27 ms·
US judge finds NSO Group liable for hacking journalists via WhatsApp
- deleted 2y ago[deleted]
- dudeinjapan 2y ago[flagged]
- jredwards 2y agoWell, good. But also: build better software.
- mrkeen 2y agoAhem we don't do that here. We get to market faster before our runway ends so we don't risk our exit.
- ChrisMarshallNY 2y agoI support this. It’s not possible to be “perfect,” but if we do our best to get there, we’ll make really good stuff. It’s unlikely to happen, though, as we have a system that explicitly rewards writing crap, because it makes money. As long as we fail to reward good work, we will continue to get poor work.
- dylan604 2y ago> As long as we fail to reward good work, we will continue to get poor work. I think that's a bit off. The problem is that we continue to reward poor work so the poor work continues.
- ChrisMarshallNY 2y agoThat's correct. I was being generous. Note that even my fairly mild statement was not received well. People really don't like discussion of improving the Quality of software, here. Too much money to be made in not-so-good stuff.
- saagarjha 2y agoCorrection: people don't really like low-quality comments that don't bring anything to the table beyond "let's make everything better".
- ChrisMarshallNY 2y agoCome on, you know me better than that. In this case, the comment fit the conversation. The original comment was a short, pithy, and rather sarcastic one that was, nonetheless, correct. They pointed out that we need to write higher-Quality software, in order to give folks like the NSO people fewer “hooks.” The NSO folks are smart, dedicated people, that, in other circumstances, we would admire for their creativity and intelligence. They often take advantage of mistakes (or deliberate decisions) made by folks that we may find less admirable. I like this community and medium, and sincerely want to be a “good citizen.” The opportunity to interact with people like you, is a privilege that I respect and value. We may not always agree on everything, but I find many of your contributions to be inspiring, educational, and relevant, so I appreciate you. You have taught me lessons, and have changed my mind, and, I’m sure, will continue to do so. You have great insight, knowledge, and experience, which I value, and appreciate you sharing it (for example: https://saagarjha.com/blog/2023/12/22/swift-concurrency-waits-for-no-one/ https://saagarjha.com/blog/2023/12/22/swift-concurrency-wait...). People like you, are why I like this place. We have no social interaction, so I have no idea if we’d get along, IRL. I would like to think we would, but I’m often wrong, and not afraid to promptly admit it. For myself, I try to participate by making very specific suggestions, and “keeping it focused on me.” I don’t attack others, even if I find what they say to be quite offensive (or if they attack me, which is fairly common). Most times, I don’t feel that my comments would improve things, even if I vehemently disagree with someone, so they are best left unsaid. I don’t participate in any other social media, and I’m retired, so I do spend a fair bit of time, here. I spent most of my career at a corporation that was all about Quality, and I suppose it must have rubbed off on me. At that company, Quality was a religion, and they took it to the point of obsession. After leaving, I have tried to practice their mindset in my continuing work. I write software that can have a big impact on the lives of its users, so I take Quality seriously, in order to reduce things like attack surface. I feel as if the current tech community has a baseline ethos of “write code as badly as we can get away with,” and that ethos is rewarded. I don’t think that treatises on better unit testing will be of interest to folks with that mindset. I feel as if the mindset, itself, is the issue, and code dumps won’t make a difference. I often reference stuff I’ve written, not because I want traffic (I could absolutely care less, whether or not folks read my stuff. I write for myself), but because I don’t want to litter the place with “wall of text” commentary (as you can see, I lean prolix). A quick link to an article that I wrote, going into great detail, is better than a massive comment that won’t have as much information. For example: https://news.ycombinator.com/item?id=42478993 https://news.ycombinator.com/item?id=42478993 Are those articles specific enough?
- deleted 2y ago[deleted]
- amelius 2y agoIf it's approved by the AppStore, then it should be good, no?
