8 ms·
Pegasus spyware seller: Blame our customers not us for hacking
- dstroot 5y ago"Guns don't kill people. People kill people." "Spyware doesn't spy on you. [Other] People spy on you." Guns are a much better analogy than cars.
- AlexAndScripts 5y ago"Traces of spyware on the phones of leaked targets is simply a coincidence"
- teekert 5y agoInsane right? If that statement were true imagine what that must mean, 37 out of "a random selection of" 67 phones infected... (because the statement implies the 67 are a random selection from all phones worldwide). They have more issues if the statement is true than if it is not!
- inglor 5y agoThink about this reasonably. I've worked with intelligence bodies before and they would never run something like pegasus on a cloud or connected to the internet. Products like Pegasus are almost always an on-prem enterprise-product it's simply the only model that makes sense security wise. If you were a client of NSO would you trust them to not look at the data? My guess is that the list is from one of NSO's other products or someone trying to gather business intelligence on NSO - for example: location tracking, check when user is online etc - anything that can reasonably justify the data not being sensitive enough for customers like security agencies to be OK with it being in the cloud. Consider if any of those dictators would want the US and Israeli governments to have access to whomever they're tapping on.
- teknopaul 5y agoConsider if any of those dictators would want the US and Israeli governments to have access to whomever they're tapping. That's why they don't buy from the US or Israeli government: they buy from NSO who are a bunch of crooks.
- imwillofficial 5y ago> would never run something like pegasus on a cloud or connected to the internet. Intel agencies use the cloud extensively for all sorts of use cases. This is 100% fact. Google “Amazon C2E”
- guli 5y ago"Once the rockets go up, who cares where they come down"
- nebulous1 5y ago"Zats not mein department!" says Werner von Braun
- tut-urut-utut 5y agoAfter the London test was successful, gehen wir zum Mond
- teknopaul 5y agoSimple thought experiment for NSO... Has anyone successfully used your software to drive their kids to school? Has anyone successfully used your software to kill an enemy? I'm with the guns analogy, probably closer to illicit arms dealer in NSO's case.
- dangerface 5y agoThis is why guns and spyware should be illegal.
- JohnWhigham 5y agoPutting aside whatever contracts governments have with gun manufacturers, the rest of the market is largely the average person that uses them for sporting or for self-defense. There's not that kind of benign market for Pegasus that the NSO Group can hide behind. The average person wouldn't be using Pegasus (if they could even afford it) to go after drug dealers/pedophiles/etc. Something like Pegasus can really only be used for nefarious purposes. I'm not buying their "People kill people!" argument.
- pjmlp 5y agoThe benign market of people that use said self-defense weapons on schools and shopping malls?
- imwillofficial 5y agoWould you agree, that of the total amount of guns sold, that a tiny percentage are used for mass shootings? A vanishingly small minority of users hurting society. Let’s compare that with the list we have. All the users are being spied on illegally. Some leading to deaths. 100% of use is society harming. Guns are a tool statistically not used often for crime. NSO’s software on the other hand is used for crime exclusively. (I do not want to get into a gun debate. I’m only using guns in my example because the GP alluded to mass shootings)
- wongarsu 5y ago> The average person wouldn't be using Pegasus (if they could even afford it) to go after drug dealers/pedophiles/etc. Vigilante justice certainly wouldn't be a benign market, even if someone did that with Pegasus (or guns)
- goldenkey 5y agoI'm confused how you can paint individual violence in broad strikes and promote government violence as sanctioned? Tyranny happens when governments have a monopoly on force. Vigilantism is necessary when the government is corrupt or inefficient. To look past the need for individual retribution and justice is naive. I don't even have to search for 2 minutes before I can bring up countless articles about missing children, murders, thefts, and other immoral acts that the police or federal agencies do not care or have enough resources to address. These victims' only recourse is vigilantism. It's easy to sit in an ivory tower of bureaucracy when you haven't been affected by the corruption or incompetence of the nanny state. Read this for size: https://www.nytimes.com/2020/12/13/world/americas/miriam-rodriguez-san-fernando.html https://www.nytimes.com/2020/12/13/world/americas/miriam-rod...
- bradleyjg 5y agoDo you think US companies ought not sell guns to the Mexican government?
- gameswithgo 5y agoi think us companies ought not sell guns to anyone
- bradleyjg 5y agoNo police departments, no militaries. We’ll all just sing kumbaya and the world will be at peace? The flower children have returned apparently.
