39 ms·
Three ex-US intelligence officers admit hacking for UAE
- akulbe 5y agoI'm confused. Isn't this considered treason?? They get no jail time? They get to buy their way out?! > “Hackers-for-hire and those who otherwise support such activities in violation of U.S. law should fully expect to be prosecuted for their criminal conduct.” I know they lose their clearances and pay a bunch of money, but this seems like it merits a lot more punishment than that.
- freeslave 5y agoUAE is a US ally and so they likely do not want to put a chill on their relations. "The United Arab Emirates has been described as the United States' best counter-terrorism ally in the Gulf by Richard A. Clarke, the U.S. national security advisor and counter-terrorism expert." https://en.wikipedia.org/wiki/United_Arab_Emirates%E2%80%93United_States_relations https://en.wikipedia.org/wiki/United_Arab_Emirates%E2%80%93U...
- colechristensen 5y agoTreason has a pretty narrow definition, if you aren’t directly conspiring with a foreign power (and at that probably an enemy) against the US, it probably isn’t treason. People like to jump to that judgement, but it almost never happens.
- cheschire 5y agoIt's not probably, title 18[0] is pretty clear that it's an enemy that matters. However, since the United States is at war with a noun, then that makes the definition of enemy very flexible. 0: https://www.law.cornell.edu/uscode/text/18/2381 https://www.law.cornell.edu/uscode/text/18/2381
- colechristensen 5y agoYes that flexibility of what counts as an enemy is why the word “probably” was used.
- xxpor 5y agoWell first, treason specifically is very narrowly defined in the US. >Treason against the United States, shall consist only in levying War against them, or in adhering to their Enemies, giving them Aid and Comfort. They didn't levy war against the US, or adhere to an enemy (because the UAE isn't one). But in general, it's not illegal for US citizens to join foreign armies (if they aren't enemies). Lots of Jewish citizens, for example, serve in the IDF. "According to the U.S. code, any citizen who "enlists or enters himself, or hires or retains another to enlist or enter himself, or to go beyond the jurisdiction of the United States with intent to be enlisted or entered in the service of any foreign prince, state, colony, district, or people as a soldier or as a marine or seaman … shall be fined under this title or imprisoned not more than three years, or both." But a court ruling from 1896 involving U.S. citizens who fought with Cuban revolutionaries against Spanish colonial rule interpreted this to mean that it was only illegal for citizens to be recruited for a foreign army in the United States, not to simply fight in one." https://foreignpolicy.com/2011/09/02/is-it-legal-for-americans-to-fight-in-another-countrys-army/ https://foreignpolicy.com/2011/09/02/is-it-legal-for-america...
- ChrisMarshallNY 5y agoThere were also the Flying Tigers, in 1941. I think they may have been enlisted soldiers, though, as opposed to private citizens. https://en.wikipedia.org/wiki/Flying_Tigers https://en.wikipedia.org/wiki/Flying_Tigers
- this2shallPass 5y ago> Lots of Jewish citizens, for example, serve in the IDF. How many is "Lots"? Apparently the US doesn't keep records of this phenomenon that are easily accessible. This article^ from 2017 says 1,000 Jewish Americans serve in the IDF. Of the ~7,000,000 Jewish Americans, that's ~0.0143% of Jewish Americans serving in the IDF. If 1,000 joined and served each year, and live to an average age of 70, doesn't that mean ~50,000 people? That would mean ~0.714% of Jewish Americans having served in the IDF. ^ https://www.thedailybeast.com/1000-americans-are-serving-in-the-israeli-army-and-they-arent-alone https://www.thedailybeast.com/1000-americans-are-serving-in-... approximate number. 7.153-7.5 million are good estimates.
- deleted 5y ago[deleted]
- literallyaduck 5y agoLaws are for the little people who don't have important friends. Want to hack? Want to call China as a US general? As long as you are in good standing with the Party you can write your own ticket. Edit: Just a year ago our feeds were full of people complaining about a call to Russia from an underlying who was not a US general.
- x86_64Ubuntu 5y agoI don't think calling China as a US general is in the same bucket as hacking for hire.
- _3u10 5y agoInforming the Chinese of an insurrection in the US chain of command that the general himself is leading is far worse.
