3 ms·
Apple knows since at least 2016 of NSO activities on their devices and servers, while selling this image of privacy competence. This long period of inaction, f
by udev 5y ago
Apple knows since at least 2016 of NSO activities on their devices and servers, while selling this image of privacy competence.
This long period of inaction, from 2016 to now is unacceptable.
- freejazz 5y agoIt's as if you don't get the point about legal standing. Apple can only take action now because of a court deciding that Facebook's TOS forum clause is actually binding. If they filed the case prior to such a holding, it'd have been dismissed.
- salawat 5y ago>If they filed the case prior to such a holding, it'd have been dismissed. ...Or when Facebook eventually followed up, you'd be making the excuse Facebook was justified in waiting for Apple to test the waters? Somebody has to move first.
- spiderice 5y agoSounds to me like GP really WANTS this to be “telling”, when in reality it obviously isn’t.
- udev 5y agoWhat if Facebook never filed? Would Apple never be able to act on this? If they would have acted, why didn't they do it before Facebook?
- freejazz 5y ago"What if Facebook never filed? Would Apple never be able to act on this?" If there wasn't precedent that Apple's TOS venue clause was binding, then the case would have been thrown out as I just previously explained. "If they would have acted, why didn't they do it before Facebook?" Because the case would have been dismissed as I just explained.
- timeon 5y agoYeah what if? What if I have lived in wonderland?
- udev 5y agoIndeed, a wonderland where it is OK for a 2 trillion dollar company to take 5 years to fix vulnerabilities that put in danger many of its users worldwide.
- _djo_ 5y agoThat assumes, wrongly, that Apple only patched the vulnerabilities used by NSO since 2016 in iOS 14.8. In reality, Apple has been reacting to and fixing new exploits all the time, with NSO Group (and others) successfully finding new ones to replace those that got patched. For instance, the main class of NSO-related attacks has been via the Messages app and related frameworks, which were relatively poorly designed in terms of their original security architecture. Apple has since 2016 substantially hardened those subsystems, including with a new 'BlastDoor' isolation layer specifically for Messages in iOS 14. That closed off entire classes of exploits, but is clearly not perfect.
- deleted 5y ago[deleted]