- orwin 5y agoDon't worry, the trend is changing fast. Pre 2021, i had a lot of friend dismissing violence as a legitimate protection and worker empowerment, now some are buying guns. Like i said in a previous comment, i personally won't be able to draw a gun on another person, but doing the same as the BPP used to do do have some appeal to me. Walking the door of your company and saying "hi" to your factory manager with a gun on open carry must feel good.
- gameswithgo 5y agoover abundance of guns does kill people, though. that we could imagine that this shouldn’t be the case doesn’t really matter in the real world. the idea that we can scatter tools of enormous power around and just not worry about it is crazy
- TheAdamAndChe 5y agoThe real worry from these tools is relative power. A man with a knife can kill a few people. A man with a rifle can kill a few dozen people. A man with a few zero days can cripple infrastructure around the country and cause hundreds if not thousands of deaths. Relative power asymmetries are why nuclear, chemical, and biological weapons are banned by international law.
- inglor 5y agoI see their point - I think weapon sales (like Pegasus) should be regulated but blaming the company is kind of silly. It's exactly like blaming Colt for weapon sales. Should weapon sales be regulated? Sure. Is NSO regulated by both the Israeli and US government? Sure. Are those governments doing a good job regulating NSO? No. Is the poor job of their regulation causing people to get hurt and NSO is complicit? Yes. The solution in this case is to regulate selling Pegasus as strictly as selling weapons like the F-35 rather than like an AR-15.
- Lio 5y agoIs it not more like blaming the people selling ransomware tools?
- dariusj18 5y agoOnly if their customers are state actors
- kenniskrag 5y agothe definition of ransomeware tools can be hard imho. There is still an ongoing discussion about what are hacking tools and sometimes wireshark is called as example. E.g. they describe their tools as: > develops best-in-class technology to help government agencies detect and prevent a wide-range of local and global threats.
- inglor 5y agoPeople selling ransomware tools are not legal companies regulated by the Israeli and US government. If NSO didn't pay income tax or wasn't regulated by governments I'd agree. To be clear: I think the poor job regulating tools like Pegasus by governments is due to their incompetence in regulating this sort of weapon not to gain something. I also think a lot of this PR is because NSO likes it to get more clients as this sort of PR shows that their tool works - you never hear this sort of PR about their many many competitors in this space (like Verint, HackingTeam etc). We are enabling them instead of shutting them down which is unfortunate. Similarly if you were making stealth fighter jets underground and selling them to dictators it'd be more like ransomware.
- JCWasmx86 5y agoWell. If they sell spyware to others, they should at least ensure/check, that it is only used against criminals and by democratic states.
- NullPrefix 5y ago"criminals" and "democratic states" are very subjective terms.
- JCWasmx86 5y agoI agree with you. You would have to find some accurate definition for "What is a democracy?", e.g. look at the freedom of press, freedom of election (E.g. are there any inconsistencies in the last elections), conflicts in a country. Based on a lot of factors you could probably say "This is a democracy" or "This is somewhere between". But still no good solution. And criminal would be too far, as such spyware should only be used against extremely serious crimes, e.g. warcrimes or terrorism
- tut-urut-utut 5y agoRather the opposite, they should be used only against “small crimes”, since those crimes are universal. What you call serious crimes are highly political topics. Ones hero is anothers war criminal, and the same guy may be both freedom fighter and terrorist, depending who you ask.
- seoaeu 5y agoThe exact lines might be blurry, but that doesn't mean you can't try. Like there's plenty of countries that plainly aren't democracies
- imwillofficial 5y agoSo in your mind, democracy is the only valid form of government?
- 5y ago
- bradleyjg 5y agoThis is a pretty reasonable point in my opinion. These are all countries allied with many of our own. Where is the government to government pressure to curb this bad behavior? Why is the private sector expected to be the guardian of civil liberties in other countries and the public sector let off the hook?
- srean 5y ago> Why is the private sector expected to be the guardian of civil liberties in other countries and the public sector let off the hook? https://en.wikipedia.org/wiki/Wassenaar_Arrangement#2013_amendments https://en.wikipedia.org/wiki/Wassenaar_Arrangement#2013_ame...
- bradleyjg 5y agoHas the government of wherever you live remonstrated Italy, Mexico, and India?
- srean 5y agoI live in India ! and I severely oppose indiscriminate use of this weaponry for political advantage. As far as I recall French judiciary has started investigations.
- bradleyjg 5y agoShouldn’t you and your fellow voters being holding your government accountable for what it is doing with these tools rather than getting angry with vendors for selling things to your democratically elected government?
- srean 5y agoThat was a rather judgmental, presumptuous and a personal accusation, but why should we be doing only one and not the other, when like minded folks can and in my mind should do both. Why do you feel the need to defend a company that is in breach of internationally accepted norms of legal behavior with such dual use weapon systems. Anything personal ?