- dukeofdoom 5y agoPelosi said Trump will be 'fumigated out' if he refuses to leave the White House. How was that supposed to happen, if not for the military. Communication between Pelosi and Military leaders were ongoing. "House Speaker Nancy Pelosi said she spoke to Joint Chiefs of Staff Gen. Mark Milley about precautions that could block President Trump from “ordering a nuclear strike” or accessing launch codes and starting military hostilities" Source: https://www.cnbc.com/2021/01/08/pelosi-prevent-trump-from-launching-nuclear-strike.html https://www.cnbc.com/2021/01/08/pelosi-prevent-trump-from-la...
- deleted 5y ago[deleted]
- _3u10 5y agoDid he refuse to leave?
- 5y ago
- andrewnicolalde 5y agoMaybe not treason, but surely espionage?
- diskzero 5y agoPeople like to use the term treason a lot, but as it is defined under Article III, Section 3 of the US Constitution, their actions are not treasonous. If you can prove otherwise, I am all for it though! Specifically, the were charged with: Violations of U.S. export control, computer fraud and access device fraud laws. The Department filed the DPA today, along with a criminal information alleging that the defendants conspired to violate such laws. I think they are losers, scumbags and unethical and I hope that no one who reads HN ever hires them and that they never work in any capacity that comes into contact with IT, Infosec or any other hi-tech industry.
- _3u10 5y agoHow is going to work for more money a loserish activity? My understanding is that the US contractors underpay so being patriotic Americans they went to work for a better company.
- deleted 5y ago[deleted]
- jjulius 5y agoIs income really the only signifier of what makes an activity loserish to you? Not who they work for, the work they're doing, who it may target, the rules they may actively be choosing to break in the process, etc.?
- _3u10 5y agoLooking at the document it appears that they are working for the same nation state, they just cut out the red tape and a few layers of middlemen. Most people feel in the software field feel the ITAR regulations as applied to code are ridiculous including but not limited to the EFF. Most consider it to be an abridgment of their 1st amendment rights.
- diskzero 5y agoHaving a desire to increase your income is fine. For some, it is their primary motivation, for others it is a result of being recognized for producing valuable results. Each person has their own moral code; for some, even working for Google or Facebook falls outside of that code. I have worked with various companies that have contracts with the US military and other agencies. I wouldn't say they underpay. I would actually say they pay pretty well, but once again, this has to align with whatever your personal values are. Some people are quite happy to work for a three letter acronym agency and couldn't ever conceive of working for a FAANG or a foreign entity. I am sorry that a general perception of Americans might be that we are mercenary and will run after the highest paying opportunity. There are 300 million of us, and I would say that a majority of Americans are driven by values that don't include the theft of national intelligence assets or chasing after money no matter the consequence.
- MattGaiser 5y agoI assume because the country is an ally they don't get in as much trouble.
- mhh__ 5y agoJonathan Pollard, though? It definitely varies.
- snarf21 5y agoTreason is only for poor and unconnected people. The rule makers are very careful to never make white collar crime super punishable.
- RealityVoid 5y agoIt's really, historically no different than any soldier that chooses to fight in another country's war, and that is pretty common along history. Usually, they were only punished if the geopolitical scenery called for it.
- lainga 5y agoFamously https://en.wikipedia.org/wiki/Karl_Llewellyn https://en.wikipedia.org/wiki/Karl_Llewellyn was in Paris when WWI broke out, but managed to reach Germany, and briefly fought alongside (without joining) the German Army.
- jnwatson 5y agoThis is exactly what NSO does and they don’t get charged with anything. Mudge sells Cobalt Strike out in the open. The only difference is these guys didn’t set up a company first.
- Thorrez 5y agoNSO employees aren't US citizens. I wonder if Mudge has a license.
- benja123 5y agoNSO is an Israeli company, which means they need to follow Israeli export laws when it comes to weapons. All of NSO contracts will first go through the Israel Defense Ministry. The US has a similar process, where companies that sell weapons to foreign governments need to get permission from the US DOD. In this case Marc, Ryan and Daniel did not go through the DOD and that is why they are being charged.
