5 ms·
> "NSO is a technology company. We do not operate the system, nor do we have access to the data of our customers, yet they are obligated to provide us with such
by fossuser 5y ago
> "NSO is a technology company. We do not operate the system, nor do we have access to the data of our customers, yet they are obligated to provide us with such information under investigations."
This is an abdication of responsibility and I agree the substance and tone of the response from them is really bad.
Just because you don't have direct customer data access does not mean that you don't hold some responsibility for how the tools you sell can and will be used. This is especially the case when you sell zero day security exploits in very high risk use cases.
This response suggests the culture on the inside is probably as bad as it looks from the outside. Based on this, I'd guess abuse of their tools is lot worse than what's publicly known.
A serious company operating in a high risk space would lead the messaging with and own the high risk issue directly and how they try to contain it in order to do pragmatic good in difficult areas. Instead we see a childish almost petulant, knee-jerk response that the bad things are 'not their fault' because they're just a software company.
These guys are just rationalizing their own bad behavior.
https://zalberico.com/essay/2020/06/13/zoom-in-china.html https://zalberico.com/essay/2020/06/13/zoom-in-china.html
- jonplackett 5y agoI think it’s worse than just abdicating responsibility. As if they just didn’t know bad things cound happen. They’re selling this software to literal tyrants. They knew full well what this would be used for.
- cbsmith 5y agoI don't think they're claiming they didn't know bad things could happen. Their "Transparency and Responsibility Report" is essentially a detailed accounting of how they weighed that risk when licensing their software. I think one can certainly take issue with their approach, but they don't appear to be naive about the risks.
- fossuser 5y agoTheir response in this post suggests they don't view this targeting as related to them or their responsibility. > "The list is not a list of targets or potential targets of Pegasus. > "The numbers in the list are not related to NSO group. > "Any claim that a name in the list is necessarily related to a Pegasus target or Pegasus potential target is erroneous and false. > "NSO is a technology company. We do not operate the system, nor do we have access to the data of our customers, yet they are obligated to provide us with such information under investigations." My read of this is it's the kind of carefully worded intel-like response, basically saying the people targeted are not Pegasus(tm) targets because Pegasus is the name of the product and it 'technically' doesn't do the targeting on its own, the customers do the targeting - therefore not our fault and not related to us, we just sell software. (Even though the customers used NSO software to do the targeting, sold to them by NSO).
- cbsmith 5y agoI said they don't appear to be abdicating responsibility for the risk their software could be used for bad things to happen. If you look at the report, it's all about weighing that risk against the risks of not licensing their software. They are abdicating responsibility for the list, which doesn't seem unreasonable since the Pegasus Project has been pretty explicit that they don't know where the list came from, who put it together, or why any particular entry was put in to the list. The Pegasus Project guys have already walked back their statement that the list is phones that have been targeted by Pegasus, so... It very much sounds like someone found some HLR logs and then failed to determine whether that list was specific to Pegasus or not. It seems very unlikely that there'd be HLR logs that would be specific to Pegasus somewhere, so I'm not sure how anyone could expect them to take responsibility for such a list.
- fossuser 5y agoThanks for the details - given that, they could have written a real response to the allegations rather than this blog post they posted and it would have come across better. This blog post comes across very defensive somewhat clueless, doesn't inspire confidence. I get why they'd not want to engage with the media (media writers are often useless at best, if not actively/intentionally harmful with regard to this kind of technical nuance), but that's no excuse for the response they have here. If they were going to go direct they should have done it right. For the curious, their report: https://www.nsogroup.com/wp-content/uploads/2021/06/ReportBooklet.pdf https://www.nsogroup.com/wp-content/uploads/2021/06/ReportBo...