5 ms·
When did anyone mention code signing or developer accounts?
by FDSGSG 5y ago
When did anyone mention code signing or developer accounts?
- AnthonyMouse 5y agoWhat did you suppose they needed a hundred Apple IDs for?
- DaiPlusPlus 5y agoThe article doesn’t say. I’m curious to find out myself.
- abinmn 5y agoA detailed forensic report was published by Amnesty on some of the methodologies NSO used. https://www.amnesty.org/en/latest/research/2021/07/forensic-methodology-report-how-to-catch-nso-groups-pegasus/ https://www.amnesty.org/en/latest/research/2021/07/forensic-...
- Operyl 5y agoSending the malware via iMessage, assuming the flaw was part of iMessage and not standard SMS.
- tremon 5y agoBut if they did that, Apple wouldn't need the EULA because then they could throw the CFAA at them.
- Operyl 5y agoCould be used for attempting to find metadata on users then, etc. there’s a few things I could guess.
- arcticbull 5y agoI believe the CFAA is a criminal law, and charges would have to be brought by an AG. This is a civil case.
- FDSGSG 5y agoThis is not correct, civil suits over CFAA violations are common.
- alasdair_ 5y agoDoes the CFAA apply to an Isreali firm sending a text message from Isreal?
- FDSGSG 5y agoYes, it can. You can find Apple's lawyers explanation in the complaint under the "JURISDICTION AND VENUE" heading https://www.apple.com/newsroom/pdfs/Apple_v_NSO_Complaint_112321.pdf https://www.apple.com/newsroom/pdfs/Apple_v_NSO_Complaint_11...
- FDSGSG 5y ago... That's exactly what they did? From the complaint: >Count One >Violations of Computer Fraud and Abuse Act https://www.apple.com/newsroom/pdfs/Apple_v_NSO_Complaint_112321.pdf https://www.apple.com/newsroom/pdfs/Apple_v_NSO_Complaint_11... The EULA is used to establish jurisdiction, and for the separate breach of contract claim. Apple has servers around the world, without the EULA the jurisdiction isn't necessarily obvious.
- kergonath 5y agoThey are throwing the CFAA at then. However, the CFAA is an American law, which would be challenging to apply in a foreign court. So they are using the EULA to sue in California. It’s all in the article.
- FDSGSG 5y agoI have no idea why people are speculating about this. Unsurprisingly the publicly available complaint explains exactly what the Apple IDs were used for. https://www.apple.com/newsroom/pdfs/Apple_v_NSO_Complaint_112321.pdf https://www.apple.com/newsroom/pdfs/Apple_v_NSO_Complaint_11... >50. On information and belief, Defendants created more than one hundred Apple IDs using Apple’s systems to be used in their deployment of FORCEDENTRY >51. On information and belief, after obtaining Apple IDs, Defendants executed the FORCEDENTRY exploit first by using their computers to contact Apple servers in the United States and abroad to identify other Apple devices. Defendants contacted Apple servers using their Apple IDs to confirm that the target was using an Apple device. Defendants would then send abusive data created by Defendants through Apple servers in the United States and abroad for purposes of this attack. The abusive data was sent to the target phone through Apple’s iMessage service, disabling logging on a targeted Apple device so that Defendants could surreptitiously deliver the Pegasus payload via a larger file. That larger file would be temporarily stored in an encrypted form unreadable to Apple on one of Apple’s iCloud servers in the United States or abroad for delivery to the target.