- skywhopper 5y agoIt’s interesting to me that NSO spokesperson says “we don’t have any customer data”, but they also confidently assert they know how many times these hacks are used. I’ve seen the same pattern in other stories. Unfortunately the reporting never goes into how the tech works. I assume there have to be at least some SaaS aspects given what is known about its capabilities, which would mean they have access to a lot more information than they are letting on.
- inglor 5y agoThe common way to do this in on-prem deployments is to hard-limit the user to a small amount of hacks (let's say 10). The more a tool like Pegasus is used the more it's exposed and the bigger the risk companies like Verint (or NSO in this case) of losing their 0-days take.
- mshanowitz 5y agoAnother part of this story is that the company completely denies their connection to this "list". The media thus far has presented very little evidence that this list is actually from NSO Group. They have provided no information on how this list was obtained and 67 phones (out of 50k) seems like a very small amount of phones (with a 55 percent success rate) to use as a basis for an international story across many major media outlets. These stories only consist of that this or this person is on the "list" (no evidence at all of spyware on their phone).
- inglor 5y agoMy theory is that NSO is paying for this PR blitz since companies like NSO need physical sales and now that international travel is back they need a lot of articles that talk about how powerful/dangerous the NSO hacking tools are. Basically "look at it from a Saudi prince's perspective".
- mshanowitz 5y agoI've seen no PR blitz. I'm honestly just a little skeptical seeing how some stories gained mainstream acceptance over the years without much basis in fact
- JKCalhoun 5y agoA spyware company denying their connection to a list that would cause them embarrassment is so unsurprising that we should probably simply ignore it — not a relevant data point. While I agree "the media" ought to back up their data with sources I think we can agree that data like this is only going to be provided with extraordinary precautions. Therefore I am also unsurprised that the source has not been revealed. I'm probably more skeptical than the average person (the past so many years has convinced me of that) but if you're going to suggest this list of phone numbers is a plant and part of a conspiracy you ought to at least suggest who would be behind this and why. That "the media" made this up whole cloth strains credibility.
- mshanowitz 5y ago
- boomboomsubban 5y agoIf there is no NSO master list of numbers targeted and they have no possession of customer data, then how are they also aware of how many numbers their clients target a year?
- grugq 5y agoLicensing.
- boomboomsubban 5y agoSo honor system? Or a local deployment software that requires NSO authentication but doesn't share any data?
- grugq 5y agoIt is an on prem system. The customer pays per agent deployed. They buy a license for some number (N) of agents. NSO doesn’t know where those N agents are, but it knows that there are N of them.
- rdtwo 5y agoIf you make software that is designed to disable power installations you are telling me you shouldn’t be held responsible when it’s used? The company and all of its employees are complicit in multiple murders and acts of espionage. They all deserve to rot in jail as an example to others
- boomboomsubban 5y ago>you are telling me you shouldn’t be held responsible when it’s used? No? This has nothing to do with my post about how their denial of having customer data includes them saying they have customer data.
- NiceWayToDoIT 5y agoIn all this I am thinking about scale, and how many political leaders are using same tool to spy their political opponents? I am thinking about just a few countries in which governments have discretionary right not do disclose how and where they spending tax money to the public. Does anyone know's technically how is this tool exactly deployed, in the sense what prevents Chinese intelligence using same tool to spy on US officials?
- inglor 5y agoThe US and Israeli governments approve the sales according to news articles I've found: so one thing preventing China from using Pegasus is the US government not green-lighting it. Additionally: you can count on China already having comparable technology anyway.
- NiceWayToDoIT 5y agoI guess once you have a phone it would not be too difficult to do reverse engineering, but I am still confused with level of vulnerability SMS / WhatUp / IMessage what does it mean a link other type "unknown" zero-day !? It is very odd, on one side governments complaining about other govs are hacking and safty, and at the same time requesting back-doors from tech giants, all the while tech people are saying "crying at loud you cannot have both at the same time", and this is going on for past 20 years ...
- WaitWaitWha 5y ago> The US and Israeli governments approve the sales according to news articles I've found Link to this news article, please.
- WaitWaitWha 5y agoMost likely the base/server tool "calls home". i.e. there is a client loaded on the target device, there is a server at the gov agency. The server has number of uses and targets. When the uses are exhausted, it phones home to NSO Group. This is very much the model for other spyware tools, forensic tools, and phone repair tools. This would also work well with the objection that they "don't have servers in Cyprus". It also explain how NSO Group would know how many targets the tool maybe loaded on, but not actually have the list.