- kindeyooweee 2y agomade me chuckle needed this :)
- nico 2y ago> "Surveillance companies should be on notice that illegal spying will not be tolerated." That is kinda funny, although sad at the same time On the flip side, I guess that means META allows WhatsApp users being only “legally spied” on
- throwaway290 2y ago"Unauthorized hostility against pioneer detected"
- dylan604 2y agoIsn't that obvious though? Meta wants exclusive spying rights to its users. You spying on users with Meta's products is not allowed. If you want to spy on your users, build an app that's so popular billions of people sign up willingly to allow you to spy on them. Have you no decency?
- talldayo 2y ago> Meta wants exclusive spying rights You're allowed to say "The NSA", we're all adults here. No need to speak in euphemisms.
- trogdor 2y agoEvery social media company allows legal spying. Warrants and wiretap orders are issued every day in the United States.
- sangnoir 2y agoWith end-user-device-controlled e2ee, the only information available to law enforcement is metadata. With a warrant, they could seize your device (or the backups, if unencrypted)
- dsp 2y agoUnfortunately, I don’t think end-to-end encryption guarantees much when it comes to legal intercept in proprietary messaging apps. The intercept functionality could be done in the client and capture data, not just metadata.
- akira2501 2y agoWhich is ironic considering the FBI and CISA just today announced that you _should_ use WhatsApp and not use SMS for two factor authentication. Although they point out the biggest problem is mobile users click on links in SMS. We live in a mostly captured and anti consumer environment. I'm not sure there's any great advice. https://www.newsnationnow.com/business/tech/fbi-warns-against-using-two-factor-text-authentication/ https://www.newsnationnow.com/business/tech/fbi-warns-agains...
- magic_hamster 2y agoOf course there is. Always prefer an authenticator app over SMS. Also, Passkeys are supposed to be a big upgrade in this regard.
- bawolff 2y agoWhatsapp is not still vulnerable to the hack (as far as we know) and SMS applications have had similar vulnerabilities in the past.
- immibis 2y agoDidn't the US fund those guys to do exactly that?
- sabbaticaldev 2y ago[flagged]
- deleted 2y ago[deleted]
- dmantis 2y agoThere should be no difference with usual botnet owner/ransomware gangs and such companies. Management should go to prison for good 20-30 years for that and being extradited worldwide. Considering that ransomware gangs are probably less harmful to the society than guys who hack journalists and politicians, putting their lifes at literal risks, not just their pockets. There should be no "legal" hacking of someone's devices apart from extraction of data from already convicted people in public court with the right to defend themselves
- bawolff 2y agoIts not like this is that different than traditional "weapons" (i hate the "cyberweapons" analogy, but if the shoe fits). Sell guns to governments, even unsavoury ones, it is very rare anything will happen to you except in pretty extreme cases. Sell guns to street gangs, well that is a different story. Like i don't think this situation is different because it is "hacking".
- Neonlicht 2y agoAll the cartels in Mexico buy their guns from America and nobody is going to jail over it.
- lupusreal 2y agoPeople do in fact get sent to prison for that, straw purchases are a federal felony. Not all of them actually get caught, which is true of any crime.
- oaththrowaway 2y agoExcept when the ATF does it, no big deal
- buo 2y agoMore information about this: https://en.wikipedia.org/wiki/ATF_gunwalking_scandal https://en.wikipedia.org/wiki/ATF_gunwalking_scandal
- ilrwbwrkhv 2y agoI thought Whatsapp and signal share the same encryption
- bawolff 2y agoThe attack wasn't targeting the encryption part of whatsapp (afaik). Encryption is important but it often is not the weakest link in the security chain.
- mjg59 2y agoThe encryption isn't alleged to have been compromised. The app itself deals with a lot of untrusted input (eg, thumbnailing video files you've been sent) so there's a meaningful attack surface outside the protocol itself.
- ruined 2y agonote for signal users: in settings, you can disable link previews and automatic media download.
- stavros 2y agoWhy are link previews a problem? Presumably I only generate previews for links I've vetted.