- shmatt 5y agoThis is an increasing problem in Israel as well. Soldiers who spent years in the exploit-finding units of 8200 (Israeli NSA) can work for NSO and stay in Israel. But they can also leave the country and work for foreign entities. Sometimes without even knowing who their employer is One famous case was "Dark Matter" a UAE company who set up offices in Cyprus and offered 8200 soldiers 7 figures (in USD) a year salaries to relocate, outside of the Israeli Government oversight - which NSO need to adhere to, and work for them
- jackpirate 5y agoI'd love to read more about this if you have a source.
- SpikedCola 5y agoDarknet Diaries [0] does an episode that involves DarkMatter [0] https://darknetdiaries.com/episode/47/ https://darknetdiaries.com/episode/47/
- shmatt 5y agoYou'd have to depend on Google Translate quality but this is a good article https://www.themarker.com/technation/.premium-1.7972249 https://www.themarker.com/technation/.premium-1.7972249
- ThisIsTheWay 5y agoIn addition to Darknet Diaries, there is a lot of interesting info in Nicole Perlroth's new book titled "This Is How They Tell Me the World Ends" https://www.bloomsbury.com/us/this-is-how-they-tell-me-the-world-ends-9781635576061/ https://www.bloomsbury.com/us/this-is-how-they-tell-me-the-w...
- azemetre 5y agoSeconding this recommendation. It's a great history of how the exploit market came to be in general.
- 5y ago
- academia_hack 5y agoIf you actually read OP's link, the charges seem to have nothing to do with the fact that these individuals once worked for the US gov. Instead, the US federal government seems to be asserting that knowledge of offensive security tools and practices in Cybersecurity consultancy is somehow ITAR restricted in the same way that a weapon blueprint would be. That strikes me as absolutely preposterous and I'm disappointed the defendants settled rather than pushed back on obvious federal overreach into the lives and careers of private persons.
- x86_64Ubuntu 5y agoThere's a lot of stuff that's ITAR restricted. You can't be privy to classified information such as submarine prop design, or turbine blade design, and then branch off your own for other clients using said information.
- deleted 5y ago[deleted]
- sterlind 5y agoUnder ITAR you can't even sell your own submarine props to foreign countries, even if you were never exposed to classified designs, right? That's why ITAR originally applied to PGP.
- sneak 5y agoYes, and I thought DJB settled once and for all that computer code doesn’t fall under ITAR.
- LatteLazy 5y agoSettle now OR spend 20 years and millions of dollars fighting it and relying on judges who've never used a computer to understand complicated technical matters...
- jacquesm 5y ago
- thepasswordis 5y agoIncreasingly it seems like our elites look at The US as a resource to be mined, not a home, not a collaborative project.
- MattGaiser 5y agoThe definition of "elites" at this point just seems to mean any government employee or even anyone educated to the point of a bachelor's degree.
- ishjoh 5y agoFor better or worse I've started to think of 'elites' more as people that have differential outcomes in regards to the law. So in this case these people are 'elites' because they managed to stay out of prison for hacking US citizens and doing corporate espionage. A non-elite would be in prison for these actions, and there are lots of people who are in prison for hacking others.
- genericuser314 5y agoIsn't your definition an example of a No True Scotsman fallacy? Aren't you liable to wind up in situations where you find yourself saying "Ah-hah, now that person I thought was not one of the elite is now one of the elite because they didn't go to prison. Ah-hah, now that person I thought was one of the elite is not one of the elite, because they are going to prison."?
- ishjoh 5y agoFrom my original comment. "For better or worse I've started to think of 'elites' more as people that have differential outcomes in regards to the law" So it's not that elites don't go to prison, in this case they didn't, it's that they get extremely favorable outcomes as compared to the average population. Epstein is a good example of this. The first time he was convicted he spent a meager 1 year in prison in conditions that would never be afforded to the general public. These hackers are another good example of this, they got a large fine but they're not spending any time in prison, and yet lots of people have gotten prison time for hacking. Being elite is a lot different from being Scottish, in that there are only vague signals for being elite, and none of them are so easy to measure as being Scottish. I think it's safe to say that the vast majority of elites are wealthy, but I don't believe that all wealthy people are elites. There are people with a lot of localized power like mayors or state senators, but those people certainly aren't nationally elite. To my mind the clearest signal is when the system interacts with a person, how does the system behave, versus when it interacts with an average person. Now this is by no means a definition, just how I've started thinking about the question of who is elite.
