlab.ca/tag/hacking-team/ https://citizenlab.ca/tag/hacking-team/
- Goety 5y agoSo how do we defend the defenseless?
- swarnie_ 5y agoYou could start by not funding an expansionist apartheid state?
- wiz21c 5y agoand a nuclear power who didn't sign the Treaty on the Non-Proliferation of Nuclear Weapons...
- llimos 5y agoWhy is that worse than a nuclear power who did, and contravened it? Not sure why you think countries should be bound by treaties they didn't sign.
- sofixa 5y agoBecause the treaty exists to prevent the very thing Israel did - covert nuclear arms development and covert sharing of know-how ( like Israel probably did with Apartheid South Africa). It's like criticizing a country for not being in the Paris climate accord for their environmental record/refusing to lower emissions - yeah, that's kind of the the point.
- pajko 5y agoHere is a detailed analysis: http://info.lookout.com/rs/051-ESQ-475/images/lookout-pegasus-technical-analysis.pdf http://info.lookout.com/rs/051-ESQ-475/images/lookout-pegasu... Official manual: https://archive.org/details/nso-pegasus/ https://archive.org/details/nso-pegasus/
- tingle 5y agoThis interesting analysis was written in 2016. Is there a more recent version ?
- bertil 5y agoI understand that the title makes an assumption that the first paragraph has to walk away from in its last sentence, but I appreciate Schneier’s nuance when framing the question. The spying isn’t new. The list is probably broader than many people assumed, but the real news is that NSO own security isn’t great. More importantly, if you believe that digital-weapons-for-hire are not a good idea, spreading doubt about their reliability is probably more effective than painting those companies as invincible hackers. They made an architectural choice that exposed their clients. Therefore, if you are a prospect for a similar technology, think hard when they present their tools, and challenge decisions that might expose you.
- cblconfederate 5y ago> that NSO own security isn’t great Better. it s good that they have bad security. they arent in the security business, quite the opposite. It's a company that has found the legal loophole to sell theft-as-a-service. Kind of like banks compared to robbers.
- qeternity 5y agoIf I were a similarly acronym’ed three letter intelligence agency that wanted to shut down a private sector competitor, this is exactly what I would do.
- marcosdumay 5y agoLet them destroy each other then.
- tzury 5y agotime to shut down this company.
- anigbrowl 5y agoWhat a shame /s
- Arjuna144 5y agoMy first reaction to this was that all would need mobile phones with physical off switches for camera/microphone and internet but even such swtiches do not protect against such advanced spy operations. I think such software should be treated like weapons of war for which there are international regulations and obervations
- fsflover 5y agoHardware kill switches do protect from spying whenever they are off. How can they not? Librem 5 phone has them.
- jokoon 5y agoYeah, well, not really happy about this, because the goal was probably to delete traces of involvement and clients. Some people will also probably turn up dead, unless they hide or seek asylum.
- yawaworht1978 5y agoLive by the hack, die by the hack, i suppose.
- deleted 5y ago[deleted]
- deleted 5y ago[deleted]
- trasz 5y agoToo bad it didn’t include the list of employees.
- agilob 5y agoAfter Snowden leaked the documents a group of voluneers created a project to watch the watchers. They started scraping data from public profiles, social media, job offers etc. They were harassed for it, project was taken under wikileaks umbrella, it's not much maintained anymore. Somehow(!?) it doesn't have any info about NSO Group (or I can't find it), but there are plenty other doggy organisations archived there https://icwatch.wikileaks.org/ https://icwatch.wikileaks.org/ https://www.youtube.com/watch?v=xipI-0HU010 https://www.youtube.com/watch?v=xipI-0HU010
- teekert 5y agoThe iOS tool scans a backup, but the Android tool "check-for-infection tool" checks for messages pointing to NSO domains. I recently got a strange massage, is this list public?
- linuxguy2 5y agohttps://github.com/AmnestyTech/investigations/tree/master/2021-07-18_nso https://github.com/AmnestyTech/investigations/tree/master/20...
- Shindi 5y agoRight here is another argument in favor of string privacy protection. Even if NSO was a righteous and holy actor (spoiler: it's not), they can be hacked any time and now that data is public. Same reason govts shouldn't spy on their citizens: even when you fully believe in your own govt, they can be hacked.
- Cthulhu_ 5y agoSame reason why encryption shouldn't be weakened or backdoored ("think of the children / terrorists!"); if there's a weakness or backdoor, someone that shouldn't will find and exploit it. Or it'll leak from the one point that can decrypt it.
- dwild 5y ago> Right here is another argument in favor of string privacy protection. Even if NSO was a righteous and holy actor (spoiler: it's not), they can be hacked any time and now that data is public. This doesn't show that we need strong privacy protection, this show that asking for privacy protection isn't enough and goes way beyond privacy protection. Even if you got GDPR in every first world country, NSO will still exist, intelligence gathering will still exist. Zerodium exist for god sake, it's a public facing company to buy zero days. Even if you got both them and NSO shut down, believe me, others companies will do the exact same, they'll just do it more secretly.
- dogma1138 5y agoIs there any good explanation of what that list actually is and where it came from?