- 3eb7988a1663 2y agoIt seems like most of the exploits come down to blowing up a parser of one data format or another. Myriad from which to choose, they are written in C for historical reasons, and probably play fast and loose with validation in the name of performance.
- stavros 2y agoTrue, I guess you're right.
- 2y ago
- ShonT 2y ago[dead]
- alecco 2y agoAaaaand it's flagged out of the front page. @dang, so early in the day this is obviously some coordinated manipulation. 31. 206 points 9 hours ago US judge finds Israel's NSO Group liable for hacking journalists via WhatsApp (reuters.com) 22. 37 points 8 hours ago My Pal, the Ancient Philosopher (nautil.us) 15. 4 points 4 hours ago Testing for Thermal Issues Becomes More Difficult (semiengineering.com) 18. 11 points 2 hours ago The Christmas story of one tube station's 'Mind the Gap' voice (2019) (theguardian.com)
- sabbaticaldev 2y agoProbably done by the same NSO Group. But for US americans they are the good criminals, the chosen criminals
- layer8 2y ago“@dang” doesn’t do anything. Email hn@ycombinator.com.
- dang 2y agoCorrect. If someone had emailed hn@ycombinator.com sooner, we would have fixed this sooner.
- stonesthrowaway 2y agoI'm shocked! But don't worry, I'm sure the nytimes, wsj, ap, etc will run hit pieces on this outrageous behavior by israel.
- Der_Einzige 2y agoDang doesn’t buy that anything ever actually happens here (just like the meme). I’m pretty sure dang is deeply associated with the IC.
- dang 2y agoOh you guys.
- throawayonthe 2y ago[dead]
- myth_drannon 2y ago[flagged]
- wslh 2y agoThere are many other companies beyond NSO Group, if I were a journalist I would write a more comprehensive list of them and educate about this whole "industry".
- talldayo 2y agoNSO Group is unique in that they are entirely sheltered from (largely due) criticism by their government, creating an unaccountable and injust basis of relations between the United States and Israel that many readers are concerned by. There simply aren't any other comparably corrupt "cybersecurity" outfits in the world. Kinda similar to how the IDF has never been charged with war crimes despite several of their service-members being recorded breaking the law in their Israeli fatigues. It's not that international law was never broken, it's that Israel considers themselves above the rule of law and international bases of morality. That type of behavior absolutely must be called out in it's lonesome, such that no nation ever repeats Israel's embarrassing mistake.
- wslh 2y ago[flagged]
- Bilal_io 2y agoThe number of crimes they've committed is also disproportional to their size.
- wslh 2y ago[flagged]
- MomsAVoxell 2y agoWhat other nation besides the USA and its 5-eyes lackeys willfully murders children almost every day in their own ‘self defense’? Got a list of states that murder more people than the USA/5-eyes and Israel right now?
- dudeinjapan 2y agoYou have to be really bad if Meta are somehow the good guys in the article.
- Bilal_io 2y agoThe victims are the good guys. Meta is just not happy that their platform was exploited. Even if you consider them to be the bad guys, they needed to sue to curtail the bad PR
- dudeinjapan 2y agoYou’re right. That’s the right way to look at it.
- deleted 2y ago[deleted]
- iluvcommunism 2y ago[flagged]
- nothercastle 2y ago[flagged]
- deleted 2y ago[deleted]
- zhengiszen 2y ago[flagged]
- solumunus 2y ago[flagged]
- stonesthrowaway 2y ago[flagged]
- solumunus 2y ago[flagged]
- rexpop 2y ago[flagged]
- Bilal_io 2y agoAgreed. And no sensible adult should refer to the genecide in Gaza as being deep in the algorithm.