- badRNG 5y agoThere is an incredibly well produced podcast episode on these ex-NSA engineers working for the UAE that came out a couple of years ago. Check out Darknet Diaries Ep47: Project Raven [1]. Synopsis is that the UAE hires ex-NSA employees as "penetration testers" and when they enter the country for cybersecurity work, some are pulled aside to be briefed to an opportunity called "Project Raven" to assist Emirati intelligence with targeting, allegedly in the interest of counter-terrorism. The thing is, only Emiratis have "hands on keyboard" while the US engineers sit beside them and guide them, which supposedly dodges any legal concerns. Those who Jack interviewed decided to leave Project Raven when it became clear they were targeting dissidents, human rights activists, and later, Americans. As you might imagine, ex-NSA employees who target US citizens for a foreign government are breaking the law. I do wonder if it's these ex-Project Raven engineers that have led prosecutors down the road to where we are now. [1] https://darknetdiaries.com/episode/47/ https://darknetdiaries.com/episode/47/
- bpodgursky 5y ago> The thing is, only Emiratis have "hands on keyboard" while the US engineers sit beside them and guide them, which supposedly dodges any legal concerns. I find it pretty hard to believe any judge would buy this.
- Enginerrrd 5y agoYou're probably right, but I think it also depends... Is a professor at MIT teaching cyber security exploit development guilty of the same crime? What about a consultant teaching how to use a particular tool or how to look for a particular family of exploits? (Potentially legally dodgy, depending on the client, but probably ok in a lot of grey areas) What about a consultant which performs a passive audit of a target for a 3rd party? (Starting to get pretty dodgy, but probably depends both on the 3rd party and the target and the nature of the audit) It's... probably not so cut-and-dry. Though I agree that it doesn't sound like a get-out-of-jail-free card.
- jareklupinski 5y ago
- robbiet480 5y agoMore interesting to me is that one of the named persons, Daniel Gericke, is the CIO of ExpressVPN [1] which sold yesterday, the same day that the DoJ came to this prosecution agreement (!), for just under $1 billion. [2] [1]: https://www.cnet.com/tech/services-and-software/expressvpn-cio-among-three-facing-1-6-million-doj-fine-project-raven/ https://www.cnet.com/tech/services-and-software/expressvpn-c... [2]: https://www.techradar.com/news/expressvpn-to-join-kape-in-largest-deal-ever-in-vpn-industry https://www.techradar.com/news/expressvpn-to-join-kape-in-la...
- tyingq 5y agoHah. Anticipated bail money, perhaps :)
- joe_the_user 5y agoDouble hah, original headline: "Three Former U.S. Intelligence Community and Military Personnel Agree to Pay More Than $1.68 Million to Resolve Criminal Charges" - That billion more than covers. Given the circumstances, the settlement is a bit paltry.
- nostromo 5y agoIt's crazy to me how many unscrupulous actors there are in the VPN space where you really really need to trust your provider. I don't trust my ISP much at all, but I still trust them more than almost any VPN provider.
- downWidOutaFite 5y agoI don't trust any security-oriented software of any kind.
- latchkey 5y agoWhy would you want to trust your VPN provider? That's like saying: "you really really need to trust a Bitcoin miner" I'd hope the VPN service is built and operated in a way that doesn't require trust, but provides the same level of security. edit: Since there is confusion in the responses. I'd prefer to trust no-one.
- ComodoHacker 5y agoAs a non-US person, could someone explain a legal construct of "paying $XXX to resolve criminal charges"? Doesn't "criminal" mean there must be some real punishment?
- parhamn 5y agoCriminal charges can end in fines and no jail time. Prosecutors can negotiate plea deals (including fines) to avoid going to court. I don't know enough to comment on if this is something that happens often (it certainly doesn't feel appropriate) in cases like this.
- Paradox0 5y agoPaying a fine isn't a real punishment?
- charonn0 5y agoIt's not a fine. That's the problem.
- Paradox0 5y agoSure, it's a "financial penalty", technically. Plea deals are common in many jurisdictions, and the settlement imposes additional penalties. They're being punished.