- srean 5y agoThat is a line that signatories of the Wassenar arrangement cannot take. Israel is not officially a signatory but their own laws pull-requests the Wassenar arrangement and its amendments. The agreement legislates what dual-use systems (that is weapons systems that also have civilian use) can countries export and under what legal obligations and conditions. According to the agreement, producer/seller of dual use weapons systems is under obligation to ensure that the buyer is not abusing the weapon. Break in compliance makes the producer/seller culpable. I think what this means is that if a country wants they can find legal ways of making Israel culpable. Realistically though, I doubt USA will let that happen.
- rdtwo 5y agoHow is that guy not in jail. This guy did basically the exact same thing as Russian hackers except at a much larger scale
- helsinkiandrew 5y ago> But NSO Group said it had no knowledge of how some phones on the list contained remnants of spyware. > It could be "a coincidence", the spokesman said. I guess it could, but probably not
- egberts 5y agoMisuse of your product as not intended is the fault of the user. Pure and simple.
- srean 5y agoNot under normal export control laws that legislate the sale of dual purpose weaponry. As per Wassenaar arrangement the producer is liable for abuse by the buyer. Its the sellers obligation to monitor that it is being used according to all applicable national and international laws. https://en.wikipedia.org/wiki/Wassenaar_Arrangement#2013_amendments https://en.wikipedia.org/wiki/Wassenaar_Arrangement#2013_ame...
- egberts 5y ago… As intended …
- rdtwo 5y agoYeah that might apply to things where the use is mostly legitimate like a car but not so much when the thing you are making is by design used for espionage. These sorts of tools sold only be sold to the country you reside in and you better not be planning any international travel
- deleted 5y ago[deleted]
- TOMDM 5y agoI really wish the public narrative concerning spyware would shift to something analogous to how we see the state monopoly on violence. The police are a necessary institution that needs oversight and criticism to ensure that the dignity and rights of the population are preserved as much as possible. To that end, we don't hand over the role to private militia that has sparse regulation and no accountability. NSO Group are the private police with sparse regulation and no accountability of the spyware world. They don't simply sell the means to an end, they operate and deploy those means on behalf of customers. Just as we shouldn't accept police hiring private forces to kick down doors to check in on suspects, we shouldn't accept the contracting of services from NSO Group.
- grugq 5y agoThe FBI uses private contractors for highly specialised tasks, and they perform a law enforcement role also.
- um_ya 5y agoIf I were Apple, I'd try to arbitrage these exploits by getting somebody on the inside to find out where the attack vectors are. I blame the companies for being exploitable.
- pelasaco 5y agoAre they? I see them more as Glock, H&K and other defense manufacturing company than a private militia.. no?
- TOMDM 5y agoI'd argue that they're like those manufacturing companies and a militia rolled into one. They don't simply develop the malware and give it to customers to deploy, they operate and deploy their spyware on behalf of those customers as well.
- pelasaco 5y agoThey operate the infrastructure. For me it's clear a SaaS (spyware as a service (TM)) But to avoid the whataboutism, the flip side of the coin is that NSO democratize the access to those tools, normally restricted to just a small group of countries.
- dangerface 5y ago> So there should not be a list like this at all anywhere. No there really shouldn't and yet there is, this is why every one is pissed at you NSO. > You know, if a customer decides to misuse the system, he will not be a customer anymore. If NSO has no access to customer data how do they know if their customers misuse the system? If they did find evidence of their customers misusing the system what stops them just ignoring it as a coincidence while putting out the pr message "We must hold ourselves to a higher standard"
- akagusu 5y agoDrug dealers: blame our customers not us for selling drugs No one will ever accept this kind of argument from a drug dealer, but yet they happily admit this kind of argument from this and other countless companies that business practices go against the public interest. Anyone can tell me why?
- ecnahc515 5y agoUh, plenty of people accept this argument, it’s part of the idea of the movement behind legalizing all/most drugs. Look at marijuana, the drug dealer is now a business, and very few people are mad at dispensaries for selling pot. In the end, if it wasn’t them, it would be someone else. If governments weren’t buying spyware from NSO, they would be making it themselves or finding another group who builds exploits.
- refaev78 5y agoThat's just not true. They say the list is fake. The proofs are false. That they can't have 50ĸ targets. And that all clients sign to only track terrorists, and will lose much if not.
- southerntofu 5y agoSounds like how Amesys tried to defend itself in french public media a decade ago when the arab spring surveillance contracts were made public: "We make software that catches terrorists and pedophiles" was the slogan back then.