- fastball 2y agoGenocide is an attempt to eradicate a group. The only group Israel is trying to eradicate is Hamas. They're not genociding Palestinians, they're genociding Hamas. Are they killing an excessive number of civilians as collateral damage? Certainly seems like it. But collateral damage is not genocide. If they wanted to genocide the Palestinians, they'd be shipping 'em to camps and gassing them, like the Nazis did. Looking at it another way: let's say that (hypothetically) Hamas stopped using people as humans shields by firing rockets from hospitals and building tunnels under schools. Do you think the number of non-combatants killed by the IDF would go down? Because I do, and to me that says Israel's goal is not in fact killing non-combatant civilians, even if they're killing far too many as is.
- kdbg 2y agoI'm not a lawyer so maybe I'm misunderstanding something but the plaintiff is Whatsapp, not the journalists. This isn't really about holding NSO Group accountable for hacking journalists at all The fact journalists were compromised seems only incidental, the ruling is about weather or not NGO Group "exceeded authorization" on WhatsApp by sending the Pegasus installation vector through WhatsApp to the victims and not weather they were unauthorized in accessing the victims. Its a bit of a subtle nuance but I think its important. Quoting the judgement itself: > The court reasoned that, because all Whatsapp users are authorized to send messages, defendants did not act without authorization by sending their messages, even though the messages contained spyware. Instead, the court held that the complaint’s allegations supported only an "exceeds authorization" theory. > The nub of the fight here is semantic. Essentially, the issue is whether sending the Pegasus installation vector actually did exceed authorized access. Defendants argue that it passed through the Whatsapp servers just like any other message would, and that any information that was 'obtained' was obtained from the target users' devices (i.e., their cell phones), rather than from the Whatapp servers themselves > [...removing more detailed defendant argument...] > For their part, plaintiffs point to section (a)(2) itself, which imposes liability on whoever "accesses a computer" in excess of authorized access, and "thereby obtains information from any protected computer" pointing to the word "any" > [...] > As the parties clarified at the hearing, while the WIS does obtain information directly from the target users’ devices, it also obtains information about the target users' device via Whatsapp servers. Adding a little more detail that comes from the prior dockets and isn't in the judgement directly but basically NSO Group scripted up a fake Whatsapp client that could send messages that the original application wouldn't be able to send. They use this fake client to send some messages that the original application wouldn't be able to send which provide information about the target users' device. In that the fake client is doing something the real client cannot do (and fake clients are prohibited by the terms) they exceeded authorization. Think about that for a moment and what that can mean. I doubt I'm the only person here who has ever made an alternative client for something before. Whatapp (that I recall) does not claim that the fake client abused any vulnerabilities to get information just that it was a fake client and that was sufficient. Though I should note that there were some redacted parts in this area that could be relevant. I dunno, I mean the CFAA is a pretty vague law that has had these very broad applications in the past so I'm not actually surprised I was just kinda hopeful to see that rolled back a bit after the Van Bruen case a few years ago and the supreme court had some minor push back against the broad interpretations that allowed ToS violations to become CFAA violations. Edit: Adding a link to the judgement for anyone interested: https://storage.courtlistener.com/recap/gov.uscourts.cand.350613/gov.uscourts.cand.350613.494.0_1.pdf https://storage.courtlistener.com/recap/gov.uscourts.cand.35... Edit2: And CourtListener if you want to read the other dockets that include the arguments from both sides (with redactions) https://www.courtlistener.com/docket/16395340/facebook-inc-v-nso-group-technologies-limited/?filed_after=&filed_before=&entry_gte=&entry_lte=&order_by=desc https://www.courtlistener.com/docket/16395340/facebook-inc-v...
- o999 2y agoNSO Group: Relationship with the Israeli state https://en.wikipedia.org/wiki/NSO_Group#Relationship_with_the_Israeli_state https://en.wikipedia.org/wiki/NSO_Group#Relationship_with_th...
- CamelCaseName 2y agoI'm quite surprised by the corporate history section. Specifically, NSO Group is worth a lot less than I thought it was, even at its peak. ($1B+ valuation) Also, the amount of infighting is... Surprising perhaps? Less surprising is the number of spinoffs out of it, and the number of competing Israeli spyware groups. I'm constantly surprised by how good he Israeli startup environment seems to be. Why is this? How are there so many acquisitions out of there?