- tehwebguy 5y agoYou are right that a fine is a real penalty but that’s not the real problem. The problem is that someone who committed the same crime but has less money wouldn’t qualify for this option.
- Paradox0 5y agoIs that true? I'm not a lawyer, but I know that in certain criminal plea agreements, such as in antitrust cases, the financial penalty can be paid over installments, the size of which is tied to the company's financial performance. See e.g. > If the parties agree that the recommended fine needs to be paid in installments because of the defendant's inability to pay the entire amount immediately, the plea agreement will include the installment schedule and any interest terms.(58) The payment of a special assessment(59) and any recommendation on a term of probation(60) or expedited sentencing(61) for corporations, or requests by individual defendants to be placed in a specific correctional facility,(62) will also be addressed in the plea agreement. https://www.justice.gov/atr/speech/us-model-negotiated-plea-agreements-good-deal-benefits-all https://www.justice.gov/atr/speech/us-model-negotiated-plea-... And to get back to the original comment I replied to, this critique seems like it would apply to any financial punishment, not something that came down to a technical distinction between "fine" and "financial penalty".
- rank0 5y agoThe punishment seems pretty insignificant here. I am surprised the DoJ isn't pursuing prison time.
- legrande 5y agoThere is a lot of CFAA[0] trial evasion going on perhaps? [0] https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act
- pianoben 5y agoIt sounds like the three defendants are also cooperating with ongoing investigations; that would certainly play a role in the terms of the deal, if so.
- atatatat 5y agoJust so I'm clear: are you saying the DOJ is on whole more or less corrupted than the orgs "below" it?
- rank0 5y agoI'm not making any assertion about DOJ corruption. I just thought they took this sort of behavior very seriously. (violating export controls, computer fraud and access device fraud) I was discussing this case with a former DOJ attorney and he was saying that it's hard to know what exactly went into the calculation for penalties. Apparently cooperation with DOJ on future investigations can play a big role so idk what to think.
- openasocket 5y agoI really don't think deferred prosecution is warranted here, this should have been a plea deal. I'm ambiguous on whether or not these guys should serve jail time, but they deserve a criminal conviction and a criminal record.
- 5faulker 5y agoWon't be the first time this happens...
- clarle 5y agoBased on the timeline, is U.S. Company Two Google or Apple? Who had security patches released in September 2016 and August 2017?
- deleted 5y ago[deleted]
- wwwdonohue 5y agoFunny quote from Lori Stroud: > The bureau’s dedication to justice is commendable... the most significant catalyst to bringing this issue to light was investigative journalism - the timely, technical information reported created the awareness and momentum to ensure justice A lot of moral superiority there when based on how Stroud has talked about her own work with Project Raven [1], she was perfectly happy to help the UAE kidnap, torture, and disappear dissidents (including children), human rights activists, and journalists. [1] https://www.reuters.com/investigates/special-report/usa-spying-raven/ https://www.reuters.com/investigates/special-report/usa-spyi...
- 0x00000000 5y agoYeah I don’t understand how what they did isn’t an ITAR violation. The contractor Cyberpoint is still active on IC contracts (https://www.cyberpointllc.com/joinus/#/jobs https://www.cyberpointllc.com/joinus/#/jobs)
- truted2 5y ago> to obtain remote, unauthorized access to any of the tens of millions of smartphones and mobile devices utilizing a U.S. Company Two-provided operating system U.S. Company Two provides a mobile operation system. Hmmm, now who could that be?