- kortilla 2y agoThings like this are similar to law firms. The shelf life of vulnerabilities means that there isn’t a lot of intellectual property owned by the company. The value is in the people’s skills. So once people get really good they quickly realize they can make more by starting their own company and siphoning off client relationships.
- tokioyoyo 2y agoValuations don’t really matter in their playing field. It’s more about power and politics, rather than raw numbers.
- akira2501 2y ago[flagged]
- fortran77 2y ago[flagged]
- s5300 2y ago[dead]
- ThinkBeat 2y agoIt is hard to believe that NSO group is allowed to operate. They sell technology to horrible places, they cause death torture, and a host of less horrible things. Yet they are protected by the US and Israel, which I believe is the case that they have backdoors into all of it, and getting the targets to actually install this malware on their own saves a lot time. All good, except for the actual real world victims.
- bigfatkitten 2y ago> It is hard to believe that NSO group is allowed to operate. They sell technology to horrible places, they cause death torture, and a host of less horrible things. That describes the entire Israeli defence industry, and a fair sized portion of Israel's cybersecurity industry, based on the stomach-churning sales pitches I've received. NSO are not unique, they just got unlucky.
- tptacek 2y agoIt describes the entire defense industry, and a fair sized portion of the cybersecurity industry, full stop.
- EMIRELADERO 2y ago> based on the stomach-churning sales pitches I've received. Care to elaborate? This could be news story-worthy
- tptacek 2y agoHow do you "not" allow them to operate? People write things like this that seem premised on the idea that Bahrain wouldn't have implant technology if you shuttered NSO, but the only thing that would actually change is who the invoice got sent to. These companies have an unbeatable value proposition, lots of competition, and the lowest capital investment requirements of any intelligence product. I really feel like people aren't thinking this stuff through. Exploits and implants are not rocket science. There aren't a huge number of people in the world that are world-class at reliably exploiting modern targets, but it's not like there's just like 20 of them or something. later In case it's unclear from the comment: I don't think this is a good thing. I'm speaking positively, not normatively.
- FpUser 2y agoTreating NSO owners / decision makers the same way as Gary McKinnon would be more appropriate. But I guess they are more "equal".
- sweeter 2y agoDarknet Diaries did a few podcast episodes on the NSO group from the perspective of people who have directly interacted with or have been the target and it really puts it into perspective how horrific they are. They operate under the protection of the US and are directly allowed to spy on US citizens without any recourse whatsoever. One particularly grotesque case was the illegal wire tapping of Ben Suda after launching a criminal probe in to Israeli war crimes, which they used to threaten the prosecutor and used it to hide evidence that they knew was under scrutiny or take the cases to court just to drop it so they can tell the ICC that they did make an attempt to prosecute, which is a loophole that disallows the ICC to take up those cases. I'm certain many countries do this stuff, as well as operate botnets and threaten journalists... but the uniqueness here is that these intel groups located in Israel operate under complete protection of the US without any scrutiny or oversight alongside the US government. We are living in this dystopian universe that people have warned about, for decades at this point.
- tptacek 2y agoThe US hosts and protects firms that are better at this than NSO, and not just because they're smart enough not to be in the news.
- rolandthomas 2y ago[dead]
- kindeyooweee 2y agoafter spending time with pegasus / that group of tools for a few years can honestly say if you have family, friends etc the damage isn't that bad if you are a refugee or fleeing with ambiguous rights etc it could lead to death but that is mitigated by the fact the people buying may not necessarily be able to get deep into the weeds to figure out how it works most get the leaked source follow a playbook etc so most western journalists should be safe unless they incurred the wrath of five eyes or something at which point running would be futyl :)
- jamalFr7 2y ago[dead]
- securemepro 2y agoHopefully, this sends a strong precedent on privacy. Kudos as privacy wins again. Cyberseb.com