- kccqzy 5y agoMy first thought was that it must be Apple. But the article says, > In August 2017, U.S. Company Two updated the operating system for its smartphones and other mobile devices, limiting KARMA 2’s functionality. I didn't find any meaningful security updates by Apple in August 2017: https://support.apple.com/en-us/HT201222 https://support.apple.com/en-us/HT201222 The only one listed on that page was about using HTTP to send analytics data, which I don't think is the one that disabled KARMA 2. Then I looked at Google. There are multiple RCE vulns with severity Critical during these two months: https://source.android.com/security/bulletin/2016-09-01 https://source.android.com/security/bulletin/2016-09-01 and https://source.android.com/security/bulletin/2017-08-01 https://source.android.com/security/bulletin/2017-08-01
- tyrfing 5y agoIt's Apple, see the Reuters report from 2019: https://www.reuters.com/investigates/special-report/usa-spying-karma/ https://www.reuters.com/investigates/special-report/usa-spyi... Here's KARMA: https://citizenlab.ca/2016/08/million-dollar-dissident-iphone-zero-day-nso-group-uae/ https://citizenlab.ca/2016/08/million-dollar-dissident-iphon... Looking at CVEs, my guess for KARMA 2 is CVE-2017-8248, patched in 10.3.3. Bit of a stretch, though. Looks like whatever was patched was never really publicized. https://nvd.nist.gov/vuln/detail/CVE-2017-8248 https://nvd.nist.gov/vuln/detail/CVE-2017-8248
- bmcn2020 5y agoDoes anyone know whether the spyware mentioned is anyhow related to Project Pegasus[1? It's also really interesting that Apple patched Security issues for iOS that was targeted by NSO Group and makes me wonder if that might be the same vulnerabilities exploited by the UAE hacker for higher company [2]. [1] [https://cybernews.com/news/expressvpn-cio-daniel-gericke-fined-335-000-for-cyber-espionage https://cybernews.com/news/expressvpn-cio-daniel-gericke-fin...] [2] https://www.npr.org/2021/09/14/1036869715/apple-issues-critical-patch-to-fix-security-hole-exploited-by-spyware-company https://www.npr.org/2021/09/14/1036869715/apple-issues-criti...
- teslademigod1 5y agoUAE, NSO and minimal punishment or reaction from the US. Story of the last few decades
- aborsy 5y agoHow does the security of a Google Pixel phone with Android or GrapheneOS compare with iPhone’s security? The iOS exploits sound scary. Some of them are even zero click.
- nebula8804 5y agoWhat makes you think GrapheneOS is any better? Yeah its open source but it must be looked at a lot less than any iPhone. Is security by 'open but not as well examined' actually more secure?
- atatatat 5y agoThis specific example is kind of a bad place to prove that generally correct mindset.
- nebula8804 5y agoI seriously doubt the developers of GrapheneOS have really done as much due diligence on their custom ROM as Apple has done on iOS. For one, Apple controls the whole stack down to the CPU. GrapheneOS is forced to rely on many external parties to not be hostile from Google with their Android stack to the Linux base to whatever the SOC maker has put into their silicon.
- hikerclimber1 5y agoBusinesses are allowed to deduct miles driven on cars. But the problem with this is they are allowed to use the car for personal as well. This should be illegal. With today’s technology gps and phone we should be able to track where these people go especially for business meetings. They should have to disclose this information.
- Jerry2 5y agoNo jail time? I guess when you're a member of IC, regular laws don't apply to you.
- errantmind 5y agoOne of these officers is CIO of ExpressVPN. Can you really trust a service with these ties, which also just sold to an ad agency? I personally would not.
- kchoudhu 5y agoGood.
- smashah 5y agoWhile being federal agents they try to spread democracy with bombs. Once they leave, the pretence is dropped and squash any organic calls for democracy and dissent with hacking. Outraged when these countries are hacking individuals? Then also be outraged when you sell them F35s
- cowshit 5y agoagain......// oh you already banned me over notthing FUCK HACKER NEWS FUCK HACKER NEWS FUCK YOU FUCK YOU
- sneak 5y agoI wish my friends could buy their way out of hacking charges from the DOJ instead of having to get tortured for months and months in US prisons.
- stjohnswarts 5y agoThere's really no reason why they should be able to buy their way out of prison time. It's kind of a shame. Justice is supposed to be blind, including to financial assets of the perps.
- aerostable_slug 5y agoA reminder that former members of military special operations units admitted assassinating political opponents for UAE. No one was prosecuted. https://sofrep.com/news/exclusive-interview-with-an-american-mercenary-who-ran-combat-ops-in-yemen/ https://sofrep.com/news/exclusive-interview-with-an-american... https://spotterup.com/episode-44-dale-comstock-former-army-special-forces-cag-operator-merc-and-much-more/ https://spotterup.com/episode-44-dale-comstock-former-army-s...